Reach a private database without installing anything on your servers.

Tailscale answers the same need through the network: an agent on every machine, and everything becomes reachable. That is excellent. When you are allowed to deploy it. Kestro goes through the doors that already exist, your SSH keys and your cloud access, and asks nobody’s permission.

macOS 11+ · Windows soon

Two ways to reach the same database

One changes your network. The other uses the doors already there.

These are not two versions of the same product: they are two different decisions, and one of them commits your infrastructure.

Tailscale

Install an agent on every machine to reach
or a subnet router, and its routes
Describe the access in a policy
Get infrastructure to agree
 
After that: everything is reachable, for everyone,
from anywhere, permanently.

Kestro

Nothing to install on your servers.
Your SSH keys, your gcloud, your aws.
No policy to write, no approval to obtain.
 
The door opens when you need it,
from your machine, and closes when you say so.
 
$ psql "$(kestro url notes-db)"

Point by point

What each one asks for, and what each one gives.

TailscaleKestro
To install on the machines you reachan agent, or a subnet routernothing
Decision requiredan infrastructure change, so an approvalnone: you use the access you already have
What authenticatesyour identity provider and a policyyour SSH keys, gcloud, aws, untouched
Scopethe whole team, permanentlyyour machine, when you decide
Works while your Mac is offyes, the network staysno
Access logyesno
On a machine you do not administerno, without an agent there is no nodeyes, if ssh or your cloud tool reaches it
Cloud SQL, IAP, Session Managermoot: the network replaces themyes, through your official tools
Platformsnearly all of themmacOS only
Costfree plan for personal use, then per user€29.99$29.99£25.99CHF 25.90CA$40.99A$45.99 once

Checked on 4 August 2026, from Tailscale’s public documentation.

What Kestro brings

Four things a private network does not settle.

Tailscale makes machines reachable. What remains is opening the right door, at the right moment, and knowing which one is open.

  1. You have nothing to ask for

    Deploying an agent onto production is a team decision, often slow, sometimes refused. Opening a tunnel with the keys you were already given is not one: it is the access you already hold, used differently.

  2. Cloud doors stay cloud doors

    Cloud SQL through the official proxy, a VM through IAP, an EC2 through Session Manager: these are the paths Google and AWS document, with their logging and their IAM. Kestro uses them rather than routing around them.

  3. You can see what is open

    A private network makes everything reachable all the time, which is the point, and means you no longer know what you are connected to. Here each door is a row, production carries a red edge, and “Close all” shuts them in one gesture.

  4. And the rest of the day

    Your repositories and their branch, the docker compose services, your pinned scripts, the addresses you watch: same panel, same shortcut.

CodeFileView14:43
Kestro1 tunnel open · 1 service isn’t answering
Filter tunnels⌘FNew tunnel
bastion-prodprodSSHshellbastion.kestro.internalclosed
notes-dbstagingPostgreslocalhost:5432pg-staging.eu-west-1.rdsopen
run-eventsprodMongolocalhost:27017mongo-prod.atlasclosed
⌘K palette↑↓ navigate␣ togglecloses if you click elsewhere
run-tracker , zsh
Applying 2 migrations to shop-staging-db…
20240612_add_orders_index ok
done in 1.4s
run-tracker , zsh
# every door, and which ones are open
tunnel notes-db ouvert :5432
tunnel run-events ouvert :27017
tunnel bastion-prod fermé

On your machine

Everything stays with you.

Your connections run from your computer to your servers, never through us.

  • No account

    Nothing to create, no password.

  • Your keys stay put

    SSH, Google Cloud, AWS: Kestro uses your own tools, locally.

  • No usage statistics

    We don’t know what you open, or when.

  • One exception

    Your licence renews with us. Nothing else leaves.

When Tailscale is the right choice

Three cases where you want it, not us.

These are two tools answering the same question from opposite ends. Here are the cases where the other end is the right one.

  • It has to work without you

    A service that must reach another service, a machine that must stay reachable overnight, an on-call rota: Kestro stops with your session. A private network does not.

  • It is a team decision

    Giving ten people revocable access, with a log and a policy, is exactly what Tailscale does and exactly what Kestro does not. We have no accounts, no administration, no audit log: it is a personal tool.

  • You are not on macOS

    Kestro only runs on macOS 11 and later. The Windows version is in the works; there is no Linux version planned.

Pricing

You pay once. That’s it.

A tool you open forty times a day shouldn’t send an invoice every month.

Kestro licence

€29.99$29.99£25.99CHF 25.90CA$40.99A$45.99€39.99$39.99£34.99CHF 33.90CA$54.99A$61.99 · Launch offer · upcoming price

1 computer · one-time

  • Every feature of the app, no tiers, no “Pro” edition
  • One year of updates included, then renew if you want to
  • The app stays yours, renewed or not
  • One key, the same on all your computers
  • Switch machines whenever you like, no limit
  • No account to create: the key arrives by email

Or download it for free first →

Refunded within 14 days, no questions asked.

Questions we get asked

Can both live side by side?

Yes, and it is a common case. If your team has deployed a private network, your machines are reachable and Kestro treats it as any other network: an SSH tunnel to an internal address works the same. The two compete over nothing: one makes the machine reachable, the other opens the door and tells you it is open.

Is Kestro less secure than a private network?

It opens nothing new: it uses the access you already have (your SSH keys, your gcloud session, your aws profile) and copies none of it. A tunnel lasts as long as you leave it open, against a network reachable at all times. What is missing, though, is real: there is no access policy, no audit log, no central revocation. For personal use that is moot; for ten people on production it is exactly what you need, and Tailscale is what you want.

Do I have to install anything on my servers?

No, nothing. That is the fundamental difference between the two approaches. Kestro uses the doors that already exist: sshd, the Cloud SQL proxy, IAP, Session Manager. If you can connect to a machine today from your terminal, Kestro can too, and nothing changes on the server side.

What if I am not allowed to deploy an agent?

That is the case that brings us the most email. A contractor, a client, infrastructure you do not manage, a security team that has not decided: what is left is the access you were given. Kestro works with that, and asks nobody’s permission.

Does the trial ask for a card?

No, and it does not ask for an account either. You download, you get 7 full days. No card is asked for until you decide to buy.