Secure access without the network
An ecosystem that makes fleet work effortless for employees and contractors.
Write to us — we'll answer and show a demo: [email protected]
01 · Problem
How do you organize access?
ATMs, CNC machines, substations — a fleet of thousands of devices with no reliable connectivity. Engineers need access to workstations and devices that is accountable and works offline.
Option A
One shared account everywhere
- one password for thousands of devices
- the journal shows the same account, not a person
- revoking one engineer means rotating the password fleet-wide
Option B
Personal accounts on every device
- a hundred engineers and a thousand devices — a hundred thousand accounts
- every hire, departure or rotation updates the whole fleet
- unmanageable on an offline fleet
The best option — Tessera
Role accounts + identity in the credential
- accounts on the device follow roles, not people
- who logged in, under which role and for how long — written in the credential
- full accountability for every login
- accounts don't multiply
- access revoked per person, no password rotation
- works offline
What about classic access systems? Vault, Teleport, LDAP/Active Directory and other centralized systems must reach their server at login time: no connectivity — no access (or a hole that bypasses the check). A fleet with no network egress at all is simply out of their reach.
02 · Products
One ecosystem, three products
Tessera Access
Certificate login
Certificate-based authentication for workstations and devices — offline, with rights handed down a chain: every link can only narrow the rights. Already in production across bank ATM fleets.
Every login carries a person's name; the journal can't be forged; access is revoked per person.
Learn more →Tessera Codes
One-time-code login
The engineer's phone instead of a hardware key. The code is one-time, bound to the device, verified offline.
The same accountability, with nothing to hand out — a phone is enough.
Learn more →Census
Access as code
The permissions and service accounts of the whole Linux fleet live in one signed file. Deviations from it are visible at once. Open source.
You see who holds which rights on every machine — before an incident, not after.
Learn more →How to choose
- Fully offline, even with no server at all → Tessera Access
- You can run a server — and logins get simpler: a phone instead of a hardware key → Tessera Codes
- Putting the machines' own permissions in order → Census
03 · Comparison
How is this different from AD, LDAP and bastions?
The difference is not a feature list — it's the architecture: where the access decision lives.
| Criterion | Tessera | Active Directory / LDAP | PAM bastions (Vault, Teleport) |
|---|---|---|---|
| Login without connectivity | Normal mode: validation happens entirely on the device | Needs a domain controller; cached logon helps briefly and only those who logged in before | No link to the bastion — no login |
| Devices with no network egress | The primary scenario | The device must be domain-joined and able to see the domain | Not applicable |
| Accounts on the device | Accounts follow roles, not people; identity lives in the credential | A personal account for every engineer | Shared accounts hidden behind the bastion |
| Revoking access | Revocation list + short validity: access expires on its own | Disabling the account takes effect once the device sees the domain | Instant, while the server is up |
| Contractors | Delegation: the contractor issues to their people, rights can only narrow | Accounts in your domain, or cross-domain trusts | Temporary accounts on the server |
| Login audit | A tamper-evident journal on the device itself | Logs live on the controller; an offline device stays silent | Session recording on the proxy |
04 · Open core
Open core, commercial management
Open AGPL-3.0
- Tessera Engine — login validation and rights enforcement
- Tessera Login — Linux login module (PAM)
- Certificate login
- Basic roles: groups, sudoers
- Tamper-evident action journal on the device
Commercial enterprise
- Tessera Control — fleet management, access revocation, inventory
- Tessera Codes — one-time QR codes
- Astra mandatory-integrity adapter
- SELinux adapter
- Fleet-wide journal collection, SIEM export
- GOST cryptography (CryptoPro)
- Windows adapter roadmap
The principle: everything that checks a login on the device is open source — your security team can read it. Credential issuance, delivery and fleet management are commercial.
Let's discuss a pilot
We'll show offline login on your scenario: ATMs, a shop floor, substations. Tell us about your fleet — we'll come back with a concrete pilot plan.
or email us: [email protected]