Tessera
FeaturesHow it worksSecurityPricingDocsDownload
Sign in Get started
FeaturesHow it worksSecurityPricingDocsDownload Sign in Get started

Tessera Privacy Policy

Version 1.6 — effective 2026-08-17

This policy explains what personal data Tessera handles when you visit tessera.company or use the Tessera customer portal, why, and for how long.

It does not describe the Tessera software itself. The Controller and clients run on your own infrastructure: your session content, audit logs, target credentials and the identities of your own users never reach us. See the End User License Agreement, section 5.


1. Who is responsible

The data controller is Societatea cu Răspundere Limitată “Tessera Limited” (SRL Tessera Limited), a company registered in the Republic of Moldova under IDNO 1026023127260, with its registered office at str. Miorița 1/c, MD-2028, Chișinău, Republic of Moldova.

Contact for any privacy question or request: legal@tessera.company.

2. What we collect, and why

When you create a portal account. Your email address, a hash of your password (argon2id — we never store the password itself), and the name of your organisation. If you sign in with GitHub, Google or Microsoft instead, we store the provider name and the account identifier it gives us rather than a password. If you enable two-factor authentication we store the TOTP secret, encrypted.

We do not ask for or store your name, postal address, phone number or date of birth.

Why: to create and operate your account. Legal basis: performance of a contract.

When you are signed in. Each session record holds your IP address and browser user-agent, so that you can see and revoke your own sessions and so we can detect account takeover.

Why: security of the service. Legal basis: legitimate interest.

When you do something that matters. An audit entry recording the action (sign-in, password change, licence reissue, a billing change), who did it, when, and from which IP address.

Why: security, and being able to answer “who changed this” for you and for us. Legal basis: legitimate interest.

When you invite a colleague. The email address you enter, so we can send the invitation.

When you buy a subscription. See section 4 — the payment itself is not handled by us.

When your controller collects its licence. A Tessera controller you run yourself can be linked to your account so it fetches its licence automatically. When it does, it sends a random identifier it generated on its own first run, its software version, and the IP address the request came from. We keep the identifier so your account page can show how many controllers are running on one subscription, and the version so support knows what you are on.

The identifier is not derived from your hardware and tells us nothing about the machine. The controller sends nothing about what you do with it — not your users, not the systems you connect to, not your sessions or commands.

A controller running an offline licence does the same thing once a day, and additionally names the licence it is running, so that we can see whether one licence file is in use in more places than it was sold for. If that controller is on an isolated network the report never reaches us, nothing in the software depends on it, and you will see “never reached the portal” in its licence panel — which is the expected state for a genuinely air-gapped installation. You may block it at your firewall; we would rather say that plainly than have you find it in a packet capture. What we may do if the reports show a licence used beyond what was paid for is set out in section 2 of the EULA.

Why: to operate the licence and to know how our software is deployed. Legal basis: performance of a contract, and our legitimate interest in seeing that a subscription is used as agreed.

3. Cookies and local storage

The portal sets three cookies. All of them are strictly necessary — without them you cannot sign in or stay signed in — and they are all first-party.

NameWhat it is forLifetime
tess_sessionKeeps you signed in. Contains a random identifier, not your data. HttpOnly, Secure, SameSite=Lax.12 hours
tess_csrfProtects you against cross-site request forgery. Readable by the page on purpose, because the app must send it back on every request.12 hours
tess_oauthHolds the state of a sign-in with GitHub, Google or Microsoft while it is in progress.10 minutes

Two other things are stored in your browser only and never sent to us: the page you asked for before signing in (cleared as soon as you arrive there), and, on the documentation pages, whether you chose the light or dark theme.

The website sets no cookies of its own. It sets two only if you accept the banner described below, and they belong to Google Analytics.

We measure visits, and nothing more. The website uses Google Analytics 4 to count visits and see which pages are read. Every advertising feature of it is switched off in code: no remarketing, no ad personalisation, no data passed to any Google advertising product. There is no session recording, no third-party error reporting and no tracking in the portal at all. We do not profile you and we do not sell anything about you.

CookieWhat it is forLifetime
_gaTells one browser from another, so a returning visitor is not counted twice. A random identifier — we cannot connect it to your account.13 months
_ga_XBECBLGFLYThe state of the current visit.13 months

Nothing is loaded from Google until you accept. The usual cookie banner lets the tag load immediately and asks it to behave itself; ours does not load it at all. Until you click Accept, no request goes to Google, so Google does not receive your IP address for your visit. Decline, and none ever is. Your answer is kept in your browser, expires after 13 months, and can be changed from the Cookies entry in the footer of every page — declining afterwards also deletes the two cookies above. The full list is in the Cookie Policy.

Legal basis: your consent, which you may withdraw at any time.

Fonts and everything else are served from our own servers. Loading a font or a script from someone else’s CDN would hand your IP address to that company on every page view, so we do not do it — including the payment provider’s own script, which we bundle from source instead. Analytics is the one exception, it is the one you are asked about, and it is the only third-party host our Content-Security-Policy allows a script from.

One further piece of third-party content exists, and it is on the billing page only: the checkout itself is a frame served by Polar, our merchant of record. Opening it lets Polar see your IP address and browser, which is unavoidable — that frame is where you type your card number, and keeping it on their domain and inside their systems is precisely what stops us from ever handling it. Our Content-Security-Policy permits that one frame and nothing else.

4. Who else is involved

We keep the list of processors deliberately short.

  • Polar Software, Inc. (Delaware, United States) — our merchant of record. When you buy a subscription, the purchase is a transaction between you and Polar; they handle payment, invoicing and sales tax under their own terms, as their own controller for that transaction. We pass them your email address and your organisation name so the invoice can be issued. Their checkout runs in a frame on our billing page, so they also receive your IP address and browser when it opens. We never see or store your card details — the card is typed into their frame, on their domain, inside their systems.
  • Google Ireland Limited — website analytics, and only if you accepted it. It receives your IP address, the pages you view on this website, and the identifier in the _ga cookie; Google processes it in the United States as well as the EU, under the EU-US Data Privacy Framework and the standard contractual clauses in its data processing terms. It never receives anything from the portal, and nothing that identifies you by name or email.
  • Hetzner Online GmbH — hosting. The portal and its database run on servers in Germany (EU).
  • Cloudflare, Inc. — the network in front of our websites. It filters abusive traffic and terminates the encrypted connection, which means it processes the IP address of every visitor and, briefly, the content of every request. Cloudflare is not an advertising or analytics service for us, and we have disabled its analytics features. Apart from the analytics you agreed to and the Polar checkout frame, our pages load nothing from a third party — and that is enforced by our Content-Security-Policy rather than promised.
  • Zoho Corporation B.V. (Netherlands) — email. It delivers the account messages we send you (address verification, password resets, billing notices) and hosts the mailboxes behind our published addresses, so it processes your address and anything you write to us. Our account is on Zoho’s EU infrastructure.

Where your data is. The portal and its database run in Germany (EU). Analytics data, if you accepted it, is processed by Google in the EU and the United States. We are established in the Republic of Moldova, which is outside the EU/EEA, and our own staff administer the service from there — so your data is stored in the EU but accessed from Moldova. Beyond that, data leaves the EU/EEA only as needed for the payment processing described above and for Cloudflare’s global network, which routes requests through the location nearest to you. Payment processing means the United States, where Polar is established: your email address, organisation name and the IP address that opens the checkout are processed there.

5. How long we keep it

  • Sessions — deleted when you sign out, and in any case within 12 hours.
  • Audit entries — the IP address is removed after 90 days; the entry itself is deleted after 12 months.
  • Account data — kept while your account exists. Delete your account, or write to legal@tessera.company, and it goes.
  • Billing records — Polar keeps what tax law requires it to keep; that is governed by their policy, not ours.
  • Analytics — the cookies expire after 13 months. Google deletes the event-level data behind our reports after 2 months, the shortest retention it offers and the one our property is set to; the aggregated counts that remain in its reports are not tied to you.

6. Your rights

If you are in the EU, the EEA or the United Kingdom you can ask us to give you a copy of your data, correct it, delete it, hand it to you in a portable form, or object to a processing we base on legitimate interest. Write to legal@tessera.company. We answer within one month.

You may also complain to your national data protection authority.

7. Security

Passwords are hashed with argon2id and never stored in readable form. Two-factor secrets and licence signing keys are encrypted at rest. All traffic is over HTTPS. Sessions are bound to a random identifier, expire after 12 hours, and can be revoked at any time.

8. Changes

If we change this policy materially we will raise the version above and tell account holders by email. The version in force when you signed up is recorded against your account.


Questions about this policy: legal@tessera.company

Questions: legal@tessera.company


Tessera

Self-hosted access broker for SSH, Kubernetes, databases and RDP.

Release notes, and what we are building next.

Follow on LinkedIn

Product

  • Features
  • How it works
  • Security
  • Pricing
  • Customer portal

Docs

  • Introduction
  • Deploy
  • Operations
  • Configuration

Compare

  • All comparisons
  • vs Teleport
  • vs StrongDM
  • vs Boundary

Resources

  • Blog
  • Security model
  • Editions
  • FAQ
  • Licence terms (EULA)
© 2026 Tessera Limited SRL legal@tessera.company IDNO 1026023127260 · str. Miorița 1/c, MD-2028, Chișinău, Republic of Moldova
Privacy Terms Refunds Licence Cookies
Built to be trusted.

We would like to count visits with Google Analytics, which needs a cookie. Nothing is loaded and nothing is stored unless you accept. What this sets.