[{"data":1,"prerenderedAt":956},["ShallowReactive",2],{"{\"cv\":1789159649371,\"version\":\"published\"}widgets\u002Fnavigation-bar":3,"{\"cv\":1789159649371,\"resolve_relations\":[\"ResourceFeatureCard.resource\"],\"version\":\"published\"}\u002Fblog\u002Fterniion-vs-tailscale-speed-security-and-the-control-plane-question":66},{"data":4,"headers":45},{"story":5,"cv":42,"rels":43,"links":44},{"name":6,"created_at":7,"published_at":8,"updated_at":9,"id":10,"uuid":11,"content":12,"slug":32,"full_slug":33,"sort_by_date":22,"position":34,"tag_list":35,"is_startpage":15,"parent_id":36,"meta_data":22,"group_id":37,"first_published_at":38,"release_id":22,"lang":39,"path":40,"alternates":41,"default_full_slug":22,"translated_slugs":22},"Navigation Bar","2026-08-05T05:55:49.585Z","2026-08-07T15:41:09.255Z","2026-08-07T15:41:09.269Z",205700094329908,"be34732b-2155-45e7-8ee2-86e1157a8cb4",{"_uid":13,"component":14,"showMarketingBanner":15,"marketingBannerContent":16},"e7a8d72d-8af8-452e-87b2-de4098162fb9","NavigationBar",false,{"type":17,"content":18},"doc",[19],{"type":20,"attrs":21,"content":23},"paragraph",{"textAlign":22},null,[24],{"text":25,"type":26,"marks":27},"See us at Black Hat booth #7505","text",[28],{"type":29,"attrs":30},"textStyle",{"color":31},"#000000","navigation-bar","widgets\u002Fnavigation-bar",0,[],205696803161001,"e116d2fb-7cac-4697-9dcb-91d9283aecc3","2026-08-05T06:19:33.200Z","default","\u002F",[],1789158981,[],[],{"cache-control":46,"connection":47,"content-length":48,"content-type":49,"date":50,"etag":51,"referrer-policy":52,"sb-be-version":53,"server":54,"vary":55,"via":56,"x-amz-cf-id":57,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":63,"x-runtime":64,"x-xss-protection":65},"max-age=0, public, s-maxage=604800, stale-if-error=3600","keep-alive","986","application\u002Fjson; charset=utf-8","Fri, 11 Sep 2026 20:47:59 GMT","W\u002F\"ed4e258c6d5a3919826609eba551325d\"","strict-origin-when-cross-origin","5.959.0","nginx\u002F1.29.1","Origin","1.1 4b1f2d5e8ba06f891aac0914bfcf0ce0.cloudfront.net (CloudFront)","-jRtnwmwkgQHSOChC2kF4bF1WiRNHmEqGTBVSSsHzZjtGmgUmzGWZQ==","CMH68-P4","Miss from cloudfront","nosniff","SAMEORIGIN","none","524a3d68-2893-4568-972a-ed859ea97009","0.022357","0",{"data":67,"headers":946},{"story":68,"cv":42,"rels":770,"links":945},{"name":69,"created_at":70,"published_at":71,"updated_at":72,"id":73,"uuid":74,"content":75,"slug":764,"full_slug":765,"sort_by_date":753,"position":34,"tag_list":766,"is_startpage":15,"parent_id":756,"meta_data":22,"group_id":767,"first_published_at":768,"release_id":22,"lang":39,"path":22,"alternates":769,"default_full_slug":22,"translated_slugs":22},"Terniion vs. Tailscale: Speed, Security, and the Control-Plane Question","2026-09-11T20:06:53.790Z","2026-09-11T20:36:20.828Z","2026-09-11T20:36:20.845Z",219003346101234,"0a6eba3f-60a4-439b-a0a3-8af481a1ff7e",{"Tags":76,"_uid":77,"body":78,"title":79,"content":80,"component":453,"seoOgImage":454,"keyTakeaways":460,"previewImage":525,"previewTitle":527,"relatedContent":528,"seoDescription":763,"previewDescription":763},"","69a52ed9-008b-4441-a3c4-57b32d15254b",[],"Tailscale vs Terniion: Speed, security, and the control plane question",{"type":17,"attrs":81,"content":82},{"backgroundColor":22},[83,91,99,110,118,126,134,142,150,158,166,174,182,190,198,222,232,241,249,258,266,274,282,290,298,306,314,323,337,351,365,379,387,395,429,437,445],{"type":20,"attrs":84,"content":85},{"textAlign":22},[86],{"text":87,"type":26,"marks":88},"Tailscale earned its reputation by taking WireGuard with its modern, well-built cryptography, wrapping it in a setup process so painless that IT teams stopped filing VPN tickets and started just connecting. For labs, small teams, and personal tailnets, that reputation still holds. Anyone using it as a reason to skip evaluating access architecture for a distributed, security-conscious organization has the right instinct pointed at the wrong question.",[89],{"type":29,"attrs":90},{"color":31},{"type":20,"attrs":92,"content":93},{"textAlign":22},[94],{"text":95,"type":26,"marks":96},"What separates them is what each one trusts, who holds that trust, and what happens the moment that trust is misplaced, more than which tool is easier to turn on.",[97],{"type":29,"attrs":98},{"color":31},{"type":100,"attrs":101,"content":103},"heading",{"level":102,"textAlign":22},2,[104],{"text":105,"type":26,"marks":106},"Two Different Ideas of Trust",[107],{"type":29,"attrs":108},{"color":109},"#F68D2E",{"type":20,"attrs":111,"content":112},{"textAlign":22},[113],{"text":114,"type":26,"marks":115},"Tailscale is a mesh overlay. Every device that joins a tailnet becomes a node that other authorized devices can reach directly, coordinated by Tailscale's own control plane, which handles key exchange and NAT traversal behind the scenes. That control plane is the reason Tailscale works as smoothly as it does, and also the reason adopting it is an infrastructure decision as much as a client install. A third party sits in the coordination path of every device pairing, even when it never touches the payload itself.",[116],{"type":29,"attrs":117},{"color":31},{"type":20,"attrs":119,"content":120},{"textAlign":22},[121],{"text":122,"type":26,"marks":123},"Terniion, Xiid's secure access platform, starts from a different premise: what if no standing trust existed at all? Terniion's patented technology opens a single outbound-only path between two specific processes, for exactly as long as that task needs it. There's no tailnet to join, no shared mesh to onboard onto, no coordination server holding keys on your behalf. When the process finishes, the path closes itself.",[124],{"type":29,"attrs":125},{"color":31},{"type":20,"attrs":127,"content":128},{"textAlign":22},[129],{"text":130,"type":26,"marks":131},"Device-to-device versus process-to-process is the core difference. A compromised device on a tailnet keeps a seat at the table until an admin manually revokes it. A compromised Terniion session has nothing left to compromise once the process it was scoped to is done.",[132],{"type":29,"attrs":133},{"color":31},{"type":20,"attrs":135,"content":136},{"textAlign":22},[137],{"text":138,"type":26,"marks":139},"Tailscale built plenty worth acknowledging. Its access control lists based on user identity, group, and tag are fine-grained. It integrates cleanly with existing SSO and MFA providers, streams logs to SIEM tools for teams that need the audit trail, and can stand up an exit node when you need to route traffic through a single egress point. Those capabilities matter. They still operate one layer above the process, at the device and the identity attached to it.",[140],{"type":29,"attrs":141},{"color":31},{"type":100,"attrs":143,"content":144},{"level":102,"textAlign":22},[145],{"text":146,"type":26,"marks":147},"The Cost of a Coordination Server",[148],{"type":29,"attrs":149},{"color":109},{"type":20,"attrs":151,"content":152},{"textAlign":22},[153],{"text":154,"type":26,"marks":155},"Tailscale's hosted control plane is convenient, and that convenience is the product. But it's also a dependency. A self-hosted option (Headscale) exists for teams that want out from under Tailscale's infrastructure, but it drops enterprise features like SSO, which is why most organizations run the hosted version and accept the control-plane relationship that comes with it. Keys are also tied to devices rather than to a moment in time, so they tend to outlive the task they were issued for.",[156],{"type":29,"attrs":157},{"color":31},{"type":20,"attrs":159,"content":160},{"textAlign":22},[161],{"text":162,"type":26,"marks":163},"For any team that has to answer \"who could see this in transit\" during an audit, that question isn't hypothetical. Terniion sidesteps it by never holding your credentials or reading your traffic in the clear, and by running fully on-prem or air-gapped when that's the requirement, with no coordination service, self-hosted or otherwise, standing in the middle.",[164],{"type":29,"attrs":165},{"color":31},{"type":100,"attrs":167,"content":168},{"level":102,"textAlign":22},[169],{"text":170,"type":26,"marks":171},"How This Plays Out for a Distributed Team",[172],{"type":29,"attrs":173},{"color":109},{"type":20,"attrs":175,"content":176},{"textAlign":22},[177],{"text":178,"type":26,"marks":179},"Picture a healthcare or financial services company with a distributed workforce and a rotating set of contractors who need narrow access to specific internal tools. On Tailscale, every contractor's device joins the tailnet, gets scoped down through ACLs, and has to be manually offboarded the day the contract ends. Miss that step, and the device keeps its network position. Multiply that across dozens of contractors a year, and manual key hygiene at scale stops being a minor operational note and starts being the thing your next audit flags.",[180],{"type":29,"attrs":181},{"color":31},{"type":20,"attrs":183,"content":184},{"textAlign":22},[185],{"text":186,"type":26,"marks":187},"On Terniion, there's no device to onboard or offboard in the first place. Access is defined at the process level, tied to the specific workload a contractor's tool needs to reach. When the contract ends and the workload is decommissioned, the access ends with it. Nobody has to remember to revoke anything, because there was never a standing grant to revoke.",[188],{"type":29,"attrs":189},{"color":31},{"type":100,"attrs":191,"content":192},{"level":102,"textAlign":22},[193],{"text":194,"type":26,"marks":195},"Comparable Speed, Faster Where It Counts",[196],{"type":29,"attrs":197},{"color":109},{"type":20,"attrs":199,"content":200},{"textAlign":22},[201,206,217],{"text":202,"type":26,"marks":203},"Xiid ran both platforms, along with direct public connectivity, WireGuard, OpenVPN, and IPsec, through the same ",[204],{"type":29,"attrs":205},{"color":31},{"text":207,"type":26,"marks":208},"constrained edge test",[209,215],{"type":210,"attrs":211},"link",{"href":212,"uuid":22,"anchor":22,"target":213,"linktype":214},"https:\u002F\u002Fyoutu.be\u002FVsHNHodsSss","_self","url",{"type":29,"attrs":216},{"color":31},{"text":218,"type":26,"marks":219},": an older client on a satellite-style consumer uplink, reaching AWS and Google Cloud endpoints across three regions each. The goal wasn't a lab-perfect throughput ceiling. It was the question a buyer has: does the stronger security model cost meaningful performance on a realistic connection?",[220],{"type":29,"attrs":221},{"color":31},{"type":20,"attrs":223,"content":224},{"textAlign":22},[225],{"text":226,"type":26,"marks":227},"TCP throughput, median Mbps",[228,230],{"type":29,"attrs":229},{"color":31},{"type":231},"bold",{"type":20,"attrs":233,"content":234},{"textAlign":22},[235],{"type":236,"attrs":237},"image",{"id":238,"alt":76,"src":239,"title":76,"source":76,"copyright":76,"meta_data":240},187908283969211,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F616x131\u002F42926555bf\u002Fthroughput.png",{},{"type":20,"attrs":242,"content":243},{"textAlign":22},[244],{"text":245,"type":26,"marks":246},"On short-haul U.S. paths, the two land in the same practical band. On the long-haul Singapore route, exactly the kind of intercontinental link where constrained connections usually fall apart, Terniion held 5.79 Mbps while Tailscale dropped to 2.15. Terniion's throughput there is more than double.",[247],{"type":29,"attrs":248},{"color":31},{"type":20,"attrs":250,"content":251},{"textAlign":22},[252],{"text":253,"type":26,"marks":254},"TCP connection setup time, milliseconds",[255,257],{"type":29,"attrs":256},{"color":31},{"type":231},{"type":20,"attrs":259,"content":260},{"textAlign":22},[261],{"type":236,"attrs":262},{"id":263,"alt":76,"src":264,"title":76,"source":76,"copyright":76,"meta_data":265},187908076818099,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F509x314\u002F98d56565db\u002Ftcp-setup-time.png",{},{"type":20,"attrs":267,"content":268},{"textAlign":22},[269],{"text":270,"type":26,"marks":271},"Setup time matters more than it sounds like it should, because it's the tax every short-lived connection pays before it does any work: REST calls, CI\u002FCD jobs, admin dashboards, anything that opens and closes connections all day. Across every region tested, Terniion connected somewhere between four and sixteen times faster than Tailscale. A pipeline making 500 calls spends 25 seconds waiting on Tailscale-style setup times and roughly 4 seconds waiting on Terniion's.",[272],{"type":29,"attrs":273},{"color":31},{"type":100,"attrs":275,"content":276},{"level":102,"textAlign":22},[277],{"text":278,"type":26,"marks":279},"Where Each Platform Fits",[280],{"type":29,"attrs":281},{"color":109},{"type":20,"attrs":283,"content":284},{"textAlign":22},[285],{"text":286,"type":26,"marks":287},"Tailscale solved a problem worth solving: getting a distributed team onto a private network without touching firewall rules. For developer teams that want device identity, convenience, and a fast path to \"it just works,\" that's still a legitimate answer.",[288],{"type":29,"attrs":289},{"color":31},{"type":20,"attrs":291,"content":292},{"textAlign":22},[293],{"text":294,"type":26,"marks":295},"Where it runs out of room is exactly where the stakes go up: regulated data, critical infrastructure, remote or field sites on unreliable links, and any environment where a single compromised device shouldn't translate into standing network access. That's a structural limit of building around device trust and a shared control plane, rather than process-bound, ephemeral access.",[296],{"type":29,"attrs":297},{"color":31},{"type":20,"attrs":299,"content":300},{"textAlign":22},[301],{"text":302,"type":26,"marks":303},"Terniion was built for that second category from the start: no open inbound ports, no long-lived keys to rotate, no coordination server to trust, and access that's scoped to a task instead of a tailnet.",[304],{"type":29,"attrs":305},{"color":31},{"type":100,"attrs":307,"content":308},{"level":102,"textAlign":22},[309],{"text":310,"type":26,"marks":311},"Frequently Asked Questions",[312],{"type":29,"attrs":313},{"color":109},{"type":20,"attrs":315,"content":316},{"textAlign":22},[317],{"text":318,"type":26,"marks":319},"FAQs about Tailscale vs. Terniion",[320,322],{"type":29,"attrs":321},{"color":31},{"type":231},{"type":20,"attrs":324,"content":325},{"textAlign":22},[326,332],{"text":327,"type":26,"marks":328},"Is Terniion a Tailscale replacement, or something you run alongside it?",[329,331],{"type":29,"attrs":330},{"color":31},{"type":231},{"text":333,"type":26,"marks":334}," Either. Terniion doesn't require ripping out an existing VPN or mesh network to prove itself. Most teams start it on a single high-value application, run it next to Tailscale, and expand from there once the access model earns its place.",[335],{"type":29,"attrs":336},{"color":31},{"type":20,"attrs":338,"content":339},{"textAlign":22},[340,346],{"text":341,"type":26,"marks":342},"Does moving to process-bound access mean re-architecting how my team works?",[343,345],{"type":29,"attrs":344},{"color":31},{"type":231},{"text":347,"type":26,"marks":348}," No. Access is tied to the process definition rather than a manually managed device or user list. When the workload deploys, its access comes with it, and there's no ACL sheet to maintain as people join or leave.",[349],{"type":29,"attrs":350},{"color":31},{"type":20,"attrs":352,"content":353},{"textAlign":22},[354,360],{"text":355,"type":26,"marks":356},"Why does connection setup time matter if my throughput is already fine?",[357,359],{"type":29,"attrs":358},{"color":31},{"type":231},{"text":361,"type":26,"marks":362}," Because most traffic runs as hundreds of short connections a day rather than one long file transfer, and a setup-time advantage compounds every time a script, container, or API call opens a new one, which is most of the time.",[363],{"type":29,"attrs":364},{"color":31},{"type":20,"attrs":366,"content":367},{"textAlign":22},[368,374],{"text":369,"type":26,"marks":370},"What happens if a device running Tailscale is lost or stolen?",[371,373],{"type":29,"attrs":372},{"color":31},{"type":231},{"text":375,"type":26,"marks":376}," Its keys stay valid on the tailnet until an admin manually revokes that device, a manageable process as long as someone notices quickly. Terniion doesn't have an equivalent step, because there's no long-lived device key sitting on the endpoint to steal in the first place.",[377],{"type":29,"attrs":378},{"color":31},{"type":100,"attrs":380,"content":381},{"level":102,"textAlign":22},[382],{"text":383,"type":26,"marks":384},"Access should end when its purpose does.",[385],{"type":29,"attrs":386},{"color":109},{"type":20,"attrs":388,"content":389},{"textAlign":22},[390],{"text":391,"type":26,"marks":392},"Tailscale made private connectivity easier. But for security-conscious organizations, connecting is only the beginning. The harder questions are ",[393],{"type":29,"attrs":394},{"color":31},{"type":396,"content":397},"bullet_list",[398,409,419],{"type":399,"content":400},"list_item",[401],{"type":20,"attrs":402,"content":403},{"textAlign":22},[404],{"text":405,"type":26,"marks":406},"What remains trusted",[407],{"type":29,"attrs":408},{"color":31},{"type":399,"content":410},[411],{"type":20,"attrs":412,"content":413},{"textAlign":22},[414],{"text":415,"type":26,"marks":416},"Who controls that trust",[417],{"type":29,"attrs":418},{"color":31},{"type":399,"content":420},[421],{"type":20,"attrs":422,"content":423},{"textAlign":22},[424],{"text":425,"type":26,"marks":426},"How long access survives its original purpose",[427],{"type":29,"attrs":428},{"color":31},{"type":20,"attrs":430,"content":431},{"textAlign":22},[432],{"text":433,"type":26,"marks":434},"Terniion makes the task, not the device’s network membership, the boundary of access. Its process-bound model is designed to close the path when the work ends, rather than leave standing access behind for someone to manage.",[435],{"type":29,"attrs":436},{"color":31},{"type":20,"attrs":438,"content":439},{"textAlign":22},[440],{"text":441,"type":26,"marks":442},"The constrained-edge results presented here reinforce that architectural case: competitive or higher throughput and consistently faster connection setup. In these tests, tighter access boundaries did not require a performance sacrifice.",[443],{"type":29,"attrs":444},{"color":31},{"type":20,"attrs":446,"content":447},{"textAlign":22},[448],{"text":449,"type":26,"marks":450},"For organizations protecting regulated data, critical infrastructure, or distributed operations, the choice should turn on more than deployment convenience. It should turn on the access they are willing to leave in place. ",[451],{"type":29,"attrs":452},{"color":31},"BlogPost",{"id":455,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":456,"copyright":76,"fieldtype":457,"meta_data":458,"is_external_url":15},219008125219147,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F3000x3000\u002Ffa621fb7f7\u002Fmesh-security.jpg","asset",{"size":459},"3000x3000",{"type":17,"attrs":461,"content":462},{"backgroundColor":22},[463],{"type":396,"content":464},[465,475,485,495,505,515],{"type":399,"content":466},[467],{"type":20,"attrs":468,"content":469},{"textAlign":22},[470],{"text":471,"type":26,"marks":472},"Tailscale and Terniion both skip legacy VPN hardware, but they trust different things. Tailscale trusts the device. Terniion trusts the process, and only for the moment it needs access.",[473],{"type":29,"attrs":474},{"color":31},{"type":399,"content":476},[477],{"type":20,"attrs":478,"content":479},{"textAlign":22},[480],{"text":481,"type":26,"marks":482},"A compromised device keeps its place on Tailscale's tailnet until an admin manually revokes it. A compromised Terniion session has nothing left to compromise once its task ends.",[483],{"type":29,"attrs":484},{"color":31},{"type":399,"content":486},[487],{"type":20,"attrs":488,"content":489},{"textAlign":22},[490],{"text":491,"type":26,"marks":492},"On constrained-edge testing, the two platforms land in the same practical range on short-haul U.S. connections. On the long-haul AWS Singapore path, Terniion held more than double Tailscale's throughput.",[493],{"type":29,"attrs":494},{"color":31},{"type":399,"content":496},[497],{"type":20,"attrs":498,"content":499},{"textAlign":22},[500],{"text":501,"type":26,"marks":502},"Terniion connected four to sixteen times faster than Tailscale across every region tested, a meaningful edge for the short-lived connections most applications run all day.",[503],{"type":29,"attrs":504},{"color":31},{"type":399,"content":506},[507],{"type":20,"attrs":508,"content":509},{"textAlign":22},[510],{"text":511,"type":26,"marks":512},"Tailscale's hosted control plane is a dependency, and its self-hosted option (Headscale) drops SSO. Terniion runs fully on-prem or air-gapped, with no coordination service standing in the middle.",[513],{"type":29,"attrs":514},{"color":31},{"type":399,"content":516},[517],{"type":20,"attrs":518,"content":519},{"textAlign":22},[520],{"text":521,"type":26,"marks":522},"Terniion makes the task, not the device's network membership, the boundary of access, so it closes when the work ends instead of waiting for someone to notice and revoke it.",[523],{"type":29,"attrs":524},{"color":31},{"id":455,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":456,"copyright":76,"fieldtype":457,"meta_data":526,"is_external_url":15},{"size":459},"Tailscale vs. Terniion: A zero trust access comparison",[529],{"_uid":530,"variant":531,"resource":532,"component":761,"hideLabel":15,"background":762},"ff159ea5-0631-4862-8cfa-75e77b37cbe4","oneThirdLeftPhoto",[533],{"name":534,"created_at":535,"published_at":536,"updated_at":537,"id":538,"uuid":539,"content":540,"slug":751,"full_slug":752,"sort_by_date":753,"position":754,"tag_list":755,"is_startpage":15,"parent_id":756,"meta_data":22,"group_id":757,"first_published_at":758,"release_id":22,"lang":39,"path":22,"alternates":759,"default_full_slug":22,"translated_slugs":22,"_stopResolving":760},"TCP Setup Time is the VPN Metric Nobody's Measuring","2026-06-15T23:18:21.831Z","2026-07-27T21:01:55.503Z","2026-07-27T21:01:55.521Z",187907693916850,"c7245ec6-2dc5-4e77-aa7e-1fd3b4f3d38d",{"Tags":76,"_uid":77,"body":541,"title":534,"content":542,"component":453,"seoOgImage":717,"keyTakeaways":721,"previewImage":746,"previewTitle":534,"relatedContent":748,"seoDescription":749,"previewDescription":750},[],{"type":17,"content":543},[544,550,562,567,572,580,591,593,598,603,608,615,620,625,632,638,643,648,655,660,670,677,682,712],{"type":100,"attrs":545,"content":547},{"level":546,"textAlign":22},3,[548],{"text":549,"type":26},"And it’s the one that breaks modern infrastructure.",{"type":20,"attrs":551,"content":552},{"textAlign":22},[553,555,560],{"text":554,"type":26},"If you've ever benchmarked a VPN, you've probably done it the same way everyone else does: spin up ",{"text":556,"type":26,"marks":557},"iperf3",[558],{"type":559},"code",{"text":561,"type":26},", push as much TCP as the pipe will carry, and write down a Mbps number. It's a clean test. It's also the wrong number to chase for most of what runs on modern infrastructure.",{"type":20,"attrs":563,"content":564},{"textAlign":22},[565],{"text":566,"type":26},"APIs, dashboards, monitoring, control planes, CI agents, and database health checks. These aren't bandwidth-bound workloads. They open lots of short-lived connections, do a small amount of work, and tear down. For that pattern, throughput tells you almost nothing. Setup time tells you everything.",{"type":20,"attrs":568,"content":569},{"textAlign":22},[570],{"text":571,"type":26},"Xiid® benchmarked Terniion’s SealedTunnel technology against WireGuard, Tailscale, OpenVPN, IPsec, and a direct public path from an intentionally constrained edge client (Ubuntu on an older Xeon, behind WiFi, on a consumer\u002Fsatellite-class uplink) into six AWS and GCP endpoints. The throughput results were competitive. The setup time results weren't even close.",{"type":100,"attrs":573,"content":575},{"level":574,"textAlign":22},5,[576],{"text":577,"type":26,"marks":578},"Seven to twenty-two milliseconds. Across every path.",[579],{"type":231},{"type":20,"attrs":581,"content":582},{"textAlign":22},[583,586],{"type":236,"attrs":584},{"id":263,"alt":76,"src":264,"title":76,"source":76,"copyright":76,"meta_data":585},{},{"text":587,"type":26,"marks":588},"TCP setup time, median milliseconds across three runs. Lower is faster.",[589],{"type":590},"italic",{"type":20,"attrs":592},{"textAlign":22},{"type":20,"attrs":594,"content":595},{"textAlign":22},[596],{"text":597,"type":26},"Across every path tested, SealedTunnel's setup time stayed inside a 7-to-22 ms band. Everything else lived between 47 and 258 ms, with the long-haul AWS Singapore path pushing every traditional transport past a quarter-second.",{"type":20,"attrs":599,"content":600},{"textAlign":22},[601],{"text":602,"type":26},"The mechanism is straightforward. The application connects to a local STLink binding while the encrypted tunnel path is already established. So a new connection from your code to the local binding completes at near-loopback speed, regardless of how far the remote endpoint actually sits.",{"type":20,"attrs":604,"content":605},{"textAlign":22},[606],{"text":607,"type":26},"This is not raw network RTT, and we don't claim it is. The practical effect is what matters: application-level connection setup completes in single-digit milliseconds even across an intercontinental path.",{"type":100,"attrs":609,"content":610},{"level":546,"textAlign":22},[611],{"text":612,"type":26,"marks":613},"Setup time compounds fast.",[614],{"type":231},{"type":20,"attrs":616,"content":617},{"textAlign":22},[618],{"text":619,"type":26},"A request budget of 250 ms per TCP setup sounds tolerable until you put it in context. A modestly chatty service: think of a dashboard refreshing widgets, a health-check sweep, or an integration that polls a REST endpoint; can open a thousand connections in a minute. At 250 ms each, that's over four minutes of pure connection setup before a single byte of payload moves. Push the same workload through SealedTunnel and the same thousand connections cost about twenty seconds.",{"type":20,"attrs":621,"content":622},{"textAlign":22},[623],{"text":624,"type":26},"That's the difference between a dashboard that feels live and one that feels broken. It's the reason a teammate three time zones away thinks the system is down when it's just shaking hands.",{"type":100,"attrs":626,"content":627},{"level":546,"textAlign":22},[628],{"text":629,"type":26,"marks":630},"On the path where edge links break, throughput nearly doubled.",[631],{"type":231},{"type":20,"attrs":633,"content":634},{"textAlign":22},[635],{"type":236,"attrs":636},{"id":238,"alt":76,"src":239,"title":76,"source":76,"copyright":76,"meta_data":637},{},{"type":20,"attrs":639,"content":640},{"textAlign":22},[641],{"text":642,"type":26},"For completeness: SealedTunnel stayed inside the same practical throughput envelope as every other tested transport on US paths. On the long-haul AWS Singapore path, it pulled meaningfully ahead — 5.79 Mbps median TCP, versus 1.99-3.08 Mbps for the rest.",{"type":20,"attrs":644,"content":645},{"textAlign":22},[646],{"text":647,"type":26},"Intercontinental paths are where constrained edge links suffer most. In this run, SealedTunnel's path through the connector service delivered a better effective TCP route than even the direct public link.",{"type":100,"attrs":649,"content":650},{"level":546,"textAlign":22},[651],{"text":652,"type":26,"marks":653},"Speed is the bonus. Architecture is the product.",[654],{"type":231},{"type":20,"attrs":656,"content":657},{"textAlign":22},[658],{"text":659,"type":26},"And connection time is the visible win. SealedTunnel requires no open inbound ports on the protected endpoint. The tunnel is outbound-only. The endpoint is non-addressable from the public internet so there are no IPs to expose, no listeners to scan, no NAT traversal contortions. Access is process-to-process, not subnet-to-subnet, so a compromised endpoint cannot pivot across the network. There is nothing on the other end to pivot into except the specific service you mapped.",{"type":20,"attrs":661,"content":662},{"textAlign":22},[663,668],{"type":236,"attrs":664},{"id":665,"alt":76,"src":666,"title":76,"source":76,"copyright":76,"meta_data":667},187908457623230,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F1020x184\u002F6f92ff05cc\u002Fscreenshot-2026-06-03-082213.png",{},{"text":669,"type":26},"For organizations securing remote sites, field systems, regulated workloads, or critical infrastructure, that's the result that matters. The speed result is a nice surprise on top of it.",{"type":100,"attrs":671,"content":672},{"level":546,"textAlign":22},[673],{"text":674,"type":26,"marks":675},"Pick SealedTunnel when these are true.",[676],{"type":231},{"type":20,"attrs":678,"content":679},{"textAlign":22},[680],{"text":681,"type":26},"Reach for it when any of these describe your situation:",{"type":396,"content":683},[684,691,698,705],{"type":399,"content":685},[686],{"type":20,"attrs":687,"content":688},{"textAlign":22},[689],{"text":690,"type":26},"You can't open inbound ports, whether for regulated, field, or critical-infrastructure access.",{"type":399,"content":692},[693],{"type":20,"attrs":694,"content":695},{"textAlign":22},[696],{"text":697,"type":26},"Your workload is connection-chatty: APIs, dashboards, monitoring, short-lived service calls.",{"type":399,"content":699},[700],{"type":20,"attrs":701,"content":702},{"textAlign":22},[703],{"text":704,"type":26},"You're operating over messy edge links: NAT-heavy, satellite, and branch sites with consumer uplinks.",{"type":399,"content":706},[707],{"type":20,"attrs":708,"content":709},{"textAlign":22},[710],{"text":711,"type":26},"You need to limit lateral movement to specific services, not whole subnets.",{"type":20,"attrs":713,"content":714},{"textAlign":22},[715],{"text":716,"type":26},"Want the full methodology, raw data, and limitations in the Xiid edge-to-cloud benchmark paper? Read it, then run it yourself. A setup-time gap this wide either holds up or it doesn't.",{"id":718,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":719,"copyright":76,"fieldtype":457,"meta_data":720,"is_external_url":15},201601587046755,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F5472x3648\u002F3767323510\u002Fdeveloper-writes-ai-code-laptop.jpg",{},{"type":17,"content":722},[723],{"type":396,"content":724},[725,732,739],{"type":399,"content":726},[727],{"type":20,"attrs":728,"content":729},{"textAlign":22},[730],{"text":731,"type":26},"Throughput benchmarks are the wrong metric for modern infrastructure: APIs, dashboards, CI agents, and monitoring tools open many short-lived connections, where setup time — not bandwidth — determines whether a system feels live or broken.",{"type":399,"content":733},[734],{"type":20,"attrs":735,"content":736},{"textAlign":22},[737],{"text":738,"type":26},"In Xiid's benchmarks across AWS and GCP endpoints, SealedTunnel's TCP setup time stayed in a 7–22 ms band; every other transport (WireGuard, Tailscale, OpenVPN, IPsec) ranged from 47 to 258 ms, a difference that compounds to minutes of connection overhead on chatty workloads.",{"type":399,"content":740},[741],{"type":20,"attrs":742,"content":743},{"textAlign":22},[744],{"text":745,"type":26},"The speed advantage is a byproduct of architecture: SealedTunnel requires no open inbound ports, makes endpoints non-addressable from the public internet, and limits connectivity to process-to-process rather than subnet-to-subnet, eliminating lateral movement risk in addition to reducing latency.",{"id":718,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":719,"copyright":76,"fieldtype":457,"meta_data":747,"is_external_url":15},{},[],"TCP setup in 7-22 ms. Every other tested VPN: 47-258 ms. Why setup time, not throughput, is the metric that breaks modern infrastructure.","VPN setup time benchmark: SealedTunnel™ vs WireGuard, IPsec","vpn-setup-time-benchmark-sealedtunnel","blog\u002Fvpn-setup-time-benchmark-sealedtunnel","2026-06-03",-10,[],193139877037850,"cc858941-5ce0-4d46-b9a0-9f30b85cc8aa","2026-06-03T18:53:00.000Z",[],true,"ResourceFeatureCard","white","Tailscale made private networking painless. See where its device-trust model runs out of room, and how Terniion compares on real throughput and setup-time data.","terniion-vs-tailscale-speed-security-and-the-control-plane-question","blog\u002Fterniion-vs-tailscale-speed-security-and-the-control-plane-question",[],"49c885e4-b3a7-4c8a-abe6-8a610518e0bc","2026-09-11T20:27:13.081Z",[],[771],{"name":534,"created_at":535,"published_at":536,"updated_at":537,"id":538,"uuid":539,"content":772,"slug":751,"full_slug":752,"sort_by_date":753,"position":754,"tag_list":943,"is_startpage":15,"parent_id":756,"meta_data":22,"group_id":757,"first_published_at":758,"release_id":22,"lang":39,"path":22,"alternates":944,"default_full_slug":22,"translated_slugs":22},{"Tags":76,"_uid":77,"body":773,"title":534,"content":774,"component":453,"seoOgImage":916,"keyTakeaways":918,"previewImage":940,"previewTitle":534,"relatedContent":942,"seoDescription":749,"previewDescription":750},[],{"type":17,"content":775},[776,780,788,792,796,802,811,813,817,821,825,831,835,839,845,851,855,859,865,869,876,882,886,912],{"type":100,"attrs":777,"content":778},{"level":546,"textAlign":22},[779],{"text":549,"type":26},{"type":20,"attrs":781,"content":782},{"textAlign":22},[783,784,787],{"text":554,"type":26},{"text":556,"type":26,"marks":785},[786],{"type":559},{"text":561,"type":26},{"type":20,"attrs":789,"content":790},{"textAlign":22},[791],{"text":566,"type":26},{"type":20,"attrs":793,"content":794},{"textAlign":22},[795],{"text":571,"type":26},{"type":100,"attrs":797,"content":798},{"level":574,"textAlign":22},[799],{"text":577,"type":26,"marks":800},[801],{"type":231},{"type":20,"attrs":803,"content":804},{"textAlign":22},[805,808],{"type":236,"attrs":806},{"id":263,"alt":76,"src":264,"title":76,"source":76,"copyright":76,"meta_data":807},{},{"text":587,"type":26,"marks":809},[810],{"type":590},{"type":20,"attrs":812},{"textAlign":22},{"type":20,"attrs":814,"content":815},{"textAlign":22},[816],{"text":597,"type":26},{"type":20,"attrs":818,"content":819},{"textAlign":22},[820],{"text":602,"type":26},{"type":20,"attrs":822,"content":823},{"textAlign":22},[824],{"text":607,"type":26},{"type":100,"attrs":826,"content":827},{"level":546,"textAlign":22},[828],{"text":612,"type":26,"marks":829},[830],{"type":231},{"type":20,"attrs":832,"content":833},{"textAlign":22},[834],{"text":619,"type":26},{"type":20,"attrs":836,"content":837},{"textAlign":22},[838],{"text":624,"type":26},{"type":100,"attrs":840,"content":841},{"level":546,"textAlign":22},[842],{"text":629,"type":26,"marks":843},[844],{"type":231},{"type":20,"attrs":846,"content":847},{"textAlign":22},[848],{"type":236,"attrs":849},{"id":238,"alt":76,"src":239,"title":76,"source":76,"copyright":76,"meta_data":850},{},{"type":20,"attrs":852,"content":853},{"textAlign":22},[854],{"text":642,"type":26},{"type":20,"attrs":856,"content":857},{"textAlign":22},[858],{"text":647,"type":26},{"type":100,"attrs":860,"content":861},{"level":546,"textAlign":22},[862],{"text":652,"type":26,"marks":863},[864],{"type":231},{"type":20,"attrs":866,"content":867},{"textAlign":22},[868],{"text":659,"type":26},{"type":20,"attrs":870,"content":871},{"textAlign":22},[872,875],{"type":236,"attrs":873},{"id":665,"alt":76,"src":666,"title":76,"source":76,"copyright":76,"meta_data":874},{},{"text":669,"type":26},{"type":100,"attrs":877,"content":878},{"level":546,"textAlign":22},[879],{"text":674,"type":26,"marks":880},[881],{"type":231},{"type":20,"attrs":883,"content":884},{"textAlign":22},[885],{"text":681,"type":26},{"type":396,"content":887},[888,894,900,906],{"type":399,"content":889},[890],{"type":20,"attrs":891,"content":892},{"textAlign":22},[893],{"text":690,"type":26},{"type":399,"content":895},[896],{"type":20,"attrs":897,"content":898},{"textAlign":22},[899],{"text":697,"type":26},{"type":399,"content":901},[902],{"type":20,"attrs":903,"content":904},{"textAlign":22},[905],{"text":704,"type":26},{"type":399,"content":907},[908],{"type":20,"attrs":909,"content":910},{"textAlign":22},[911],{"text":711,"type":26},{"type":20,"attrs":913,"content":914},{"textAlign":22},[915],{"text":716,"type":26},{"id":718,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":719,"copyright":76,"fieldtype":457,"meta_data":917,"is_external_url":15},{},{"type":17,"content":919},[920],{"type":396,"content":921},[922,928,934],{"type":399,"content":923},[924],{"type":20,"attrs":925,"content":926},{"textAlign":22},[927],{"text":731,"type":26},{"type":399,"content":929},[930],{"type":20,"attrs":931,"content":932},{"textAlign":22},[933],{"text":738,"type":26},{"type":399,"content":935},[936],{"type":20,"attrs":937,"content":938},{"textAlign":22},[939],{"text":745,"type":26},{"id":718,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":719,"copyright":76,"fieldtype":457,"meta_data":941,"is_external_url":15},{},[],[],[],[],{"cache-control":46,"connection":47,"content-encoding":947,"content-type":49,"date":948,"etag":949,"referrer-policy":52,"sb-be-version":53,"server":54,"transfer-encoding":950,"vary":951,"via":952,"x-amz-cf-id":953,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":954,"x-runtime":955,"x-xss-protection":65},"gzip","Fri, 11 Sep 2026 20:48:01 GMT","W\u002F\"c3b5092f64b09826c9866be23dbab1cb\"","chunked","Origin,Accept-Encoding","1.1 03093c003b20d410ed3ec3e4bb2d569c.cloudfront.net (CloudFront)","gHclwKGdwL6L2B3oDuzKWyXEBJUnlh4Y0uLSdy1R62koxs4FKBeBqA==","5e4b8ad3-6f2e-47f5-8dde-3463f3d4257d","0.033236",1789159680911]