
DNS Filtering by Control D packages an existing integration into a single purchase. Control D is a DNS filtering service that blocks malicious, phishing, and unapproved domains before a device connects to them. The new add-on lets customers apply Control D’s filtering profiles directly through Tailscale’s own policy engine, by user, group, tag, or device, rather than managing two separate consoles.
Tailscale PAM addresses a different piece of that problem: privileged access to specific infrastructure rather than DNS destinations. Tailscale acquired Border0 in March 2026, the technology behind Tailscale PAM. Tailscale PAM lets teams grant one-click access to specific servers, databases, Kubernetes clusters, and web applications, without handing out standing passwords or API keys. Every session, human or AI agent, gets logged and can be scoped to a specific time window for audits and compliance.
Aperture turns VPN identity into an AI gateway
Aperture is Tailscale’s AI gateway. It gives an AI agent an identity on a tailnet, the same way a device or a person already gets one, then routes that agent’s model calls and tool use through Tailscale’s private network instead of the open internet. That extends the same core idea behind Tailscale’s original VPN, identity-based access instead of network-based access, to AI agents specifically.





















