Secure access without the network

An ecosystem that makes fleet work effortless for employees and contractors.

Write to us — we'll answer and show a demo: [email protected]

01 · Problem

How do you organize access?

ATMs, CNC machines, substations — a fleet of thousands of devices with no reliable connectivity. Engineers need access to workstations and devices that is accountable and works offline.

Option A

One shared account everywhere

  • one password for thousands of devices
  • the journal shows the same account, not a person
  • revoking one engineer means rotating the password fleet-wide

Option B

Personal accounts on every device

  • a hundred engineers and a thousand devices — a hundred thousand accounts
  • every hire, departure or rotation updates the whole fleet
  • unmanageable on an offline fleet

The best option — Tessera

Role accounts + identity in the credential

  • accounts on the device follow roles, not people
  • who logged in, under which role and for how long — written in the credential
  • full accountability for every login
  • accounts don't multiply
  • access revoked per person, no password rotation
  • works offline

What about classic access systems? Vault, Teleport, LDAP/Active Directory and other centralized systems must reach their server at login time: no connectivity — no access (or a hole that bypasses the check). A fleet with no network egress at all is simply out of their reach.

03 · Comparison

How is this different from AD, LDAP and bastions?

The difference is not a feature list — it's the architecture: where the access decision lives.

Comparison of Tessera with Active Directory/LDAP and PAM bastions
Criterion Tessera Active Directory / LDAP PAM bastions (Vault, Teleport)
Login without connectivity Normal mode: validation happens entirely on the device Needs a domain controller; cached logon helps briefly and only those who logged in before No link to the bastion — no login
Devices with no network egress The primary scenario The device must be domain-joined and able to see the domain Not applicable
Accounts on the device Accounts follow roles, not people; identity lives in the credential A personal account for every engineer Shared accounts hidden behind the bastion
Revoking access Revocation list + short validity: access expires on its own Disabling the account takes effect once the device sees the domain Instant, while the server is up
Contractors Delegation: the contractor issues to their people, rights can only narrow Accounts in your domain, or cross-domain trusts Temporary accounts on the server
Login audit A tamper-evident journal on the device itself Logs live on the controller; an offline device stays silent Session recording on the proxy

04 · Open core

Open core, commercial management

Open AGPL-3.0

  • Tessera Engine — login validation and rights enforcement
  • Tessera Login — Linux login module (PAM)
  • Certificate login
  • Basic roles: groups, sudoers
  • Tamper-evident action journal on the device

Commercial enterprise

  • Tessera Control — fleet management, access revocation, inventory
  • Tessera Codes — one-time QR codes
  • Astra mandatory-integrity adapter
  • SELinux adapter
  • Fleet-wide journal collection, SIEM export
  • GOST cryptography (CryptoPro)
  • Windows adapter roadmap

The principle: everything that checks a login on the device is open source — your security team can read it. Credential issuance, delivery and fleet management are commercial.

Let's discuss a pilot

We'll show offline login on your scenario: ATMs, a shop floor, substations. Tell us about your fleet — we'll come back with a concrete pilot plan.

or email us: [email protected]