Teleport
Open-source infrastructure identity platform with strong enterprise logos and a stale 2022 unicorn valuation.
Teleport has real product depth and enterprise proof, but investment underwriting is constrained by a stale 2022 unicorn valuation, unverified current ARR, and licensing and procurement friction risks.
Cover facts
Company profile
Teleport is a private infrastructure identity company founded in 2015 that unifies access and policy for servers, Kubernetes clusters, databases, web apps, machines, and AI agents. The company grew from an open-source access project into a multi-module commercial platform spanning Zero Trust Access, Machine and Workload Identity, Identity Governance, Identity Security, and the Beams agentic runtime. Teleport has raised $165M across three disclosed rounds, reached a $1.1B valuation in May 2022, and has strong named customer proof across technology, fintech, and regulated infrastructure, but its current financial profile remains largely undisclosed.
- Website
- goteleport.com
- Founded
- 2015-01-01
- Founders
- Ev Kontsevoy, Alexander Klizhentas, Taylor Wakefield
- Founding location
- Oakland, California, USA
- Headquarters
- Oakland, California, USA
- Product
- Certificate-based infrastructure identity platform covering SSH, Kubernetes, databases, web apps, Windows/RDP, MCP servers, machine identities, and AI-agent runtimes.
- Customers
- Mid-market and enterprise engineering, platform, security, fintech, and regulated infrastructure teams.
- Business model
- Usage-based enterprise SaaS and self-hosted software monetized by monthly active users, machine/workload identities, and protected resources; free community tier only for smaller companies.
- Stage
- Series C private
- Funding status
- $110M Series C at $1.1B valuation in May 2022; $165M disclosed total funding; no verified new round since.
Executive summary
Top strengths
- Unified certificate-based access architecture across SSH, Kubernetes, databases, web apps, and machine identities.
- Open-source distribution and strong developer credibility supported by a large GitHub footprint.
- Blue-chip named customers including Nasdaq, DoorDash, IBM Instana, Carta, Samsung, Elastic, and Snowflake.
- Strong investor syndicate with Kleiner Perkins, S28, Bessemer, and Insight supporting category creation.
- New AI-agent identity and Beams positioning may create an additional growth wedge if adoption materializes.
Top risks
- The $1.1B Series C valuation is stale and screens rich versus 2026 public identity and PAM comparables.
- The only current ARR figure ($49M for 2024) is a third-party estimate rather than company-confirmed data.
- The June 2024 community-license change may weaken bottom-up conversion and community goodwill.
- Public sources support FedRAMP compliance tooling, but do not verify a FedRAMP authorization for Teleport Cloud itself.
- Large competitors and cloud-native alternatives can bundle adjacent identity and privileged-access capabilities.
Open gaps
- Current ARR, gross margin, burn, cash runway, and NRR are not publicly disclosed.
- The 600+ customer figure is company-stated and not independently verified.
- Teleport Cloud FedRAMP authorization status remains unconfirmed from accessible public sources.
- Cap-table terms, liquidation preferences, and board composition beyond announced investors remain private.
- Secondary-market pricing or any refreshed post-2022 valuation evidence is not publicly available.
Contents
01Company Overview
1.1 Identity, mission, product, and headquarters
Teleport is the self-described "AI Infrastructure Identity Company," headquartered at 2100 Franklin St, Suite 400, Oakland, California 94612. The company modernizes identity, access, and policy for infrastructure, positioning the product as a platform that simultaneously improves engineering velocity and raises resilience against identity-based attacks. The company was originally incorporated as Gravitational Inc. and renamed itself Teleport in 2021, migrating from gravitational.com to goteleport.com; the blog post announcing the name change explicitly states that the Teleport product became the company's primary focus. The legal entity retains the Gravitational Inc. corporate name on package-signing certificates (Apple Developer ID QH8AA5B8UP Gravitational Inc.), confirming the corporate continuity. Teleport describes its product as a unified identity layer that replaces fragmented access management systems across servers (SSH), Kubernetes, databases, RDP, web applications, and MCP servers with a certificate-authority model that issues short-lived credentials tied to the identity of the requestor. This architecture aligns with the NIST SP 800-207 Zero Trust Architecture framework, which defines zero trust as eliminating implicit trust based on network location and requiring per-request authentication and authorization. The revenue model, per the public pricing page, is usage-based, metered by Monthly Active Users (MAU), Machine and Workload Identities (MWI), and Teleport Protected Resources (TPR). A free Community Edition exists for companies under 100 employees and $10M in annual revenue, while Enterprise Edition requires commercial engagement. The company is privately held; no revenue, margin, cash, or burn data is publicly disclosed.[CO001, CO002, CO003, CO004, CO005, CO006]
| metric | value/status | date | confidence | gap |
|---|---|---|---|---|
| Founding year | 2015 | 2015 | high | |
| Legal name | Gravitational Inc. (d/b/a Teleport) | 2021 | high | |
| Headquarters | 2100 Franklin St Suite 400 Oakland CA 94612 | 2026-06 | high | |
| Stage | Private / Series C | 2022-05 | high | |
| Latest valuation (USD B) | 1.1 | 2022-05 | medium | No post-2022 round confirmed; mark is ~4 years stale |
| Series A raised (USD M) | 25 | 2019 approx | high | Exact date not stated in blog |
| Series B raised (USD M) | 30 | 2021 | high | |
| Series C raised (USD M) | 110 | 2022-05 | high | |
| Total disclosed raised (USD M) | 165 | 2022-05 | high | |
| ARR 2024 (USD M, estimated) | ~49 (GetLatka, unconfirmed) | 2024-12 | low | Unverified third-party estimate; not confirmed by company |
| Headcount (estimated) | ~246 (GetLatka Nov 2025) | 2025-11 | low | Estimated; no official headcount disclosed |
| GitHub stars | 15000+ | 2024-06 | medium | As of community license blog post; may have grown |
| Named customers | 600+ | 2026-06 | medium | Company claim; no third-party verification of total count |
| Revenue model | Usage-based (MAU / MWI / TPR) | 2026-06 | high | |
| Source code license | AGPLv3 (unchanged) | 2024-06 | high | |
| Binary/image license | Commercial (restricted for large cos since Teleport 16) | 2024-06 | high | |
| FedRAMP status | FIPS/compliance tooling only — no SaaS ATO confirmed | 2026-06 | medium | No public evidence of ATO for Teleport Cloud |
All financial figures are disclosed company data unless noted as estimated. GetLatka ARR and headcount are third-party estimates and are not independently confirmed. Valuation is the 2022 Series C mark; no refresh is available.
[CO001, CO004, CO014, CO015, CO016, CO018]Publicly supportable KPIs show a well-capitalized private company with strong enterprise logos, but key financial metrics remain unconfirmed and the valuation mark is four years stale.
ARR and headcount are GetLatka third-party estimates; all other values are from disclosed company or investor materials.
[CO014, CO015, CO016, CO017, CO018, CO020]1.2 Founders, leadership, and key-person concentration
Teleport was founded in 2015 by three co-founders who met while working at Rackspace following that company's acquisition of Mailgun, a developer email infrastructure startup the three had built. Ev Kontsevoy serves as CEO and is the primary public voice for the company. Alexander Klizhentas (known as Sasha) serves as CTO. Taylor Wakefield serves as COO. All three remain in active executive roles, as confirmed by the Teleport about page as of the run date. The founders' shared background in cloud infrastructure and developer tooling is the clearest founder-market fit signal available in public sources. Leadership beyond the founding team includes Jeff Bunten as CRO and Diana Jovin as CMO, both of whom appear in external press coverage. Jovin was quoted at RSAC in April 2026 and is cited in the newsroom as CMO. Bunten is listed on the about page as CRO. Key-person risk is material: Kontsevoy is the signatory for all three fundraising announcements, is the named spokesperson for the Agentic Identity Framework launch and the Fortune Cyber 60 announcement, and is cited in every major external interview. No public board membership beyond the investors named at funding rounds is disclosed by the company.[CO007, CO008, CO009, CO010, CO011, CO012]
| person | role | background | founder-market fit / functional coverage | key-person dependency |
|---|---|---|---|---|
| Ev Kontsevoy | Co-founder and CEO | Co-founded Mailgun (acquired by Rackspace); built cloud infrastructure at Rackspace | Deep infrastructure and developer-tooling context; led all three fundraising rounds | Critical — all fundraising, public strategy, and external spokesperson roles concentrated |
| Alexander Klizhentas | Co-founder and CTO | Co-founded Mailgun with Kontsevoy; distributed systems and security engineering background | Technical leadership for open-source core and enterprise product architecture | High — technical roadmap and architecture decisions |
| Taylor Wakefield | Co-founder and COO | Co-founded Mailgun; go-to-market and operational leadership background | Operational scale-up; co-leads alongside Kontsevoy on commercial execution | Medium — supports CEO but shared operational weight reduces single-point risk |
| Jeff Bunten | CRO | Enterprise sales leadership; joined after Series C to scale commercial motion | Enterprise revenue growth; owns sales and channel | Medium — external-facing revenue but accountable to founders |
| Diana Jovin | CMO | Cybersecurity marketing background; quoted at RSAC 2026 | Brand, demand generation, and product marketing for the AI infrastructure identity narrative | Low — marketing function; replaceable at market |
Board composition beyond named investor board members (Mary D'Onofrio / Bessemer; Matt Koran / Insight observer) is not disclosed. No independent director names appear in public materials.
[CO007, CO008, CO009, CO010, CO011, CO012]1.3 Funding history, valuation, and capital structure
Teleport has disclosed three funding rounds totaling $165M. The first was a $25M Series A led by Kleiner Perkins, announced on the company blog when the company was still operating as Gravitational. The Series A blog post named early customers NASDAQ, Splunk, TicketMaster, Mulesoft, and Samsung, and noted the company had recently reached profitability. The Series A was followed by a $30M Series B led by S28 Capital and Kleiner Perkins in 2021; that round followed a quarter with net new ARR up 5x year-over-year and ARR up 2.5x compared to Q2 2020, suggesting the company's revenue was scaling rapidly off a small base. The company did not disclose ARR in dollar terms at that time. The largest round, a $110M Series C led by Bessemer Venture Partners with participation from Insight Venture Partners, was announced in May 2022 at a $1.1B valuation. Bessemer's investment blog (bvp.com) and the Teleport announcement blog both confirm this valuation. The Series C named ARR up 2.8x year-over-year and net new ARR up 4.5x at the time of the round, and came less than a year after the Series B. Mary D'Onofrio from Bessemer joined the board; Matt Koran from Insight joined as a board observer. No public evidence of a subsequent funding round after May 2022 has been identified. The $1.1B valuation mark is therefore approximately four years old as of the run date, and private-market conditions have materially changed since then. GetLatka, a third-party data aggregator, reported in a 2025 snapshot that Teleport raised $140M across two rounds, which differs from the company's disclosed $165M across three rounds. GetLatka also estimated the company's 2024 revenue at $49M and headcount at approximately 246 as of late 2025; these figures are unconfirmed third-party estimates and should not be treated as verified financial data.[CO013, CO014, CO015, CO016, CO017, CO018]
| stakeholder | role | investment / involvement | control or economic importance | diligence ask |
|---|---|---|---|---|
| Kleiner Perkins | Led Series A; co-led Series B | $25M Series A + participation in $30M Series B | Earliest institutional backer; board presence implied but not confirmed post-C | Confirm current board seat or observer status and ownership stake |
| S28 Capital | Led Series B alongside Kleiner Perkins | Co-lead of $30M Series B | Series B lead; stake likely diluted at Series C | Confirm current ownership stake and any governance rights |
| Bessemer Venture Partners | Led Series C | $110M Series C; Mary D'Onofrio joined board | Largest disclosed external investor; current board seat confirmed at round | Confirm board composition and current ownership stake post-Series C |
| Insight Venture Partners | Participated in Series C | Significant participation in $110M Series C; Matt Koran board observer | Series C participant; board observer rights at round date | Confirm observer status and current ownership stake |
| Ev Kontsevoy / Klizhentas / Wakefield | Founding management team | Founding equity; no buyout or secondary disclosed | Likely controlling shareholders; internal cap table unknown | Obtain cap table from company counsel to confirm ownership and dilution |
| Employee equity holders | Current and former employees | Standard equity grants; option pool size unknown | Collective alignment mechanism; option pool overhang affects dilution math | Request option pool size and vesting schedule data from company |
| S28 Capital follow-on | Potential follow-on investors | Not confirmed post-Series C; no public evidence of follow-on | Unknown; no post-2022 round disclosed | Request latest cap table and any ROFR or pro-rata rights exercised |
Cap table is private; all stakes are inferred from public fundraising disclosures and may not reflect secondary transactions or grants since the Series C. GetLatka shows $140M raised across 2 rounds, diverging from the disclosed $165M across 3 rounds.
[CO014, CO015, CO016, CO017, CO018, CO019]Teleport's public record runs from a 2015 founding through a $1.1B Series C in 2022 and into an AI-agent product expansion in 2026, with the 2024 license change as the most adverse operational milestone.
Series A date is approximate (2019 is inferred from KP perspectives post; exact close month is not confirmed in reviewed sources). All other dates are from official announcements.
[CO013, CO014, CO015, CO016, CO025, CO027]1.4 Milestones, scale, and product evolution
Teleport's milestone history shows a company that moved from a developer-focused access tool to a full infrastructure identity platform over roughly a decade. The open-source Teleport project was made public in 2016 on GitHub under the AGPLv3 license; the repository had accumulated over 15,000 stars by the time of the June 2024 community license blog post. The company added Kubernetes access, database access (PostgreSQL, MongoDB, MySQL), Windows RDP access, and most recently MCP server access across successive major releases. Teleport 16 (June 2024) and Teleport 17 (October 2024) are the most recent major versions, with Teleport adopting an annual major-release cadence. Named customer logos that appear in official materials include NASDAQ, Snowflake, DoorDash, IBM (Instana), Carta, GoTo, Exness, KnowBe4, Turo, Gladly, ThredUP, ExtraHop, and others. The case-study page lists more than a dozen detailed case studies, and the careers page references "more than 600 customers around the globe." The company received recognition in 2025 and 2026 from the Fortune Cyber 60 list (October 2025) and the Citizens Securities Cyber 66 list (April 2026). In January 2026 Teleport launched the Agentic Identity Framework, an AI-focused roadmap for securing AI agents in production infrastructure. In June 2026 Teleport announced Beams, a new product providing trusted runtimes for AI agents at beams.run.[CO024, CO025, CO026, CO027, CO028, CO029]
| date | event | type | amount/valuation/status | participants | implication |
|---|---|---|---|---|---|
| 2015 | Gravitational Inc. founded; Teleport project begun | founding | $0 funding | Ev Kontsevoy, Alexander Klizhentas, Taylor Wakefield | Infrastructure access for multi-cloud identified as the founding problem |
| 2016 | Teleport open-sourced on GitHub under AGPLv3 | product | 15,000+ GitHub stars by 2024 | Gravitational team | Open-source adoption strategy; community growth becomes competitive moat |
| 2016-2018 | Early customer base — NASDAQ, Splunk, Samsung named at Series A | scale | Gravitational | Enterprise logos acquired before institutional capital; proof of enterprise demand | |
| 2019 (approx) | Series A closed led by Kleiner Perkins | financing | $25M raised; KP led | Kleiner Perkins (Bucky Moore) | First institutional capital; company had recently reached profitability |
| 2021 | Series B closed led by S28 Capital and Kleiner Perkins | financing | $30M raised; ARR 2.5x YoY vs Q2 2020 | S28 Capital, Kleiner Perkins; Bucky Moore quote cited | ARR tripling trajectory confirmed; database access (MongoDB) launched with round |
| 2021 | Gravitational officially renames to Teleport; moves to goteleport.com | governance | Gravitational/Teleport leadership | Brand unified around product name; corporate entity remains Gravitational Inc. | |
| 2022-05 | Series C closed led by Bessemer Venture Partners | financing | $110M raised; $1.1B valuation | Bessemer (Mary D'Onofrio), Insight (Matt Koran observer) | Unicorn milestone; ARR 2.8x YoY at round; last known external valuation |
| 2024-06 | Teleport 16 released; community binary license changed to commercial | product | Teleport team | Compiled binaries/images restricted to commercial license; AGPLv3 source unchanged | |
| 2025-10-30 | Named to 2026 Fortune Cyber 60 list | regulatory | Fortune / Lightspeed / AWS | Third-party growth recognition; 600+ customer reference cited in press release | |
| 2026-01-27 | Agentic Identity Framework launched | product | Teleport; Ev Kontsevoy statement | AI-first identity roadmap; positions Teleport for agentic AI infrastructure security | |
| 2026-04-07 | Named to Citizens Securities Cyber 66 list | regulatory | Citizens Securities cybersecurity research team | Peer recognition as hottest private cybersecurity company; AI identity angle highlighted | |
| 2026-06 | Beams public beta launched at beams.run | product | Teleport | Separate product for AI agent infrastructure; expands TAM beyond human/machine identity |
Dates without month/day are approximate from blog posts. Series A date is inferred from KP perspectives post; exact month not confirmed. No funding event is confirmed after the May 2022 Series C.
[CO013, CO014, CO015, CO016, CO024, CO025]Teleport's open-source community and enterprise customer base feed a usage-based revenue engine, constrained by a stale 2022 valuation mark, a restricted community license, and an unconfirmed FedRAMP ATO gap.
[CO001, CO006, CO014, CO015, CO016, CO024]1.5 License change, FedRAMP positioning gap, and adverse signals
The most material recent adverse development is the June 2024 community license change. Starting with Teleport 16, the company switched compiled Community Edition binaries and container images from Apache 2.0 to a commercial license. The new license allows free commercial use only for companies with fewer than 100 employees and under $10M in annual revenue. The AGPLv3 license on the source code repository was not changed, meaning large companies can still compile from source, but the convenience of downloading pre-built binaries is now restricted. This move is consistent with other open-core companies protecting community monetization but represents a clear tightening of the community offering that some users and enterprises noticed critically. On FedRAMP, Teleport's public documentation and marketing describe the product as enabling customers to meet FedRAMP compliance requirements. Teleport Enterprise builds are compiled against FIPS 140-validated cryptographic modules, and the FedRAMP documentation page describes how Teleport helps achieve specific FedRAMP controls. However, no evidence in the publicly available corpus confirms that Teleport's own cloud service has received a FedRAMP Authorization To Operate (ATO). The FedRAMP positioning is as a compliance-enabling tool, not as a FedRAMP-authorized service provider. This gap matters for federal buyers who may expect the SaaS itself to carry an ATO. Adverse product signals from third-party review platforms are also notable. PeerSpot reviewers cite initial setup complexity, RBAC configuration difficulty, and integration challenges with SIEM and monitoring tools. A competitor comparison page from StrongDM claims Teleport's agent-based architecture requires agents running as root on every monitored server, creating a new attack surface; the same page claims Teleport Cloud has reliability issues including outages during updates. These claims originate from a competing vendor and should be read critically, but they represent the categories of weakness that evaluating buyers consider.[CO033, CO034, CO035, CO036, CO037, CO039]
1.6 Exhibits
02Market Analysis
2.1 Market Scope, Adjacencies, and Substitutes
Teleport's own positioning and product architecture make the market boundary broader than classic privileged access management but narrower than the entire zero-trust stack. The company describes itself as an AI Infrastructure Identity company and sells certificate-based access for SSH, Kubernetes, databases, Windows, internal web apps, machine identities, and AI-related infrastructure workflows. That means the included spend is the control plane for infrastructure access: privileged access, workload identity, access audit, and compliance-oriented infrastructure access modernization. It does not justify counting broad workforce IAM, customer identity, endpoint security, SIEM, or general AI application spend as core market value, even if those budgets sometimes influence the deal. The status quo substitute set is still large — VPNs, bastions, long-lived keys, database passwords, cloud-native point IAM, and manual audit workflows all compete for the same job. An adverse competitor view from StrongDM is useful here because it argues Teleport remains a point solution for modern cloud estates rather than a universal access platform, which is a real constraint on inflated TAM narratives.[CM001, CM002, CM003, CM004, CM005, CM006]
| Segment/Category | Included Spend | Excluded Spend | Primary Buyer | Relevance to Teleport |
|---|---|---|---|---|
| Privileged access management for infrastructure | Privileged-session control, just-in-time access, audit, database and server access brokering | General workforce SSO, consumer identity, non-privileged app login | CISO / security engineering | Core narrow market lens and closest paid control budget |
| Zero-trust infrastructure access | Identity-aware access for SSH, Kubernetes, databases, RDP, internal web apps, policy enforcement | Endpoint, network, and data controls not tied to infrastructure access workflows | Security architecture / platform engineering | Broader but still relevant adjacent market lens |
| Machine and workload identity | Certificate issuance for bots, services, CI-CD, and infrastructure workloads | General secrets management or PKI spend unrelated to access workflows | Platform engineering / security platform | High relevance because Teleport monetizes MWI directly |
| Compliance and audit automation tied to access | FedRAMP, SOC 2, evidence capture, session recording, access review support | Full GRC suite spend, external auditor fees, broad compliance consulting | Security / compliance / public-sector program owner | Adjacency that expands deal value but should not be counted as standalone TAM |
| AI agent identity and access control | Identity, authorization, and audit for agentic infrastructure actions and MCP-linked workflows | General AI model training, application-layer copilots, and non-infrastructure AI tooling | Security platform / AI platform owner | Emerging expansion vector for Teleport's positioning |
| Workforce IAM / CIAM / endpoint or SIEM tools | Only admin-access slices that directly touch infrastructure identity | Routine employee SSO, customer identity, endpoint prevention, general log analytics | CIO / IAM / IT operations | Adjacent but mostly excluded from core Teleport market sizing |
Boundary table separates the monetizable infrastructure-identity control plane from broader identity, endpoint, and analytics categories that may influence deals but should not be counted as core TAM.
[CM001, CM002, CM004, CM005, CM006, CM007]2.2 Sizing Lenses and Estimate Variance
The sizing evidence supports a layered view rather than a single headline TAM. A narrow PAM lens from Precedence Research puts the market at $4.50 billion in 2025, while two broader zero-trust estimates place the market around $36.96 billion in 2024 and $40.01 billion in 2025, with long-range forecasts extending materially higher. Teleport likely sits between those lenses because it addresses privileged infrastructure access and identity control, but does not capture every network, endpoint, data, and application control dollar embedded in broad zero-trust research. Category language is also still settling: Bessemer described infrastructure access as a new product category, which helps explain why analyst coverage spans overlapping definitions rather than one settled taxonomy. Demand signals are strong enough to support a real market, not just a concept. Teleport reports 600-plus customers, and its 2026 survey plus 2026 newsroom evidence show AI-driven identity concerns rising quickly. Even so, a precise Teleport SAM or SOM cannot be isolated from public evidence because customer mix, contract value, and deployment distribution remain undisclosed, and one Fortune Business Insights PAM source returned the wrong content entirely.[CM009, CM010, CM011, CM012, CM013, CM014]
| Publisher | Base Year | Market Scope | Value (USD B) | CAGR (%) | Methodology | Confidence | Limitation |
|---|---|---|---|---|---|---|---|
| Precedence Research | 2025 | Privileged Access Management | 4.5 | 23.4 | Global analyst market model with 2034 forecast | Medium | Narrower scope than Teleport's full product footprint and vendor methodology is not fully transparent |
| Grand View Research (archived) | 2025 | Privileged Access Management | Archived category listing retained as evidence of category coverage | Low | Retained source did not yield a clean public headline number for this run | ||
| Fortune Business Insights | 2026 | Privileged Access Management | Attempted triangulation source | Low | URL returned unrelated agricultural content, so the PAM estimate was unusable | ||
| Grand View Research (archived) | 2024 | Zero Trust Security | 36.96 | 16.6 | Broad zero-trust market estimate through 2030 | Medium | Includes broader controls than infrastructure access alone |
| Precedence Research | 2025 | Zero Trust Security | 40.01 | 16.39 | Broad zero-trust market estimate through 2035 | Medium | Useful TAM ceiling but too broad to treat as Teleport SAM |
| Teleport Infrastructure Identity Survey | 2026 | AI identity demand proxy | Enterprise survey measuring AI initiative intensity and preparedness | Medium | Demand signal rather than a direct market-value estimate |
Null values mark sources that were useful for triangulation or limitation analysis but did not produce a recoverable market-size number in the retained evidence set.
[CM009, CM010, CM011, CM012, CM015, CM018]Teleport sits between a narrow PAM core and a broad zero-trust ceiling, with an emerging AI identity layer increasing urgency inside the reachable middle layer.
Lens boundaries are analytical syntheses based on product scope and standards mapping; only the outer-market reference points come from published analyst numbers.
[CM013, CM014, CM015, CM017]Published market references span from narrow PAM current value to broad zero-trust long-range forecasts, showing why one TAM number would overstate precision.
Range endpoints use published current and long-range figures in USD billions; midpoint values are display aids, not new sourced market estimates.
[CM009, CM010, CM011, CM012, CM016, CM018]2.3 Buyer Types, Budget Ownership, and Adoption Path
Teleport's buyer map is cross-functional because the product collapses security, platform, and compliance workflows into one access layer. Day-to-day users are typically platform engineers, SRE or DevOps teams, security engineers, infrastructure administrators, and database or Kubernetes operators. Budget ownership depends on the purchase trigger. Security-led deals often sit with the CISO organization, platform-led rollouts can be owned by engineering infrastructure teams, and compliance-led public-sector or regulated-enterprise deals often pull in GRC stakeholders because FedRAMP and SOC 2 evidence collection matter alongside access control. Pricing reinforces that shared ownership: Teleport charges on monthly active users and machine/workload identities, so the commercial model expands with identity adoption rather than with one fixed appliance footprint. Developer-led evaluation still matters because the open repository has 15,000-plus stars, but enterprise conversion appears strongest in regulated and cloud-native organizations, including large financial-services buyers. The weakest fit appears in legacy-heavy hybrid estates where buyers prioritize broad protocol coverage and simpler migration over Teleport's cloud-native depth.[CM019, CM020, CM021, CM022, CM023, CM024]
| Segment | Buyer Role | User | Payer | Budget Owner | Adoption Trigger |
|---|---|---|---|---|---|
| Regulated cloud enterprise | CISO or security platform lead | Platform engineers, security engineers, DB/Kubernetes admins | Security budget | Security organization with platform partnership | Need to replace VPN or bastion access with auditable certificate-based controls |
| Federal or public-sector contractor | Compliance lead plus security architecture | Admins and operators handling regulated workloads | Security and compliance program budget | Program owner accountable for authorization evidence | FedRAMP evidence, FIPS requirements, and centralized session audit needs |
| Platform-native midmarket SaaS | Head of platform engineering | SRE, DevOps, developers | Engineering infrastructure budget | Platform engineering | Desire to unify SSH, Kubernetes, and database access without standing secrets |
| AI-native infrastructure team | Security platform owner or AI platform lead | Agent builders, MLOps, platform engineers | Shared security and platform budget | Cross-functional security/platform owner | Need to assign non-human identity, authorization, and audit to agents or MCP workflows |
| Legacy-heavy hybrid enterprise | IT infrastructure or access-management lead | Admins across mixed legacy and modern systems | Central IT or security budget | Often shared or contested | Migration pressure exists but adoption slows if protocol breadth and legacy support matter more than cloud-native depth |
Buyer map reflects likely budget ownership from Teleport pricing, compliance use cases, product scope, and customer-profile evidence rather than disclosed win-rate data.
[CM019, CM020, CM021, CM022, CM023, CM024]Security, platform, compliance, and AI stakeholders participate in different proportions depending on the segment and trigger.
Matrix cells are qualitative weights synthesized from product scope, pricing, compliance use cases, community signal, and adverse competitor positioning rather than disclosed segment revenue mix.
[CM020, CM021, CM022, CM024, CM025, CM026]2.4 Regulatory, AI, Cloud, and Security Drivers
Demand is being pulled forward by a mix of standards, compliance pressure, cloud complexity, and new AI-agent risk. NIST SP 800-207 gives zero trust a formal architecture definition, while CISA's Zero Trust Maturity Model operationalizes that architecture across five pillars and three cross-cutting capabilities, which legitimizes budget allocation for identity-centric infrastructure controls. Teleport benefits when those abstract frameworks translate into concrete FedRAMP and SOC 2 access-control requirements, especially because it documents FIPS 140 support and control mappings. AI adds a sharper near-term catalyst. Teleport's 2026 survey says 92% of respondents have near-term AI initiatives, 79% are evaluating or deploying agentic AI, only 13% feel extremely prepared, and 60% have had or suspect AI-related incidents. Separate 2026 newsroom data says 73% of cybersecurity leaders are hearing enterprise questions about AI agent security. At the same time, multi-cloud sprawl and the broader cloud-era shift toward unified control planes support the category. The main adoption drag is not lack of need but switching cost: buyers still have to unwind incumbents, re-architect access paths, and decide whether Teleport's modern-cloud strengths outweigh legacy-coverage concerns.[CM027, CM028, CM029, CM030, CM031, CM032]
| Factor | Direction | Type | Timing | Implication | Diligence Ask |
|---|---|---|---|---|---|
| NIST and CISA zero-trust frameworks | Positive | Regulatory/standards | Now | Creates durable architecture language and budget legitimacy for identity-centric access controls | Ask how much pipeline is explicitly mapped to federal or enterprise zero-trust programs |
| FedRAMP and FIPS access-control evidence | Positive | Compliance | Now | Improves fit with regulated buyers and public-sector contractors | Request exact share of revenue from regulated sectors and proof of control-map reuse in deals |
| SOC 2 infrastructure-access requirements | Positive | Compliance | Now | Pulls security and audit stakeholders into the buying process | Ask whether SOC 2-driven wins come with premium pricing or just faster conversion |
| AI initiative intensity and AI-agent security concern | Positive | Market demand | Now to 24 months | Expands Teleport from human access into machine and agent identity budgets | Request pipeline split between core access deals and AI-identity add-ons |
| Multi-cloud and open control-plane complexity | Positive | Technical | 12 to 36 months | Supports a unified access plane rather than many point credentials | Ask how Teleport wins differ in single-cloud versus multicloud estates |
| Usage-based MAU and MWI pricing | Mixed | Commercial | Now | Can reduce entry friction but makes budget growth dependent on identity expansion and pricing transparency | Request cohort expansion data by user identities versus machine identities |
| Incumbent switching cost from VPN, PAM, IAM, and audit workflows | Negative | Operational | Now | Lengthens sales cycles and raises proof-of-value burden | Ask for median deployment time, migration services usage, and competitive displacement data |
| Legacy-system coverage critique | Negative | Competitive | 12 to 24 months | Narrows fit in heterogeneous estates and supports adverse competitor messaging | Ask for win-loss data by environment complexity and protocol coverage roadmap |
Table mixes positive and negative factors because market adoption depends on both budget creation and migration friction; timing is directional, not a company-issued forecast.
[CM027, CM028, CM029, CM030, CM031, CM032]Most Teleport evaluations appear to move from risk or compliance trigger into a scoped pilot before broader identity expansion.
Adoption sequence is a synthesized pattern drawn from compliance positioning, pricing structure, customer proof, and competitive constraints; it is not a disclosed funnel conversion chart.
[CM028, CM030, CM032, CM034, CM035, CM036]2.5 Adoption Barriers, Diligence Gaps, and Contradictory Evidence
The biggest market-analysis constraint is not weak demand; it is weak precision. Public sources do not isolate how much of Teleport's addressable spend comes from regulated enterprises, public-sector contractors, AI-native teams, or existing customer expansion. The last disclosed financing event is still the May 2022 Series C at a $1.1 billion valuation, so the outside world is interpreting a fast-moving category through a stale capital-market anchor. The published market estimates are directionally useful but methodologically inconsistent because PAM and zero-trust reports use different scope definitions, and the accessible Fortune Business Insights PAM URL returned unrelated agricultural content instead of a usable market page. Teleport's own materials are rich on product breadth and compliance alignment, but they do not disclose public win rates, deployment duration, churn, ACV, or split between self-hosted and cloud deals. As a result, conviction on demand direction is reasonable, while conviction on monetizable share and efficient capture remains materially lower until management provides segment-level revenue and conversion evidence.[CM037, CM038, CM039, CM040, CM041, CM042]
2.6 Exhibits
03Competitors
3.1 Landscape
Teleport's competitor set is broader than classic password-vault PAM. The closest field includes incumbent suites such as CyberArk, BeyondTrust, and Delinea; modern infrastructure-access challengers such as StrongDM and HashiCorp Boundary; and adjacency from Okta, which can extend existing workforce identity relationships into privileged server access. Bessemer's infrastructure-access framing helps explain why buyers do not evaluate Teleport inside only one box: the practical job spans connectivity, authentication, authorization, and audit across servers, clusters, databases, and increasingly AI-operated infrastructure workflows. Independent comparison and review sites reinforce that this is the active buyer short list. The market therefore is not a winner-take-all feature race but a segmentation contest between broad enterprise incumbents, cloud-native specialists, and identity-platform bundlers, with Teleport strongest where buyers want one modern control plane rather than a legacy vault plus point proxies.[CP015, CP016, CP017, CP041, CP042]
| Competitor | Category | Scale | Target Segment | Differentiation | Key Limitation |
|---|---|---|---|---|---|
| Teleport | Infrastructure identity / modern PAM | Private; 15,000+ GitHub stars and 600+ customers disclosed elsewhere | Cloud-native enterprises, regulated infrastructure teams, platform engineering | Unified CA + proxy architecture across SSH, Kubernetes, databases, RDP, workloads, and AI agents | Legacy-heavy estates may prefer broader protocol coverage and simpler migration narratives |
| CyberArk | Incumbent enterprise PAM | $20.63B market cap; $1.30B TTM revenue | Large hybrid enterprises and regulated security teams | Unified PAM platform, zero-standing-privilege positioning, strong compliance and audit posture | Heavier legacy-enterprise motion can feel less developer-native than Teleport |
| BeyondTrust | Incumbent PAM / privileged remote access | Large incumbent vendor; public corpus emphasizes Gartner standing rather than current financials | Enterprise security, third-party/vendor access, hybrid IT | Least-privilege framing, credential injection, VPN replacement, vendor privileged access | Less evidence in retained set of Teleport-style unified cloud-native control plane |
| Delinea | Incumbent PAM / secret vaulting | Private vendor; scale not publicly quantified in retained set | Broad enterprise PAM buyers, especially secret-vault and rotation use cases | Fast deployment language, discovery, password rotation, session monitoring, AI session analysis | Private financial visibility is thin and architecture remains closer to classic secret management |
| StrongDM | Cloud-native challenger / access broker | Private vendor now inside Delinea; direct attack-marketing visible | Hybrid enterprises needing modern plus legacy access coverage | Identity Firewall narrative, continuous authorization, full session visibility, broader protocol/auth method coverage | Relies heavily on competitor framing in retained evidence; public pricing and scale are sparse |
| HashiCorp Boundary | Identity-aware access proxy | HashiCorp-backed product with large adjacent community | Platform teams already using HashiCorp identity and infrastructure stack | SSO plus dynamic credentials via Vault for least-privileged access | Narrower product surface than Teleport across databases, compliance packaging, and AI identity |
| Okta | IAM-adjacent privileged access | $20.65B market cap; $2.91B TTM revenue | Existing Okta identity customers extending into server access | Cross-sell from workforce identity, static credential elimination, SSH/RDP session recording | Infrastructure depth is narrower than Teleport for Kubernetes, databases, and broader access brokering |
Coverage is intentionally partial: it focuses on the direct and adjacent vendors most likely to appear in Teleport buyer evaluations for PAM and infrastructure identity as of June 2026, not every long-tail admin-access or cloud-native point tool.
[CP015, CP017, CP041, CP042]Ordinal map showing which vendors pair modern zero-credential posture with the strongest enterprise distribution leverage.
Axis scores are evidence-backed ordinal judgments derived from public-company scale, installed-base cues, architectural positioning, and product-page claims; they are not market-share measurements.
[CP004, CP005, CP010, CP012, CP014, CP021]3.2 Incumbent PAM
CyberArk, BeyondTrust, and Delinea still define the incumbent end of the market because they sell privileged access into broad enterprise and hybrid estates, not only into greenfield cloud teams. CyberArk's official positioning emphasizes a single PAM platform, cyber-risk reduction, audit and compliance outcomes, and zero-standing-privilege access across hybrid environments. BeyondTrust tells a similar story around least privilege, credential injection, and privileged remote access that can remove the need for VPNs and known credentials. Delinea's Secret Server remains anchored in vaulting, discovery, password rotation, and session monitoring, with new AI-driven session analysis language layered on top. None of these vendors market themselves as Teleport-style open infrastructure identity platforms, but the overlap is material enough that Teleport must win by architecture simplicity for modern estates, not by assuming incumbents are trapped in old password-vault workflows.[CP004, CP005, CP006, CP007, CP024, CP025]
3.3 Cloud-Native Challengers
StrongDM, HashiCorp Boundary, and Okta matter because they attack Teleport from three different angles. StrongDM competes head-on for modern infrastructure access, but it frames itself as easier for mixed estates because it supports more legacy systems and authentication methods and does not require Teleport's exact certificate-only operating model. Boundary is narrower, yet technically important: its identity-aware proxy plus Vault integration gives it credibility for teams already standardized on HashiCorp tooling. Okta approaches the market from an IAM adjacency route, extending SSO, ephemeral server access, and session recording into Linux and Windows infrastructure for customers that already trust Okta as an identity control plane. Together these challengers show why Teleport cannot rely on cloud-native branding alone; each rival brings a distinct distribution mechanism, from platform adjacency to direct attack ads to bundle-led cross-sell.[CP008, CP009, CP010, CP012, CP013, CP014]
| Vendor | Pricing Model | Billing Unit | Key Capabilities | Pricing Transparency | Notable Gap |
|---|---|---|---|---|---|
| Teleport | Self-serve list pricing plus enterprise packaging | Monthly active users and machine/workload identities | Unified access, audit, machine identity, identity security, agentic identity add-ons | High relative to peers | Realized discounts, enterprise minimums, and attach rates are undisclosed publicly |
| CyberArk | Sales-led enterprise contracts | Custom quote / contract scope not public in retained set | Unified PAM, zero-standing-privilege, audit/compliance, hybrid access | Low | Public list pricing absent; difficult to compare TCO against Teleport |
| BeyondTrust | Sales-led enterprise contracts | Custom quote / deployment scope not public in retained set | Least privilege, PRA, credential injection, vendor access | Low | Retained corpus does not show public unit pricing or deployment minimums |
| Delinea | Sales-led enterprise contracts | Custom quote / vault or module scope not public in retained set | Secret vaulting, discovery, rotation, session monitoring, AI session analysis | Low | Private pricing and packaging detail remains sparse |
| StrongDM | Sales-led packaging after Delinea acquisition | Custom quote / user-resource scope not public in retained set | Identity Firewall, continuous authorization, session visibility, broad protocol coverage | Low | Comparison-heavy messaging but little comparable list-price detail |
| Okta | Platform bundle or add-on sales motion | Custom quote / seat scope not public in retained set | Privileged server access, zero standing privilege, SSH/RDP recording, SSO extension | Low | Likely bundled economics are opaque from public product pages |
| HashiCorp Boundary | Open-source / enterprise hybrid packaging | Open source plus commercial terms not public in retained set | Identity-aware proxy, SSO, dynamic credentials via Vault, session management | Medium-low | Public retained sources explain architecture more clearly than commercial terms |
This table compares packaging posture and transparency rather than realized price leadership because most competitors do not publish apples-to-apples public rates in the retained evidence set.
[CP027, CP028, CP029, CP038]3.4 Teleport Differentiation
Teleport's clearest differentiation is structural rather than cosmetic. Its Auth Service acts as a certificate authority for users, machines, and resources, while the Proxy Service brokers access across SSH, Kubernetes, databases, RDP, web apps, and machine identities without relying on long-lived shared credentials. That lets Teleport pitch an access plane where authentication, authorization, and audit are unified instead of stitched together from a vault, jump host, VPN, and scattered policy engines. The company has also expanded outward: recent releases highlighted IdP-compromise mitigations, a broader identity-security layer, machine and workload identity, and a new Agentic Identity Framework for AI systems. Those moves widen the category Teleport is trying to own. The tradeoff is that Teleport's old open-source discovery advantage is less clean after the 2024 community-license change, so architectural coherence now matters more than community goodwill alone.[CP001, CP002, CP003, CP018, CP019, CP020]
| Capability | Teleport | CyberArk | BeyondTrust | Delinea | StrongDM | Okta | HashiCorp Boundary |
|---|---|---|---|---|---|---|---|
| Certificate-based auth | Yes — core architecture across users, hosts, and workloads | Partial — supports ephemeral models but official framing is broader PAM | Partial — least privilege and PRA, but not framed as CA-first | Partial — secret-vault first, not CA-first in retained set | Partial — supports certificate-based auth among multiple auth methods | Partial — removes static SSH keys/passwords for server access | Partial — identity-aware proxy with external auth and dynamic creds |
| Ephemeral privileges | Yes — short-lived certs and just-in-time access | Yes — zero-standing-privilege positioning | Yes — privileged remote access and least privilege | Partial — session control and rotation, but less explicit ZSP framing | Yes — continuous policy enforcement with no standing privileges | Yes — zero standing privileges for servers | Yes — least-privileged access with dynamic credentials via Vault |
| Session recording | Yes — command, video, and audit recording | Yes — PAM audit/compliance core | Yes — secure remote access and session monitoring | Yes — session monitoring built in | Yes — full session visibility | Yes — records privileged access via SSH and RDP | Yes — records and manages privileged sessions |
| Kubernetes support | Yes — first-class access path | Unknown in retained set | Unknown in retained set | Unknown in retained set | Unknown in retained set | No public evidence in retained set | No public evidence in retained set |
| Database access | Yes — SQL and NoSQL through Teleport proxy | Partial — multi-cloud/hybrid PAM, DB specifics not emphasized in retained set | Unknown in retained set | Unknown in retained set | Unknown in retained set | No public evidence in retained set | No public evidence in retained set |
| AI / agentic identity | Yes — Agentic Identity Framework and Beams | No public evidence in retained set | No public evidence in retained set | Partial — AI-driven session analysis language | Yes — agentic AI identity messaging on homepage | No public evidence in retained set | No public evidence in retained set |
| Open-source distribution | Partial — source available, compiled artifacts commercially restricted for larger companies | No | No | No | No public evidence in retained set | No | Partial — open-source lineage and docs orientation |
| Cloud-native architecture | Yes — unified CA/proxy plane for modern infrastructure | Partial — hybrid and multicloud PAM emphasis | Partial — remote-access and vendor PAM emphasis | Partial — secret-vault and automation emphasis | Yes — modern access control plane and adaptive controls | Partial — extends identity cloud into servers | Yes — identity-aware proxy for cloud infrastructure |
Cells are limited to capabilities evidenced in retained sources; Unknown means the reviewed corpus did not support a stronger statement, not that the vendor lacks the feature.
[CP001, CP004, CP006, CP007, CP009, CP012]Teleport leads on breadth across modern infrastructure resource types, while incumbents and adjacencies are strongest on enterprise distribution or specific privileged-access workflows.
Matrix values only reflect capabilities directly supported by retained sources; Partial or No often means narrower or less explicit evidence rather than definitive functional absence.
[CP001, CP004, CP006, CP009, CP013, CP021]3.5 Moat Risks
Teleport has real switching-cost potential, but the moat is conditional rather than unbreakable. Once a customer standardizes audit logs, certificate issuance, access workflows, and compliance evidence on one platform, replacement becomes operationally painful. That dynamic benefits incumbents too, which is why CyberArk and BeyondTrust can still defend accounts even as the market modernizes. Teleport also faces three direct risks. First, large public comparables such as CyberArk and Okta have much larger balance sheets and installed bases, giving them room to bundle or discount. Second, StrongDM's adverse messaging around legacy fit and root-agent architecture gives buyers a concrete counter-thesis in hybrid estates. Third, public customer-review evidence is more supportive than hostile, but the retained set is still thin on large-scale onboarding pain, leaving investors without decisive proof that Teleport's deployment model scales frictionlessly across conservative enterprises.[CP023, CP024, CP025, CP029, CP031, CP032]
| Moat Claim | Supporting Evidence | Threat | Severity | Mitigation/Diligence Ask |
|---|---|---|---|---|
| Unified infrastructure identity plane | Teleport CA + proxy architecture spans multiple resource types under one audit model | CyberArk, BeyondTrust, and Okta continue adding zero-standing-privilege and session capabilities | High | Request win/loss data by resource type and proof that unified architecture shortens deployment or reduces admin burden |
| Developer-led discovery and open-source pull | Public repo scale and historical community roots create awareness | Community-license restrictions reduce bottom-up goodwill and make Boundary-style open lineage more attractive | High | Request community funnel, self-serve conversion, and post-v16 contribution or adoption trends |
| Modern cloud-native fit | Teleport and StrongDM are optimized for modern infrastructure workflows | StrongDM attacks Teleport on legacy coverage and root-agent architecture in hybrid estates | High | Request protocol roadmap, deployment-hardening evidence, and win-loss split for legacy-heavy prospects |
| Compliance and trust posture | Security-audit publication plus identity-security docs support enterprise trust | Incumbents already own large compliance relationships and can bundle adjacent controls | Medium | Request enterprise reference calls in regulated sectors and control-level displacement examples |
| AI and machine identity expansion | Teleport now markets Agentic Identity Framework, Beams, and machine/workload identity | Competitors may add agentic features quickly, while current market demand is still forming | Medium | Request attach-rate, pipeline, and monetization evidence for AI and non-human identity modules |
| Switching-cost accumulation after rollout | Policy, audit, cert issuance, and access workflows can become embedded once deployed | Large public comparables have stronger distribution and discount capacity before Teleport is entrenched | High | Request median time-to-value, renewal or expansion data, and proof of competitive displacement against CyberArk or Okta |
Risk register focuses on moat durability rather than generic product risk; severity reflects competitive pressure, not a quantified probability model.
[CP023, CP024, CP025, CP035, CP036, CP037]Compact indicators showing where Teleport is strongest versus where larger rivals still hold the advantage.
[CP018, CP021, CP022, CP035, CP036, CP037]04Financials
4.1 Commercial model, revenue structure, and customer base
Teleport's commercial model is usage-based and multi-product. The pricing page discloses three billing metrics: Monthly Active Users (MAU) for Zero Trust Access and Identity Governance modules, Machine/Workload Identities (MWI) for the Machine and Workload Identity module, and Teleport Protected Resources (TPR) for Identity Security. No public list price is disclosed; all pricing requires commercial engagement with the sales team. Enterprise Edition supports cloud, on-premises (standard and FIPS), multi-region high availability, and hybrid deployment modes. The Beams AI agent runtime product entered public beta in June 2026 and is not yet publicly priced. The Community Edition free tier — available for companies under 100 employees and under $10M annual revenue since the June 2024 license change — creates a deliberate forcing function for commercial conversion as customers grow. Customer case studies show the breadth of enterprise deployment: GoTo (Indonesia's largest digital platform, managing multi-cloud access across complex infrastructure), Exness (regulated global trading firm with stringent security requirements), Gladly (SaaS platform with SOC 2 compliance requirements), and ExtraHop (security-focused cloud network detection company). Each represents a different vertical and compliance posture. The careers page states more than 600 customers globally as of October 2025. Revenue drivers visible from public materials include: (1) usage expansion as MAU, MWI, and TPR metrics grow with infrastructure scale without requiring re-negotiation; (2) community-to-enterprise conversion as companies cross the 100-employee or $10M AR threshold; (3) multi-module upsell as customers adopt Identity Governance, Identity Security, and AI agent identity modules; and (4) AI agent market opportunity through Beams and the Machine Workload Identity module. Session recording, database access, and MCP server access also create upsell in compliance-sensitive sectors.[CI001, CI014, CI015, CI016, CI033, CI034]
| stream | mechanism | billing metric | current status | revenue quality | diligence ask |
|---|---|---|---|---|---|
| Zero Trust Access (human) | Usage-based SaaS — human users and protected resources | MAU and TPR | Active — Enterprise Edition; Community free for small cos | Good for model clarity; no ARPU published | Provide blended MAU ARPU and YoY expansion rate |
| Machine and Workload Identity | Usage-based SaaS — non-human and AI agent identities | MWI | Active — separate module; AI agent demand growing | High growth potential; AI agent wave drives MWI demand | Provide MWI count and net-new MWI growth rate |
| Identity Governance | Usage-based SaaS — governance overlay on human access | MAU | Active — upsell to existing human-access customers | Upsell potential; no attach rate or ASP lift published | Provide cross-sell attach rate and revenue contribution |
| Identity Security | Usage-based SaaS — shadow access discovery and anomaly | TPR | Active — upsell to existing customers | Compliance-driven demand; separate pricing tier | Provide revenue share of compliance-driven module |
| Beams AI Agent Runtimes | Emerging — AI agent infrastructure runtimes | Unknown (beta) | Public beta June 2026; not yet priced | Unproven; too early for revenue modeling | Confirm pricing and signed beta commitments |
| Community-to-Enterprise conversion | License gate at 100 employees and $10M AR | Conversion events | Active since Teleport 16 (June 2024) | Likely driver of new ARR; no conversion rate data | Provide monthly cohort conversion data |
All streams inferred from public pricing page, documentation, and blog posts. No official ARR breakdown by stream or module has been disclosed. Beams product is in beta with no disclosed pricing.
[CI001, CI014, CI015, CI016, CI033]| dimension | Teleport (private) | CyberArk CYBR (public) | Okta OKTA (public) |
|---|---|---|---|
| Pricing model | Usage-based (MAU / MWI / TPR); no public list price | Subscription + usage; per-user and per-resource | Subscription; per-user and per-service |
| Enterprise pricing disclosure | Contact sales only; no list price | Partially public; contract values private | Partially public; enterprise tier private |
| Community/free tier | Yes — companies <100 employees, <$10M AR | No significant free tier | No significant free tier |
| Revenue 2024 (USD) | ~$49M (GetLatka estimate; unconfirmed) | $1.00B (reported in SEC filings) | $2.61B (reported in SEC filings) |
| Market cap / valuation (USD) | $1.1B (May 2022 mark; stale by ~4 years) | $20.63B (June 2026) | $20.65B (June 2026) |
| Implied revenue multiple | ~22x ARR (at GetLatka estimate) | ~15.9x revenue (June 2026) | ~7.1x revenue (June 2026) |
Teleport figures are from company disclosures or GetLatka estimates only. CyberArk and Okta figures from companiesmarketcap.com (sourced from public SEC filings). Teleport valuation is the 2022 Series C mark.
[CI002, CI009, CI010, CI015]Teleport converts infrastructure demand into usage-based revenue through a community-to-enterprise funnel and multi-module upsell, but the link between deployment scale and retained gross margin is entirely opaque.
Qualitative bridge only; no public pricing, ARPU, or gross margin data is available. ARR of $49M is an unconfirmed third-party estimate from GetLatka.
[CI001, CI016, CI033, CI039]4.2 Revenue and ARR estimates — an entirely unverified picture
Teleport discloses no financial data. The only publicly available ARR estimate comes from GetLatka, a third-party data aggregator, which reported that Teleport hit $49M in revenue in December 2024. GetLatka also estimated headcount at approximately 246 as of late 2025. These figures have not been confirmed by Teleport, any investor, or any independent source. GetLatka's own funding summary shows $140M across 2 rounds, diverging from the company-disclosed $165M across 3 rounds, further eroding confidence in the dataset's completeness. Working backward from the ARR growth rates disclosed in funding announcements: the Series C blog (May 2022) reported total ARR up 2.8x and net new ARR up 4.5x year-over-year; the Series B blog (2021) reported total ARR up 2.5x and net new ARR up 5x year-over-year versus Q2 2020. If these growth rates are correct and the company was tracking to triple revenue in 2021 per the Series B era disclosures, the implied ARR at the Series C close was approximately $17–20M. Growing from that level to $49M by 2024 implies a post-fundraising CAGR of roughly 22%, a significant deceleration from the pre-Series-C trajectory. This cannot be confirmed without management data, but it is directionally consistent with the broader SaaS market slowdown in 2022–2024. GTM efficiency metrics are completely absent. No sales cycle length, CAC, payback period, or quota attainment data is public. The best proxy for GTM effectiveness is the customer count trajectory (600+ cited in 2025) and the quality of named logos, but neither converts to revenue-per-customer or expansion rate without further data.[CI002, CI003, CI005, CI006, CI012, CI013]
| metric | value | date/period | confidence | source | gap note |
|---|---|---|---|---|---|
| ARR (estimated) | ~$49M | 2024-12 | low | GetLatka (third-party; unconfirmed) | Not verified by company or independent source |
| ARR growth at Series B | 2.5x YoY | 2021 | medium | Teleport Series B blog (official) | Absolute ARR in dollars not stated |
| ARR growth at Series C | 2.8x YoY | 2022-05 | medium | Teleport Series C blog (official) + BVP investment blog | Absolute ARR in dollars not stated |
| Estimated ARR at Series C close (derived) | ~$17–20M (inferred) | 2022-05 | low | Inferred from GetLatka $49M and implied CAGR | Not confirmed; calculation assumes flat 2022-2024 |
| Post-Series-C implied CAGR | ~22% per year (inferred) | 2022–2024 | low | Derived from estimated ARR path | Deceleration from pre-Series-C growth trajectory |
| ARR per employee (estimated) | ~$199K | 2024/2025 | low | Derived from GetLatka ARR and headcount estimates | Double-estimated; treat as directional only |
| ARR / capital raised ratio | ~0.30x | 2024-12 | low | Derived from GetLatka ARR / $165M disclosed raised | Below efficient SaaS benchmark of 0.5–1.0x |
| Gross margin | Not disclosed | unknown | No public source | Blocking gap; cannot underwrite without disclosure | |
| Net revenue retention (NRR) | Not disclosed | unknown | No public source | Critical for valuation; expansion rate unknown |
All financial metrics are either company-cited growth rates (percentage only) or GetLatka third-party estimates. No audited or management-provided financials are available for any period. NRR and gross margin are entirely unknown from public sources.
[CI002, CI003, CI004, CI005, CI006, CI024]Public evidence supports a credible infrastructure demand signal and usage-based expansion logic, but breaks down entirely before CAC, NRR, and gross margin can be quantified.
Qualitative bridge using public demand signals and customer case study evidence. ARR and unit economics figures are unavailable.
[CI002, CI004, CI005, CI020, CI034, CI035]4.3 Valuation and comparable public-market multiples
The only external valuation data point for Teleport is the $1.1B mark from the May 2022 Series C. As of June 2026, this mark is approximately four years old and has not been refreshed. At GetLatka's $49M estimated ARR, the implied revenue multiple is approximately 22.4x — materially above where comparable public cybersecurity companies traded in mid-2026. CyberArk Software (CYBR), the closest publicly traded comparable for privileged access management, had a market cap of approximately $20.63B and TTM revenue of approximately $1.30B as of June 2026, implying roughly a 15.9x revenue multiple. CyberArk revenue grew from approximately $590M in 2022 to $1.30B TTM in 2025, a 2.2x increase in roughly three years. Okta (OKTA), the closest identity and access management comparable, had a market cap of approximately $20.65B and TTM revenue of approximately $2.91B as of June 2026, implying approximately 7.1x. Okta revenue grew from $1.85B to $2.91B over the same period (1.6x growth). Both companies are substantially larger in revenue than Teleport's estimated ARR. At the midpoint of these two public peers' revenue multiples (~11x), $49M ARR implies Teleport's enterprise value at approximately $540M, well below the $1.1B mark. Even at CyberArk's 15.9x multiple, the implied value is approximately $779M. At the Series C close in May 2022, CyberArk itself traded at approximately $5.27B market cap on $590M revenue (~9x), and Okta at ~$10.94B on $1.85B revenue (~6x), suggesting Teleport's 22x+ implied multiple was already ~2x the comparable range at issuance. The private-market premium implicit in the 2022 mark has likely eroded further under post-2022 market corrections.[CI007, CI008, CI009, CI010, CI011, CI026]
| round | date | amount (USD M) | lead investors | valuation (USD M) | implication |
|---|---|---|---|---|---|
| Series A | 2019 (approx) | 25 | Kleiner Perkins (Bucky Moore) | Not stated | Company stated near profitability; NASDAQ Splunk Samsung named as customers |
| Series B | 2021 | 30 | S28 Capital and Kleiner Perkins | Not stated | ARR 2.5x YoY; on track to triple revenue in 2021 per Series B blog |
| Series C | 2022-05 | 110 | Bessemer Venture Partners; Insight Venture Partners | 1100 | ARR 2.8x YoY; last known external valuation; ~4 years stale at run date |
| Post-Series C | No evidence | Unknown | Not identified | Unknown | No public financing event since May 2022; cap table is private |
All round data from official Teleport blog posts and Bessemer/Kleiner Perkins investor publications. GetLatka shows $140M across 2 rounds, missing the Series A; divergence from disclosed $165M reduces confidence in GetLatka data completeness. No SEC Form D found in EDGAR for any round.
[CI005, CI006, CI013, CI022, CI023, CI030]Applying mid-2026 public peer multiples to GetLatka's $49M ARR estimate produces a wide valuation range below the May 2022 $1.1B mark in most scenarios.
All scenarios apply June 2026 public-market revenue multiples from companiesmarketcap.com to GetLatka's unconfirmed $49M ARR estimate. These are illustrative sensitivity ranges, not formal valuations. The $75M ARR scenario is hypothetical and not supported by any public source.
[CI007, CI008, CI009, CI010, CI011, CI037]4.4 Cost structure, capital adequacy, and financial verdict
Teleport's cost structure is completely opaque in public materials. No COGS breakdown, gross margin figure, infrastructure cost, or personnel expense data is available. The best reference points are from public cybersecurity SaaS peers, where gross margins typically run 65–75% for infrastructure-oriented products. If Teleport's gross margin is in that range, $49M ARR could generate $32–37M in gross profit — a serviceable foundation, but one that must support ongoing product investment, G&A, and sales cost without disclosed data on what those costs are. Capital adequacy is similarly opaque. The company has raised $165M across three disclosed rounds, with the most recent $110M Series C in May 2022. No new financing has been publicly confirmed since. At an industry-typical cash burn rate for a company of Teleport's stage, the Series C proceeds could support three to five years of operations depending on burn discipline — suggesting the company may not need new capital immediately, but this is entirely speculative without actual balance-sheet data. No debt, credit facility, or project finance is disclosed. The financial verdict is mixed. The demand signal is real: 600+ enterprise customers, regulated-industry logos, and Fortune Cyber 60 recognition all indicate an active go-to-market. The revenue model is well- structured for land-and-expand dynamics. However, the underwriting case is blocked by fundamental opacity: no verified ARR, no gross margin, no NRR, no burn rate, no current valuation. The 2022 mark implies a multiple that is difficult to defend at current public-market comparables. Any investment at or near the $1.1B mark requires an updated 409A or data room disclosure to resolve the core valuation question.[CI019, CI020, CI021, CI022, CI023, CI024]
| gap | what is missing | why it matters | severity | diligence path |
|---|---|---|---|---|
| Revenue / ARR (actual) | Management-reported ARR with module and cohort breakdown | GetLatka $49M is unconfirmed; cannot build revenue model | blocking | Request financial data room with ARR bridge and cohort analysis |
| Gross margin | COGS breakdown — infrastructure hosting SRE support costs | Gross margin determines real unit economics and valuation floor | blocking | Request P&L with COGS and SaaS Metrics snapshot from CFO |
| Net revenue retention (NRR) | Expansion minus churn rate across cohorts by module | NRR above 120% would justify premium multiple; baseline unknown | blocking | Request monthly cohort expansion and churn going back to 2021 |
| Burn rate and runway | Monthly cash burn and cash balance at most recent quarter-end | Cannot assess financial risk without knowing when company needs capital | blocking | Request cash position and 12-month cash forecast from CFO |
| GTM efficiency metrics | CAC payback period quota attainment and sales cycle length | Without GTM efficiency data cannot underwrite sales scalability | material | Request SaaS Metrics deck or equivalent management presentation |
All gaps are standard data-room requests for a private company. Absence of this data does not indicate distress — it is normal for a private company. The company must disclose this data in any due-diligence process for a meaningful equity investment or secondary transaction.
[CI012, CI013, CI025, CI030]Four-dimension assessment of Teleport's financial transparency, covering capital, revenue, cost, and competitive positioning — with most cells graded low or unknown for private-company reasons.
Matrix assessments are qualitative judgments based on public evidence as of the run date. Actual financial data from a management data room would materially change this assessment.
[CI009, CI010, CI012, CI025, CI026, CI027]4.5 Exhibits
05Product & Technology
5.1 Product Definition and Module Map
Teleport is a certificate authority (CA) and identity-aware access proxy that implements SSH, RDP, HTTPS, Kubernetes API, and a variety of SQL and NoSQL database protocols. The product is distributed as a single Go binary that combines authentication, authorization, auditing, and tunneling in one deployable unit. Teleport operates internal Certificate Authorities for both hosts and users; every identity — human, machine, or AI — receives a short-lived certificate rather than a long-lived credential, eliminating secrets sprawl at the architecture level. The product suite now spans five branded product pillars: Zero Trust Access (SSH, Kubernetes, databases, RDP, web apps), Machine & Workload Identity (non-human service credentials), Identity Governance, Identity Security (access analytics and threat detection), and the Agentic Identity Framework (AI agent identity + Beams runtime). The feature matrix distinguishes Enterprise Cloud, Enterprise Self-Hosted, and Community Edition, with Beams trusted runtimes exclusive to Enterprise Cloud. Each major release has shipped every four months historically; version 18 (current) arrived July 2025 with version 19.0 planned. The June 2024 community-license change restricted compiled binaries for companies with over 100 employees or $10 M+ AR, a shift with lasting ecosystem implications.[CE001, CE002, CE003, CE004, CE005, CE006]
| Module / product | Primary user | Status / maturity | Differentiation | Diligence gap |
|---|---|---|---|---|
| Zero Trust Access — SSH | Engineer / admin | GA, production at major enterprises | Certificate-only auth, no SSH keys; audit logging per session | Legacy-protocol support gap vs StrongDM |
| Zero Trust Access — Kubernetes | Platform / DevOps engineer | GA | kubectl cert injection; per-pod RBAC; session recording of kubectl exec | Agent runs as root on nodes — additional attack surface |
| Zero Trust Access — Databases | DBA / developer | GA; PostgreSQL, MySQL, MongoDB, CockroachDB and more | Protocol-level access control without client-side config changes | Full DB protocol coverage list not publicly enumerated per version |
| Zero Trust Access — Windows / RDP | IT admin / engineer | GA; agentless RDP through Teleport Web UI | No separate RDP client needed; screen-level session recording | Clipboard access flagged as security gap by PeerSpot users |
| Zero Trust Access — Web Apps | Engineer / internal user | GA | HTTPS proxy with identity-based access and audit events | SSO depth per identity provider not detailed publicly |
| Zero Trust Access — MCP Servers | AI developer / platform team | GA (Community and Enterprise) | First-class MCP enrollment; per-tool audit events | Operational maturity and production scale unverified |
| Machine & Workload Identity | Service / CI-CD / workload | GA | tbot issues short-lived certificates; no standing service secrets | SPIFFE/SVID interop depth not fully documented externally |
| Identity Governance | Security / compliance team | GA (Enterprise) | Access lists, nested groups, JIT access requests, ChatOps integrations | Nested Access Lists introduced in v17 — maturity new |
| Identity Security | CISO / security analyst | GA (Enterprise) | Crown Jewels monitoring, SQL-editor access queries, anomaly alerting | AI alerting model accuracy and false-positive rate not disclosed |
| Beams — Agentic Runtime | AI developer / platform team | Public beta (Enterprise Cloud only), June 2026 | Firecracker VM isolation, LLM Proxy, Delegated Identity | Beta only; GA timeline undisclosed; Cloud-only restricts self-hosted deployments |
Maturity ratings based on official Teleport feature matrix and release notes. Community Edition gaps noted where applicable.
[CE001, CE002, CE003, CE004, CE005, CE006]Five product pillars layered over the unified Auth and Proxy control plane.
[CE001, CE002, CE003, CE004, CE005, CE006]5.2 Architecture and Operating Model
Teleport's control plane consists of two canonical services: the Auth Service (the cluster CA, config store, and audit-log collector) and the Proxy Service (the public-internet entry point and reverse-tunnel hub). These two services are stateless relative to each other, communicate over gRPC, and can be scaled horizontally for high availability. On Teleport Cloud, both services are fully managed by Teleport Inc.; on Enterprise Self-Hosted, customers operate them on their own infrastructure. Resource enrollment follows three paths: Teleport Agents (deployed as daemons on target machines and reverse-tunnelled back to the Proxy), agentless mode for certain protocols, and Machine & Workload Identity tokens (tbot-based short-lived certificates for workloads). The authentication flow is consistent across protocols: a user (or machine) runs tsh login, receives a client certificate, and that certificate is accepted by SSH, Kubernetes, database, RDP, and MCP proxies without re-authentication. Session recording is configurable at node or proxy level, synchronously or asynchronously, and captures full PTY output for SSH and Kubernetes, screen content for desktop sessions, and query streams for database sessions. StrongDM's competitive analysis notes that Teleport agents run as root on target servers, creating an additional attack surface; the company also criticizes limited legacy-protocol support and intermittent cloud reliability. PeerSpot users independently flag RBAC complexity, initial-setup burden, and clipboard-access security in RDP sessions as real friction points.[CE010, CE011, CE012, CE013, CE014, CE015]
| Layer / component | Role | Dependency | Risk |
|---|---|---|---|
| Auth Service | Internal CA; config store; audit-log collector | Requires persistent backend (etcd, DynamoDB, Postgres, or Teleport Cloud storage) | Single point of failure if HA not configured; key rotation policy must be exercised |
| Proxy Service | Public-internet entry; reverse-tunnel hub; Web UI server | Auth Service via gRPC; TLS routing for all protocols on port 443 | StrongDM claims cloud reliability issues and up-to-6-hour downtime on updates |
| Teleport Agent | Runs on target node; reverse-tunnels traffic back to Proxy | Target OS (Linux/Windows); root-level access required for most modes | Agent as root expands attack surface on every enrolled host |
| tbot (MWI agent) | Issues and renews short-lived certificates for workloads | Teleport Auth Service; SPIFFE-compatible certificate format | tbot credential exposure if process isolation is weak |
| Certificate Authorities | Sign host and user certs; enable zero-trust cluster membership | Hardware Security Module optional; BoringCrypto for FIPS | CA compromise would invalidate entire cluster; rotation automation needed |
| Session Recording Store | Captures PTY/screen/query streams; tamper-resistant audit | S3-compatible object store or Teleport Cloud storage | Users can attempt to conceal PTY commands via encoding (documented risk) |
| Identity Security Analytics | SQL-editor queries on access graph; Crown Jewels monitoring; AI anomaly detection | Ingests logs from Okta, AWS, GitHub; Teleport audit stream | AI alerting accuracy not independently validated |
| Beams Runtime (beta) | Firecracker microVM per agent session; LLM Proxy; Delegated Identity | OpenAI / Anthropic inference endpoints; Teleport identity layer | Beta; Enterprise Cloud only; GA timeline undisclosed |
Architecture based on official Teleport docs and feature matrix; StrongDM claims are competitor-sourced and may be biased.
[CE010, CE011, CE014, CE015, CE016, CE017]How a user or machine authenticates and obtains access to a protected resource.
[CE010, CE011, CE012, CE013]5.3 Agentic Identity and Machine & Workload Identity
Teleport Machine & Workload Identity (MWI) provides non-human service accounts using the same certificate-based model as human access. Services authenticate via tbot, receive short-lived X.509 or SSH certificates, and those certificates authorize access to databases, Kubernetes clusters, internal APIs, and MCP servers — all logged to the same audit trail. This creates a single identity fabric for humans and machines rather than a parallel secret-management system. The Agentic Identity Framework, announced January 2026, extends that model to AI agents. It defines four layers: identity (cryptographic agent certificates), access (RBAC/ABAC enforcement through the Teleport proxy), security (behavioral monitoring and locks), and scheduling (orchestration patterns for Kubernetes and Temporal). The June 2026 public beta of Beams added two concrete capabilities: LLM Proxy (sits between an agent and its inference endpoint, logs every request/response, enforces per-Beam allowlists) and Delegated Identity (allows a human or orchestrator to assign least-privilege permissions to an agent session). Each Beam runs in a Firecracker microVM with ephemeral storage, injected identity, virtual networking, and a session-bound lifecycle of approximately 24 hours. Beams is currently Enterprise Cloud only and in public beta — not generally available.[CE020, CE021, CE022, CE023, CE024, CE025]
| User job | Current workflow without Teleport | Teleport solution | Measurable benefit stated | Limitation / gap |
|---|---|---|---|---|
| Engineer SSH access to cloud host | Distribute SSH keypairs; rotate manually; no central audit | tsh login → short-lived cert → ssh user@host; auto audit log | Eliminates standing SSH keys; 80% drop in time spent on access (company-claimed) | Agent must run as root on target; legacy OS support limited |
| Kubernetes cluster access | kubectl with long-lived kubeconfig tokens; separate RBAC per cluster | Teleport injects cert into kubeconfig; RBAC centralized; per-query audit | Single SSO for all k8s clusters; per-exec session recording | Agent footprint adds ops complexity |
| Database access (Postgres/MySQL) | Direct DB credentials; shared passwords; no query audit | Teleport DB proxy; short-lived cert; query-level audit log | No DB credentials on developer laptop | Not all DB engines supported in all versions |
| Windows desktop (RDP) | Separate RDP clients; VPN + RDP credentials stored on laptops | Browser-based RDP through Teleport Web UI; no RDP client needed | Screen-capture session recording; no VPN required | Clipboard security concern noted in user reviews |
| AI agent access to infrastructure | Agents impersonate users with static API keys and unchecked permissions | tbot issues agent its own certificate; RBAC enforced at proxy; queries logged | 100% auditable agentic workflow (company-claimed) | Beams still in public beta; self-hosted Beams not supported |
| FedRAMP / compliance audit | Manual log collection across VPN, bastion, and cloud IAM | Teleport covers AC-02, AC-03, AC-07, AU-02, AU-12 and more natively | Accelerates FedRAMP-Moderate ATO; FIPS 140-3 validated module | FedRAMP ATO timing depends on full customer stack |
Benefit statements are company-claimed unless otherwise noted; independent quantification not available.
[CE010, CE012, CE013, CE014, CE015, CE029]Dependencies between the Agentic Identity Framework components and external services.
[CE020, CE021, CE022, CE023, CE024, CE025]5.4 Trust, Compliance, and Roadmap
Teleport Enterprise includes FIPS 140-validated cryptographic modules. Versions 17.7.3+ and 18.0.0+ use BoringCrypto CMVP certificate #4735 (FIPS 140-3); earlier versions used certificate #4407 (FIPS 140-2). This makes Teleport a viable accelerator for FedRAMP-Moderate authorization because it covers AC-02 through AU-12 and other NIST SP 800-53 controls natively. Teleport also documents SOC 2 coverage across four of nine control categories (CC6, CC6 physical, CC7, CC8). An independent security audit by Cure53 in 2019 found no critical vulnerabilities; the single high-severity directory-traversal issue in the roles API was patched in the same release. The release cadence is one major version per year (switching from four-month cadence); version 18 is the current supported release (EOL August 2027) and version 17 the stable supported release (EOL August 2026). Upcoming roadmap items include Linux Desktop Access (remote sessions to Linux hosts), directory-sharing enhancements for Windows RDP, and AI-summarized session recordings in Identity Security. The community-license change starting with version 16 (June 2024) is the most significant ongoing trust risk: compiled binaries, container images, and AMIs are no longer Apache-licensed for companies above 100 employees or $10 M AR. The source code remains AGPLv3, but most enterprises consume compiled artifacts, making the commercial restriction the effective license.[CE029, CE030, CE031, CE032, CE033, CE034]
| Control / certification | Status | Scope | Gap / caveat |
|---|---|---|---|
| FIPS 140-3 (BoringCrypto | Active | Teleport Enterprise v18+ compiled binaries | Only Enterprise builds; Community Edition not FIPS |
| FIPS 140-2 (BoringCrypto | Active for older releases (pre-17.7.3) | Teleport Enterprise v16–17 series | Being superseded by FIPS 140-3 module |
| FedRAMP coverage (AC, AU controls) | Supported via FIPS builds + RBAC + audit logging | Infrastructure access controls; not a full ATO | Customer must obtain their own ATO; Teleport is an enabler |
| SOC 2 (CC6, CC7, CC8) | Documented mapping available | Enterprise Edition; four of nine control categories | SOC 2 compliance features not available in Community Edition |
| Third-party security audit (Cure53) | Completed 2019; no critical vulnerabilities found | Full source-code audit; one high-severity issue patched same release | Audit is 2019; no more-recent public third-party audit disclosed |
| Apple code signing | Active (Developer ID QH8AA5B8UP, Gravitational Inc.) | macOS packages and binaries | Certificate expires 2026-07-27; renewal status unconfirmed publicly |
| Community Edition commercial license (v16+) | Active since June 2024 | Companies with 100+ employees or $10 M+ AR must purchase Enterprise | License change disrupts open-source ecosystem; AGPLv3 source remains available |
| Session recording security (PTY obfuscation risk) | Documented limitation in official docs | SSH and Kubernetes sessions | Users can encode commands to conceal activity; BPF Enhanced Recording mitigates |
Compliance status reflects publicly documented official claims and linked CMVP certificates; no independent third-party verification post-2019.
[CE029, CE030, CE031, CE032, CE033, CE034]| Date / version | Feature / milestone | Status | Implication | Source |
|---|---|---|---|---|
| July 2025 (v18.0.0) | Teleport 18 current release; AWS IAM Identity Center preview | Released; EOL August 2027 | Core GA release; sets foundation for 2026 product roadmap | Official docs |
| November 2024 (v17.0.0) | Teleport 17 stable; Identity Security Crown Jewels; Nested Access Lists | Released; EOL August 2026 | Crown Jewels and Nested Access Lists are new; maturity still emerging | Official blog |
| June 2024 (v16.0.0) | Teleport 16; community license commercial restriction; IdP hardening | Released | Community Edition now restricted for enterprises; ecosystem impact ongoing | Official blog + community license announcement |
| January 2026 | Agentic Identity Framework announced; four-layer AI security roadmap | Announced | Defines architecture for AI agents; commercial implementation in progress | Press release |
| June 2026 | Beams public beta — LLM Proxy and Delegated Identity in Firecracker VM | Public beta (Enterprise Cloud only) | GA timeline undisclosed; self-hosted customers excluded from beta | Press release |
| Week of July 6, 2026 (v18.10.0) | Patch cycle continues; 18.10.0 planned cloud rollout | Planned | Confirms four-month patch cadence within major version | Official upcoming-releases docs |
| Future (v19.0.0) | Linux Desktop Access; multi-directory Windows RDP; AI-summarized session recordings | On roadmap; date not disclosed | Linux desktop extends RDP coverage; AI summaries reduce investigation time | Official upcoming-releases docs |
Dates based on official release announcements and docs; Beams GA timeline is not publicly disclosed.
[CE034, CE035, CE036, CE037, CE008, CE026]Maturity and competitive differentiation across Teleport's key capability areas.
Maturity ratings derived from official docs and feature matrix; competitive differentiation is author assessment based on architecture analysis and competitor comparisons.
[CE001, CE003, CE005, CE006, CE020, CE025]5.5 Exhibits
06Customers
6.1 Customer Segmentation and Buying Profile
Teleport's buyer is primarily the engineering or platform-security team at mid-to-large enterprises, particularly in technology, financial services, and global digital platforms. The product is bought by infrastructure engineering leaders (VPs of Engineering, Platform Engineers, CISOs), with DevOps and SRE teams as the primary users. The official customer page and case studies show a consistent pattern of companies seeking to replace VPN-plus-shared-credentials approaches with certificate-based infrastructure access. Verticals represented in public case studies include fintech (Carta, Exness), global SaaS platforms (GoTo, Gladly), network detection (ExtraHop), and enterprise observability (IBM Instana). The Series A funding announcement named Nasdaq (stock exchange), Splunk (SIEM/observability), TicketMaster (live entertainment), Mulesoft (API integration), and Samsung (consumer electronics), while Series C specifically named Nasdaq, DoorDash, and Snowflake. The Fortune Cyber 60 press release (October 2025) stated "more than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud," depend on Teleport — the most expansive customer base claim to date, though this is company-stated. Geography is heavily North America and global-tech, with GoTo based in Southeast Asia (Indonesia) and Exness operating globally across financial markets. Company size ranges from growth-stage (Series-B era customers) to major public enterprises (Nasdaq, Samsung, IBM). The Community Edition provides a top-of-funnel acquisition path for smaller companies and teams under 100 employees or $10 M AR, with Enterprise sales triggered by the commercial license threshold.[CU001, CU002, CU003, CU004, CU005, CU006]
| Segment | Buyer / User | Primary use case | Public scale / proof | Gap |
|---|---|---|---|---|
| Tech-native enterprise (fintech/SaaS/cloud) | VP Engineering / CISO / Platform team | Certificate-based SSH, K8s, DB access; compliance (SOC 2, ISO 27001) | Carta, Exness, Gladly, ExtraHop, GoTo confirmed in case studies | NRR, contract size, and churn not disclosed |
| Global digital platforms (e-commerce, mobility, gaming) | Platform/SRE engineer | Multi-cloud access unification; Kubernetes private cluster access | GoTo (SE Asia platform), Rush Street Interactive (gaming), Turo (car-sharing) | No disclosed deployment size metrics |
| Enterprise observability / infrastructure tooling vendors | Cloud Architect / Infrastructure team | Secure access to cloud-native observability tools; compliance proof | IBM Instana (IBM-owned); ExtraHop; KnowBe4 | Only IBM Instana has a detailed case study |
| Financial services / stock exchanges | Security / compliance team | FedRAMP-ready; audit logging for regulatory compliance | Nasdaq named in Series A and C; "3 of top 5 financial services firms" (Fortune Cyber 60) | NVIDIA unverified; individual financial firm case studies absent |
| Startup / SMB community (sub-threshold) | Dev / DevOps engineer | Free community edition for companies under 100 employees / $10 M AR | 15,000+ GitHub stars; broad open-source adoption signal | Community-to-Enterprise conversion rate unknown |
Segmentation based on public case studies, funding blog named customers, and official press releases. Revenue or seat concentration across segments is not publicly disclosed.
[CU001, CU002, CU003, CU004, CU005, CU010]How a typical enterprise customer discovers, evaluates, deploys, and expands Teleport.
[CU001, CU002, CU003, CU030, CU031]6.2 Adoption Trajectory and Scale Signals
Teleport's most authoritative customer-count statement comes from the October 2025 Fortune Cyber 60 press release: "More than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport." This is company-stated and cannot be independently audited. Earlier milestones include the Series A blog's "handful of early adopters to an impressive portfolio of some of the world's largest and most innovative companies" and the Series C tracking of "net new ARR up 4.5x year over year." The Getlatka database (as of November 2025) reported approximately $49 M in annual revenue and ~246 employees, consistent with mid-market SaaS scale. The case study page lists at least 15 named customers publicly — GoTo, Exness, Gladly, ExtraHop, IBM Instana, Carta, KnowBe4, Turo, Rush Street Interactive, Buyers Edge, ThredUP, Qwilt, Mapgears, ECMWF, Flywheel — plus many more described without names. The diversity spans North American SaaS, global fintech, gaming, e-commerce, biomedical research, and weather infrastructure. Deployment depth appears to run deep: Exness reports "hundreds of Kubernetes clusters across on-prem and cloud" managed through Teleport, and GoTo describes Teleport managing access "across multiple cloud providers" for their vast infrastructure. Teleport has been named to the Fortune Cyber 60 for multiple years and was recognized as a "revenue category mover" in the Citizens Cyber 66 April 2026 report, indicating continued business momentum. Independent revenue data is limited; Getlatka's $49 M estimate is unverified. NVIDIA appears on some unofficial logo walls but is not confirmed in any official press release or case study — treated here as a gap.[CU010, CU011, CU012, CU013, CU014, CU015]
| Milestone / metric | Value | Date / source | Confidence | Gap |
|---|---|---|---|---|
| Named customer count (official statement) | >600 companies | October 2025 (Fortune Cyber 60 press release) | Low-Medium (company-stated; not independently verified) | No independent audit; stated by Teleport |
| Net-new ARR growth (Series C era) | 4.5x YoY net-new ARR; 2.8x total ARR YoY | March 2022 (Series C blog) | Medium (historical; consistent with disclosed funding) | Not updated since 2022; growth rate unknown now |
| Revenue estimate (independent) | ~$49 M annual revenue in 2024 | November 2025 (Getlatka) | Low (estimated; methodology undisclosed) | Independent estimate; not confirmed by Teleport |
| Named case studies on official page | 15+ named customer stories | June 2026 (Teleport case study page) | High (directly observed) | Sample of enterprise customers; not representative of full base |
| GitHub stars (open-source adoption signal) | >15,000 stars | June 2024 (community license announcement) | Medium (company-stated; current count not re-fetched) | GitHub star count not independently re-fetched as of runDate |
| Recognized as "revenue category mover" | Citizens Cyber 66 2026 recognition | April 2026 (Citizens Securities report) | Medium (independent analyst firm recognition) | Report is not publicly available in full |
| Employees | ~246 employees | November 2025 (Getlatka) | Low (estimated) | Third-party estimate; not confirmed by Teleport |
Values are from public sources; NRR, GRR, logo count, and ARR are private. Getlatka revenue and headcount estimates are unverified third-party data.
[CU010, CU011, CU012, CU013, CU014, CU016]Estimated conversion stages from open-source community to enterprise customer.
Stage sizes are estimated; only GitHub star count and 600+ enterprise figure are officially stated. Community-to-enterprise conversion rate is not publicly disclosed.
[CU010, CU013, CU014]6.3 Named Customer Proof and Case Study Quality
Six customers have deep, publicly documented case studies on goteleport.com, all confirming production use: **IBM Instana** (acquired by IBM 2020): Cloud Architect Hunter Madison replaced VPN-plus-shared-credentials with Teleport for Dropwizard access and states this is the third company where he has led a Teleport migration. Quote: "This is company number three I've done this at, to have Teleport in play to give us the ability to go and help our security posture." Confirms production use; independent and specific. **Carta** (fintech, $7 B+ valuation): Integrated Teleport with Okta for Kubernetes and database RBAC, role-based access policies with fine-grained auditing, and streamlined developer onboarding/offboarding. Confirms SOC 2/ISO 27001 compliance use. Production at scale. **GoTo** (Southeast Asia's largest digital platform, publicly listed): Replaced in-house tools with Teleport for private Kubernetes clusters ("all our Kubernetes clusters are private—meaning they can't be accessed publicly"). Production at multi-cloud scale; compliance-driven (publicly listed company). **Exness** (global fintech, regulated financial services): "Teleport was the only evaluated solution that met every requirement" including full automation, GitOps readiness, SSO, and machine identity. Production across hundreds of Kubernetes clusters. Confirmed compliance with PCI DSS, SOC 2, and ISO 27001. **Gladly** (SaaS CX platform): Uses Teleport as certificate authority for RBAC instead of static SSH keys. Confirms secretless server access for compliance and evidence-based security audits. **ExtraHop** (network detection and response): Secured half a dozen Kubernetes clusters each running hundreds of individual nodes with Teleport for identity-based SSH and Kubernetes access. Verified logos from official press releases: Nasdaq, DoorDash, Snowflake, Splunk, TicketMaster, Mulesoft, Samsung (Series A/C blogs). Square, Elastic, and Bloomberg appear on the official customer page but lack individual case studies. NVIDIA is not verified in official sources.[CU019, CU020, CU021, CU022, CU023, CU024]
| Customer | Sector | Deployment confirmed | Outcome / quote | Verification status | Source |
|---|---|---|---|---|---|
| IBM Instana | Enterprise observability (IBM subsidiary) | Production — Kubernetes, databases, SSH | This is company number three I've done this at, to have Teleport in play | Verified: official case study on goteleport.com | Official case study |
| Carta | Fintech (cap table management) | Production — Kubernetes RBAC, databases, Okta SSO integration | SOC 2/ISO 27001 compliance; improved developer onboarding | Verified: official case study on goteleport.com | Official case study |
| GoTo | Southeast Asia digital platform (publicly listed) | Production — private Kubernetes clusters, multi-cloud | Teleport fit our requirements perfectly for private K8s access | Verified: official case study on goteleport.com | Official case study |
| Exness | Global fintech / trading technology (regulated) | Production — hundreds of K8s clusters, databases, SSH, web apps | Teleport was the only evaluated solution that met every requirement | Verified: official case study on goteleport.com | Official case study |
| Gladly | SaaS customer experience platform | Production — secretless SSH access, RBAC, compliance auditing | Session recording as audit evidence for compliance | Verified: official case study on goteleport.com | Official case study |
| ExtraHop | Network detection and response (cybersecurity) | Production — 6 K8s clusters, hundreds of nodes each | Identity-based authorization for all K8s API queries and SSH commands | Verified: official case study on goteleport.com | Official case study |
| Nasdaq | Stock exchange (financial markets) | Stated customer (no individual case study) | Named as customer in Series A blog and Series C Bessemer quote | Verified: official blog posts | Series A blog; Series C blog |
| DoorDash | Food delivery platform | Stated customer (no individual case study) | Named by Bessemer in Series C investment blog | Verified: official Series C blog | Series C blog |
| Snowflake | Cloud data platform | Stated customer (no individual case study) | Named by Bessemer in Series C investment blog | Verified: official Series C blog | Series C blog |
| Splunk | SIEM / observability (now Cisco) | Stated customer (no individual case study) | Named in Series A blog | Verified: official Series A blog | Series A blog |
| Samsung | Consumer electronics / global enterprise | Stated customer (no individual case study) | Named in Series A blog | Verified: official Series A blog | Series A blog |
| NVIDIA | AI compute / semiconductor | Not confirmed | Not found in any official press release or case study | Unverified: not in official sources | Gap — no source |
Verification status reflects whether the customer name appears in an official Teleport-published source (case study, blog, press release). 'Unverified' means the name appears only on third-party or community lists, not in official sources. NVIDIA is a documented gap.
[CU019, CU020, CU021, CU022, CU023, CU024]Quality and depth of public customer proof across key dimensions.
Scores reflect author assessment of publicly available evidence; customers without case studies are limited to named references only.
[CU019, CU020, CU021, CU022, CU023, CU024]6.4 Retention, Expansion, and Concentration Risk
Teleport does not publicly disclose NRR, GRR, logo churn, or renewal rates. The Series C blog mentioned ARR growing 2.8x year over year and net-new ARR up 4.5x, consistent with strong expansion from existing customers, but these figures are from 2022 and are now historical. PeerSpot users report that Teleport "changed our workflow by centralizing access control," and several reviewers describe it as a sticky replacement for legacy SSH key workflows — both signals of high switching costs. The depth of enterprise deployments at Exness (hundreds of Kubernetes clusters), GoTo (multi-cloud, multi-vertical), and ExtraHop (hundreds of individual nodes) suggests high infrastructure integration depth that creates meaningful switching costs. IBM Instana's cloud architect explicitly notes this is his third Teleport deployment across different companies, which is a strong signal of advisor-driven repeat adoption. Expansion risk: StrongDM's competitive critique argues that Teleport lacks legacy-protocol support and SIEM integration, which could limit expansion to customers with mixed legacy/cloud environments. The community-license change (v16+) restricts the free community tier for large companies, potentially increasing friction for commercial expansion from the community funnel. Concentration is a material risk: publicly named customers skew heavily toward tech-native companies in fintech and cloud infrastructure; healthcare, manufacturing, government, and retail sectors are underrepresented in public proof. Fortune Cyber 60 noted "three of the top five financial services firms," which is significant concentration in a single vertical.[CU029, CU030, CU031, CU032, CU033, CU034]
| Signal | Evidence | Confidence | Limitation |
|---|---|---|---|
| Advisor-driven repeat deployment | IBM Instana's cloud architect confirms third Teleport deployment across different companies | High | Single individual cited; not representative sample |
| Deep infrastructure integration (switching costs) | Exness — hundreds of K8s clusters; GoTo — multi-cloud; ExtraHop — hundreds of nodes | High | Depth metrics inferred from case studies; not aggregate retention data |
| Community ecosystem loyalty (open-source) | 15,000+ GitHub stars; ongoing community forum activity | Medium | Stars are lagging indicator; current activity not separately measured |
| Positive user reviews (PeerSpot) | Described as solid, secure, productivity-enhancing; replaces legacy tools | Medium | PeerSpot review count not disclosed; may be curated sample |
| NRR / GRR (quantitative) | Not disclosed | Low (not available) | Critical retention metric; no proxy available publicly |
| Contract length / renewal rate | Not disclosed | Low (not available) | No public disclosure of contract terms or renewal benchmarks |
| Churn signals (adverse) | StrongDM claims Teleport Cloud reliability issues; PeerSpot reviews cite setup friction | Medium | Competitor critique may be biased; but PeerSpot reviews are independent |
Retention evidence is qualitative and indirect. Quantitative NRR, GRR, and renewal data are private. Advisor-driven repeat deployment is a strong qualitative signal but based on a single individual.
[CU019, CU029, CU030, CU031, CU032, CU033]| Risk factor | Evidence | Severity | Diligence ask |
|---|---|---|---|
| Vertical concentration (tech-finance) | Publicly named customers are heavily fintech, cloud, and SaaS; healthcare and manufacturing absent | Material | Ask for sector breakdown of ARR across verticals |
| Financial services concentration | Three of top five financial services firms named; Nasdaq is sole named financial exchange | Material | Request top-10 customer concentration as % of ARR |
| Community-to-Enterprise conversion friction | License change for v16+ restricts community users above 100 employees / $10 M AR | Material | Measure change in community → enterprise conversion rate post-v16 |
| NVIDIA logo unverified | NVIDIA not found in any official Teleport source; may appear on unofficial logo walls | Minor | Confirm whether NVIDIA is an active enterprise customer |
| Competitive loss risk (legacy protocols) | StrongDM claims Teleport lacks legacy-protocol support; limits expansion in mixed environments | Material | Request competitive win/loss data for deals involving legacy systems |
| Self-hosted customer upgrade path | Beams and some Identity Security features Cloud-only; self-hosted customers may lag | Minor | Ask for self-hosted vs Cloud split of enterprise customers |
Concentration risk is inferred from public named-customer evidence; private ARR concentration data is not available.
[CU034, CU035, CU036, CU037, CU038, CU039]Qualitative retention signal strength across key dimensions for the six case-study customers.
Scores are 0-100 qualitative assessments based on public case study evidence; no quantitative NRR or renewal data is publicly available.
[CU019, CU020, CU021, CU022, CU023, CU024]6.5 Exhibits
07Risks
7.1 License Change and Open-Source Community Risk
Teleport created a self-inflicted trust risk when it moved Community Edition compiled artifacts from Apache 2.0 to a commercial license starting with Teleport v16 in June 2024. The policy applies to companies with 100 or more employees or at least $10 million of annual revenue, and it also blocks resale or embedding of Community Edition artifacts. That change matters because Teleport built much of its category credibility through developer adoption and had more than 15,000 GitHub stars when the announcement was made. The source code remains available, but the practical thing most enterprises consume is the binary, image, or AMI, so the commercial restriction changes the lived developer experience even if the repository stays public. The resulting risk is broader than social-media backlash. It creates fork incentives, reduces bottom-up evangelism, complicates upgrade paths from older Apache-licensed builds, and invites criticism that Teleport is no longer behaving like a conventional infrastructure open-source project under the Open Source Initiative definition.[CR001, CR002, CR003, CR004, CR005, CR006]
| Rule / license / case | Jurisdiction | Status | Likelihood | Severity | Mitigation | Residual exposure | Diligence path |
|---|---|---|---|---|---|---|---|
| Teleport v16 Community Edition commercial license | Global commercial use | Active since June 2024 for larger companies and blocks resale/embed | High | High | Clear commercial upsell path and source availability reduce near-term confusion | High because trust damage and fork incentives remain | Review license text, SKU enforcement, and customer upgrade policy |
| Open Source Initiative Open Source Definition | Global open-source norm | Usage-restricted commercial terms do not align with OSI open-source criteria | High | Medium | Teleport can still maintain a public repo and community docs | High because developer perception may not recover quickly | Request legal memo on OSS positioning and community communications |
| FedRAMP authorization posture for Teleport Cloud | United States public sector | Docs describe customer compliance acceleration; no public Teleport Cloud authorization found | Medium | High | FIPS-enabled builds and control mappings support customer ATO work | Medium to high because procurement teams may expect vendor authorization | Confirm whether any cloud service authorization package exists and who owns boundary controls |
| FIPS 140-3 cryptographic boundary representation | United States regulated buyers | Supported in specified builds using BoringCrypto certificate #4735 | Low | Medium | Official version guidance narrows approved deployment range | Low to medium because version drift can still create compliance mistakes | Verify exact build versions used by target customers and sales claims |
| Legacy Apache-licensed artifact provenance | Existing enterprise users | Older versions remain under prior terms but upgrade path changes economics and obligations | Medium | Medium | Version pinning and contract review can reduce surprise | Medium because mixed-version estates may create legal and operational friction | Map which customers rely on pre-v16 artifacts and planned migration timing |
Rows focus on public legal and compliance issues that can change procurement, upgrade, or community outcomes; they are not a substitute for contract review.
[CR001, CR002, CR004, CR007, CR016, CR017]Relative view of Teleport's top residual risk buckets after visible public mitigants.
[CR006, CR014, CR018, CR026, CR033, CR041]7.2 Self-Hosted Complexity and Operational Risk
Teleport's architecture delivers strong control and audit benefits, but it pushes operational burden onto customers in ways that can become investment risk. Competitor materials from StrongDM argue that Teleport agents run as root on target servers, creating a meaningful privileged attack surface, and they also frame Teleport as a potential single point of failure when the control plane is not designed for high availability. Those claims are directional rather than neutral, but they align with customer-review evidence that large deployments can be complicated to configure and operate. The self-hosted model requires customers to own infrastructure sizing, patching, upgrade sequencing, disaster recovery, and outage planning for auth and proxy components. Teleport has published security-audit material and FIPS 140-3 support, which are real mitigants, but those do not erase architecture fragility or implementation complexity. FedRAMP adds another layer: Teleport documents how customers can satisfy control families with the product, yet the public corpus does not show Teleport Cloud itself holding a FedRAMP authorization, which can create confusion in public-sector sales cycles.[CR010, CR011, CR012, CR013, CR014, CR015]
| Failure Mode | Likelihood | Severity | Mitigation Maturity | Residual Exposure | Unresolved Gap |
|---|---|---|---|---|---|
| Privileged agents running as root become an additional attack surface on managed servers | Medium | High | Medium | High in sensitive environments until hardening evidence is shown | Need hardening guidance, incident history, and customer security review outcomes |
| Auth/proxy control plane outage blocks infrastructure access when HA is misdesigned | Medium | High | Medium | High because access interruption hits mission-critical workflows | Need uptime history, reference architectures, and failover test evidence |
| Self-hosted deployments accumulate patching, upgrade, and disaster-recovery burden | High | Medium | Medium | Medium to high for lean customer teams | Need support-load metrics, HA runbooks, and version upgrade failure data |
| Limited legacy protocol or authentication support narrows fit in hybrid estates | Medium | Medium | Low | Medium because rivals can win mixed-environment deals | Need detailed protocol coverage matrix and win-loss data by environment |
| Enterprise RBAC and setup complexity slow initial rollout | High | Medium | Medium | Medium because complexity damages time-to-value | Need implementation timelines, services attach rate, and review sentiment by deployment size |
| FedRAMP marketing is misread as service-level authorization for Teleport Cloud | Medium | High | Low to medium | Medium because public-sector diligence can stall late | Need explicit sales language, objection handling, and authorization boundary documentation |
Operational risk is driven by architecture and deployment burden rather than by evidence of a specific disclosed incident in the current corpus.
[CR010, CR011, CR012, CR013, CR014, CR015]7.3 Competitor Pressure and Market Concentration Risk
Teleport is operating in attractive categories, but attractive categories draw larger and better-capitalized rivals. CyberArk and Okta each carried market capitalizations above $20 billion in June 2026, with materially larger revenue bases than Teleport's estimated scale, giving them more room to bundle privileged access, absorb product overlap, and outspend Teleport in enterprise sales. StrongDM attacks Teleport on legacy-system coverage and operational simplicity, which matters because many enterprise access estates are hybrid rather than cloud-native. HashiCorp Boundary remains an identity-aware proxy alternative with open-source roots, while AWS, Google Cloud, and Microsoft all provide native IAM and privileged-access features that can be good enough for cloud-only buyers. Teleport's 600-plus customers and named recognition on the 2026 Fortune Cyber 60 and Citizens Cyber 66 lists show real market traction, but they also raise the bar: once a vendor is in top-tier enterprise evaluations, feature gaps, packaging friction, and license trust questions are tested against better-funded platforms rather than against no incumbent at all.[CR019, CR020, CR021, CR022, CR023, CR024]
| Competitor/Dependency | Type | Competitive Threat/Failure Scenario | Severity | Mitigation | Residual Exposure |
|---|---|---|---|---|---|
| CyberArk | Incumbent PAM suite | Uses scale, broad enterprise relationships, and large product surface to bundle against Teleport | High | Differentiate on developer experience and modern infrastructure workflows | High |
| Okta Privileged Access | Identity-platform adjacency | Expands PAM into an existing IAM base and compresses standalone demand | High | Win on infrastructure depth, session recording, and platform breadth across SSH/Kubernetes/databases | High |
| StrongDM | Direct modern access competitor | Wins hybrid or legacy accounts by positioning simpler deployment and broader protocol coverage | Medium | Improve legacy support proof and self-hosted operating clarity | Medium |
| HashiCorp Boundary | Open-source-style alternative | Captures buyers who want identity-aware proxying without Teleport's new commercial-license baggage | Medium | Emphasize broader product surface and enterprise controls | Medium |
| AWS/GCP/Azure native IAM and PIM tools | Cloud-platform dependency | Cloud-only teams decide native controls are good enough and avoid another control plane | Medium | Focus on multicloud, hybrid, audit, and just-in-time workflows | Medium |
| Open-source goodwill and community channel | Ecosystem dependency | License distrust weakens referrals, contributors, and low-friction adoption | High | Rebuild trust with transparent roadmap and fair packaging | High |
This register blends named competitors with ecosystem dependencies because Teleport's risk is partly a product-feature battle and partly a distribution-trust battle.
[CR020, CR021, CR022, CR023, CR024, CR025]Indicative competitive pressure scores combining scale, adjacency, and substitution risk.
Scores are ordinal threat scores synthesized from scale, bundling power, and fit-based substitution risk; they are not market-share estimates.
[CR020, CR021, CR022, CR023, CR024, CR026]7.4 Financial Opacity and Valuation Risk
The financial debate around Teleport is defined less by visible weakness than by missing visibility. Public funding history is clear through the March 2022 Series C, when Teleport announced a $110 million round at a $1.1 billion valuation led by Bessemer Venture Partners, bringing cumulative funding to roughly $140 million across Series A, B, and C. What is not clear is current scale, margin structure, cash efficiency, or profitability. The only ARR figure in the source set is a GetLatka estimate of $49 million for 2024, and that figure is unverified by Teleport. If it were directionally correct, the last disclosed valuation would imply roughly a 22 times ARR multiple, which is demanding for a private infrastructure company without public proof of growth durability. Because no newer round is visible in the provided corpus, investors are forced to underwrite against a four-year-stale price anchor. That combination of stale mark, estimated ARR, and absent unit-economics data makes downside harder to quantify and gives better-resourced public comparables more influence over market sentiment.[CR028, CR029, CR030, CR031, CR032, CR033]
7.5 People, Execution, and Strategic Risk
Teleport's strategic risk now comes from trying to defend a mature infrastructure-access franchise while simultaneously expanding into agentic AI identity. Leadership concentration is notable: Ev Kovyrin, Sasha Klizhentas, and Taylor Wakefield still occupy the CEO, CTO, and COO roles at the center of product, engineering, and operating execution. The public material reviewed does not disclose a succession plan, broader bench depth, or current employee count, limiting external comfort on management redundancy. At the same time, Teleport has recast itself as an AI Infrastructure Identity Company, announced an Agentic Identity Framework in January 2026, and launched Beams in public beta in June 2026. Those moves may create genuine upside, but they also introduce roadmap complexity, support burden, and governance questions around delegated permissions, audit coverage, and agent runtime isolation. The core risk is not that the company should avoid AI-adjacent expansion; it is that investors still need evidence that the new motion strengthens the existing access business rather than distracting from it before monetization and controls are mature.[CR035, CR036, CR037, CR038, CR039, CR040]
| Role/Function | Dependency or Gap | Likelihood | Severity | Mitigation | Diligence Path |
|---|---|---|---|---|---|
| Founding leadership | Three co-founders still anchor strategy, engineering direction, and operations | Medium | High | Founders are experienced and still visibly active | Request org chart, delegated leaders, and succession planning materials |
| Compliance and public-sector GTM | FedRAMP positioning requires precise boundary ownership and buyer education | Medium | High | FIPS support and official control mapping help | Request public-sector pipeline, objection logs, and authorization ownership matrix |
| Agentic product team | AI identity expansion may dilute focus from core PAM execution | Medium | High | Reuse certificate, audit, and policy primitives from core platform | Request roadmap staffing split and GA readiness criteria for Beams |
| SRE and customer success | Self-hosted complexity can increase support burden and slow renewals | High | Medium | Reference architectures and managed cloud offering can reduce pain | Request support ratios, escalation metrics, and renewal data by deployment model |
| Finance and planning | No public profitability, burn, or growth disclosure limits external confidence | Medium | Medium | Prior blue-chip investors provide some signaling value | Request board pack metrics, current ARR, burn, and runway assumptions |
People risk is elevated because Teleport now spans core access security, regulated-buyer sales, and a new AI-runtime motion simultaneously.
[CR035, CR036, CR037, CR038, CR039, CR042]| Risk | Monitorable Trigger | Threshold/Event | Action Implication |
|---|---|---|---|
| License/community backlash | Meaningful fork traction or major enterprise objections tied to v16 licensing | Top-of-funnel loss or named deals blocked because Community Edition is no longer treated as open source | Re-underwrite growth efficiency and ecosystem moat downward |
| FedRAMP ambiguity | Public-sector diligence requests vendor authorization evidence | Teleport cannot show clear service-boundary language or any vendor authorization package | Delay underwriting of government expansion and escalate compliance review |
| Control-plane resilience | Reference architecture and outage evidence | No persuasive HA, DR, or uptime evidence for self-hosted or cloud operations | Treat architecture fragility as thesis-negative for mission-critical deployments |
| Financial opacity | Current ARR, burn, and margin pack | Management cannot reconcile 2024 estimate with current operating metrics | Haircut valuation and demand a wider downside case |
| AI pivot execution | Beams beta conversion and governance milestones | No clear adoption, GA path, or policy controls by next diligence milestone | Treat AI upside as free option rather than as value-bearing core thesis |
| Competitive displacement | Win-loss and renewal data | Legacy-support or bundle-driven losses rise against StrongDM, Okta, or CyberArk | Lower pricing power assumptions and sales-efficiency expectations |
These triggers are intentionally monitorable so diligence can separate fixable disclosure gaps from structural reasons to stop or reprice.
[CR031, CR033, CR041, CR043, CR044, CR045]How Teleport's license, architecture, and strategy risks propagate into growth and valuation.
[CR008, CR011, CR018, CR026, CR033, CR037]7.6 Exhibits
08Valuation
8.1 Investment Thesis and Anti-Thesis
The investment thesis starts with market structure and positioning rather than current financial disclosure. Teleport sells into privileged access management and zero-trust access, two security budgets that remain strategically important even in slower software spending environments. Precedence Research sizes PAM at $4.50B in 2025 growing at 23.4% CAGR, while zero trust is a much larger $40.01B market growing at 16.39% CAGR. Teleport also benefits from a developer-led distribution story: the open-source repository has built broad awareness, the company claims 600+ customers, and official references highlight adoption by three of the top five financial services firms. The investor base—Bessemer, Insight, Kleiner Perkins, and S28—adds credibility, and the 2026 Agentic Identity Framework / Beams repositioning offers a plausible narrative for expanding beyond classic human privileged access into machine and AI-agent identity. The anti-thesis is stronger than a normal late-stage software diligence memo because the key underwriting variable is still not publicly verified. GetLatka's unconfirmed $49M 2024 ARR estimate is the only current revenue anchor; if used, it implies roughly 22.4x EV/ARR against the stale $1.1B March 2022 Series C mark. That is richer than CyberArk's roughly 15.8x verified public multiple and far above Okta's roughly 7.1x. Competition is not theoretical: CyberArk, Okta, BeyondTrust, StrongDM, and Boundary all frame adjacent infrastructure access problems. The 2024 community-license change may also reduce the bottom-up open-source funnel that originally differentiated Teleport. Finally, the absence of FedRAMP authorization for Teleport Cloud narrows near-term federal upside, while no new primary round, IPO filing, or public liquidity signal has reset valuation expectations since 2022.[CV010, CV011, CV012, CV016, CV017, CV019]
| Side | Argument | Evidence Anchor | What Would Change the View |
|---|---|---|---|
| Thesis | Large and expanding PAM and zero-trust markets can support long-duration category growth. | PAM $4.50B in 2025; zero trust $40.01B in 2025. | Market growth slows materially or Teleport fails to convert TAM into verified ARR growth. |
| Thesis | Open-source distribution, GitHub traction, and 600+ customers suggest durable product relevance. | GitHub stars and enterprise customer claims support awareness and adoption. | Evidence of community decline, weak conversion, or major customer churn would weaken this. |
| Thesis | Bessemer, Insight, Kleiner Perkins, and S28 make the syndicate credible for future financing or exits. | Series A/B/C disclosures and investor commentary. | If the next round is flat/down or insiders avoid supporting a process, syndicate strength matters less. |
| Thesis | The 2026 AI-agent identity repositioning could expand Teleport beyond classic human privileged access. | Agentic Identity Framework and Beams launches. | If Beams fails to monetize or remains a demo narrative, the premium should disappear. |
| Anti-thesis | The only public ARR anchor is an unconfirmed $49M estimate, implying an expensive ~22.4x multiple. | GetLatka plus Series C valuation math. | Verified ARR materially above $70M with strong growth would narrow the valuation concern. |
| Anti-thesis | CyberArk, Okta, BeyondTrust, StrongDM, and Boundary all pressure achievable multiples. | Public comp data and competitor product pages. | A clear feature and growth gap in Teleport's favor could support a premium again. |
| Anti-thesis | The CE license change may weaken bottom-up community-led acquisition. | Official license-change announcement and GitHub/community context. | If conversion efficiency and self-serve pipeline stayed strong after the change, this risk falls. |
| Anti-thesis | FedRAMP absence and no public IPO or secondary signal reduce near-term optionality. | FedRAMP-oriented materials without authorization plus no later financing/IPO mark. | Authorization progress or a formal financing/exit process would improve the risk-adjusted view. |
Arguments are framed only around valuation relevance; they are not a generic quality scorecard.
[CV010, CV011, CV012, CV016, CV017, CV019]Public evidence supports product relevance but not a clean underwriting case at the stale valuation mark.
[CV010, CV011, CV012, CV019, CV024, CV025]8.2 Valuation Context and Comparable Set
Teleport's only disclosed valuation mark is the March 2022 Series C: $110M raised at a $1.1B post-money valuation led by Bessemer Venture Partners with Insight Venture Partners participating. Series B in 2021 added $30M, Series A in 2020 added $25M, and disclosed lifetime primary capital is therefore about $140M. No later primary financing, secondary quote, IPO filing, or other public mark has been announced in the official newsroom, leaving investors to assess a four-year-stale price against 2026 software comp conditions. The critical problem is not that $1.1B was impossible in 2022; it is that current public evidence does not confirm the operating scale that would justify keeping that mark today. GetLatka estimates 2024 ARR at $49M, but it is explicitly an estimated single-source data point rather than company disclosure. If that estimate is directionally correct, the stale mark implies about 22.4x EV/ARR. CyberArk provides the closest public PAM anchor at about $20.63B market cap and $1.30B TTM revenue, or roughly 15.8x. Okta, a broader identity platform that now sells privileged access, trades nearer 7.1x. Those public multiples are not perfect one-for-one equivalents, but they do establish gravity: Teleport needs either materially more ARR than $49M, much faster present-day growth than is publicly verified, or a durable AI-identity premium to deserve the old private mark. Without that proof, the valuation reads as expensive rather than simply premium.[CV001, CV002, CV003, CV004, CV005, CV006]
| Comparable | Category | Revenue/ARR Metric | Multiple/Valuation | Status | Relevance to Teleport | Limitation |
|---|---|---|---|---|---|---|
| Teleport (last mark) | Private infrastructure security | Estimated $49M ARR (2024 GetLatka) | $1.1B / ~22.4x ARR | Stale private round mark | Direct subject; shows what must be justified today | ARR is unconfirmed and the mark dates to March 2022 |
| CyberArk | Public PAM leader | $1.30B TTM revenue (June 2026) | ~15.8x revenue | Current public comp | Closest transparent PAM anchor for valuation gravity | Larger scale, public disclosure, and more mature product breadth |
| Okta | Public identity platform with PAM | $2.91B TTM revenue (June 2026) | ~7.1x revenue | Current public comp | Shows identity-market valuation floor with PAM adjacency | Broader category and different margin/growth mix |
| Private security SaaS reference band | Private growth reference | $40M-$60M ARR | ~8x-15x ARR | Illustrative private range | Useful for base-case private pricing discipline | Band is contextual rather than a single traded asset |
| High-growth premium band | Private upside reference | ARR with verified >50% growth | ~15x-25x ARR | Illustrative upside range | Shows the threshold needed for a premium mark to hold | Requires verified growth and often better disclosure than Teleport offers publicly |
Table mixes direct public comps with reference bands because no later Teleport financing or reliable private secondary mark is public. Revenue and ARR figures are time-specific and not normalized for net cash.
[CV006, CV007, CV008, CV025, CV039, CV041]Implied enterprise value from the $49M ARR estimate across selected revenue multiples.
Values round to the nearest million and use the single-source $49M ARR estimate only as a sensitivity anchor.
[CV005, CV006, CV025, CV041]8.3 Scenario Analysis and Sensitivity
The scenario range depends far more on verified revenue scale and growth durability than on spreadsheet complexity. In the bull case, Teleport's AI Infrastructure Identity repositioning works, Beams becomes a credible agent-identity wedge, and ARR compounds above 35% annually from the $49M 2024 estimate to roughly $85M by 2027. Applying a 15x multiple—roughly the high end of a transparent public PAM anchor rather than an aggressive AI bubble multiple— yields approximately $1.28B, only modestly above the old mark. That is an acceptable but not spectacular late-stage upside case. The base case assumes the product remains relevant and customer quality is solid, but growth settles closer to 25% annually. That reaches about $73M ARR by 2027. At 10x to 12x, consistent with a healthy but not euphoric security-software multiple band, implied value is about $730M to $875M. The bear case assumes the license transition slows developer-led acquisition, competitors pressure pricing, and the AI repositioning takes longer than the narrative suggests; under 15% annual growth, ARR only reaches about $60M, and a 6x to 8x range implies $360M to $480M. Put differently, most realistic paths need either better-than- public growth evidence or a lower entry price before risk-adjusted returns become compelling.[CV031, CV032, CV033, CV034, CV038, CV039]
| Scenario | Key Assumptions | 2027E ARR | Multiple Applied | Implied Valuation USD | Probability Signal |
|---|---|---|---|---|---|
| Bull | AI identity products gain traction, growth stays above 35%, and customer quality supports a premium multiple. | $85M | 15x | $1.28B | Upside case; requires verified growth and successful AI monetization |
| Base | Core access platform remains relevant, growth moderates to about 25%, and no major margin shock emerges. | $73M | 10x-12x | $730M-$875M | Most plausible on current evidence |
| Bear | License headwinds, comp pressure, and slower expansion hold growth near 15% with lower comp tolerance. | $60M | 6x-8x | $360M-$480M | Downside case if current narrative outpaces fundamentals |
ARR scenarios are derived from the $49M 2024 GetLatka estimate and should be treated as illustrative rather than company guidance.
[CV031, CV032, CV033, CV034, CV039, CV041]Bull, base, and bear value ranges show how little margin of safety exists around the stale mark.
Ranges are scenario outputs derived from the $49M ARR estimate and selected comp bands; they are not management guidance.
[CV031, CV032, CV033, CV034]8.4 Exit Readiness and Final Diligence Asks
Exit readiness is mixed. On the positive side, the founding team remains visible, the company continues launching product, and the investor syndicate is deep enough to support either a strategic sale or a later IPO attempt. The most plausible strategic acquirers are large security or infrastructure vendors that already touch identity, PAM, or zero-trust workflows, such as CyberArk, Palo Alto Networks, Cisco, or Microsoft. That said, nothing in the public record indicates that Teleport is currently on an IPO path, and there is no disclosed liquidity mechanism resetting price discovery for late-stage holders. The strategic-exit argument is therefore a possibility, not a valuation backstop. The diligence burden is high because the missing evidence sits exactly where valuation should be anchored: verified ARR for 2024 and 2025, current growth rate, net revenue retention, gross margin, burn, cap-table preferences, and the practical effect of the CE license change on new logo creation. Federal market expansion is another gating item because Teleport discusses FedRAMP-oriented use cases but does not have public authorization for Teleport Cloud. A prudent investor should therefore treat this as a data-room-dependent decision rather than a conviction round based on narrative momentum alone.[CV020, CV035, CV036, CV037, CV042, CV044]
| Trigger | Threshold/Event | Transmission to Thesis | Action Implication |
|---|---|---|---|
| ARR verification fails | Verified ARR is materially below $49M or 2025 ARR is not growing credibly | Entry multiple rises well beyond already-expensive public and private reference points | Pause or reprice below the stale $1.1B mark |
| Growth quality disappoints | Current YoY growth is below 25% or NRR is below 100% | Base case becomes too optimistic and multiple support compresses | Move from research-more to avoid unless price resets |
| Gross margin is weak | Gross margin is below software-like thresholds or burn is structurally heavy | AI or infrastructure narrative does not convert into attractive SaaS economics | Require a very different valuation framework or pass |
| License change hurts funnel | Community-led pipeline meaningfully declines after the CE shift | Bottom-up differentiation and capital efficiency weaken together | Discount long-term growth assumptions and CAC efficiency |
| Federal readiness stalls | No credible FedRAMP path for Teleport Cloud in target vertical strategy | Government and regulated TAM narrative becomes more limited than pitched | Remove federal upside from sizing and scenario ranges |
These are pre-commitment diligence triggers rather than post-investment operating KPIs.
[CV016, CV024, CV035, CV036, CV040, CV048]| Topic | Missing Evidence | Why It Matters | Owner/Diligence Path |
|---|---|---|---|
| ARR verification | Audited or CFO-attested ARR for 2024 and 2025 plus customer bridge | The current public anchor is a single-source estimate | Finance data room and customer cohort review |
| Growth and retention | Current YoY growth, NRR, churn, and expansion cohorts | Premium multiple logic depends on verified quality of growth | CFO package, board deck, and cohort analytics |
| Economics | Gross margin, burn, runway, and sales efficiency | Without unit economics the entry price cannot be stress tested | Finance workstream and management interviews |
| Cap table | Preference stack, anti-dilution terms, and liquidation rights | Preference overhang can impair return even if enterprise value grows | Company counsel and financing document review |
| License-change impact | Pipeline mix before and after CE transition | Community motion changes could alter CAC and conversion assumptions | GTM analytics review with product and sales leadership |
| FedRAMP roadmap | Authorization plan, timing, and go-to-market dependence on federal buyers | Government TAM cannot be fully counted without an execution path | Security/compliance review and federal pipeline diligence |
Each ask is directly tied to a valuation variable that is currently opaque in public materials.
[CV024, CV035, CV036, CV042, CV043, CV048]8.5 Recommendation and Evidence Assessment
The recommendation is research-more with medium confidence, a high risk rating, and an expensive valuation stance. Teleport appears strategically relevant, customer-validated, and well backed, but the investment committee does not need to decide whether the company is good; it needs to decide whether the entry price is supportable today. On currently public evidence, it is not. The 2022 $1.1B mark can only be defended if one assumes either meaningfully higher current ARR than the sole GetLatka estimate, a still-elevated growth rate that has not been publicly disclosed since Series C, or a premium AI-identity valuation regime that public comps do not yet validate. The evidence base is directionally useful but incomplete. Official sources strongly support the financing history, customer signaling, and product narrative, and public comps provide a clean benchmark showing that verified-sector multiples are lower than Teleport's implied estimated multiple. What is missing are the core financial disclosures that turn a narrative into a price. The recommendation should only improve if Teleport can verify ARR above roughly $70M, show NRR above 100%, confirm current growth at or above 25% YoY, provide visibility into gross margin and burn, and demonstrate either government-readiness progress or concrete exit timing. Until then, this remains a promising company with underwritten valuation risk.[CV005, CV006, CV024, CV025, CV032, CV034]
| Dimension | Assessment | Rationale |
|---|---|---|
| Recommendation | research-more | Public evidence is directionally positive but insufficient to underwrite the $1.1B mark. |
| Confidence | medium | Funding history and comps are clear, but ARR and current growth are not company verified. |
| Risk rating | high | Stale valuation, unconfirmed ARR, competitive pressure, and no public profitability data elevate downside risk. |
| Valuation stance | expensive | ~22.4x on unconfirmed ARR is above CyberArk's verified ~15.8x public revenue multiple. |
| Decision implication | Wait for financial verification | Require verified ARR, growth, NRR, margins, and cap-table visibility before advancing. |
Assessment is based on public evidence available on 2026-06-20 and uses GetLatka's unconfirmed $49M ARR estimate solely as a working anchor.
[CV004, CV005, CV006, CV024, CV025]IC-ready scoring balances market quality against evidence quality and valuation support.
[CV012, CV019, CV024, CV025, CV035, CV042]8.6 Exhibits
Disclaimer
This report is based on publicly available information and includes clearly marked third-party estimates where Teleport has not disclosed current metrics.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Teleport is headquartered at 2100 Franklin St, Suite 400, Oakland, California 94612 and describes itself as the AI Infrastructure Identity Company. | High | SO001, SO002 |
| CO002 | The company was originally incorporated as Gravitational Inc. and officially renamed itself Teleport in 2021, moving to the goteleport.com domain. | Medium | SO006 |
| CO003 | Teleport's corporate signing certificates still use "Developer ID QH8AA5B8UP Gravitational Inc." confirming the legal entity is still Gravitational Inc. | Medium | SO002 |
| CO004 | Teleport was founded in 2015 by Ev Kontsevoy, Alexander Klizhentas, and Taylor Wakefield. | High | SO003, SO019 |
| CO005 | Teleport's pricing is usage-based, metered by Monthly Active Users, Machine and Workload Identities, and Teleport Protected Resources. | Medium | SO010 |
| CO006 | Teleport Community Edition is free only for companies with fewer than 100 employees and annual revenue under $10M; larger companies must purchase Enterprise Edition. | High | SO007, SO010 |
| CO007 | Ev Kontsevoy serves as Co-founder and CEO, Alexander Klizhentas as Co-founder and CTO, and Taylor Wakefield as Co-founder and COO, all of whom are listed on the Teleport about page as of June 2026. | High | SO002, SO008 |
| CO008 | Jeff Bunten is listed as CRO and Diana Jovin as CMO on the Teleport about page. | Medium | SO002, SO028 |
| CO009 | All three co-founders previously worked together at Rackspace after that company acquired Mailgun, a developer email infrastructure startup they had built. | Medium | SO019 |
| CO010 | Ev Kontsevoy is the named author or spokesperson for all three fundraising blog posts, the Agentic Identity Framework launch, and the Fortune Cyber 60 press release. | Medium | SO003, SO004, SO005, SO013, SO011 |
| CO011 | No independent director names or full board composition have been disclosed by Teleport in public materials as of June 2026. | Low | |
| CO012 | Mary D'Onofrio from Bessemer Venture Partners joined the Teleport board at the Series C close; Matt Koran from Insight joined as a board observer. | Medium | SO003 |
| CO013 | Teleport raised a $25M Series A led by Kleiner Perkins; the company had reached profitability before the round and named NASDAQ, Splunk, TicketMaster, Mulesoft, and Samsung as customers. | High | SO005, SO019 |
| CO014 | Teleport raised a $30M Series B led by S28 Capital and Kleiner Perkins in 2021, following a quarter with net new ARR up 5x and total ARR up 2.5x year-over-year versus Q2 2020. | Medium | SO004 |
| CO015 | Teleport raised a $110M Series C led by Bessemer Venture Partners at a $1.1B valuation in May 2022, with net new ARR up 4.5x and total ARR up 2.8x year-over-year at the time of the round. | High | SO003, SO018 |
| CO016 | Total disclosed funding for Teleport across all three rounds is $165M. | High | SO003, SO004, SO005 |
| CO017 | GetLatka reported that Teleport raised $140M across 2 rounds, which diverges from the company-disclosed $165M across 3 rounds, suggesting GetLatka missed the Series A. | Low | SO020 |
| CO018 | No publicly available evidence of a Teleport funding round after the May 2022 Series C has been identified, and no SEC Form D filings for Gravitational Inc. or Teleport Inc. were found in EDGAR searches. | Medium | SO003, SO004, SO005 |
| CO019 | The $1.1B Series C valuation mark is approximately four years old as of June 2026, and private-market conditions tightened materially in 2022–2024. | Medium | SO003 |
| CO020 | GetLatka estimated Teleport's 2024 revenue at $49M, describing this as the revenue milestone the company hit in December 2024; this is a third-party estimate not confirmed by Teleport. | Low | SO020 |
| CO021 | GetLatka reported Teleport employs approximately 246 people as of late 2025; this is an unverified third-party estimate. | Low | SO020 |
| CO022 | Teleport's Series A blog stated the company had recently reached profitability before the round; no current profitability data is disclosed. | Medium | SO005 |
| CO023 | The Teleport careers page and press release state that more than 600 companies depend on Teleport as of October 2025. | Medium | SO008, SO011 |
| CO024 | Named customers from Teleport public materials include NASDAQ, Snowflake, DoorDash, IBM (Instana), Carta, GoTo, Exness, KnowBe4, Turo, Gladly, ThredUP, ExtraHop, and Rush Street Interactive. | Medium | SO009, SO015, SO016 |
| CO025 | The Teleport open-source GitHub repository had over 15,000 GitHub stars as of the June 2024 community license blog post. | Medium | SO007, SO023 |
| CO026 | The Teleport open-source project has been on GitHub under the AGPLv3 license since 2015 and supports SSH, Kubernetes, databases, RDP, web applications, and MCP servers. | Medium | SO023, SO007 |
| CO027 | Teleport releases major product versions on approximately a four-month cycle; Teleport 16 was released in June 2024 and Teleport 17 in October 2024. | Medium | SO007 |
| CO028 | Teleport was named to the 2026 Fortune Cyber 60 list in October 2025, recognizing rapid growth and commitment to delivering identity security solutions. | Medium | SO011 |
| CO029 | Teleport was named to the Citizens Securities 2026 Cyber 66 list in April 2026, recognizing it as one of the hottest privately held cybersecurity companies. | Medium | SO012 |
| CO030 | Teleport's Agentic Identity Framework was announced on January 27, 2026, providing a roadmap for deploying autonomous AI agents in production infrastructure with cryptographic identity. | Medium | SO013 |
| CO031 | Beams (beams.run) entered public beta in June 2026 as a Teleport product providing trusted runtimes for AI agents, running each agent in isolated Firecracker VMs with built-in identity and no secrets. | Medium | SO024, SO027 |
| CO032 | Teleport's 2026 Infrastructure Identity Survey of 200+ infrastructure leaders found that 79% were evaluating or deploying agentic AI and 69% said AI adoption required significant changes to identity management. | Medium | SO025 |
| CO033 | Starting with Teleport 16 in June 2024, compiled Community Edition binaries and container images were moved from the Apache 2.0 license to a commercial license; the AGPLv3 source code repository was not changed. | Medium | SO007 |
| CO034 | Teleport's FedRAMP documentation describes how Teleport FIPS mode can help customers achieve FedRAMP authorization, but does not represent a FedRAMP ATO for Teleport's own SaaS. | Medium | SO014, SO026 |
| CO035 | No public evidence confirms that Teleport's own cloud service has received a FedRAMP Authorization To Operate (ATO) from the FedRAMP Program Management Office. | Medium | |
| CO036 | PeerSpot reviewers cite initial setup complexity, RBAC configuration difficulty, SIEM integration gaps, and pricing concerns for large companies as key areas for improvement. | Medium | SO022 |
| CO037 | StrongDM's competitor comparison page claims Teleport's agents run as root on every monitored server and that Teleport Cloud experiences availability issues during updates. | Low | SO021 |
| CO038 | Teleport's product secures SSH, Kubernetes, databases, RDP, web applications, and MCP servers through a certificate-authority model that issues short-lived credentials. | Medium | SO023, SO001 |
| CO039 | Teleport conducted a security audit by Cure53 in 2019, resulting in no critical vulnerabilities found; the company has committed to regular third-party security audits. | Medium | SO017 |
| CO040 | The global PAM market was estimated at $4.5B in 2025 and is projected to grow to $29.88B by 2034 at a 23.4% CAGR according to Precedence Research. | Medium | SO029 |
| CO041 | Teleport's competitive context includes public cybersecurity companies such as CyberArk (market cap ~$20B, revenue ~$1B in 2024) and Okta (market cap ~$20B, revenue ~$2.9B in 2025), both of which are substantially larger by revenue than Teleport's estimated ARR. | Low | SO029 |
| CO043 | NIST SP 800-207 (2020) defines zero trust architecture as eliminating implicit trust based on network location and requiring per-request authentication and authorization — the framework Teleport's products implement for infrastructure access. | Medium | SO030 |
| CO042 | The Bessemer BVP investment blog described Teleport as "the easiest, most secure way to access infrastructure" and noted that 2021 saw a 50% increase in attacks on corporate networks. | Medium | SO018 |
| CM001 | Teleport positions itself as an AI Infrastructure Identity company spanning human, machine, and AI identities. | Medium | SM001, SM015 |
| CM002 | Teleport's published product scope covers SSH, Kubernetes, databases, Windows, web apps, machine identities, and related infrastructure workflows. | Medium | SM024, SM028 |
| CM003 | Bessemer described infrastructure access as a new and exciting product category when explaining its Teleport investment. | Medium | SM012 |
| CM004 | A disciplined Teleport market definition should include privileged infrastructure access, workload identity, audit, and compliance-linked access modernization spend. | Medium | SM024, SM028, SM006 |
| CM005 | A disciplined Teleport market definition should exclude most workforce IAM, CIAM, endpoint, SIEM, and non-infrastructure AI application spend. | Medium | SM024, SM028, SM007 |
| CM006 | VPNs, bastions, long-lived credentials, cloud-native point IAM, and manual audit workflows remain status-quo substitutes for Teleport. | Medium | SM024, SM015 |
| CM007 | FedRAMP, SOC 2, and access-audit use cases expand Teleport's commercial relevance without turning the company into a full GRC or broader identity vendor. | Medium | SM016, SM017, SM018 |
| CM008 | StrongDM argues that Teleport is a point solution for modern cloud architecture and lacks broader legacy-system fit. | Low | SM029 |
| CM009 | Precedence Research values the global privileged access management market at $4.50 billion in 2025 and forecasts $29.88 billion by 2034. | Medium | SM009 |
| CM010 | Archived Grand View Research evidence values the global zero-trust security market at $36.96 billion in 2024 with a 16.6% CAGR through 2030. | Medium | SM010 |
| CM011 | Precedence Research values the global zero-trust security market at $40.01 billion in 2025 and forecasts $182.59 billion by 2035. | Medium | SM011 |
| CM012 | Published market estimates diverge because PAM and zero-trust reports use overlapping but not identical scope definitions and forecast windows. | Medium | SM009, SM010, SM011 |
| CM013 | Teleport's practical TAM sits between narrow PAM and broad zero-trust security because the product spans infrastructure access and identity but not every control category inside zero trust. | Medium | SM001, SM024, SM028 |
| CM014 | The market taxonomy around infrastructure identity is still forming rather than universally settled. | Medium | SM012 |
| CM015 | AI adoption expands Teleport's SAM because 92% of survey respondents report near-term AI initiatives and 79% are evaluating or deploying agentic AI. | Medium | SM003 |
| CM016 | Enterprise preparedness lags AI adoption because only 13% of respondents feel extremely prepared and 60% have had or suspect AI-related incidents. | Medium | SM003 |
| CM017 | Teleport reports more than 600 customers, including three of the top five financial services firms, which demonstrates real market adoption but not precise share. | High | SM004, SM027 |
| CM018 | The retained Fortune Business Insights PAM URL could not be used for triangulation because it returned unrelated agricultural content instead of PAM analysis. | Medium | SM026 |
| CM019 | Teleport's primary operational users are platform engineers, security engineers, infrastructure admins, and Kubernetes or database operators. | Medium | SM024, SM028 |
| CM020 | Budget ownership commonly sits with either the security organization or platform engineering, depending on whether the trigger is control posture or operational fragmentation. | Medium | SM022, SM023 |
| CM021 | Teleport's MAU and MWI pricing model ties commercial expansion to identity adoption rather than to a fixed appliance or seat bundle. | Medium | SM022 |
| CM022 | Compliance-led deals pull in public-sector or regulated-program owners because Teleport markets FedRAMP and FIPS alignment as part of the value proposition. | Medium | SM016, SM018, SM019 |
| CM023 | SOC 2-oriented buyers use Teleport as infrastructure access control rather than as a general-purpose compliance platform. | Medium | SM017, SM023 |
| CM024 | The public GitHub repository has more than 15,000 stars, which supports developer-led awareness and evaluation. | Medium | SM025 |
| CM025 | Teleport's disclosed customer proof is strongest in large regulated enterprises, including major financial-services institutions. | Medium | SM004, SM023 |
| CM026 | Legacy-heavy hybrid enterprises are less naturally aligned with Teleport when broad protocol coverage is prioritized over cloud-native depth. | Low | SM029 |
| CM027 | Zero trust has both a formal standards anchor in NIST SP 800-207 and an operational maturity framework in CISA's Zero Trust Maturity Model. | High | SM006, SM007 |
| CM028 | Teleport links its infrastructure-access controls to FedRAMP and SOC 2 requirements, which turns compliance from an adjacency into a concrete demand driver. | Medium | SM016, SM017, SM018 |
| CM029 | Teleport reports that 73% of cybersecurity leaders are hearing enterprise customer questions about AI agent security. | Medium | SM005 |
| CM030 | Teleport's 2026 survey says 92% of respondents have near-term AI initiatives and 79% are evaluating or deploying agentic AI. | Medium | SM003 |
| CM031 | Investor and cloud-market commentary from BVP and Kleiner Perkins supports the view that multi-cloud complexity and AI are reinforcing demand for unified infrastructure control planes. | Medium | SM012, SM013, SM014 |
| CM032 | Usage-based MAU and MWI pricing can reduce initial adoption friction while making long-run spend dependent on identity growth. | Medium | SM022, SM003 |
| CM033 | Fortune Cyber 60 and Cyber 66 recognition strengthen Teleport's category legitimacy with enterprise buyers. | Medium | SM004, SM005 |
| CM034 | Switching costs remain material because buyers must unwind incumbent access workflows and test whether Teleport's strengths offset migration burden and coverage gaps. | Medium | SM024, SM029 |
| CM035 | Teleport documents support for FIPS 140 cryptographic modules, which materially improves fit for regulated and public-sector access programs. | High | SM016, SM018 |
| CM036 | Demand is structurally strongest in regulated and cloud-native environments and weaker in legacy-dense estates. | Medium | SM023, SM024, SM029 |
| CM037 | Public evidence does not isolate Teleport's SAM or SOM by segment, geography, deployment model, or average contract value. | Medium | SM021, SM022, SM023 |
| CM038 | Market-sizing evidence is directionally useful but methodologically inconsistent because the sources blend narrow PAM and broad zero-trust definitions. | Medium | SM009, SM011, SM026 |
| CM039 | The Fortune Business Insights page failure is a genuine research limitation rather than a minor formatting issue because it removes one potential triangulation point. | Medium | SM026 |
| CM040 | Teleport's public materials are richer on product breadth and compliance mapping than on win rates, deployment duration, churn, or segment economics. | Medium | SM001, SM023, SM027 |
| CM041 | Adverse competitor framing that Teleport is a point solution for modern cloud estates is relevant when testing whether the company can claim a broad cross-environment market. | Low | SM029 |
| CM042 | The market thesis is stronger on demand direction than on precise monetizable share until management discloses segment-level revenue and expansion evidence. | Medium | SM003, SM004, SM022 |
| CM043 | Teleport's last disclosed financing event remains the May 2022 Series C of $110 million at a $1.1 billion valuation, leaving public market interpretation anchored to stale capital data. | High | SM002, SM012 |
| CM044 | Teleport also frames automation of identity and access evidence collection as a FedRAMP acceleration vector, which broadens the compliance-driven budget conversation. | Medium | SM019, SM020 |
| CM045 | Archived Grand View coverage shows that privileged access management is tracked as a standalone analyst category even though not every retained source yielded usable public figures. | Medium | SM008, SM026 |
| CP001 | Teleport's core product is a certificate-authority and proxy architecture that issues short-lived credentials and brokers access across multiple infrastructure resource types. | Medium | SP016, SP017, SP021 |
| CP002 | Teleport's current platform scope now spans zero trust access, machine and workload identity, identity security, and an explicit agentic identity layer. | High | SP021, SP022, SP024, SP025, SP031 |
| CP003 | Recent Teleport releases have added IdP-compromise mitigations, a broader identity-security layer, and agentic-identity packaging, showing product expansion beyond classic SSH access. | Medium | SP018, SP019, SP022 |
| CP004 | CyberArk presents PAM as a unified platform for controlling elevated access and explicitly markets zero-standing-privilege access in hybrid and multicloud environments. | High | SP002, SP003 |
| CP005 | CyberArk's public-company scale was about $20.63 billion in market cap and $1.30 billion in trailing revenue as of June 2026. | Medium | SP012, SP013 |
| CP006 | BeyondTrust competes on least privilege, credential injection, secure remote access, and vendor privileged access rather than on a developer-led infrastructure identity narrative. | Medium | SP004, SP005 |
| CP007 | Delinea Secret Server remains centered on vaulting, discovery, password rotation, session monitoring, and AI-driven session analysis. | Medium | SP006 |
| CP008 | StrongDM is now positioned inside Delinea through the publicly announced acquisition, tightening the overlap between cloud-native access brokering and incumbent PAM suites. | Medium | SP001, SP006 |
| CP009 | StrongDM markets continuous policy enforcement, full session visibility, and no standing privileges on top of an Identity Firewall foundation. | Medium | SP001 |
| CP010 | StrongDM's direct comparison page explicitly says Teleport lacks support for legacy systems and some authentication protocols and that Teleport agents running as root create an additional attack surface. | Medium | SP026 |
| CP011 | PeerSpot reviewers praise Teleport for centralized access control, role-based permissions, smoother SSH key management, and strong visibility during incidents. | Medium | SP009 |
| CP012 | HashiCorp Boundary is an identity-aware proxy that integrates with external identity providers and HashiCorp Vault to deliver single sign-on and dynamic credentials for least-privileged access. | Medium | SP008 |
| CP013 | Okta Privileged Access extends Okta's identity platform into Linux and Windows server access with zero-standing-privilege framing and recorded SSH or RDP sessions. | Medium | SP007 |
| CP014 | Okta's public scale was about $20.65 billion in market cap and $2.91 billion in trailing revenue as of June 2026. | Medium | SP014, SP015 |
| CP015 | The main buyer consideration set around Teleport includes CyberArk, BeyondTrust, Delinea, StrongDM, Okta, and Boundary rather than only one-for-one open-source lookalikes. | Medium | SP010, SP011, SP027 |
| CP016 | Teleport competes in a broader infrastructure-identity category that combines connectivity, authentication, authorization, and audit across multi-cloud infrastructure workflows. | High | SP027, SP028 |
| CP017 | Because competitors span incumbent PAM suites, cloud-native access brokers, and IAM adjacency, Teleport is being evaluated across both direct and adjacent budget lines. | Medium | SP010, SP011, SP027 |
| CP018 | Teleport's historical open-source distribution and public repository still create awareness advantages relative to fully proprietary incumbents. | Medium | SP023, SP030 |
| CP019 | The June 2024 community-license change reduced Teleport's practical open-source advantage because larger companies can no longer freely use compiled Community Edition artifacts. | Medium | SP023 |
| CP020 | Teleport backs its trust story with a published security audit and explicit identity-security documentation, which matters in enterprise infrastructure-access evaluations. | High | SP020, SP021 |
| CP021 | Teleport's architecture supports certificate-based access across SSH, RDP, Kubernetes, databases, and machine or workload identities, reducing long-lived secret sprawl. | Medium | SP016, SP017, SP025 |
| CP022 | Teleport's Agentic Identity Framework and machine-identity products widen competition into non-human identity and AI-operated infrastructure workflows. | High | SP022, SP024, SP025 |
| CP023 | StrongDM's critique implies that Teleport's certificate-centric design is strongest in modern estates and potentially weaker in legacy-heavy environments. | Medium | SP026, SP016 |
| CP024 | CyberArk and BeyondTrust can credibly encroach on Teleport's cloud-native accounts because both market least-privilege, secure remote access, and zero-standing-privilege outcomes rather than only password vaulting. | Medium | SP003, SP005 |
| CP025 | PAM switching costs accumulate through vaulted credentials, policy engines, approval workflows, session archives, and compliance evidence that buyers do not want to rebuild. | High | SP002, SP003, SP004, SP005, SP006 |
| CP026 | HashiCorp Boundary has narrower public product breadth than Teleport in the retained set, but its Vault integration gives it real leverage inside existing HashiCorp-oriented platform teams. | Medium | SP008 |
| CP027 | Teleport is more transparent on list pricing and edition boundaries than most direct competitors because the company publishes pricing and feature segmentation publicly. | High | SP029, SP031 |
| CP028 | CyberArk, BeyondTrust, Delinea, StrongDM, Okta, and Boundary generally use sales-led or quote-led packaging in the retained evidence set, limiting public apples-to-apples pricing comparison. | Medium | SP001, SP003, SP005, SP006, SP007, SP008 |
| CP029 | Public retained pricing evidence is enough to compare transparency and packaging posture, but not enough to prove Teleport is absolutely cheaper than strong alternatives after discounting or bundling. | Medium | SP029, SP003, SP005, SP006, SP007, SP008 |
| CP030 | Teleport's differentiation is architectural unification: one access plane for authentication, authorization, and audit across modern infrastructure resources. | Medium | SP016, SP017, SP021 |
| CP031 | The retained independent review set is more supportive than hostile: public review evidence highlights ease of deployment and security visibility more than onboarding pain. | Medium | SP009 |
| CP032 | PeerSpot reviewers describe Teleport adoption in workflow terms: centralize access control, improve visibility during incidents, and replace ad hoc SSH key handling with more consistent policy. | Medium | SP009 |
| CP033 | Delinea's acquisition of StrongDM raises the competitive ceiling against Teleport because a modern access-broker story can now be paired with a larger incumbent PAM relationship base. | Medium | SP001, SP006 |
| CP034 | Okta competes less as a deep infrastructure specialist than as an adjacency play that can bundle privileged server access into an existing identity-cloud relationship. | Medium | SP007, SP014, SP015 |
| CP035 | Teleport faces a major scale asymmetry because CyberArk and Okta each exceed $20 billion in market cap, giving them greater room to bundle, cross-sell, and absorb overlap. | Medium | SP012, SP013, SP014, SP015 |
| CP036 | Adverse competitive evidence against Teleport is concentrated on legacy coverage and root-agent architecture rather than on an absence of core session-control or audit capabilities. | Medium | SP026, SP009 |
| CP037 | Teleport's community-license change weakens its competitive contrast versus open-source-oriented alternatives because buyers must now separate source availability from binary-use rights. | Medium | SP023, SP030 |
| CP038 | Comparable public pricing remains structurally incomplete because most rivals do not publish equivalent seat, workload, or contract-unit pricing in the retained set. | Medium | SP001, SP003, SP005, SP006, SP007, SP008 |
| CP039 | The retained 2026 freshness evidence is uneven across the field: Teleport and Delinea or StrongDM show visible 2026 signals, but equivalent 2026 update detail for CyberArk, BeyondTrust, Okta, and Boundary is thin. | Medium | SP001, SP022 |
| CP040 | Teleport's resource-type breadth still exceeds what the retained Okta and Boundary sources show, especially for Kubernetes, databases, machine identity, and AI-oriented access control. | Medium | SP007, SP008, SP021, SP024, SP025, SP031 |
| CP041 | The market remains segmented rather than fully converged, so Teleport's competitive success depends on winning the right estate profile rather than being universal across all privileged-access jobs. | Medium | SP010, SP011, SP026, SP027 |
| CP042 | Incumbent PAM vendors skew toward broad hybrid-enterprise security buyers, while Teleport, StrongDM, and Boundary skew toward platform teams and Okta sells into its existing IAM base. | Medium | SP001, SP003, SP005, SP007, SP008, SP016 |
| CI001 | Teleport's pricing is usage-based, metered by Monthly Active Users, Machine and Workload Identities, and Teleport Protected Resources; no public list price is stated and all pricing requires commercial engagement with the sales team. | Medium | SI013 |
| CI002 | GetLatka estimated Teleport's 2024 revenue at $49M, describing it as a December 2024 milestone; this is an unconfirmed third-party estimate not corroborated by any official source. | Low | SI012 |
| CI003 | No Teleport revenue estimate more recent than GetLatka's 2024 snapshot has been found in public sources; Teleport's 2025-2026 recognition press releases do not include revenue data. | Medium | SI012, SI015 |
| CI004 | At $49M estimated ARR and ~246 estimated employees, the implied ARR-per-employee ratio is approximately $199K, consistent with mid-stage infrastructure SaaS but below top-decile benchmarks. | Low | SI012 |
| CI005 | The Teleport Series C blog (May 2022) reported total ARR up 2.8x and net new ARR up 4.5x year-over-year at the time of the round; Bessemer's investment blog confirmed this growth trajectory. | High | SI015, SI014 |
| CI006 | The Teleport Series B blog (2021) reported total ARR up 2.5x and net new ARR up 5x year-over-year versus Q2 2020. | Medium | SI016 |
| CI007 | At GetLatka's $49M ARR estimate, the $1.1B Series C valuation implies a revenue multiple of approximately 22.4x ARR — materially above where public cybersecurity peers traded in mid-2026. | Low | SI012, SI015 |
| CI008 | The $1.1B Series C valuation from May 2022 has not been refreshed by any public subsequent financing event, secondary transaction, or management disclosure, making it approximately four years stale. | Medium | SI015 |
| CI009 | CyberArk Software had a market cap of approximately $20.63B and TTM revenue of approximately $1.30B as of June 2026, implying a revenue multiple of approximately 15.9x. | High | SI019, SI011 |
| CI010 | Okta had a market cap of approximately $20.65B and TTM revenue of approximately $2.91B as of June 2026, implying a revenue multiple of approximately 7.1x. | High | SI021, SI011 |
| CI011 | Applying the midpoint of CyberArk's and Okta's mid-2026 public revenue multiples (~11x) to Teleport's $49M estimated ARR produces an implied enterprise value of approximately $540M, well below the $1.1B 2022 mark. | Low | SI019, SI021, SI012 |
| CI012 | Teleport discloses no official revenue, gross margin, burn rate, or cash position data in any public-facing materials; the company is not required to file financial statements as a private entity. | Medium | SI015, SI013 |
| CI013 | No SEC Form D or other federal securities registration filing has been found for Gravitational Inc. or Teleport Inc. on EDGAR, preventing independent verification of investor ownership stakes. | Medium | SI011 |
| CI014 | Teleport has four commercial billing modules: Zero Trust Access (MAU/TPR), Machine and Workload Identity (MWI), Identity Governance (MAU), and Identity Security (TPR) — each a separate upsell opportunity with its own billing metric. | Medium | SI013 |
| CI015 | Teleport Enterprise Edition requires commercial contact for all pricing; no public list price is disclosed for any product tier or module. | Medium | SI013 |
| CI016 | The June 2024 community license change restricts compiled Community Edition use to companies with fewer than 100 employees and less than $10M AR, creating a commercial conversion gate for mid-market growth. | Medium | SI018 |
| CI017 | Teleport's Beams AI agent runtime and the Machine/Workload Identity module (docs/ai-agents-mwi) confirm the platform is actively building for AI agent identity as a production revenue surface, with agents receiving unique cryptographic identity enforced at access time. | Medium | SI005, SI010 |
| CI018 | GetLatka's funding summary for Teleport shows $140M across 2 rounds, diverging from the company-disclosed $165M across 3 rounds, suggesting GetLatka missed the Series A or has incomplete sourcing. | Low | SI012 |
| CI019 | No SEC Form D or equivalent state securities filing was publicly identified for Gravitational/Teleport, consistent with the company relying on state-level exemptions or other non-federal registration paths for its three private placement rounds. | Medium | SI011 |
| CI020 | The PAM market was estimated at $4.5B in 2025 and projected to reach $29.88B by 2034 at a CAGR of 23.4% per Precedence Research, providing a strong market tailwind for Teleport. | Medium | SI026, SI027 |
| CI021 | The PAM market's 23.4% CAGR implies the market nearly doubles every 3.5 years, providing strong tailwinds for Teleport across the infrastructure PAM and zero-trust identity segments. | Medium | SI026 |
| CI022 | Bessemer Venture Partners' investment thesis for the Series C framed Teleport as "the defining solution" to infrastructure access, citing a 50% increase in corporate network attacks in 2021. | Medium | SI014 |
| CI023 | Insight Venture Partners participated significantly in the $110M Series C, with Matt Koran joining the board as an observer; no post-Series C investor update is publicly available. | Medium | SI015 |
| CI024 | At $49M estimated ARR and $165M total raised, Teleport's implied capital efficiency (ARR / capital raised) is approximately 0.30 — below the commonly cited efficient SaaS benchmark of 0.5–1.0. | Low | SI012, SI015, SI016, SI017 |
| CI025 | The key outstanding financial gaps for Teleport include audited ARR, gross margin, NRR, burn rate, cash balance, option pool size, and current cap table — none of which are publicly available. | Medium | |
| CI026 | CyberArk revenue grew from approximately $590M in 2022 to $1.30B TTM in 2025, a 2.2x increase in roughly three years. | High | SI020, SI011 |
| CI027 | Okta revenue grew from approximately $1.85B in 2022 to $2.91B TTM in 2026, a 1.6x increase in roughly four years. | High | SI022, SI011 |
| CI028 | Teleport disclosed total funding of $165M across three rounds: $25M Series A, $30M Series B, and $110M Series C. | High | SI015, SI016, SI017 |
| CI029 | PeerSpot reviews highlight pricing concerns for large companies and initial setup complexity as recurring Teleport complaints, indicating enterprise price sensitivity is an active competitive dynamic. | Medium | SI023, SI024 |
| CI030 | No public evidence of secondary market transactions, tender offers, or equity pricing events involving Teleport has been identified since the May 2022 Series C. | Medium | SI015 |
| CI031 | StrongDM's competitor comparison page claims Teleport Cloud has reliability issues and that its agent- based architecture creates new security exposures; these claims originate from a direct competitor and must be weighed accordingly. | Low | SI024 |
| CI032 | Kleiner Perkins' Series A investment thesis (2019) described Gravitational as solving a once-in-a-decade opportunity in multi-cloud infrastructure — an early validation of the market thesis that Teleport's subsequent growth appears to confirm. | Medium | SI025 |
| CI033 | Teleport's MAU/MWI/TPR billing model creates natural revenue expansion as customers add infrastructure resources, without requiring re-negotiation of the commercial relationship. | Medium | SI013 |
| CI034 | The GoTo case study shows Teleport securing multi-cloud infrastructure for Indonesia's largest digital platform, illustrating the revenue expansion potential as large enterprises add workloads and users. | Medium | SI001 |
| CI035 | The Exness and Gladly case studies show Teleport serving regulated financial services and compliance- driven SaaS customers, segments where infrastructure identity tooling typically commands premium pricing. | Medium | SI002, SI003 |
| CI036 | If Teleport's ARR at the Series C close was approximately $17–20M (implied by the 2.8x growth cited) and grew to $49M by 2024, the post-fundraising CAGR was approximately 22%, significantly below the pre-Series-C rates. | Low | SI015, SI012 |
| CI037 | At the Series C close in May 2022, CyberArk traded at approximately $5.27B market cap on ~$590M revenue (~9x) and Okta at ~$10.94B on $1.85B revenue (~6x), suggesting Teleport's ~22x implied multiple was already ~2x the comparable range at issuance. | Low | SI019, SI021, SI015 |
| CI038 | Teleport's machine workload identity documentation for AI agents (ai-agents-mwi) confirms the platform issues each AI agent its own cryptographic identity, with deterministic access enforcement — a capability that underpins the Machine/Workload Identity revenue module. | Medium | SI005 |
| CI039 | Teleport's session recording architecture captures complete pseudo-terminal output for SSH sessions and database session events, providing compliance audit evidence that drives adoption in regulated industries. | Medium | SI007, SI006 |
| CE001 | Teleport is a certificate authority and identity-aware access proxy that implements SSH, RDP, HTTPS, Kubernetes API, and SQL/NoSQL database protocols, distributed as a single Go binary. | Medium | SE011, SE036 |
| CE002 | Teleport's product suite includes five pillars: Zero Trust Access, Machine & Workload Identity, Identity Governance, Identity Security, and the Agentic Identity Framework. | Medium | SE019, SE001 |
| CE003 | The Zero Trust Access product covers SSH, Kubernetes, databases, Windows/RDP, internal web apps, and MCP servers. | Medium | SE019, SE011, SE036, SE055, SE058 |
| CE004 | MCP server access is available in Community Edition, Enterprise Self-Hosted, and Enterprise Cloud, with per-tool audit events for MCP requests. | Medium | SE019, SE022 |
| CE005 | The Teleport feature matrix distinguishes Enterprise Cloud, Enterprise Self-Hosted, and Community Edition, with Beams trusted runtimes exclusive to Enterprise Cloud. | Medium | SE019, SE012 |
| CE006 | Identity Security provides SQL-editor access queries, Crown Jewels monitoring for critical assets, anomaly alerting, and integration with Okta, AWS, and GitHub audit logs. | Medium | SE023, SE010 |
| CE007 | Teleport pricing is usage-based across four billing metrics: Monthly Active Users, Machine/Workload Identity users, and Teleport Protected Resources, with no publicly listed list prices. | Medium | SE012 |
| CE008 | Teleport's Agentic Identity Framework was announced January 27, 2026, defining a four-layer architecture (identity, access, security, scheduling) for securing AI agents in production. | Medium | SE030, SE033 |
| CE009 | Teleport's 2026 Infrastructure Identity Survey of 200+ infrastructure leaders found 92% have near-term AI initiatives in infrastructure and only 13% feel extremely prepared. | Medium | SE032 |
| CE010 | The Teleport control plane consists of the Auth Service (CA, config store, audit log) and Proxy Service (public entry point, reverse-tunnel hub, Web UI), both communicating via gRPC. | Medium | SE017, SE018 |
| CE011 | The Auth Service is the only Teleport component that must be connected to a persistent backend (etcd, DynamoDB, Postgres, or Teleport Cloud storage); all other services are stateless. | Medium | SE018, SE017 |
| CE012 | Teleport authentication flow: user runs tsh login, receives a client certificate from the Auth Service, and that certificate is automatically accepted by SSH, kubectl, psql, and other CLI tools. | Medium | SE011, SE017 |
| CE013 | Teleport integrates with enterprise SSO providers including Okta, GitHub, Google Workspace, and Active Directory for identity provider authentication. | Medium | SE011, SE025 |
| CE014 | Teleport's Proxy Service implements an SSH server; Teleport Agents establish reverse tunnels to the Proxy to receive traffic from the public internet without exposing private resources. | Medium | SE017, SE018 |
| CE015 | Teleport can be deployed as Cloud (fully managed), on-premises, on-premises FIPS, multi-region high availability, hybrid, or edge; deployment type does not affect billing metrics except for multi-region HA. | Medium | SE012 |
| CE016 | StrongDM claims Teleport agents run as root on every enrolled server, creating a new attack vector; agentless mode is available but offers limited features without RBAC or granular auditing. | Medium | SE043 |
| CE017 | Session recording in Teleport supports four configurations (node-sync, node, proxy-sync, proxy) and captures PTY output for SSH and Kubernetes, screen content for desktop, and query streams for databases. | Medium | SE024 |
| CE018 | Teleport's official session recording documentation discloses that users can conceal terminal commands by encoding them (e.g., base64) or running scripts from disk, with BPF Enhanced Session Recording as a mitigation. | Medium | SE024 |
| CE019 | StrongDM claims Teleport Cloud is unreliable and that updates can cause access downtime of up to six hours; Teleport does not publish a public uptime SLA or incident history. | Low | SE043 |
| CE020 | Machine & Workload Identity uses tbot to issue short-lived X.509 or SSH certificates to non-human workloads, eliminating standing service secrets. | Medium | SE020, SE034 |
| CE021 | AI agents secured with Machine & Workload Identity receive their own cryptographic identity and operate under RBAC/ABAC enforcement at both network and protocol level, with all actions logged. | Medium | SE034, SE033 |
| CE022 | The Agentic Identity Framework is organized into four layers: identity (cryptographic agent certificates), access (RBAC/ABAC via Teleport proxy), security (behavioral monitoring), and scheduling (Kubernetes/Temporal orchestration patterns). | Medium | SE033, SE030 |
| CE023 | Beams is described as a trusted ephemeral runtime for AI agents; each Beam runs in a Firecracker microVM with ephemeral storage, injected identity, and a session-bound lifecycle of approximately 24 hours. | Medium | SE035, SE019 |
| CE024 | The LLM Proxy sits between an AI agent and its inference endpoint, logging every request and response to the Teleport audit trail and enforcing per-Beam allowlists for which inference endpoints agents can reach. | Medium | SE031, SE035 |
| CE025 | Delegated Identity allows a human operator or orchestrator to define and assign least-privilege permissions to an agent session, and was launched as part of the Beams public beta in June 2026. | Medium | SE031 |
| CE026 | Beams trusted runtimes are currently in public beta and are available only to Enterprise Cloud customers; Enterprise Self-Hosted and Community Edition deployments do not have access to Beams. | High | SE019, SE031 |
| CE027 | Beams includes built-in inference proxy support for OpenAI and Anthropic endpoints, with an option to bring your own inference endpoint. | High | SE035, SE019 |
| CE028 | The 2026 Citizens Securities Cyber 66 report survey found 73% of cybersecurity leaders are seeing enterprise customers ask how their platforms can help secure AI agents, with identity topping the list of security pain points. | Medium | SE053 |
| CE029 | Teleport Enterprise versions 17.7.3+ and 18.0.0+ include FIPS 140-3 validated cryptographic modules using BoringCrypto CMVP certificate | Medium | SE025 |
| CE030 | Teleport's FedRAMP documentation covers AC-02, AC-03, AC-07, AC-08, AC-10, AC-12, AU-02, AU-03, AU-09, AU-10, and AU-12 NIST SP 800-53 controls, supporting FedRAMP-Moderate authorization. | Medium | SE025, SE054 |
| CE031 | Teleport documents SOC 2 coverage across four of nine control categories: CC6 (control activities), CC6 (physical/logical access), CC7 (system operations), and CC8 (change management). | Medium | SE026 |
| CE032 | A Cure53 security audit of Teleport in 2019 found no critical vulnerabilities; one high-severity directory-traversal issue in the roles API was patched in the same release (v2.6.0). | Medium | SE029 |
| CE033 | No public third-party security audit of Teleport more recent than 2019 has been disclosed; the Cure53 audit covered source code version 2.x, not current v17/v18. | Medium | SE029 |
| CE034 | Teleport releases one major version per year with 24-month support; version 18 (current) was released July 2025 with EOL August 2027; version 17 (stable) EOL August 2026. | Medium | SE027 |
| CE035 | Starting with Teleport 16 (June 2024), compiled Community Edition binaries, container images, and AMIs are licensed under a commercial license restricting companies with 100+ employees or $10 M+ annual revenue. | Medium | SE008, SE009 |
| CE036 | The Teleport open-source repository on GitHub remains AGPLv3; documentation and client library code remain Apache 2.0; only compiled artifacts switched to the commercial license in June 2024. | High | SE008, SE036 |
| CE037 | Teleport's product roadmap includes Linux Desktop Access (remote sessions to Linux hosts), multiple-directory sharing for Windows RDP, and AI-summarized session recordings in Identity Security. | Medium | SE027 |
| CE038 | The Teleport GitHub open-source repository has over 15,000 GitHub stars (stated at time of community-license announcement) and is written in Go; Teleport maintains Apple code-signing and RPM/Debian signing keys published on the security page. | Medium | SE008, SE036, SE056, SE057 |
| CE039 | PeerSpot user reviews identify Teleport's initial setup and RBAC configuration complexity, SIEM integration limitations, clipboard security risk in RDP, and pricing concerns for large companies as the primary improvement areas. | Medium | SE052 |
| CE040 | NIST SP 800-207 and CISA Zero Trust Maturity Model provide regulatory frameworks for zero-trust access controls that Teleport's architecture is designed to satisfy. | Medium | SE041, SE042 |
| CE041 | Teleport Identity Governance adds access lists, access requests, approval workflows, and SCIM-driven lifecycle controls on top of the core access plane. | Medium | SE059, SE019 |
| CE042 | The Teleport Proxy Service provides the public-facing web UI, single sign-on entry point, and reverse-tunnel transport that connects users to private resources through the control plane. | Medium | SE017, SE060 |
| CE043 | Teleport authentication issues short-lived certificates to human users, services, and AI agents after they authenticate through local accounts or external identity providers with MFA. | Medium | SE017, SE061 |
| CE044 | Teleport agents are deployed onto protected infrastructure and can join clusters through multiple join methods, allowing SSH, Kubernetes, application, and database traffic to traverse the identity-aware proxy. | Medium | SE017, SE062 |
| CE045 | The tsh client is Teleport's command-line workflow surface for user logins, certificate retrieval, and protocol-specific sessions, complementing the browser UI and Teleport Connect desktop app. | Medium | SE018, SE063 |
| CU001 | Teleport's buyer persona is primarily engineering or platform-security teams at mid-to-large enterprises in technology, fintech, and global digital platforms. | Medium | SU001, SU002, SU003 |
| CU002 | Teleport's public case studies span verticals including fintech (Carta, Exness), Southeast Asia digital platform (GoTo), SaaS CX (Gladly), network detection (ExtraHop), and enterprise observability (IBM Instana). | Medium | SU001, SU002, SU003, SU006, SU007 |
| CU003 | The Series A announcement named Nasdaq, Splunk, TicketMaster, Mulesoft, and Samsung as early major customers. | High | SU008, SU022 |
| CU004 | The Series C announcement named Nasdaq, DoorDash, and Snowflake as flagship customer logos, cited by Bessemer lead investor Mary D'Onofrio. | High | SU009, SU013 |
| CU005 | The Community Edition provides a top-of-funnel acquisition channel for companies with fewer than 100 employees or less than $10 M AR; larger companies must purchase Enterprise licenses. | High | SU018, SU009 |
| CU006 | GoTo (Southeast Asia's largest digital platform, publicly listed) is a confirmed production customer; all of GoTo's Kubernetes clusters are private and Teleport was selected for secure private access. | Medium | SU002 |
| CU007 | Exness is a global fintech and trading technology company regulated under PCI DSS, SOC 2, and ISO 27001; it selected Teleport after evaluating multiple solutions and states it was the only solution meeting all requirements. | Medium | SU003 |
| CU008 | Teleport's case study page as of June 2026 lists at least 15 named customer stories including KnowBe4, Turo, Exness, Rush Street Interactive, GoTo, Carta, Buyers Edge, ExtraHop, IBM Instana, ThredUP, Qwilt, Mapgears, ECMWF, Flywheel, and Gladly. | Medium | SU001 |
| CU009 | Teleport customer geographies include North America (Carta, ExtraHop, Gladly), Southeast Asia (GoTo), global fintech (Exness), and IBM (global enterprise). | Medium | SU001, SU002, SU003 |
| CU010 | An October 2025 Fortune Cyber 60 press release by Teleport states that 'more than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport.' | Medium | SU011 |
| CU011 | The 600+ customer count from the October 2025 Fortune Cyber 60 press release is company-stated and has not been independently verified by any third-party analyst or database. | Medium | SU011, SU017 |
| CU012 | At the time of the Series C in March 2022, Teleport reported net-new ARR growth of 4.5x and total ARR growth of 2.8x year over year. | Medium | SU009, SU013 |
| CU013 | The Teleport open-source repository on GitHub has over 15,000 GitHub stars, as stated at the time of the June 2024 community license announcement. | Medium | SU018, SU014 |
| CU014 | Teleport was recognized as a 'revenue category mover' in the Citizens Securities Cyber 66 April 2026 report, indicating continued business momentum. | Medium | SU012, SU024 |
| CU015 | Series B materials stated Teleport included a major stock exchange, the biggest crypto exchanges, large gaming and e-commerce platforms among its customers at the time of the September 2021 funding. | Medium | SU010 |
| CU016 | Getlatka estimates Teleport generated approximately $49 M in annual revenue in 2024, with approximately 246 employees as of November 2025; these are unverified third-party estimates. | Low | SU017 |
| CU017 | The PAM market including infrastructure access is dominated by BFSI (banking, financial services, insurance) verticals which account for approximately 29% of market share, consistent with Teleport's heavy financial services customer concentration. | Medium | SU019 |
| CU018 | Teleport's Fortune Cyber 60 press release specifically notes 'three of the top five financial services firms' as customers, indicating significant financial-sector concentration. | Medium | SU011 |
| CU019 | IBM Instana's Cloud Architect Hunter Madison states this is his third Teleport deployment across different companies, confirming advisor-driven repeat adoption as a retention signal. | Medium | SU006 |
| CU020 | IBM Instana uses Teleport to manage secure access to Dropwizard tooling and replaced a combination of VPNs and shared credentials; the case study confirms production deployment at IBM-scale. | Medium | SU006 |
| CU021 | Carta integrated Teleport with Okta for Kubernetes and database RBAC, enabling streamlined developer onboarding/offboarding and fine-grained auditing for SOC 2 and ISO 27001 compliance. | Medium | SU007 |
| CU022 | GoTo adopted Teleport for all private Kubernetes clusters across its multi-cloud infrastructure, replacing an in-house access tool that became too complex to maintain as GoTo scaled across business verticals. | Medium | SU002 |
| CU023 | Exness operates hundreds of Kubernetes clusters across on-premises and cloud environments; Teleport was selected as the only solution meeting its requirements for automation, GitOps readiness, SSO, and machine identity. | Medium | SU003 |
| CU024 | Gladly uses Teleport as a certificate authority for RBAC rather than static SSH keys, and uses session recording as compliance evidence for security auditors and privacy-conscious customers. | Medium | SU004 |
| CU025 | ExtraHop secured six Kubernetes clusters each running hundreds of individually spun-up nodes with Teleport, replacing hardcoded and shared secrets that were creating compliance and audit gaps. | Medium | SU005 |
| CU026 | Nasdaq is a confirmed named customer cited in both the Series A announcement and in Bessemer's Series C investment statement. | High | SU008, SU009, SU013 |
| CU027 | DoorDash and Snowflake are confirmed named customers cited by Bessemer Venture Partners in the Series C investment announcement. | High | SU009, SU013 |
| CU028 | Splunk, TicketMaster, Mulesoft, and Samsung are confirmed named customers cited in the Series A funding announcement. | Medium | SU008 |
| CU029 | PeerSpot users describe Teleport as significantly improving workflow by centralizing access control and reducing manual SSH key management, indicating high stickiness once deployed. | Medium | SU023 |
| CU030 | The depth of enterprise deployments at Exness (hundreds of K8s clusters), GoTo (multi-cloud), and ExtraHop (hundreds of nodes per cluster) creates significant infrastructure integration depth and high switching costs. | Medium | SU002, SU003, SU005 |
| CU031 | Teleport does not publicly disclose NRR, GRR, logo churn, or contract renewal rates; no third-party database has independently verified these metrics. | Medium | SU017, SU009 |
| CU032 | PeerSpot reviews identify initial setup complexity, RBAC configuration difficulty, and pricing concerns as friction points that could limit adoption or cause attrition. | Medium | SU023, SU015 |
| CU033 | StrongDM's competitive analysis claims Teleport lacks legacy-protocol support, limiting expansion in mixed legacy/cloud environments, which is a potential barrier to enterprise-wide adoption. | Low | SU020 |
| CU034 | Publicly named customers are concentrated in tech-native companies (SaaS, fintech, cloud platforms); healthcare, manufacturing, government, and retail sectors are not represented in public case studies. | Medium | SU001, SU011 |
| CU035 | Teleport's Fortune Cyber 60 press release notes 'three of the top five financial services firms,' which implies significant revenue concentration in the financial services sector without disclosing individual firm names beyond Nasdaq. | Medium | SU011 |
| CU036 | The community-license change starting with Teleport v16 (June 2024) restricts the free Community Edition for companies above 100 employees or $10 M AR, potentially reducing the organic community-to-enterprise conversion pipeline. | Medium | SU018, SU009 |
| CU037 | Beams and several Identity Security features are Enterprise Cloud-only; self-hosted customers cannot access these capabilities, creating a two-tier customer experience. | Medium | SU021, SU009 |
| CU038 | NVIDIA does not appear in any official Teleport press release, funding announcement, or case study and should be considered an unverified logo-wall claim rather than a confirmed customer. | Medium | SU008, SU009, SU011 |
| CU039 | Square and Bloomberg appear on the Teleport official customer page as logo references but lack individual case studies confirming production deployment details. | Low | SU025, SU001 |
| CU040 | The PAM market (of which Teleport participates in the infrastructure access segment) was valued at approximately $4.5 B in 2025 with a projected CAGR of 23.4% to 2034, driven by rising identity-based attacks. | Medium | SU019 |
| CU041 | Teleport's official llms.txt file (June 2026) names Nasdaq, IBM, DoorDash, Elastic, and GoTo as industry-leading organizations that trust Teleport, providing an official customer reference for Elastic beyond the case study list. | Medium | SU027, SU025 |
| CU042 | Teleport's Elasticsearch integration page confirms that Teleport supports database-level RBAC and audit for Elasticsearch as a first-class protected resource, extending enterprise value beyond SSH and Kubernetes. | Medium | SU026 |
| CU043 | Turo publicly references Teleport as an infrastructure-access platform, showing adoption within a large consumer marketplace environment. | Medium | SU029 |
| CU044 | KnowBe4 appears in Teleport's official case study library, extending proof that Teleport is used inside security-focused organizations beyond fintech and cloud-native engineering teams. | Medium | SU030 |
| CU045 | TigerGraph's case study shows Teleport supporting globally distributed access-control requirements, adding a graph-database and analytics workload to the public customer mix. | Medium | SU031 |
| CU046 | ECMWF's public case study shows Teleport being used to secure access to supercomputing clusters, proving demand beyond standard SaaS infrastructure into research and HPC environments. | Medium | SU032 |
| CU047 | Rush Street Interactive's case study adds online gaming and regulated cloud security as another public customer vertical for Teleport. | Medium | SU033 |
| CU048 | Mapgears' case study highlights Teleport's secure SSH access improving customer-support workflows, broadening evidence that Teleport is used for both platform engineering and operational support access. | Medium | SU034 |
| CU049 | thredUP's case study adds retail and Kubernetes-access controls to the public customer proof set for Teleport. | Medium | SU035 |
| CU050 | Qwilt's case study indicates Teleport is used alongside operational tools such as Rundeck and Slack APIs in globally distributed content-delivery environments. | Medium | SU036 |
| CU051 | Flywheel's case study adds biomedical research and compliance-sensitive infrastructure to Teleport's public customer references. | Medium | SU037 |
| CR001 | Teleport announced that Community Edition compiled artifacts moved from Apache 2.0 to a commercial license starting with Teleport v16 in June 2024. | High | SR001, SR011 |
| CR002 | The new Community Edition terms apply to companies with at least 100 employees or $10 million of annual revenue and prohibit resale or embedding. | Medium | SR001 |
| CR003 | Teleport's repository remains public, but the practical licensing change is concentrated in binaries, images, and AMIs that many enterprises actually deploy. | Medium | SR001, SR011 |
| CR004 | The Open Source Initiative definition does not treat usage-restricted commercial licenses as open source, so Teleport Community Edition no longer fits the standard OSS definition after v16. | High | SR001, SR031 |
| CR005 | Teleport said the project had more than 15000 GitHub stars when it announced the license change, showing that any community backlash touches a large developer audience. | High | SR001, SR011 |
| CR006 | Because Teleport historically benefited from developer-led adoption, the new licensing gate can weaken bottom-up enterprise pipeline and increase willingness to test alternatives. | Medium | SR001, SR011, SR025 |
| CR007 | Enterprises that standardized on Apache-era Teleport builds face artifact-provenance and upgrade-review risk when moving into the v16+ commercial-license regime. | Medium | SR001, SR010 |
| CR008 | License-driven community distrust creates credible fork and ecosystem-goodwill risk because users who want open-source-style access controls now have clearer incentive to evaluate substitutes. | Medium | SR001, SR022, SR025 |
| CR009 | The licensing change may improve monetization conversion, but it also introduces a reputational overhang that investors must treat as a structural distribution risk rather than as a one-time announcement artifact. | Medium | SR001, SR013 |
| CR010 | StrongDM's comparison page says Teleport agents run as root on target servers, which increases the privileged software footprint on managed infrastructure. | Medium | SR016 |
| CR011 | StrongDM also frames Teleport as a potential single point of failure when the control plane is unavailable, making high-availability design mission critical. | Medium | SR016 |
| CR012 | StrongDM positions broader legacy access support as a competitive advantage over Teleport, implying fit risk in hybrid estates with older protocols or workflows. | Medium | SR016, SR017 |
| CR013 | PeerSpot review evidence points to deployment and RBAC complexity in larger environments, reinforcing the view that Teleport can be operationally heavy to roll out. | Medium | SR023, SR024 |
| CR014 | Teleport's self-hosted model requires customers to own infrastructure, patching, upgrades, and resilience planning for auth and proxy services. | Medium | SR006, SR010 |
| CR015 | Teleport published an independent Cure53 security audit and disclosed remediation of the single high-severity issue found, indicating some security-process maturity. | Medium | SR009 |
| CR016 | Teleport documents FIPS 140-3 support through BoringCrypto CMVP certificate #4735 in builds from v17.7.3+ and v18.0.0+, which is a meaningful compliance mitigant for regulated buyers. | High | SR006, SR007 |
| CR017 | Teleport's official materials explain how customers can meet FedRAMP control requirements with the product, but the reviewed public corpus does not show Teleport Cloud itself having a FedRAMP authorization. | High | SR006, SR008 |
| CR018 | That FedRAMP boundary ambiguity can create procurement friction because public-sector buyers may incorrectly assume vendor-service authorization rather than customer-system control mapping. | Medium | SR006, SR008, SR014, SR015 |
| CR019 | The PAM market is large and growing, which attracts incumbents and increases the probability of sustained competitive pressure around Teleport's core category. | Medium | SR030 |
| CR020 | CyberArk carried an approximately $20.63 billion market capitalization and $1.30 billion of TTM revenue in June 2026. | Medium | SR026, SR027 |
| CR021 | Okta carried an approximately $20.65 billion market capitalization and $2.91 billion of TTM revenue in June 2026 while marketing a Privileged Access product. | High | SR021, SR028, SR029 |
| CR022 | StrongDM explicitly attacks Teleport on legacy support, operational simplicity, and architecture footprint, showing that those are active competitive battlegrounds rather than hypothetical weaknesses. | Medium | SR016 |
| CR023 | HashiCorp Boundary provides an identity-aware proxy alternative with open-source roots, making it a credible option for buyers who want a different trust or packaging model. | Medium | SR022 |
| CR024 | Cloud-native IAM and privileged-identity features from AWS, Google Cloud, and Microsoft can be good enough substitutes for customers whose estates stay mostly within one cloud. | Medium | SR014, SR015, SR021 |
| CR025 | Teleport says it serves more than 600 customers including three of the top five financial services firms, showing real traction but also confirming that it competes in demanding enterprise evaluations. | High | SR005, SR033, SR034 |
| CR026 | Competitive pressure can slow sales cycles or compress pricing because larger rivals can bundle adjacent identity or security products and smaller rivals can exploit Teleport's license and complexity narrative. | Medium | SR016, SR020, SR021, SR024 |
| CR027 | Recent 2026 recognition on the Fortune Cyber 60 and Citizens Cyber 66 lists strengthens Teleport's visibility but does not remove feature-parity or platform-bundling risk. | High | SR033, SR034 |
| CR028 | Teleport publicly disclosed funding of $25 million in Series A, $30 million in Series B, and $110 million in Series C for roughly $140 million raised in total. | High | SR002, SR003, SR004 |
| CR029 | Teleport's Series C was announced in March 2022 at a $1.1 billion valuation led by Bessemer Venture Partners, and no newer round is visible in the provided source corpus. | High | SR002, SR012 |
| CR030 | The only ARR figure in the reviewed source set is GetLatka's estimate of $49 million for 2024, which should be treated as external and unverified. | Low | SR032 |
| CR031 | If the $49 million ARR estimate were directionally correct, Teleport's last disclosed $1.1 billion valuation would imply an ARR multiple of roughly 22 times. | Low | SR002, SR032 |
| CR032 | The current public evidence set does not disclose profitability, burn, gross margin, net retention, or cash runway. | Medium | SR002, SR005, SR032 |
| CR033 | A four-year-stale private valuation anchor combined with limited current financial disclosure creates meaningful financing and mark risk for investors entering today. | Medium | SR012, SR013, SR030, SR032 |
| CR034 | Public competitors such as CyberArk and Okta have vastly larger visible revenue bases and organizational resources than Teleport. | Medium | SR020, SR021, SR026, SR027, SR028, SR029 |
| CR035 | Teleport's official about materials identify Ev Kovyrin as CEO, Sasha Klizhentas as CTO, and Taylor Wakefield as COO, concentrating visible leadership around three co-founders. | Medium | SR005 |
| CR036 | The reviewed public corpus does not disclose a formal succession plan, management bench map, or employee-count update for Teleport. | Medium | SR005 |
| CR037 | Teleport has repositioned itself around AI infrastructure identity, expanding the company story beyond core privileged access and zero-trust access. | High | SR035, SR036 |
| CR038 | Teleport announced the Agentic Identity Framework in January 2026, showing that the company is actively investing in a still-emerging control plane for AI agents. | Medium | SR035 |
| CR039 | Beams launched in public beta in June 2026, which means product maturity, adoption proof, and support economics are still early. | Medium | SR036 |
| CR040 | Because Beams is early stage and cloud-oriented, some security-sensitive or self-hosted buyers may wait for broader maturity before treating it as production infrastructure. | Medium | SR010, SR036 |
| CR041 | Delegating infrastructure access to AI agents introduces governance questions around delegated permissions, tool-use boundaries, audit scope, and runtime isolation even when core human access controls are mature. | Medium | SR014, SR015, SR035, SR036 |
| CR042 | Teleport's compliance posture and enterprise traction help credibility, but simultaneously executing core PAM growth and a new AI-runtime motion increases roadmap complexity. | Medium | SR016, SR025, SR033, SR034, SR035 |
| CR043 | The three diligence topics most likely to change underwriting outcomes quickly are license transition exposure, FedRAMP authorization ambiguity, and current financial proof. | Medium | SR001, SR006, SR008, SR032 |
| CR044 | Practical kill criteria include unresolved v16 licensing objections, inability to prove HA resilience, failure to reconcile present commercial metrics, or over-rotation into AI before core PAM economics are proven. | Medium | SR001, SR006, SR016, SR032, SR036 |
| CR045 | The highest-value next diligence package is a legal memo on licensing, a resilience package for control-plane uptime, a precise regulated-cloud posture statement, and current board-level financial metrics. | Medium | SR001, SR006, SR008, SR023, SR032 |
| CR046 | AWS Systems Manager Session Manager offers a managed shell-access path for AWS-centric estates, reducing the need for a separate third-party infrastructure-access layer in simpler deployments. | Medium | SR037 |
| CR047 | Azure Bastion provides Microsoft-native browser and RDP or SSH access into private Azure resources, narrowing Teleport's differentiation for Azure-concentrated customers. | Medium | SR038 |
| CR048 | Google Cloud Identity-Aware Proxy offers an identity-aware control point for Google-hosted applications and VM access, making single-cloud substitution a real risk for parts of Teleport's workload mix. | Medium | SR039 |
| CR049 | Microsoft Entra Privileged Identity Management brings just-in-time privileged access and approval workflows into the Microsoft identity stack, increasing bundling pressure on standalone vendors. | Medium | SR040 |
| CR050 | Teleport's own authorization documentation shows deep RBAC and policy expressiveness, but that same policy depth can increase implementation and change-management complexity in large enterprises. | Medium | SR023, SR041 |
| CR051 | TLS Routing and proxy peering expand Teleport's network flexibility for multi-cluster estates, but they also add migration and traffic-management complexity that operators must own. | Medium | SR042, SR043 |
| CV001 | Teleport's last known post-money valuation is $1.1B from the May 2022 Series C. | High | SV001, SV008 |
| CV002 | The Series C raised $110M and was led by Bessemer Venture Partners with Insight Venture Partners participating. | High | SV001, SV008 |
| CV003 | Teleport has disclosed approximately $165M of total primary capital across Series A, Series B, and Series C. | High | SV001, SV002, SV003 |
| CV004 | No new primary equity round has been announced in official Teleport materials since May 2022, making the $1.1B mark more than four years stale as of June 2026. | Medium | SV001, SV030 |
| CV005 | GetLatka estimates Teleport's 2024 ARR at $49M, and that figure is unconfirmed by Teleport. | Low | SV010 |
| CV006 | Using the $1.1B Series C mark and the $49M GetLatka ARR estimate implies about 22.4x EV/ARR. | Medium | SV001, SV010 |
| CV007 | CyberArk had about $20.63B market capitalization and $1.30B TTM revenue in June 2026, implying roughly 15.8x EV or market cap to revenue. | Medium | SV011, SV012 |
| CV008 | Okta had about $20.65B market capitalization and $2.91B TTM revenue in June 2026, implying roughly 7.1x revenue. | Medium | SV013, SV014 |
| CV009 | CyberArk revenue increased from roughly $0.75B in 2023 to $1.00B in 2024 and to about $1.30B on a TTM basis in 2025-2026, indicating about 30% year-over-year growth. | Medium | SV012, SV020 |
| CV010 | The PAM market is sized at $4.50B in 2025 and forecast to grow at 23.4% CAGR to $29.88B by 2034. | Medium | SV015 |
| CV011 | The zero-trust security market is sized at $40.01B in 2025 and forecast to grow at 16.39% CAGR to $182.59B by 2035. | Medium | SV016 |
| CV012 | Teleport says it serves more than 600 customers, including three of the top five financial services firms. | Medium | SV001, SV004 |
| CV013 | Bessemer described Teleport as building the unified access plane for DevOps and infrastructure access. | Medium | SV008 |
| CV014 | Teleport said ARR growth was 2.5x year over year at the time of the Series B raise. | Medium | SV002 |
| CV015 | Teleport said ARR growth was 2.8x year over year at the time of Series C and that net new ARR grew 4.5x. | Medium | SV001 |
| CV016 | The 2024 community-edition license change could reduce bottom-up open-source conversion and alter ARR growth trajectory. | Medium | SV007, SV029 |
| CV017 | StrongDM, BeyondTrust, CyberArk, Okta, and HashiCorp Boundary all compete for privileged or infrastructure access workflows with more capital resources than Teleport. | Medium | SV021, SV022, SV023, SV025, SV026, SV032, SV042, SV043 |
| CV018 | Using the $49M ARR estimate and roughly 246 employees as an unverified headcount proxy implies around $199K ARR per employee. | Low | SV010, SV039 |
| CV019 | Teleport's Agentic Identity Framework launch and the Beams public beta mark a 2026 AI-agent identity repositioning. | Medium | SV031, SV033, SV034 |
| CV020 | No public secondary pricing source was located in the reviewed materials for Teleport shares as of the run date. | Low | |
| CV021 | Teleport was named to the Fortune Cyber 60 list and the Citizens Securities Cyber 66 list in 2025-2026, signaling market recognition. | Medium | SV005, SV006 |
| CV022 | Bessemer's State of the Cloud 2024 argues that AI has revived premium private-market software investing and references a $1B AI commitment. | Medium | SV009 |
| CV023 | Bessemer invested in Teleport's Series C alongside Insight Venture Partners. | High | SV001, SV008 |
| CV024 | A research-more recommendation is warranted because current public evidence is insufficient to underwrite the $1.1B mark with high confidence. | Medium | SV001, SV010, SV011, SV012, SV013, SV014 |
| CV025 | Teleport at about 22.4x unconfirmed ARR screens expensive relative to CyberArk at roughly 15.8x verified revenue. | Medium | SV001, SV010, SV011, SV012 |
| CV026 | Okta's privileged-access product expands overlap with Teleport and can compress the premium comp set available to the company. | Medium | SV023, SV013, SV014 |
| CV027 | HashiCorp Boundary provides additional infrastructure-access competition and pricing context for Teleport's access plane. | Medium | SV032 |
| CV028 | Third-party market research beyond Precedence also supports a large and growing PAM market opportunity. | Medium | SV018, SV019, SV044, SV045 |
| CV029 | AI-agent identity is an emerging segment without an established public multiple framework, increasing model risk around any premium narrative. | Medium | SV031, SV033, SV034 |
| CV030 | Teleport's Series C was priced during a 2022 software valuation regime that was materially richer than public security-software multiples in 2026. | Medium | SV001, SV009, SV011, SV012, SV013, SV014 |
| CV031 | A bull case with 35% annual growth from the $49M 2024 ARR estimate reaches about $85M ARR by 2027, and at 15x implies roughly $1.28B of value. | Medium | SV010, SV019, SV033, SV034 |
| CV032 | A base case with 25% annual growth from the $49M estimate reaches about $73M ARR by 2027, and at 10x to 12x implies about $730M to $875M. | Medium | SV010, SV009, SV011, SV012, SV013, SV014 |
| CV033 | A bear case with 15% annual growth and license-change headwinds reaches about $60M ARR by 2027, and at 6x to 8x implies about $360M to $480M. | Medium | SV007, SV010, SV009 |
| CV034 | The stale $1.1B mark sits about 26% to 50% above the base-case implied valuation range. | Medium | SV001, SV010, SV009 |
| CV035 | Reviewed public sources do not disclose Teleport profitability, gross margin, NRR, or burn rate. | Low | SV004, SV010, SV030 |
| CV036 | The absence of public FedRAMP authorization for Teleport Cloud limits near-term federal and highly regulated cloud TAM capture. | Medium | SV040, SV041 |
| CV037 | Teleport's investor syndicate includes Bessemer, Insight, Kleiner Perkins, and S28, which supports exit credibility even though it does not validate price. | Medium | SV001, SV002, SV003, SV024 |
| CV038 | Teleport has raised about 2.9 times as much capital as its estimated 2024 ARR. | Medium | SV001, SV002, SV003, SV010 |
| CV039 | High-growth security and infrastructure software companies can command roughly 15x to 25x ARR when growth is verified and sustained above 50% year over year. | Medium | SV009, SV011, SV012 |
| CV040 | Teleport's disclosed 2.8x ARR growth at Series C is historical rather than current, so present growth remains unverified. | Medium | SV001, SV010 |
| CV041 | For security software at roughly $40M to $60M ARR, a more defensible present-day private-market band is about 8x to 15x ARR unless growth is exceptional and verified. | Medium | SV009, SV011, SV012, SV013, SV014 |
| CV042 | The absence of a new funding round since 2022 and no public IPO announcement increase liquidity risk for late-stage investors. | Medium | SV001, SV030 |
| CV043 | The CE license change could raise customer acquisition costs if fewer community users convert through the old open-source funnel. | Medium | SV007, SV029 |
| CV044 | A strategic acquisition by a larger security or platform vendor is a viable exit path given Teleport's category position and customer footprint. | Medium | SV021, SV022, SV023, SV037 |
| CV045 | GetLatka labels its Teleport ARR figure as estimated, leaving a single-source dependency for public revenue analysis. | Medium | SV010 |
| CV046 | Teleport's GitHub repository has well over 15,000 stars, supporting the view that developer awareness remains meaningful. | Medium | SV029 |
| CV047 | Multiple official case studies across IBM Instana, Carta, GoTo, and Exness support Teleport's enterprise adoption narrative. | Medium | SV035, SV036, SV037, SV038, SV046, SV047 |
| CV048 | Public materials do not disclose liquidation preferences, anti-dilution terms, or cap-table structure, so entry discipline must assume unknown preference overhang. | Low | SV001, SV002, SV003, SV030 |
| CV049 | Stock Analysis revenue pages reinforce that CyberArk and Okta are already multi-hundred-million to multi-billion-dollar revenue businesses, making them more mature public comp anchors than Teleport. | Medium | SV049, SV050 |
| CV050 | Stock Analysis overview pages provide continuous public-market price discovery for CYBR and OKTA, highlighting how much stronger public valuation transparency is than Teleport's stale private mark. | Medium | SV051, SV052 |
| CV051 | Macrotrends' long-run Okta price-to-sales history underlines that public identity-software multiples have already compressed from earlier peak periods. | Medium | SV048 |
| CV052 | The gap between public-market price discovery for Okta and CyberArk and Teleport's unrefreshed 2022 private mark increases valuation-risk for any new investor entering today. | Medium | SV048, SV051, SV052 |
| CV053 | Additional public-comp data sources from Stock Analysis and Macrotrends all point investors back to the same conclusion: Teleport needs fresh ARR proof before its 2022 unicorn valuation can be defended confidently. | Medium | SV048, SV049, SV050, SV051, SV052 |
| CV054 | Yahoo Finance and Nasdaq both maintain live Okta market pages, underscoring that public peers benefit from continuous price discovery that Teleport does not have. | Medium | SV053, SV054 |
| CV055 | The presence of multiple independent market-data venues for Okta reinforces that public-comp valuation evidence is more current and auditable than Teleport's stale private mark. | Medium | SV052, SV053, SV054 |
| ID | Publisher | Title | Quote |
|---|---|---|---|
| SO001 | Teleport | Teleport: Unified Identity Securing Classic & AI Infrastructure | Teleport unifies identities — humans, machines, and AI — with strong identity implementation to speed up engineering, improve resiliency against identity-based attacks, and control AI in production infrastructure. |
| SO002 | Teleport | About Us | Teleport | Global Headquarters 2100 Franklin St, Suite 400, Oakland, CA 94612. Ev Kontsevoy — Co-founder and CEO; Alexander Klizhentas — Co-founder and CTO; Taylor Wakefield — Co-founder and COO. |
| SO003 | Teleport | Teleport Raises $110 Million Series C at $1.1 Billion Valuation | Teleport has just secured $110M in Series C funding … started with my co-founders Sasha Klizhentas and Taylor Wakefield in 2015. The new round values the company at $1.1 billion. |
| SO004 | Teleport | Teleport raises $30MM in series-B and launches secure access for MongoDB | Secured $30M in Series B funding … net new annual recurring revenue up 5x and total annual recurring revenue up 2.5x, compared to the second quarter of 2020. |
| SO005 | Teleport | Announcing our Series A | We have closed a $25MM Series A funding round led by Kleiner Perkins … customer base has exploded … including NASDAQ, Splunk, TicketMaster, Mulesoft and Samsung. We were recently able to reach profitability. |
| SO006 | Teleport | Gravitational Changes Name to Teleport | Today we are officially announcing that Gravitational is becoming Teleport … moving from gravitational.com to https://goteleport.com. |
| SO007 | Teleport | Teleport Community Edition will adopt a commercial license starting with version 16 | Starting with the June release of Teleport 16, we are switching Teleport Community Edition to a commercial license … Companies may use Teleport Community Edition on the condition they have less than 100 employees and less than $10MM in annual revenue. |
| SO008 | Teleport | Teleport Careers | Solving big problems across multiple domains for the world's most innovative companies … more than 600 customers around the globe. |
| SO009 | Teleport | Case Studies — Secure Infrastructure Access at Leading Companies | KnowBe4, Turo, Exness, Rush Street Interactive, GoTo, Carta, NASDAQ, Buyers Edge, ExtraHop, IBM Instana, ThredUP, Qwilt, Mapgears, ECMWF, Flywheel, Gladly — and many more. |
| SO010 | Teleport | Teleport Pricing | |
| SO011 | Teleport | Teleport named to 2026 Fortune Cyber 60 List | More than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport. |
| SO012 | Teleport | Teleport Named to Citizens Securities' 2026 Cyber 66 List | Teleport has been named to the Citizens Securities 2026 Cyber 66 … recognizes the most notable privately held cybersecurity companies. 73% of cybersecurity leaders are already seeing enterprise customers ask how their platforms can help secure AI agents. |
| SO013 | Teleport | Teleport Introduces Agentic Identity Framework | Teleport today announced the Teleport Agentic Identity Framework, an AI-centered framework that provides organizations with a clear roadmap for securely deploying agentic AI in production cloud and on-premises environments. |
| SO014 | Teleport | FedRAMP Compliance for Infrastructure Access | Teleport provides the foundation to meet FedRAMP requirements … This includes support for the Federal Information Processing Standard FIPS 140 … This document explains how Teleport FIPS mode works and how it can help your company to become FedRAMP authorized. |
| SO015 | Teleport | IBM Instana implements streamlined access control, visibility and compliance with Teleport | |
| SO016 | Teleport | Carta's Win/Win: Implementing Robust Security Controls while Improving Developer Productivity | |
| SO017 | Teleport | Teleport Security Audit by Cure53 — No Critical Vulnerabilities Found | No critical vulnerabilities have been discovered … The results of this second-run Cure53 security assessment of the latest release of the Teleport software … are once again very positive. |
| SO018 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Bessemer Growth leads the $110 million Series C. We believe Teleport will be the defining solution to this emerging massive problem, granting infrastructure access seamlessly without compromising security. |
| SO019 | Kleiner Perkins | Gravitational — Pulling Us Toward an Open and Multi-Cloud Future | Ev, Sasha, and Taylor identified this tension during the formative period of the cloud era while working at Rackspace via the acquisition of their first startup, Mailgun. |
| SO020 | GetLatka | Teleport — Company Financial Data and Metrics | In 2024, Teleport's revenue reached $49M … Teleport employs approximately 246 people as of 2026 … Teleport raised $140M in total funding across 2 rounds. |
| SO021 | StrongDM | StrongDM vs. Teleport — Comparison and Alternatives | The Teleport agents run as root in every server you want to audit, creating a new attack vector and a new surface to protect. Teleport cloud is unreliable and availability numbers are inaccurate. |
| SO022 | PeerSpot | Teleport Reviews — User Feedback and Ratings | Teleport requires improvements in initial setup and RBAC complexity. Integration with SIEM and monitoring tools could be enhanced. Pricing concerns affect large companies. |
| SO023 | GitHub (Gravitational) | gravitational/teleport — Open-Source Repository | Teleport provides connectivity, authentication, access controls and audit for infrastructure … SSH nodes, Kubernetes clusters, PostgreSQL, MongoDB, CockroachDB and MySQL databases, MCP, Internal Web apps, Windows Hosts. |
| SO024 | Teleport (Beams) | Beams — Trusted Runtimes for Infrastructure Agents | Beams runs each agent in an isolated Firecracker VM with built-in identity. Connected to your infrastructure and inference services — no secrets, no IAM wrestling. |
| SO025 | Teleport | The 2026 Infrastructure Identity Survey — State of AI Adoption | 79% are evaluating/deploying agentic AI … only 13% feel extremely prepared … 60% have had or suspect an AI-related security incident. |
| SO026 | Teleport | FedRAMP Compliance with Teleport — Use Cases | |
| SO027 | Teleport | Teleport Debuts Delegated Agentic Identity and LLM Proxy in Beams Public Beta | |
| SO028 | Teleport | Teleport Newsroom — Latest News and Press Releases | |
| SO029 | Precedence Research | Privileged Access Management Market Size to Hit USD 29.88 Bn by 2034 | The global privileged access management market size is accounted at USD 4.50 billion in 2025 and is predicted to increase … to approximately USD 29.88 billion by 2034, expanding at a CAGR of 23.40%. |
| SO030 | NIST | Zero Trust Architecture — NIST Special Publication 800-207 | Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location … Authentication and authorization are discrete functions performed before a session to an enterprise resource is established. |
| SM001 | Teleport | Teleport homepage | AI Infrastructure Identity Company |
| SM002 | Teleport | Teleport raises Series C | $110 million Series C financing at a $1.1 billion valuation |
| SM003 | Teleport | Infrastructure Identity Survey 2026 | 92% have near-term AI initiatives and only 13% feel extremely prepared |
| SM004 | Teleport | Teleport named to 2026 Fortune Cyber 60 list | 600+ customers including three of the top five financial services firms |
| SM005 | Teleport | Teleport named 2026 Cyber 66 hottest privately held cybersecurity companies | 73% of cybersecurity leaders see enterprise customers asking about AI agent security |
| SM006 | NIST | Zero Trust Architecture (SP 800-207) | Zero trust provides a collection of concepts and ideas designed to minimize uncertainty in enforcing accurate, least privilege per-request access decisions. |
| SM007 | CISA | Zero Trust Maturity Model | Five pillars plus three cross-cutting capabilities structure federal zero-trust implementation. |
| SM008 | Grand View Research (archived) | Privileged Access Management market report archive | |
| SM009 | Precedence Research | Privileged Access Management market | The global privileged access management market size was valued at USD 4.50 billion in 2025 and is projected to reach USD 29.88 billion by 2034. |
| SM010 | Grand View Research (archived) | Zero Trust Security market report archive | The global zero trust security market size was valued at USD 36.96 billion in 2024 and is expected to grow at a CAGR of 16.6% from 2025 to 2030. |
| SM011 | Precedence Research | Zero Trust Security market | The global zero trust security market size is calculated at USD 40.01 billion in 2025 and is forecasted to hit around USD 182.59 billion by 2035. |
| SM012 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Infrastructure access is a new and exciting product category. |
| SM013 | Bessemer Venture Partners | State of the Cloud 2024 | |
| SM014 | Kleiner Perkins | Gravitational: Pulling Us Toward an Open and Multi-Cloud Future | |
| SM015 | Teleport | Identity Security | |
| SM016 | Teleport | FedRAMP compliance documentation | Teleport provides support for FIPS 140 cryptographic modules. |
| SM017 | Teleport | SOC 2 compliance documentation | |
| SM018 | Teleport | FedRAMP compliance use case | |
| SM019 | Teleport | Accelerate FedRAMP compliance | |
| SM020 | Teleport | Automating identity access for FedRAMP 20x | |
| SM021 | GetLatka | goteleport.com company profile | |
| SM022 | Teleport | Pricing | |
| SM023 | Teleport | Case studies | |
| SM024 | Teleport | How it works | |
| SM025 | GitHub | gravitational/teleport repository | 15,000+ stars |
| SM026 | Fortune Business Insights | Privileged Access Management market page returned unrelated agricultural content | Retained URL returned content about agricultural microbials rather than privileged access management. |
| SM027 | Teleport | Newsroom | |
| SM028 | Teleport | Feature matrix | |
| SM029 | StrongDM | StrongDM vs Teleport | Teleport is a point solution for modern cloud architecture. |
| SP001 | StrongDM | StrongDM homepage | |
| SP002 | CyberArk | What is Privileged Access Management (PAM)? | |
| SP003 | CyberArk | Privileged Access Manager | |
| SP004 | BeyondTrust | Privileged Access Management (PAM) glossary | |
| SP005 | BeyondTrust | Privileged Remote Access | |
| SP006 | Delinea | Secret Server | |
| SP007 | Okta | Okta Privileged Access | |
| SP008 | HashiCorp | What is Boundary? | |
| SP009 | PeerSpot | Teleport Reviews | |
| SP010 | PeerSpot | Teleport Alternatives and Competitors | |
| SP011 | Slashdot | Teleport Alternatives | |
| SP012 | CompaniesMarketCap | CyberArk market cap | |
| SP013 | CompaniesMarketCap | CyberArk revenue | |
| SP014 | CompaniesMarketCap | Okta market cap | |
| SP015 | CompaniesMarketCap | Okta revenue | |
| SP016 | Teleport | Reference Architecture | |
| SP017 | Teleport | Core Concepts | |
| SP018 | Teleport | Teleport 16 | |
| SP019 | Teleport | Teleport 17 | |
| SP020 | Teleport | Teleport Security Audit | |
| SP021 | Teleport | Identity Security | |
| SP022 | Teleport | Teleport Introduces Agentic Identity Framework | |
| SP023 | Teleport | Teleport Community License | |
| SP024 | Teleport | Agentic Identity Framework docs | |
| SP025 | Teleport | Machine & Workload Identity | |
| SP026 | StrongDM | StrongDM vs Teleport | |
| SP027 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | |
| SP028 | Teleport | Gravitational is Teleport | |
| SP029 | Teleport | Pricing | |
| SP030 | GitHub | gravitational/teleport repository | |
| SP031 | Teleport | Feature Matrix | |
| SI001 | Teleport | GoTo Secures and Simplifies Cloud Access with Teleport | GoTo streamlines multi-cloud access management and enhances security across their infrastructure with Teleport. |
| SI002 | Teleport | Exness Elevates Global Kubernetes and Infrastructure Security with Teleport | Exness is one of the world's largest trading technology companies … As a regulated financial services provider, Exness treats security as a core business priority. |
| SI003 | Teleport | Secure Cloud Infrastructure Access with Teleport: A Gladly Case Study | Gladly selected Teleport to secure the cloud-native infrastructure … meeting international compliance requirements. |
| SI004 | Teleport | ExtraHop Secures Access with Identity to Kubernetes and Server Infrastructure | ExtraHop used Teleport to secure access to their servers and Kubernetes clusters without sacrificing speed … an identity-based approach to authorizing each developer. |
| SI005 | Teleport | Machine and Workload Identity — AI Agent Use Cases | Teleport enables you to enforce access and privileges for agents. Security must be enforced deterministically; AI agents cannot be trusted to follow high-level instructions like "don't delete production". Teleport solves this by issuing each agent its own identity. |
| SI006 | Teleport | Database Access — Enroll Resources | |
| SI007 | Teleport | Teleport Session Recording Architecture | Teleport captures the entire pseudo-terminal (PTY) output of the session. The intention is for session recording to document what a user saw when they ran a session. |
| SI008 | Teleport | Teleport LLMs.txt — Company and Product Summary | Teleport, the AI Infrastructure Identity Company, establishes a unified identity layer for infrastructure — humans, machines, workloads, and AI agents — secured cryptographically. Headquartered in Oakland, CA, Teleport operates globally. |
| SI009 | Teleport | Elasticsearch RBAC and Auditing with Teleport | |
| SI010 | Teleport | MCP Servers — Enroll Resources | |
| SI011 | U.S. Securities and Exchange Commission (EDGAR) | CyberArk Software Ltd. Form 20-F Annual Report (Fiscal Year 2024) | |
| SI012 | GetLatka | Teleport — Company Financial Data and Metrics | In 2024, Teleport's revenue reached $49M … Teleport employs approximately 246 people as of 2026 … Teleport raised $140M in total funding across 2 rounds. |
| SI013 | Teleport | Teleport Pricing | |
| SI014 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Bessemer Growth leads the $110 million Series C. We believe Teleport will be the defining solution … granting infrastructure access seamlessly without compromising security. |
| SI015 | Teleport | Teleport Raises $110 Million Series C at $1.1 Billion Valuation | Teleport has just secured $110M in Series C funding … net new annual recurring revenue up 4.5x and total annual recurring revenue up 2.8x year over year. The new round values the company at $1.1 billion. |
| SI016 | Teleport | Teleport raises $30MM in series-B and launches secure access for MongoDB | Net new annual recurring revenue up 5x and total annual recurring revenue up 2.5x, compared to the second quarter of 2020. |
| SI017 | Teleport | Announcing our Series A | We have closed a $25MM Series A funding round led by Kleiner Perkins … We were recently able to reach profitability. |
| SI018 | Teleport | Teleport Community Edition will adopt a commercial license starting with version 16 | Companies may use Teleport Community Edition on the condition they have less than 100 employees and less than $10MM in annual revenue. |
| SI019 | CompaniesMarketCap | CyberArk Software (CYBR) — Market Capitalization | As of June 2026 CyberArk Software has a market cap of $20.63 Billion USD. |
| SI020 | CompaniesMarketCap | CyberArk Software (CYBR) — Revenue | CyberArk Software's current revenue (TTM) is $1.30 Billion USD. In 2024 the company made a revenue of $1.00 Billion USD. |
| SI021 | CompaniesMarketCap | Okta (OKTA) — Market Capitalization | As of June 2026 Okta has a market cap of $20.65 Billion USD. |
| SI022 | CompaniesMarketCap | Okta (OKTA) — Revenue | Okta's current revenue (TTM) is $2.91 Billion USD. In 2025 the company made a revenue of $2.91 Billion USD an increase over the revenue in the year 2024 that were of $2.61 Billion USD. |
| SI023 | PeerSpot | Teleport Reviews — User Feedback and Ratings | Pricing concerns affect large companies … Teleport requires improvements in initial setup and RBAC complexity. |
| SI024 | StrongDM | StrongDM vs. Teleport — Comparison and Alternatives | The Teleport agents run as root in every server you want to audit, creating a new attack vector … Pricing concerns affect large companies. |
| SI025 | Kleiner Perkins | Gravitational — Pulling Us Toward an Open and Multi-Cloud Future | |
| SI026 | Precedence Research | Privileged Access Management Market Size to Hit USD 29.88 Bn by 2034 | The global privileged access management market size is accounted at USD 4.50 billion in 2025 and is predicted to increase … to approximately USD 29.88 billion by 2034, expanding at a CAGR of 23.40%. |
| SI027 | NIST | Zero Trust Architecture — NIST Special Publication 800-207 | |
| SE001 | Teleport | Teleport: Unified Identity Securing Classic & AI Infrastructure | Teleport unifies identities — humans, machines, and AI — with strong identity implementation to speed up engineering, improve resiliency against identity-based attacks, and control AI in production infrastructure. |
| SE008 | Teleport | Teleport Community Edition will adopt a commercial license starting with version 16 | Starting with the June release of Teleport 16, we are switching Teleport Community Edition to a commercial license with new restrictions |
| SE009 | Teleport | Introducing Teleport 16 - Enhanced Security and Usability with New Features | |
| SE010 | Teleport | Introducing Teleport 17 - Enhanced Security and Usability with New Features | |
| SE011 | Teleport | Teleport Explained: Concepts & Architecture Guide | Teleport is a certificate authority and identity-aware access proxy that implements protocols such as SSH, RDP, HTTPS, Kubernetes API, and a variety of SQL and NoSQL database protocols. |
| SE012 | Teleport | Teleport Pricing | |
| SE017 | Teleport | Teleport Reference Architecture | |
| SE018 | Teleport | Teleport Core Concepts | |
| SE019 | Teleport | Teleport Feature Matrix | The Teleport Agentic Identity Framework combines Teleport identity, access, governance, and monitoring capabilities to secure AI agents and the infrastructure they access. |
| SE020 | Teleport | Machine & Workload Identity Documentation | |
| SE022 | Teleport | MCP Server Access Documentation | |
| SE023 | Teleport | Teleport Identity Security Documentation | |
| SE024 | Teleport | Session Recording Architecture | |
| SE025 | Teleport | FedRAMP Compliance with Teleport | Teleport releases from 17.7.3+ and 18.0.0+ use BoringCrypto tag fips-20220613 (CMVP certificate #4735, FIPS 140-3) |
| SE026 | Teleport | SOC 2 Compliance with Teleport | |
| SE027 | Teleport | Teleport Upcoming Releases | |
| SE028 | Teleport | Identity Security Blog Post | |
| SE029 | Teleport | Teleport Security Audit by Cure53 | No critical vulnerabilities have been discovered. One high vulnerability was found: The roles API of the auth server allow directory traversal. |
| SE030 | Teleport | Teleport Introduces Agentic Identity Framework | |
| SE031 | Teleport | Beams LLM Proxy and Delegated Identity Public Beta | Two foundational identity concepts — controlling the scope of agent roles and constraining what they can access — now have a production implementation in Beams |
| SE032 | Teleport | 2026 Infrastructure Identity Survey: State of AI Adoption | 92% have near-term AI initiatives in infrastructure... but only 13% feel extremely prepared |
| SE033 | Teleport | Agentic Identity Framework Documentation | |
| SE034 | Teleport | AI Agents with Machine & Workload Identity | |
| SE035 | Beams (Teleport) | Beams — Trusted Runtimes for Infrastructure Agents | Beams runs each agent in an isolated Firecracker VM with built-in identity. Connected to your infrastructure and inference services — no secrets, no IAM wrestling. |
| SE036 | GitHub (gravitational/teleport) | Teleport Open Source Repository | Teleport is a single Go binary that integrates with multiple protocols and cloud services |
| SE041 | NIST | Zero Trust Architecture (SP 800-207) | |
| SE042 | CISA | Zero Trust Maturity Model | |
| SE043 | StrongDM | StrongDM vs Teleport Comparison | The Teleport agents run as root in every server you want to audit, creating a new attack vector and a new surface to protect... Teleport cloud is unreliable and availability numbers are inaccurate. |
| SE051 | HashiCorp | What is Boundary? | |
| SE052 | PeerSpot | Teleport Reviews | I rate it a seven because, as I mentioned, there is a security threat regarding clipboard access. |
| SE054 | Teleport | FedRAMP Compliance Use Case | |
| SE053 | Teleport | Teleport Named to Citizens Securities 2026 Cyber 66 | 73% of cybersecurity leaders are already seeing enterprise customers ask how their platforms can help secure AI agents |
| SE037 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Teleport will be the defining solution to this emerging massive problem, granting infrastructure access seamlessly without compromising security. |
| SE039 | Kleiner Perkins | Gravitational: Pulling Us Toward an Open and Multi-Cloud Future | |
| SE055 | Teleport | Teleport Database Access Documentation | |
| SE056 | Teleport | Teleport Security Page — Code Signing and Certificates | |
| SE057 | Teleport | Teleport Blog | |
| SE058 | Teleport | Elasticsearch Database Access — Self-Hosted Enrollment | |
| SE059 | Teleport | Teleport Identity Governance | |
| SE060 | Teleport | Teleport Proxy Service | |
| SE061 | Teleport | Teleport Authentication | |
| SE062 | Teleport | Deploying Teleport Agents | |
| SE063 | Teleport | Teleport tsh Client Documentation | |
| SU001 | Teleport | Teleport Customer Case Studies | When security and a frictionless engineering experience matter, the most innovative companies in the world trust Teleport for Infrastructure Identity. |
| SU002 | Teleport | GoTo Customer Case Study | All our Kubernetes clusters are private—meaning they can't be accessed publicly, both for the data plane and control plane. We needed a mechanism to securely expose this to developers, and Teleport fit our requirements perfectly. |
| SU003 | Teleport | Exness Customer Case Study | Teleport was the only evaluated solution that met every requirement. |
| SU004 | Teleport | Gladly Customer Case Study | |
| SU005 | Teleport | ExtraHop Customer Case Study | |
| SU006 | Teleport | IBM Instana Customer Case Study | This is company number three I've done this at, to have Teleport in play to give us the ability to go and help our security posture |
| SU007 | Teleport | Carta Customer Case Study | |
| SU008 | Teleport | Announcing our Series A | our customer base has exploded from a handful of early adopters to an impressive portfolio of some of the world's largest and most innovative companies, including NASDAQ, Splunk, TicketMaster, Mulesoft and Samsung. |
| SU009 | Teleport | Teleport Raises $110 Million Series C at $1.1 Billion Valuation | fantastic logos like Nasdaq, Doordash, and Snowflake, make Teleport a category-defining company |
| SU010 | Teleport | Teleport Raises $30M in Series B | |
| SU011 | Teleport | Teleport Named to 2026 Fortune Cyber 60 | More than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport to reduce risk and simplify access. |
| SU012 | Teleport | Teleport Newsroom | |
| SU013 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Its secretless security model and focus on developer productivity, along with fantastic logos like Nasdaq, Doordash, and Snowflake, make Teleport a category-defining company |
| SU014 | GitHub (gravitational/teleport) | Teleport Open Source Repository | |
| SU015 | PeerSpot | Teleport Alternatives and Competitors | |
| SU016 | Slashdot | Best Teleport Alternatives in 2026 | |
| SU017 | Latka (getlatka.com) | Teleport Revenue and Company Data | In 2024, Teleport's revenue reached $49M. Since its launch in 2015, Teleport has shown consistent revenue growth. |
| SU018 | Teleport | Teleport Community Edition License Change | |
| SU019 | Precedence Research | Privileged Access Management Market Report 2025-2034 | |
| SU020 | StrongDM | StrongDM vs Teleport Comparison | Teleport only supports more modern systems that will allow their certificate-based authentication. |
| SU021 | Teleport | 2026 Infrastructure Identity Survey | |
| SU022 | Kleiner Perkins | Gravitational: Pulling Us Toward an Open and Multi-Cloud Future | |
| SU023 | PeerSpot | Teleport Reviews | Teleport changed our workflow by centralizing access control and reducing manual SSH key management. |
| SU024 | Teleport | Teleport Named Citizens Securities 2026 Cyber 66 | recognized in the Cyber 66 report as a revenue category mover, reflecting continued business momentum |
| SU025 | Teleport | Teleport About Page | |
| SU026 | Teleport | Teleport Elasticsearch Integration | |
| SU027 | Teleport | Teleport LLMs.txt — AI Infrastructure Identity Company | trusted by industry-leading organizations including Nasdaq, IBM, Doordash, Elastic, and GoTo |
| SU028 | Fortune Business Insights | Privileged Access Management Market Size and Growth Report | |
| SU029 | Teleport | Turo Streamlines Infrastructure Access with Teleport | |
| SU030 | Teleport | KnowBe4 Case Study | |
| SU031 | Teleport | How TigerGraph Enhances Global Access Control with Teleport | |
| SU032 | Teleport | ECMWF Secure Access to Supercomputing Clusters with Teleport | |
| SU033 | Teleport | RSI Levels Up Cloud Security with Teleport Infrastructure Identity | |
| SU034 | Teleport | Mapgears Boosts Customer Support with Teleport's Secure SSH Access | |
| SU035 | Teleport | Securing Kubernetes Access with thredUP | |
| SU036 | Teleport | Enhance Global Content Delivery with Teleport, Rundeck and Slack APIs | |
| SU037 | Teleport | Secure Biomedical Research Compliance with Flywheel and Teleport Access | |
| SR001 | Teleport | A new commercial license for Teleport Community Edition | |
| SR002 | Teleport | Teleport raises $110M in Series C funding | |
| SR003 | Teleport | Gravitational raises Series A funding | |
| SR004 | Teleport | Teleport raises Series B funding | |
| SR005 | Teleport | About Teleport | |
| SR006 | Teleport Docs | FedRAMP compliance framework | |
| SR007 | Teleport Docs | SOC 2 compliance framework | |
| SR008 | Teleport | FedRAMP compliance use case | |
| SR009 | Teleport | Teleport security audit | |
| SR010 | Teleport | Teleport pricing | |
| SR011 | GitHub | gravitational/teleport | |
| SR012 | Bessemer Venture Partners | Investing in Teleport and the unified access plane | |
| SR013 | Bessemer Venture Partners | State of the Cloud 2024 | |
| SR014 | NIST | Zero Trust Architecture | |
| SR015 | CISA | Zero Trust Maturity Model | |
| SR016 | StrongDM | StrongDM vs Teleport | |
| SR017 | StrongDM | StrongDM homepage | |
| SR018 | CyberArk | What is Privileged Access Management? | |
| SR019 | CyberArk | Privileged Access Manager | |
| SR020 | BeyondTrust | Privileged Access Management (PAM) | |
| SR021 | Okta | Okta Privileged Access | |
| SR022 | HashiCorp | What is Boundary? | |
| SR023 | PeerSpot | Teleport reviews | |
| SR024 | PeerSpot | Teleport alternatives and competitors | |
| SR025 | Slashdot | Teleport alternatives | |
| SR026 | CompaniesMarketCap | CyberArk market cap | |
| SR027 | CompaniesMarketCap | CyberArk revenue | |
| SR028 | CompaniesMarketCap | Okta market cap | |
| SR029 | CompaniesMarketCap | Okta revenue | |
| SR030 | Precedence Research | Privileged Access Management market | |
| SR031 | Open Source Initiative | The Open Source Definition | |
| SR032 | GetLatka | Teleport company profile | |
| SR033 | Teleport | Teleport named to 2026 Fortune Cyber 60 list | |
| SR034 | Teleport | Teleport named to 2026 Cyber 66 | |
| SR035 | Teleport Docs | Agentic Identity Framework | |
| SR036 | Beams | Beams homepage | |
| SR037 | AWS | AWS Systems Manager Session Manager | |
| SR038 | Microsoft | What is Azure Bastion? | |
| SR039 | Google Cloud | Identity-Aware Proxy overview | |
| SR040 | Microsoft | What is Privileged Identity Management? | |
| SR041 | Teleport Docs | Teleport Authorization | |
| SR042 | Teleport Docs | TLS Routing | |
| SR043 | Teleport Docs | Proxy Peering Migration | |
| SV001 | Teleport | Teleport raises $110M in Series C funding | |
| SV002 | Teleport | Teleport raises $30M in Series B funding | |
| SV003 | Teleport | Gravitational raises Series A funding | |
| SV004 | Teleport | About Teleport | |
| SV005 | Teleport | Teleport named to the 2026 Fortune Cyber 60 list | |
| SV006 | Teleport | Teleport named to the 2026 Cyber 66 hottest privately held cybersecurity companies | |
| SV007 | Teleport | A new commercial license for Teleport Community Edition | |
| SV008 | Bessemer Venture Partners | Investing in Teleport and the unified access plane | |
| SV009 | Bessemer Venture Partners | State of the Cloud 2024 | |
| SV010 | GetLatka | Teleport company profile and estimated revenue | |
| SV011 | CompaniesMarketCap | CyberArk market capitalization | |
| SV012 | CompaniesMarketCap | CyberArk revenue history | |
| SV013 | CompaniesMarketCap | Okta market capitalization | |
| SV014 | CompaniesMarketCap | Okta revenue history | |
| SV015 | Precedence Research | Privileged Access Management Market | |
| SV016 | Precedence Research | Zero Trust Security Market | |
| SV017 | Grand View Research via Internet Archive | Zero Trust Security Market Report (archived) | |
| SV018 | Grand View Research via Internet Archive | Privileged Access Management Market Report (archived) | |
| SV019 | Fortune Business Insights | Privileged Access Management Market | |
| SV020 | Securities and Exchange Commission | CyberArk Software Ltd. EDGAR company filings | |
| SV021 | CyberArk | What is Privileged Access Management? | |
| SV022 | CyberArk | CyberArk Privileged Access Manager | |
| SV023 | Okta | Okta Privileged Access | |
| SV024 | Kleiner Perkins | Gravitational: pulling us toward an open and multi-cloud future | |
| SV025 | StrongDM | StrongDM vs Teleport | |
| SV026 | PeerSpot | Teleport alternatives and competitors | |
| SV027 | Slashdot | Teleport alternatives | |
| SV028 | Teleport | Infrastructure Identity Survey 2026 | |
| SV029 | GitHub | gravitational/teleport repository | |
| SV030 | Teleport | Teleport newsroom | |
| SV031 | Beams | Beams | |
| SV032 | HashiCorp | What is Boundary? | |
| SV033 | Teleport | Teleport introduces Agentic Identity Framework | |
| SV034 | Teleport | Beams LLM proxy with delegated identity | |
| SV035 | Teleport | IBM Instana case study | |
| SV036 | Teleport | Carta case study | |
| SV037 | Teleport | GoTo case study | |
| SV038 | Teleport | Exness case study | |
| SV039 | Teleport | Careers at Teleport | |
| SV040 | Teleport | Accelerate FedRAMP compliance | |
| SV041 | Teleport | Automating identity and access for FedRAMP 20x | |
| SV042 | BeyondTrust | BeyondTrust Privileged Remote Access | |
| SV043 | Delinea | Secret Server | |
| SV044 | Grand View Research | Privileged Access Management Market Report | |
| SV045 | Grand View Research | Zero Trust Security Market Report | |
| SV046 | Teleport | Gladly case study | |
| SV047 | Teleport | ExtraHop case study | |
| SV048 | Macrotrends | Okta price to sales ratio | |
| SV049 | Stock Analysis | CyberArk Software revenue | |
| SV050 | Stock Analysis | Okta revenue | |
| SV051 | Stock Analysis | CyberArk Software stock price and overview | |
| SV052 | Stock Analysis | Okta stock price and overview | |
| SV053 | Yahoo Finance | Okta stock price, news, quote and history | |
| SV054 | Nasdaq | OKTA stock page |