TetherBound Cloud — validation

The easy path to the same hard boundary.

We are exploring a hosted edition for people who want bounded AI access to private infrastructure without assembling MCP tunnels, runtime credentials, connector lifecycle, and team policy by hand.

Proposed architecture

Cloud outside. Trust boundary inside.

The customer Edge keeps its Tailscale identity and final policy decision in the customer environment. Cloud routes typed requests through an already connected Edge; it does not join or directly dial the customer's tailnet.

AI client

ChatGPT / Codex

Authenticates to the hosted MCP endpoint.

TetherBound Cloud

Identity · routing · audit

Checks user/workspace policy and routes typed requests through an already connected Edge.

Customer controlled

TetherBound Edge + Tailscale

Edge holds tailnet state, enforces local policy, and reaches approved hosts over the customer's private network.

What Cloud should remove

Less plumbing. Not fewer controls.

01

No developer tunnel setup

A stable authenticated MCP endpoint replaces the current need to configure and supervise a private tunnel client yourself.

02

Managed connector lifecycle

Pair an Edge connector, see its health, rotate credentials, and manage upgrades without losing its customer-side policy boundary.

03

Team governance

Map users to hosts and tools, retain audit metadata, and eventually require separate approval for narrowly typed write actions.

Proposed Cloud principles

  • Your Edge remains authoritative. Hosted policy can narrow what a connector allows, not grant something its local policy denies.
  • Tailscale identity stays at the Edge. Tailnet enrollment and persistent node state remain customer-side rather than moving into TetherBound Cloud.
  • No direct inbound Cloud path into the tailnet. Edge opens an outbound authenticated session to the hosted relay.
  • Raw host output is not retained by default. Results are streamed while audit records retain operational metadata.
  • Open edge. Edge, Agent, protocol, local policy, and platform adapters remain inspectable and self-hostable.
  • Read-only first. Future writes use typed prepare → approve → execute actions.

Why keep Tailscale underneath Cloud?

The hosted product is not intended to become another general-purpose private network. Tailscale continues to provide private connectivity and machine identity; TetherBound Cloud adds AI-user identity, routing, governance, and audit while the customer Edge performs the final local authorization decision.

Who we want to test with

People operating real private fleets: homelabs, VPSs, self-hosted services, remote development machines, agency/client environments, GPU boxes, or small production infrastructure. Mixed Linux/Windows/macOS fleets are especially useful.

Help us test the boundary.

Tell us what you run and what you would need before trusting an AI assistant with visibility into it. Please do not include passwords, private keys, private IP addresses, customer data, logs, or other secrets.