- Is the free plan actually free?
- Yes, and it does not expire. Community is self-hosted, costs nothing, and is capped at 1 seat with 5 SSH, 1 Kubernetes, 1 database and 5 RDP targets. Keyless connect with credential injection and the audit log are included; the team-governance features are what a paid plan adds.
- What counts as a seat?
- A person who can sign in to Tessera. Servers, clusters and databases are not seats — you are not charged per target, which is the usual way this gets expensive elsewhere. Paid plans start at 3 seats.
- Monthly or annual?
- Either. Annual billing is about 20% cheaper: Pro is $15 per seat per month billed annually against $19 monthly, and Ultimate is $36 against $40. Start an annual Ultimate plan in the first six months and the rate is $30.
- Do we still self-host on a paid plan?
- Always. The plan changes which features your controller unlocks, not where it runs. There is no hosted version and no vendor cloud in the access path on any tier.
- What do you see about our infrastructure?
- Nothing. The controller runs inside your perimeter and your sessions never touch us. A controller connected to the portal sends exactly two things when it refreshes its licence: a random install identifier it generates itself, and its version — so your account can show how many controllers run on one subscription. No users, no targets, no sessions.
- Can we run air-gapped?
- Yes. Instead of a controller that refreshes its licence over the network, you download a licence file covering the paid period and install it. Verification is local either way — the controller checks the signature itself and never phones home to authorise a session.
- What happens when a licence expires?
- The controller falls back to Community. It does not stop, lock you out, or hold your configuration hostage — the paid features switch off and everything else keeps working.
- Can we get a refund?
- Within 14 days of your first payment, for any reason, from a button in your account. The full terms are on the refunds page.