
Application-Aware Zero Trust Access and Privileged Access Management for Infrastructure
Border0 delivers secure access to private infrastructure for engineering, DevOps and security teams, positioning itself as an application-aware VPN that doubles as a privileged access management platform. Founded by Andree Toonk alongside a team of engineers who had built and operated large-scale internet infrastructure, the company grew out of frustration with juggling multiple VPNs, bastion hosts and static credentials scattered across systems. It keeps an office in Vancouver and runs its service as a globally distributed cloud platform.
Access is organized around what the platform calls sockets: application-aware proxy endpoints representing SSH servers, internal web applications, Kubernetes clusters, RDP and VNC desktops, databases such as PostgreSQL, MySQL, MSSQL, MongoDB and Snowflake, generic TCP services and subnet routes. A connector deployed inside customer infrastructure terminates sessions, evaluates policy in real time, injects credentials and records activity, while WireGuard-encrypted tunnels carry traffic so nothing is exposed publicly. Policies gate access by who, what, when and where against the organization's SSO identity store.
Rather than forcing a choice between VPN simplicity and PAM depth, the platform layers both: teams start with a familiar client, then add identity-aware application-level controls, just-in-time access requests aimed at zero standing privileges, session replay for SSH, database and HTTP traffic, and Terraform and REST API management for GitOps workflows. A WebAssembly client portal provides clientless browser access. In March 2026 Tailscale acquired the company, with the team joining to build out Tailscale's privileged access management capabilities.



