Pricing

Priced per person, never per server

Add a hundred hosts and the bill does not move. Free to self-host for as long as you like; pay per seat when you need the team controls.

Pricing

Start free. Pay when it's mission-critical.

Free to self-host, forever. Pay per seat only when you need the team controls — predictable pricing that's an easy win versus tools that charge per server.

Community

$0 self-hosted · 1 seat · free forever
Get started
  • Single seat — one admin account; add seats on any paid plan
  • 5 SSH · 1 Kubernetes · 1 database · 5 RDP targets
  • Keyless connect with credential injection
  • TOFU host-key pinning · stable target names
  • Audit log — events & commands (no session replay or live watch)
  • Governance controls unlock in Pro
Most popular

Pro

$19 / seat / mo · $15 billed annually · from 3 seats
Start with Pro
  • Everything in Community
  • RBAC + live RW/RO · just-in-time access
  • Session recording + live watch & force-close
  • SSO (OIDC) · Telegram alerts · bastions
  • Up to 100 targets · 50 concurrent sessions
Launch · $30 annual

Ultimate

$40 / seat / mo · $36 billed annually · from 3 seats
Go Ultimate
  • Everything in Pro
  • SCIM provisioning & white-label branding
  • SIEM / audit export + database query audit
  • Configurable Kubernetes & database policies
  • Unlimited targets & connections

Enterprise

Custom contact sales · volume pricing
Talk to us
  • Everything in Ultimate
  • Custom features & integrations built for your environment
  • Dedicated SLA & priority support
  • Procurement & security review · volume pricing

Pay yearly and save up to 20% vs. monthly. Launch offer: start an annual Ultimate plan within the first 6 months and lock in $30/seat/mo instead of $36. Bigger teams and multi-year terms get deeper discounts.

What each plan holds

CommunityProUltimate
Seats 1 from 3 from 3
SSH targets 5 up to 100 total Unlimited
Kubernetes clusters 1 up to 100 total Unlimited
Databases 1 up to 100 total Unlimited
RDP hosts 5 up to 100 total Unlimited
Concurrent sessions Unlimited 50 Unlimited

The full feature matrix, plan by plan, is in the editions reference.

Questions people ask before buying

Is the free plan actually free?
Yes, and it does not expire. Community is self-hosted, costs nothing, and is capped at 1 seat with 5 SSH, 1 Kubernetes, 1 database and 5 RDP targets. Keyless connect with credential injection and the audit log are included; the team-governance features are what a paid plan adds.
What counts as a seat?
A person who can sign in to Tessera. Servers, clusters and databases are not seats — you are not charged per target, which is the usual way this gets expensive elsewhere. Paid plans start at 3 seats.
Monthly or annual?
Either. Annual billing is about 20% cheaper: Pro is $15 per seat per month billed annually against $19 monthly, and Ultimate is $36 against $40. Start an annual Ultimate plan in the first six months and the rate is $30.
Do we still self-host on a paid plan?
Always. The plan changes which features your controller unlocks, not where it runs. There is no hosted version and no vendor cloud in the access path on any tier.
What do you see about our infrastructure?
Nothing. The controller runs inside your perimeter and your sessions never touch us. A controller connected to the portal sends exactly two things when it refreshes its licence: a random install identifier it generates itself, and its version — so your account can show how many controllers run on one subscription. No users, no targets, no sessions.
Can we run air-gapped?
Yes. Instead of a controller that refreshes its licence over the network, you download a licence file covering the paid period and install it. Verification is local either way — the controller checks the signature itself and never phones home to authorise a session.
What happens when a licence expires?
The controller falls back to Community. It does not stop, lock you out, or hold your configuration hostage — the paid features switch off and everything else keeps working.
Can we get a refund?
Within 14 days of your first payment, for any reason, from a button in your account. The full terms are on the refunds page.

Refund terms in full: the refunds page. Something here not answered? Ask us.

Start on Community. Move up when it matters.