Private infrastructure access for AI

Give AI access.
Keep it bounded.

TetherBound connects AI assistants to the systems you already run while keeping access narrow, explicit, and auditable. No public SSH ports. No shared private keys. No unrestricted shell.

Built on TailscaleLocal policy stays authoritativeTyped, bounded toolsLinux proof of concept working
Built on Tailscale

Your private network stays your private network.

TetherBound uses Tailscale for private connectivity and machine identity, then adds the AI-specific control layer: typed operations, local allowlists, hard bounds, and audit metadata.

TetherBound is an independent project and is not affiliated with or endorsed by Tailscale Inc.

AI client

ChatGPT / Codex

Asks for a specific, typed operation such as disk usage, service state, or bounded logs.

AI control boundary

TetherBound

Resolves identity, enforces host and tool policy, bounds output, and records audit metadata.

Private network + machines

Tailscale → your infrastructure

LinuxWorking
WindowsPlanned
macOSPlanned
Why TetherBound

Access without handing over the keys.

Most remote-management bridges begin with credentials and end with a shell. TetherBound starts with the operation you actually want to allow.

01

No unrestricted shell

The assistant cannot turn conversation text into arbitrary commands. The edge exposes fixed, typed capabilities with explicit inputs and bounds.

02

Private by default

The current proof of concept runs over Tailscale and an outbound MCP tunnel. Your servers do not need a new public management port.

03

Two-sided policy

Tailscale network policy and TetherBound's own local allowlists both have to permit the request. Future cloud policy can narrow local permissions, never widen them.

Useful from the start

Ask questions about real machines.

The first release is intentionally read-only: diagnosis, inventory, and understanding before remediation.

Fleet visibility

List only explicitly admitted hosts and inspect connectivity and capabilities.

System health

Summarize uptime, memory, kernel or OS details, and bounded host facts.

Disk usage

See filesystem or volume capacity without granting file-browser access.

Processes

Inspect a bounded process snapshot with filters handled as data, not shell text.

Services and logs

Check exact allowlisted services and bounded log sources rather than broad OS privileges.

Open source + hosted

Choose how much you want us to run.

The customer-side security boundary is designed to stay open and independently usable. Cloud is intended to remove platform plumbing, not local control.

Private preview

Community

The working Linux proof of concept is being prepared for a clean public open-source release.

  • Open-source Edge and Agent
  • Tailscale SSH for Linux
  • Typed read-only MCP tools
  • Idempotent setup
  • No TetherBound account required
Community status
In validation

Cloud

Hosted authentication, connectivity, policy, health, and audit around the same customer-controlled edge.

  • Hosted authenticated MCP endpoint
  • Outbound customer Edge connector
  • Central policy and audit metadata
  • Connector and host health
  • Windows and macOS agent path
Join early access
Current status

Clear about what exists and what comes next.

CapabilityStatusPath
Linux read-only inspectionWorkingTailscale SSH + local gateway
ChatGPT private connectionWorkingOpenAI Secure MCP Tunnel
Public Community releasePreparingClean open-source repository + signed releases
Windows inspectionRoadmapNative TetherBound Agent over the tailnet
macOS inspectionRoadmapNative TetherBound Agent over the tailnet
TetherBound CloudValidationHosted MCP + outbound Edge relay

What would you let an AI inspect?

We are validating TetherBound with people who run private Linux, Windows, and macOS systems. Tell us what you operate, what you would ask, and what security boundary you would need before trusting it.