Self-hosted, zero-trust privileged access management

Give your team access.
Never hand out keys.

Scoped, time-boxed access to any server or cluster — granted per session, never standing. The credential stays sealed on the broker, and every session is recorded.

One broker for SSHKubernetesDatabasesRDPOIDC SSOSCIM

ssh app-prod-01.tessera.local

→ connecting to app-prod-01 …

Last login: Sun Aug 17 16:04:11 2026 from 10.0.0.4

[tessera] Read-only session — the following commands are blocked:

apt, chmod, chown, dd, mv, rm, shutdown, systemctl, useradd

also blocked: scripts, output redirection (> / >>), sftp/scp.

root@app-prod-01:~$ rm -rf /var/log/api

[tessera] blocked — 'rm' is not allowed in read-only mode

root@app-prod-01:~$

Runs on your infrastructure — wherever it lives

How it works

One control point. Every connection.

Agentless and self-hosted — Tessera brokers SSH, Kubernetes, database and RDP access, injecting credentials on the wire and recording every session, without changing how engineers work.

Engineer SSH · k8s · DB · RDP
Tessera broker roles · approval · injection
Target server · cluster
  1. 01

    Connect like always

    Click Connect and keep using your normal SSH, kubectl, SQL and RDP tools. No new workflow to learn.

  2. 02

    Tessera grants & injects

    The broker checks the user's role and any just-in-time approval, then injects the real credential on the wire. For SSH, Kubernetes and databases the secret never touches the laptop.

  3. 03

    Every session is on the record

    Commands, queries and full replay land in an append-only log and stream to your SIEM as they happen — compliance evidence, automatically.

Capabilities · SSH · Kubernetes · Databases · RDP

One broker between your team and production

The controls security teams demand and the simplicity engineers want — across every protocol, in one self-hosted broker, with none of the enterprise bloat.

Keyless SSH

Engineers connect to any server in one click — the broker injects the credential on the wire. No keys on laptops, nothing to lose, nothing to rotate.

Kubernetes, brokered

Add a cluster once and your team gets governed access through their existing tooling — commands, logs, exec and port-forward all work, every call audited.

Databases, brokered

PostgreSQL and MySQL with credentials injected. Read-only is enforced at the SQL layer — writes and DDL are rejected before they ever reach the database.

Windows over RDP

Brokered RDP to Windows hosts. Connect opens the native client against a loopback port on your own machine; the credential is passed to it over stdin, never shown in the UI and never written to disk, and every issuance is audited.

Just-in-time access

Zero standing access. Engineers request the access they need, for as long as they need it; you approve in one tap and the grant auto-expires on its own.

Recorded & watched live

Full session replay and per-command history — plus shadow any live session and force-close it the instant something looks wrong.

Live roles, audited to SIEM

Grant view / read-only / read-write and downgrade live with no reconnect. Every login, command and approval streams to your SIEM as it happens — a copy that lives outside the broker.

Built to be trusted

Security teams sign off on it

Tessera is the control point between your engineers and production — so it's engineered to earn that position.

Self-hostedOffline-licensedAES-GCMThreat-modeled
Read the security model →
  • Credentials stay on the brokerTarget secrets are encrypted at rest (AES-256-GCM) and injected on the wire for SSH, Kubernetes and databases — nothing to leak, screenshot or forward. RDP is the exception: its credential is handed to your local client because the protocol needs it before the session exists, so it never appears in the UI and every issuance is audited.
  • Read-only where it countsKubernetes and SQL read-only are enforced at the protocol layer — mutating API calls and every write or DDL statement are rejected before they reach the cluster or database. On SSH, command filtering is a guardrail against accidental change; for a hard guarantee, point Tessera at a read-only OS account. An admin can downgrade or kill a live session instantly, no reconnect.
  • Self-hosted, nothing phones homeRuns entirely inside your perimeter — one Go binary plus Postgres, agentless on your targets. The audit log is append-only and streams to your SIEM as events happen; even licensing is verified offline.
Access should be granted for a reason, scoped to a task, and gone the moment it's done. Tessera makes that the default — not a process people route around.
The principle behind Tessera
Why Tessera

Where Tessera goes further

Most access tools control who can connect. Tessera also controls what happens once you're inside the session.

Tessera Teleport StrongDM Boundary
Where Tessera goes further
Kill write access mid-session — no reconnect flip a live session RW → RO in one tap — on SSH, Kubernetes and SQL alike
Nothing installed — and nothing reconfigured — on your targets your servers, clusters and databases stay exactly as they are
Fully self-hosted control plane no vendor cloud anywhere in the access path
One read-only switch across SSH · Kubernetes · SQL same policy, every protocol — not a per-protocol reimplementation
And everything you'd expect
Credentials injected on the controller — never on the user's machine SSH · Kubernetes · SQL
Session recording + live watch & force-close
Just-in-time access · RBAC · SSO · SCIM
Audit export to your SIEM

Checked against each vendor's own published documentation on 14 August 2026; products change, so verify before relying on it. A cross means the vendor does not document the capability, not that we tested and it failed. Capabilities vary by edition: several Boundary rows are partial because the capability requires Boundary Enterprise or HCP rather than the open-source edition; Teleport's SQL read-only covers PostgreSQL and is granted for the life of a connection, and its Kubernetes access runs an agent inside the cluster. StrongDM has been part of Delinea since March 2026. Half-circle = partial (supported with limits or extra setup). SSH command filtering is best-effort for interactive shells; Kubernetes and SQL read-only are enforced at the protocol layer.

Row by row, with where each of them beats us: Tessera vs Teleport Tessera vs StrongDM Tessera vs Boundary

Pricing

Start free. Pay when it's mission-critical.

Free to self-host, forever. Pay per seat only when you need the team controls — predictable pricing that's an easy win versus tools that charge per server.

Community

$0 self-hosted · 1 seat · free forever
Get started
  • Single seat — one admin account; add seats on any paid plan
  • 5 SSH · 1 Kubernetes · 1 database · 5 RDP targets
  • Keyless connect with credential injection
  • TOFU host-key pinning · stable target names
  • Audit log — events & commands (no session replay or live watch)
  • Governance controls unlock in Pro
Most popular

Pro

$19 / seat / mo · $15 billed annually · from 3 seats
Start with Pro
  • Everything in Community
  • RBAC + live RW/RO · just-in-time access
  • Session recording + live watch & force-close
  • SSO (OIDC) · Telegram alerts · bastions
  • Up to 100 targets · 50 concurrent sessions
Launch · $30 annual

Ultimate

$40 / seat / mo · $36 billed annually · from 3 seats
Go Ultimate
  • Everything in Pro
  • SCIM provisioning & white-label branding
  • SIEM / audit export + database query audit
  • Configurable Kubernetes & database policies
  • Unlimited targets & connections

Enterprise

Custom contact sales · volume pricing
Talk to us
  • Everything in Ultimate
  • Custom features & integrations built for your environment
  • Dedicated SLA & priority support
  • Procurement & security review · volume pricing

Pay yearly and save up to 20% vs. monthly. Launch offer: start an annual Ultimate plan within the first 6 months and lock in $30/seat/mo instead of $36. Bigger teams and multi-year terms get deeper discounts.

Take control of access —
without getting in anyone's way.

Deploy Tessera in minutes and broker your first connection today.