Konfirmity
Tailscale logo

Secure your Tailscale surface

ACL scope, node key expiry, and devices reaching further across the tailnet than they should. We don’t connect to Tailscale to collect evidence for its own sake — we connect to secure it, and the compliance artefacts follow from that work.

Book a Demo

[01] What This Surface Exposes

Where Tailscale goes wrong

Tailscale goes wrong quietly: disabling key expiry is a convenience that removes the control keeping lost devices out of your network.

  • ACLs permitting broad any-to-any access across the tailnet
  • Node keys with expiry disabled, so a lost device retains access indefinitely
  • Subnet routers advertising wider ranges than intended
  • Exit nodes enabled without a decision about what traffic they carry
  • Devices belonging to leavers still present and connected

[02] What We Secure

What we watch, catch and fix on Tailscale

On Tailscale we resolve ACL policy into effective device-to-service reachability rather than reading it as a statement of intent.

  • ACL policy resolved to effective device-to-service reachability, not read as intent
  • Key expiry checked per node, since disabling it is a convenience that removes the control
  • Subnet route advertisements audited against the intended network boundary
  • Device inventory reconciled against your HR record
  • Tailnet membership reviewed as a network access decision

[03] Where It Lands

Where Tailscale lands in your registers

Directory data drives your access reviews directly: reviewers see live entitlements rather than a spreadsheet exported three weeks ago, and leaver revocation is verified against the systems themselves. The asset register records each identity provider as a critical dependency, and the risk register carries the concentration risk that comes with it — because if this tier fails, everything behind it fails with it.

[04] How We Engage

On Tailscale specifically

On Tailscale, we remove leaver devices, re-enable key expiry, and tighten ACLs under agreed authority. Redesigning the tailnet access model we plan with your infrastructure team.

Platform licence

Everything you need to find and fix it yourself, with no ceiling on the depth of the answer.

  • Every connected tool monitored for misconfiguration and drift, with findings mapped to the assets and risks they affect
  • Remediation guidance that tells you what is wrong and exactly how to fix it — however deep or awkward the issue is. We are engineers running a security company, so the answer is the real one, not a link to vendor documentation
  • Assets, access reviews, and risk register populated from the tools themselves rather than from spreadsheets
  • Unlimited integrations and unlimited users, with anything missing built within two weeks

Managed service

Every tool you connect through Konfirmity comes under our care, with our team doing the work.

  • Continuous misconfiguration and drift monitoring across every connected tool, watched by our analysts rather than by a dashboard waiting for you
  • Incident response led by us, with containment coordinated with your team
  • Remediation performed directly wherever you have granted us the authority to act — and where we cannot act, we project-manage the fix to completion rather than handing you a ticket
  • Decision support on the tools themselves: where something is failing you on capability or costing more than it returns, we will tell you, and help you replace it

[05] Tailscale FAQs

What Tailscale access does Konfirmity need?

Konfirmity needs an API key with read access to devices, ACLs and the tailnet configuration. That covers device inventory, key expiry state and policy analysis. We do not need the ability to modify ACLs unless you ask us to remediate directly.

Why does key expiry matter so much?

Because disabling it means a device retains network access indefinitely, including a laptop that has been lost or belongs to someone who left. Konfirmity checks expiry per node rather than at tailnet level, since it is disabled per device and easy to miss.

[06] Related Integrations

Other identity & access tools we secure:

View all integrations