Built on Tailscale
A dedicated Tailscale identity provides private connectivity and machine identity for the current Linux path.
The customer-side runtime is being prepared for a clean public open-source release: a security-first MCP layer for giving ChatGPT, Codex, and other compatible clients bounded access to private machines over Tailscale. The Linux proof of concept already works end to end.
A dedicated Tailscale identity provides private connectivity and machine identity for the current Linux path.
TetherBound adds independent host/tool policy, strict host verification, typed read-only tools, and hard result limits above the network layer.
Edge, Agent, protocol, adapters, local policy, setup tooling, and conformance tests move into a clean public tetherbound repository with signed releases.
The code that actually reaches customer machines is the part users should be able to inspect. TetherBound Edge, TetherBound Agent, host adapters, protocol definitions, tool contracts, local policy, setup tooling, and security/conformance tests are intended to remain open source and independently usable.
tsnet Tailscale identity.Tailscale already solves private connectivity and machine identity well. TetherBound focuses on the layer above it: what an AI assistant is allowed to inspect, how that operation is expressed, how output is bounded, and how the decision can be audited.
The project remains independent; using Tailscale as the network and identity substrate does not imply an affiliation or partnership.
The working prototype lives in the private chatgpt-plugin-tailscale incubation repository. We are intentionally retaining that descriptive historical name while extracting the customer-side runtime into a clean public TetherBound Community repository after a secret/history review and naming migration.