初创公司尽调
尽调报告 cybersecurity Series C private 2026-06-20

Teleport

开源基础设施身份平台,拿下强势企业客户标识,但 2022 年独角兽估值已经过时。

Teleport 产品深度和企业客户验证都真实存在;但 2022 年独角兽估值已经陈旧、当前 ARR 未核实,加上许可与采购摩擦风险,投资判断仍受约束。

封面要素

最近估值 01
$1.1B [CV001]
估算员工数 04
246 employees [CO021]
创立时间 05
2015 [CO004]
总部 06
Oakland, California [CO001]

公司概况

Teleport 是一家成立于 2015 年的私有基础设施身份公司,把服务器、Kubernetes 集群、数据库、Web 应用、机器和 AI 代理的访问与策略统一起来。公司从开源访问项目长成多模块商业平台,覆盖 Zero Trust Access、Machine and Workload Identity、Identity Governance、Identity Security,以及 Beams 代理运行时。Teleport 已在三轮已披露融资中募资 $165M,2022 年 5 月估值达到 $1.1B,并在科技、金融科技和受监管基础设施领域有强势具名客户背书,但当前财务画像仍大多未披露。

官网
goteleport.com
成立时间
2015-01-01
创始人
Ev Kontsevoy, Alexander Klizhentas, Taylor Wakefield
创立地点
Oakland, California, USA
总部
Oakland, California, USA
产品
基于证书的基础设施身份平台,覆盖 SSH、Kubernetes、数据库、Web 应用、Windows / RDP、MCP 服务器、机器身份和 AI 代理运行时。
客户
中端市场和企业级工程、平台、安全、金融科技及受监管基础设施团队。
商业模式
按用量计费的企业 SaaS 和自托管软件,按月活跃用户、机器 / 工作负载身份和受保护资源变现;免费社区层只面向较小公司。
阶段
Series C private
融资情况
2022 年 5 月以 $1.1B 估值完成 $110M Series C;已披露融资总额 $165M;此后无已验证新融资轮。
[CO001, CO004, CO006, CO015, CO016, CO018, CO020]

执行摘要

主要优势

  • 基于证书的统一访问架构覆盖 SSH、Kubernetes、数据库、Web 应用和机器身份。
  • 开源分发和庞大 GitHub 足迹支撑了强开发者可信度。
  • 已披露蓝筹客户包括 Nasdaq、DoorDash、IBM Instana、Carta、Samsung、Elastic 和 Snowflake。
  • Kleiner Perkins、S28、Bessemer 和 Insight 组成的强投资人组合支撑品类创建。
  • 新的 AI-agent 身份和 Beams 定位若能落地采用,可能打开额外增长楔子。

主要风险

  • $1.1B Series C 估值已经陈旧,相比 2026 年公开身份和 PAM 可比公司显得偏贵。
  • 唯一当前 ARR 数字(2024 年 $49M)来自第三方估计,并非公司确认数据。
  • 2024 年 6 月社区许可证变更可能削弱自下而上转化和社区好感。
  • 公开资料支持其拥有 FedRAMP 合规工具,但未验证 Teleport Cloud 本身获得 FedRAMP 授权。
  • 大型竞争对手和云原生替代方案可以打包相邻身份与特权访问能力。

未决问题

  • 当前 ARR、毛利率、烧钱速度、现金跑道和 NRR 均未公开披露。
  • 600+ 客户数字由公司自述,尚未独立验证。
  • 可访问公开资料仍无法确认 Teleport Cloud 的 FedRAMP 授权状态。
  • 除已宣布投资人外,股权结构条款、清算优先权和董事会构成仍属私密。
  • 二级市场定价或任何 2022 年后更新估值证据均未公开。

目录

Chapter 01

01公司概览

1.1 身份、使命、产品和总部

Teleport 自称「AI Infrastructure Identity Company」,总部位于加利福尼亚州奥克兰 Franklin St 2100 号 Suite 400,邮编 94612。公司为基础设施改造身份、访问和策略,把产品定位成一个平台:既提升工程速度,也增强对身份攻击的韧性。公司最初注册为 Gravitational Inc.,2021 年更名为 Teleport,并从 gravitational.com 迁至 goteleport.com;宣布更名的博客明确称,Teleport 产品已成为公司的主要重心。法律实体在包签名证书上仍保留 Gravitational Inc. 公司名(Apple Developer ID QH8AA5B8UP Gravitational Inc.),证明公司延续性。 Teleport 将产品描述为统一身份层,用证书颁发机构模型取代服务器(SSH)、Kubernetes、数据库、RDP、Web 应用和 MCP 服务器之间碎片化的访问管理系统;该模型为请求者身份签发短期凭证。该架构与 NIST SP 800-207 Zero Trust Architecture 框架一致:零信任消除基于网络位置的隐式信任,并要求每次请求都认证和授权。公开定价页显示,收入模型按用量计费,计量口径包括 Monthly Active Users(MAU)、Machine and Workload Identities(MWI)和 Teleport Protected Resources(TPR)。Community Edition 对员工少于 100 人且年收入低于 $10M 的公司免费,Enterprise Edition 则需要商业接洽。公司为私有企业;未公开收入、利润率、现金或烧钱数据。[CO001, CO002, CO003, CO004, CO005, CO006]

快照 KPI 表
指标数值 / 状态日期置信度缺口
创立年份20152015
法定名称Gravitational Inc.(以 Teleport 名义经营)2021
总部2100 Franklin St Suite 400,Oakland,CA 94612(总部地址)2026-06
阶段私有 / Series C2022-05
最新估值(USD B)1.12022-052022 年后融资未确认;估值标记已过时约 4 年
Series A 融资额(USD M)252019(约)博客未说明准确日期
Series B 融资额(USD M)302021
Series C 融资额(USD M)1102022-05
已披露融资总额(USD M)1652022-05
2024 ARR(USD M,估算)~49(GetLatka,未确认)2024-12未验证的第三方估算;公司未确认
员工数(估算)~246(GetLatka,2025 年 11 月)2025-11估算值;未披露官方员工数
GitHub stars15000+2024-06截至社区许可博客发布时;可能已增长
具名客户600+2026-06公司表述;总数没有第三方验证
收入模式基于用量(MAU / MWI / TPR)2026-06
源代码许可AGPLv3(未变)2024-06
二进制 / 镜像许可商业许可(自 Teleport 16 起限制大型公司)2024-06
FedRAMP 状态仅 FIPS / 合规工具——未确认 SaaS ATO2026-06没有 Teleport Cloud ATO 的公开证据

除标注为估算外,所有财务数字均为公司披露数据。GetLatka ARR 和员工数是第三方估算,未经独立确认。估值为 2022 年 Series C 标记;没有可用更新。

[CO001, CO004, CO014, CO015, CO016, CO018]
FO003: 快照 KPI

公开可支撑的 KPI 显示,这是一家资本充足、企业 logo 强的私营公司;但关键财务指标仍未确认,估值标记已过时四年。

ARR 和员工数是 GetLatka 第三方估算;其他所有数值来自已披露的公司或投资者材料。

[CO014, CO015, CO016, CO017, CO018, CO020]

1.2 创始人、领导层和关键人物集中度

Teleport 由三位联合创始人于 2015 年创立。三人在 Rackspace 收购 Mailgun 后于 Rackspace 共事,Mailgun 是他们此前打造的开发者邮件基础设施创业公司。Ev Kontsevoy 担任 CEO,是公司最主要的公开声音。Alexander Klizhentas(Sasha)担任 CTO。Taylor Wakefield 担任 COO。截至本次报告日期,Teleport 关于页面确认三人仍在活跃高管岗位。创始团队共同具备云基础设施和开发者工具背景,这是公开来源中最清晰的创始人—市场匹配信号。 创始团队之外的领导层包括 CRO Jeff Bunten 和 CMO Diana Jovin,二人均出现在外部媒体报道中。Jovin 于 2026 年 4 月在 RSAC 被引用,新闻室也称其为 CMO。Bunten 在关于页面列为 CRO。关键人物风险不低:Kontsevoy 签署了三次融资公告,是 Agentic Identity Framework 发布和 Fortune Cyber 60 公告中的具名发言人,也出现在每一次主要外部访谈中。除融资轮中提到的投资人外,公司未公开更多董事会成员。[CO007, CO008, CO009, CO010, CO011, CO012]

领导层与创始人表
人员职位背景创始人-市场契合 / 职能覆盖关键人物依赖
Ev Kontsevoy联合创始人兼 CEO联合创立 Mailgun(被 Rackspace 收购);在 Rackspace 搭建云基础设施深厚基础设施和开发者工具背景;主导三轮融资关键——融资、公开战略和外部发言人角色均集中于其身上
Alexander Klizhentas联合创始人兼 CTO与 Kontsevoy 联合创立 Mailgun;具备分布式系统和安全工程背景负责开源核心和企业产品架构的技术领导高——技术路线图和架构决策
Taylor Wakefield联合创始人兼 COO联合创立 Mailgun;具备 GTM 和运营领导背景运营规模化;与 Kontsevoy 共同领导商业执行中——支持 CEO,但分担运营权重,降低单点风险
Jeff BuntenCRO企业销售领导背景;Series C 后加入以扩展商业打法企业收入增长;负责销售和渠道中——面向外部的收入负责人,但向创始人负责
Diana JovinCMO网络安全营销背景;RSAC 2026 被引用品牌、需求生成,以及 AI 基础设施身份叙事的产品营销低——营销职能;市场上可替换

除已具名投资人董事会成员(Mary D'Onofrio / Bessemer;Matt Koran / Insight observer)外,董事会构成未披露。公开材料中没有出现独立董事姓名。

[CO007, CO008, CO009, CO010, CO011, CO012]

1.3 融资历史、估值和资本结构

Teleport 已披露三轮融资,总额 $165M。首轮是 Kleiner Perkins 领投的 $25M Series A,公司当时仍以 Gravitational 名义运营,并在公司博客上宣布。Series A 博客列出早期客户 NASDAQ、Splunk、TicketMaster、Mulesoft 和 Samsung,并称公司近期已实现盈利。随后是 2021 年由 S28 Capital 和 Kleiner Perkins 领投的 $30M Series B;该轮发生在一个季度之后,当季净新增 ARR 同比增长 5x,总 ARR 较 2020 年 Q2 增长 2.5x,说明公司收入正从较小基数快速放大。公司当时未披露 ARR 金额。 最大一轮是 2022 年 5 月宣布的 $110M Series C,由 Bessemer Venture Partners 领投,Insight Venture Partners 参投,估值 $1.1B。Bessemer 投资博客(bvp.com)和 Teleport 公告博客均确认该估值。Series C 当时披露总 ARR 同比增长 2.8x、净新增 ARR 增长 4.5x,距离 Series B 不到一年。Bessemer 的 Mary D'Onofrio 加入董事会;Insight 的 Matt Koran 担任董事会观察员。未发现 2022 年 5 月之后后续融资轮的公开证据。因此,截至本次报告日期,$1.1B 估值标记已有约四年,私募市场环境也已明显变化。 第三方数据聚合商 GetLatka 在 2025 年快照中称 Teleport 两轮融资共 $140M,这与公司披露的三轮 $165M 不一致。GetLatka 还估算公司 2024 年收入为 $49M,2025 年底员工数约 246 人;这些数字是未经确认的第三方估算,不应视为已验证财务数据。[CO013, CO014, CO015, CO016, CO017, CO018]

利益相关方或投资人地图
利益相关方角色投资 / 参与控制权或经济重要性尽调问题
Kleiner Perkins领投 Series A;共同领投 Series B$25M Series A + 参与 $30M Series B最早机构支持者;董事会席位有暗示,但 Series C 后未确认确认当前董事席位或观察员身份,以及持股比例
S28 Capital与 Kleiner Perkins 共同领投 Series B$30M Series B 共同领投方Series B 领投方;Series C 后股份可能被稀释确认当前持股比例及任何治理权利
Bessemer Venture Partners领投 Series C$110M Series C;Mary D'Onofrio 加入董事会最大已披露外部投资人;轮次时确认当前董事席位确认董事会构成和 Series C 后当前持股比例
Insight Venture Partners参与 Series C重要参与 $110M Series C;Matt Koran 任董事会观察员Series C 参与方;轮次日期拥有董事会观察员权利确认观察员身份和当前持股比例
Ev Kontsevoy / Klizhentas / Wakefield创始管理团队创始股权;未披露买断或二级交易可能为控股股东;内部股权结构未知从公司法律顾问处取得 cap table,以确认所有权和稀释
员工股权持有人现任和前员工标准股权授予;期权池规模未知集体激励机制;期权池悬挂影响稀释测算向公司索取期权池规模和归属计划数据
S28 Capital 跟投潜在跟投投资人Series C 后未确认;没有跟投公开证据未知;未披露 2022 年后融资索取最新 cap table,以及已行使的任何 ROFR 或 pro-rata 权利

股权结构表为私有;所有持股均根据公开融资披露推断,可能不能反映 Series C 后的二级交易或授予。GetLatka 显示 2 轮融资共 $140M,与披露的 3 轮共 $165M 不一致。

[CO014, CO015, CO016, CO017, CO018, CO019]
FO001: 公司里程碑时间线

Teleport 的公开记录从 2015 年创立开始,经过 2022 年 $1.1B Series C,延伸到 2026 年 AI agent 产品扩张;其中 2024 年许可证变化是最不利的经营里程碑。

Series A 日期为近似值(2019 年由 KP perspectives 文章推断;确切交割月份未在已审阅来源中确认)。其他所有日期均来自官方公告。

[CO013, CO014, CO015, CO016, CO025, CO027]

1.4 里程碑、规模和产品演进

Teleport 的里程碑显示,公司用约十年时间从面向开发者的访问工具,走向完整基础设施身份平台。开源 Teleport 项目于 2016 年在 GitHub 以 AGPLv3 许可证公开;到 2024 年 6 月社区许可证博客发布时,仓库已累计超过 15,000 颗星。公司在连续几个大版本中加入 Kubernetes 访问、数据库访问(PostgreSQL、MongoDB、MySQL)、Windows RDP 访问,最近又加入 MCP 服务器访问。Teleport 16(2024 年 6 月)和 Teleport 17(2024 年 10 月)是最近两个主要版本,Teleport 已改用每年一个主要版本的发布节奏。 官方材料中的具名客户标识包括 NASDAQ、Snowflake、DoorDash、IBM(Instana)、Carta、GoTo、Exness、KnowBe4、Turo、Gladly、ThredUP、ExtraHop 等。案例研究页面列出十余个详细案例,招聘页面称「全球超过 600 家客户」。公司在 2025 年和 2026 年获得 Fortune Cyber 60 榜单(2025 年 10 月)和 Citizens Securities Cyber 66 榜单(2026 年 4 月)认可。2026 年 1 月,Teleport 发布 Agentic Identity Framework,这是一条面向生产基础设施中 AI 代理安全的 AI 路线图。2026 年 6 月,Teleport 宣布 Beams,这是在 beams.run 为 AI 代理提供可信运行时的新产品。[CO024, CO025, CO026, CO027, CO028, CO029]

里程碑表
日期事件类型金额 / 估值 / 状态参与方含义
2015Gravitational Inc. 成立;Teleport 项目启动创立$0 融资Ev Kontsevoy、Alexander Klizhentas、Taylor Wakefield 三位创始人将多云基础设施访问识别为创始问题
2016Teleport 在 GitHub 以 AGPLv3 开源产品到 2024 年 GitHub stars 15,000+Gravitational 团队开源采用策略;社区增长成为竞争护城河
2016-2018早期客户基础——NASDAQ、Splunk、Samsung 在 Series A 被点名规模Gravitational机构资本进入前已获得企业 logo;证明企业需求
2019(约)由 Kleiner Perkins 领投的 Series A 完成融资融资 $25M;KP 领投Kleiner Perkins(Bucky Moore)首笔机构资本;公司此前不久已达到盈利
2021由 S28 Capital 和 Kleiner Perkins 领投的 Series B 完成融资融资 $30M;ARR 较 2020 年 Q2 同比 2.5 倍S28 Capital、Kleiner Perkins;引用 Bucky Moore 发言ARR 三倍增长轨迹获确认;随该轮推出数据库访问(MongoDB)
2021Gravitational 正式更名为 Teleport;迁至 goteleport.com治理Gravitational / Teleport 领导层品牌围绕产品名统一;公司实体仍为 Gravitational Inc.
2022-05由 Bessemer Venture Partners 领投的 Series C 完成融资融资 $110M;估值 $1.1BBessemer(Mary D'Onofrio)、Insight(Matt Koran 观察员)独角兽里程碑;轮次时 ARR 同比 2.8 倍;最后已知外部估值
2024-06Teleport 16 发布;社区二进制许可改为商业许可产品Teleport 团队编译二进制 / 镜像受商业许可限制;AGPLv3 源代码不变
2025-10-30入选 2026 Fortune Cyber 60 榜单监管 / 认可Fortune / Lightspeed / AWS第三方增长认可;新闻稿引用 600+ 客户
2026-01-27Agentic Identity Framework 发布产品Teleport;Ev Kontsevoy 声明AI-first 身份路线图;将 Teleport 定位于 agentic AI 基础设施安全
2026-04-07入选 Citizens Securities Cyber 66 榜单监管 / 认可Citizens Securities 网络安全研究团队同行认可其为最热门私有网络安全公司;AI 身份角度被强调
2026-06Beams 在 beams.run 启动公测产品Teleport面向 AI agent 基础设施的独立产品;把 TAM 从人类 / 机器身份扩展出去

没有月 / 日的日期是根据博客文章推算的近似值。Series A 日期根据 KP perspectives 文章推断;准确月份未确认。2022 年 5 月 Series C 后未确认任何融资事件。

[CO013, CO014, CO015, CO016, CO024, CO025]
FO002: 公司快照逻辑

Teleport 的开源社区和企业客户群共同喂给基于用量的收入引擎,但过时的 2022 年估值标记、受限社区许可证,以及未确认的 FedRAMP ATO 缺口构成约束。

[CO001, CO006, CO014, CO015, CO016, CO024]

1.5 许可证变更、FedRAMP 定位缺口和负面信号

近期最重大的负面进展是 2024 年 6 月社区许可证变更。从 Teleport 16 开始,公司将编译后的 Community Edition 二进制文件和容器镜像从 Apache 2.0 改为商业许可证。新许可证只允许员工少于 100 人且年收入低于 $10M 的公司免费商业使用。源代码仓库的 AGPLv3 许可证未变,意味着大公司仍可从源码编译,但下载预构建二进制文件的便利性现在受限。这一动作与其他 open-core 公司保护社区变现的做法一致,但也清楚收紧了社区产品,一些用户和企业对此有批评。 FedRAMP 方面,Teleport 公开文档和营销材料称产品可帮助客户满足 FedRAMP 合规要求。Teleport Enterprise 构建使用通过 FIPS 140 验证的加密模块编译,FedRAMP 文档页说明 Teleport 如何帮助实现具体 FedRAMP 控制项。不过,公开语料中没有证据确认 Teleport 自身云服务已获得 FedRAMP Authorization To Operate(ATO)。Teleport 的 FedRAMP 定位是合规赋能工具,而不是获得 FedRAMP 授权的服务提供商。联邦买家可能预期 SaaS 本身具备 ATO,因此该缺口重要。 第三方评论平台上的负面产品信号也值得注意。PeerSpot 评论者提到初始设置复杂、RBAC 配置困难,以及与 SIEM 和监控工具集成有挑战。StrongDM 的竞品对比页面声称,Teleport 基于代理的架构要求代理以 root 身份运行在每台被监控服务器上,创造新的攻击面;同一页面还称 Teleport Cloud 存在可靠性问题,包括更新期间宕机。这些说法来自竞争供应商,应批判性阅读,但它们代表了买家评估时会考虑的弱点类别。[CO033, CO034, CO035, CO036, CO037, CO039]

1.6 图表

Chapter 02

02市场分析

2.1 市场范围、相邻领域和替代品

Teleport 自身定位和产品架构决定了市场边界:比传统特权访问管理更宽,但比整个零信任堆栈更窄。公司称自己是 AI Infrastructure Identity 公司,销售基于证书的访问,覆盖 SSH、Kubernetes、数据库、Windows、内部 Web 应用、机器身份和 AI 相关基础设施工作流。因此,可纳入的支出是基础设施访问控制平面:特权访问、工作负载身份、访问审计,以及面向合规的基础设施访问现代化。即使这些预算有时影响交易,也不足以把广义员工 IAM、客户身份、端点安全、SIEM 或通用 AI 应用支出计入核心市场价值。现状替代品仍然很多——VPN、堡垒机、长期密钥、数据库密码、云原生单点 IAM 和手工审计工作流都在争同一件事。StrongDM 的负面竞品视角在这里有用,因为它认为 Teleport 对现代云资产仍是点状方案,而非通用访问平台;这是真实约束,会压住夸大的 TAM 叙事。[CM001, CM002, CM003, CM004, CM005, CM006]

市场定义与相邻边界
细分 / 类别纳入支出排除支出主要买方与 Teleport 的相关性
面向基础设施的特权访问管理特权会话控制、即时访问、审计、数据库和服务器访问代理通用员工 SSO、消费者身份、非特权应用登录CISO / 安全工程核心窄口径市场视角,最接近付费控制预算
零信任基础设施访问面向 SSH、Kubernetes、数据库、RDP、内部 Web 应用的身份感知访问和策略执行与基础设施访问工作流无关的端点、网络和数据控制安全架构 / 平台工程更宽但仍相关的相邻市场视角
机器与工作负载身份为 bot、服务、CI-CD 和基础设施工作负载签发证书与访问工作流无关的通用密钥管理或 PKI 支出平台工程 / 安全平台高相关性,因为 Teleport 直接变现 MWI
与访问绑定的合规和审计自动化FedRAMP、SOC 2、证据采集、会话录制、访问审查支持完整 GRC 套件支出、外部审计费用、广义合规咨询安全 / 合规 / 公共部门项目负责人扩大合同价值的相邻项,但不应作为独立 TAM 计算
AI agent 身份与访问控制面向 agentic 基础设施动作和 MCP 关联工作流的身份、授权和审计通用 AI 模型训练、应用层 copilots,以及非基础设施 AI 工具安全平台 / AI 平台负责人Teleport 定位中的新兴扩张向量
Workforce IAM / CIAM / 端点或 SIEM 工具仅纳入直接触达基础设施身份的管理员访问切片常规员工 SSO、客户身份、端点防护、通用日志分析CIO / IAM / IT 运营相邻,但大多排除在 Teleport 核心市场规模之外

边界表把可变现的基础设施身份控制平面,与更广义的身份、端点和分析类别区分开;后者可能影响交易,但不应计入核心 TAM。

[CM001, CM002, CM004, CM005, CM006, CM007]

2.2 规模测算视角和估算差异

规模证据支持分层看法,而不是单一醒目的 TAM。Precedence Research 的狭义 PAM 视角认为 2025 年市场为 $4.50 billion;两个更宽的零信任估算则把市场放在 2024 年约 $36.96 billion、2025 年 $40.01 billion,长期预测明显更高。Teleport 可能位于这些视角之间,因为它解决特权基础设施访问和身份控制,但无法捕获广义零信任研究中包含的所有网络、端点、数据和应用控制支出。类别语言也仍在稳定:Bessemer 将基础设施访问描述为一个新产品类别,这解释了为什么分析师覆盖跨越多个重叠定义,而非一套固定分类法。需求信号足以支撑真实市场,而不只是概念。Teleport 报告有 600 多家客户,2026 年调研和 2026 年新闻室证据显示 AI 驱动的身份担忧正在快速上升。即便如此,公开证据仍无法隔离精确的 Teleport SAM 或 SOM,因为客户组合、合同价值和部署分布均未披露,而且一个 Fortune Business Insights PAM 来源返回的内容完全错误。[CM009, CM010, CM011, CM012, CM013, CM014]

市场规模视角对比
发布方基准年份市场范围数值(USD B)CAGR(%)方法论置信度局限
Precedence Research2025特权访问管理4.523.4全球分析师市场模型,含 2034 年预测范围窄于 Teleport 的完整产品足迹,且供应商方法论不完全透明
Grand View Research(存档)2025特权访问管理保留的类别列表作为类别覆盖证据保留来源未能为本轮提供清晰的公开头部数字
Fortune Business Insights2026特权访问管理尝试用于三角校验的来源URL 返回了无关的农业内容,因此 PAM 估算不可用
Grand View Research(存档)2024零信任安全36.9616.6到 2030 年的宽口径零信任市场估算覆盖的控制范围比单纯基础设施访问更宽
Precedence Research2025零信任安全40.0116.39到 2035 年的宽口径零信任市场估算可作为 TAM 上限参考,但口径太宽,不能当作 Teleport SAM
Teleport Infrastructure Identity Survey2026AI 身份需求代理指标衡量企业 AI 项目强度和准备度的调研需求信号,不是直接的市场规模估算

Null 值标记的是用于三角校验或限制分析、但在保留证据集中无法恢复市场规模数字的来源。

[CM009, CM010, CM011, CM012, CM015, CM018]
FM001: 市场规模分层视角

Teleport 处在狭义 PAM 核心与广义 zero-trust 天花板之间;新兴 AI 身份层又在可触达的中间层里抬高紧迫性。

分层边界是基于产品范围和标准映射的分析综合;只有外层市场参考点来自已发布的分析师数字。

[CM013, CM014, CM015, CM017]
FM002: 已发布市场估算区间

已发布市场参考从狭义 PAM 当前价值一路覆盖到广义 zero-trust 远期预测,说明单一 TAM 数字会夸大精确度。

区间端点使用已发布的当前和长期数字,单位为十亿美元;中点值是展示辅助,不是新的有来源市场估算。

[CM009, CM010, CM011, CM012, CM016, CM018]

2.3 买家类型、预算归属和采用路径

Teleport 的买家地图是跨职能的,因为产品把安全、平台和合规工作流压缩到同一个访问层。日常用户通常是平台工程师、SRE 或 DevOps 团队、安全工程师、基础设施管理员,以及数据库或 Kubernetes 运维人员。预算归属取决于采购触发点。安全主导的交易常落在 CISO 组织;平台主导的推广可由工程基础设施团队负责;合规主导的公共部门或受监管企业交易往往会拉入 GRC 相关方,因为 FedRAMP 和 SOC 2 取证与访问控制同样重要。定价也强化了这种共享所有权:Teleport 按月活跃用户和机器 / 工作负载身份收费,因此商业模型随身份采用扩张,而不是绑定一个固定设备部署规模。开发者主导评估仍然重要,因为开源仓库有超过 15,000 颗星,但企业转化似乎在受监管和云原生组织中最强,包括大型金融服务买家。最弱契合点是遗留系统较重的混合环境,买家更看重广泛协议覆盖和更简单迁移,而不是 Teleport 的云原生深度。[CM019, CM020, CM021, CM022, CM023, CM024]

细分市场与买方地图
细分市场买方角色用户付款方预算负责人采用触发点
受监管的云企业CISO 或安全平台负责人平台工程师、安全工程师、数据库 / Kubernetes 管理员安全预算安全组织,与平台团队协作需要用可审计、基于证书的控制替代 VPN 或堡垒机访问
联邦或公共部门承包商合规负责人加安全架构处理受监管工作负载的管理员和运营人员安全与合规项目预算对授权证据负责的项目负责人FedRAMP 证据、FIPS 要求,以及集中式会话审计需求
平台原生的中端 SaaS平台工程负责人SRE、DevOps、开发者工程基础设施预算平台工程希望在不保留长期密钥的情况下统一 SSH、Kubernetes 和数据库访问
AI 原生基础设施团队安全平台负责人或 AI 平台负责人Agent 构建者、MLOps、平台工程师安全与平台共享预算跨职能的安全 / 平台负责人需要把非人类身份、授权和审计分配给 agent 或 MCP 工作流
传统系统负担重的混合企业IT 基础设施或访问管理负责人跨传统与现代混合系统的管理员中央 IT 或安全预算往往共享或存在争夺迁移压力存在,但如果协议覆盖和传统系统支持比云原生深度更关键,采用速度会放慢

买方地图基于 Teleport 定价、合规用例、产品范围和客户画像证据推断可能的预算归属,而非已披露的赢单率数据。

[CM019, CM020, CM021, CM022, CM023, CM024]
FM003: 买方与细分决策地图

安全、平台、合规和 AI 相关方都会参与,但占比随细分市场和触发因素而变。

矩阵单元格是基于产品范围、定价、合规用例、社区信号和竞争对手负面定位综合出的定性权重,不是披露的细分收入组合。

[CM020, CM021, CM022, CM024, CM025, CM026]

2.4 监管、AI、云和安全驱动因素

标准、合规压力、云复杂度和新的 AI 代理风险共同把需求向前拉。NIST SP 800-207 给零信任正式架构定义,CISA 的 Zero Trust Maturity Model 又把该架构落实到五大支柱和三项跨领域能力,为围绕身份的基础设施控制预算提供正当性。当这些抽象框架转化为具体 FedRAMP 和 SOC 2 访问控制要求时,Teleport 受益,尤其因为它记录了 FIPS 140 支持和控制项映射。AI 是更尖锐的近期催化剂。Teleport 2026 年调研称,92% 受访者有近期 AI 计划,79% 正在评估或部署 agentic AI,只有 13% 觉得准备极充分,60% 已发生或怀疑发生 AI 相关事件。另一组 2026 年新闻室数据称,73% 网络安全领导者正在听到企业对 AI 代理安全的提问。与此同时,多云蔓延和云时代向统一控制平面的更广泛迁移也支撑类别。主要采用阻力不是没有需求,而是切换成本:买家仍要拆掉存量方案、重构访问路径,并判断 Teleport 的现代云强项是否足以压过遗留覆盖担忧。[CM027, CM028, CM029, CM030, CM031, CM032]

增长驱动因素与约束
因素方向类型时间影响尽调问题
NIST 和 CISA 零信任框架正向监管 / 标准现在为以身份为中心的访问控制提供持久的架构语言和预算正当性询问多少 pipeline 明确映射到联邦或企业零信任项目
FedRAMP 和 FIPS 访问控制证据正向合规现在提升与受监管买方和公共部门承包商的契合度要求提供受监管行业收入占比,以及交易中复用控制映射的证据
SOC 2 基础设施访问要求正向合规现在把安全和审计利益相关方拉进采购流程询问 SOC 2 驱动的赢单是否带来溢价,还是只是转化更快
AI 项目强度和 AI agent 安全担忧正向市场需求现在至 24 个月将 Teleport 从人类访问扩展到机器和 agent 身份预算要求拆分核心访问交易与 AI 身份附加项的 pipeline
多云与开放控制平面复杂度正向技术12 至 36 个月支撑统一访问平面,而不是一堆点状凭证询问 Teleport 在单云与多云环境中的赢单差异
基于用量的 MAU 和 MWI 定价混合商业现在可降低进入门槛,但预算增长取决于身份扩张和定价透明度要求按用户身份与机器身份拆分 cohort 扩张数据
VPN、PAM、IAM 和审计工作流带来的 incumbent 切换成本负向运营现在拉长销售周期,并抬高价值证明门槛询问中位部署时间、迁移服务使用情况和竞争替换数据
传统系统覆盖批评负向竞争12 至 24 个月缩窄在异构环境中的适配面,并支撑竞争对手的反向叙事要求按环境复杂度提供赢亏数据,以及协议覆盖路线图

表格同时列出正负因素,因为市场采用取决于预算生成和迁移摩擦;时间判断是方向性,不是公司发布的预测。

[CM027, CM028, CM029, CM030, CM031, CM032]
FM004: 从触发到规模化的典型采用路径

多数 Teleport 评估似乎从风险或合规触发开始,先进入范围明确的试点,再推进更广的身份扩张。

采用顺序是从合规定位、定价结构、客户证明和竞争约束中综合出的模式;它不是已披露的漏斗转化图。

[CM028, CM030, CM032, CM034, CM035, CM036]

2.5 采用障碍、尽调缺口和矛盾证据

市场分析最大约束不是需求弱,而是精度弱。公开来源无法隔离 Teleport 可寻址支出中有多少来自受监管企业、公共部门承包商、AI 原生团队或既有客户扩张。最近一次已披露融资事件仍是 2022 年 5 月以 $1.1 billion 估值完成的 Series C,因此外界正用一个过时资本市场锚点解读快速变化的类别。已发布市场估算方向上有用,但方法论并不一致,因为 PAM 和零信任报告使用不同范围定义,而且可访问的 Fortune Business Insights PAM URL 返回了无关农业内容,而不是可用市场页面。Teleport 自有材料在产品广度和合规对齐上很丰富,但不披露公开赢单率、部署周期、流失率、ACV,或自托管与云交易的拆分。因此,对需求方向可以有合理信心;但在管理层提供分部收入和转化证据前,对可变现份额和高效捕获的信心要低得多。[CM037, CM038, CM039, CM040, CM041, CM042]

2.6 图表

Chapter 03

03竞争格局

3.1 格局

Teleport 的竞争集合比传统密码库 PAM 更宽。最接近的阵营包括 CyberArk、BeyondTrust、Delinea 等老牌套件;StrongDM、HashiCorp Boundary 等现代基础设施访问挑战者;以及来自 Okta 的相邻竞争,Okta 可以把既有员工身份关系延伸到特权服务器访问。Bessemer 对基础设施访问的定义解释了为什么买家不会只在一个框里评估 Teleport:实际任务横跨服务器、集群、数据库,以及越来越多由 AI 操作的基础设施工作流,包含连接、认证、授权和审计。独立对比与评论网站也强化了这份活跃买家候选名单。这个市场因此不是赢家通吃的功能竞赛,而是广义企业既有厂商、云原生专家和身份平台捆绑方之间的分层竞争;Teleport 在买家想要一个现代控制平面,而不是遗留密码库加点状代理时最强。[CP015, CP016, CP017, CP041, CP042]

竞争对手画像表
竞争对手类别规模目标细分市场差异化关键限制
Teleport基础设施身份 / 现代 PAM私营;另有披露显示 GitHub star 超过 15,000,客户超过 600 家云原生企业、受监管基础设施团队、平台工程统一 CA + 代理架构,覆盖 SSH、Kubernetes、数据库、RDP、工作负载和 AI agent传统系统负担重的环境可能更偏好更宽的协议覆盖和更简单的迁移叙事
CyberArk传统企业 PAM$20.63B 市值;$1.30B TTM 收入大型混合企业和受监管安全团队统一 PAM 平台、零长期特权定位、强合规与审计姿态较重的传统企业销售动作,可能不如 Teleport 贴近开发者
BeyondTrust传统 PAM / 特权远程访问大型 incumbent 厂商;公开语料更强调 Gartner 地位,而非当前财务数据企业安全、第三方 / 供应商访问、混合 IT最小特权叙事、凭证注入、VPN 替代、供应商特权访问保留证据集中较少看到 Teleport 式统一云原生控制平面的证据
Delinea传统 PAM / 密钥库私营厂商;保留证据集未公开量化规模宽口径企业 PAM 买方,尤其是密钥库和轮换用例快速部署表述、发现、密码轮换、会话监控、AI 会话分析私营财务可见度薄,架构仍更接近经典密钥管理
StrongDM云原生挑战者 / 访问代理私营厂商,现归入 Delinea;直接攻击式营销可见需要现代与传统访问覆盖的混合企业Identity Firewall 叙事、持续授权、完整会话可见性、更宽的协议 / 认证方法覆盖保留证据高度依赖竞争对手叙事;公开定价和规模信息稀少
HashiCorp Boundary感知身份的访问代理HashiCorp 支持的产品,拥有大型相邻社区已使用 HashiCorp 身份和基础设施栈的平台团队SSO 加上通过 Vault 提供的动态凭证,用于最小特权访问在数据库、合规打包和 AI 身份上的产品面比 Teleport 窄
OktaIAM 相邻的特权访问$20.65B 市值;$2.91B TTM 收入现有 Okta 身份客户向服务器访问延伸从员工身份交叉销售、消除静态凭证、SSH/RDP 会话录制面向 Kubernetes、数据库和更广访问代理的基础设施深度比 Teleport 窄

覆盖范围有意不完整:它聚焦截至 2026 年 6 月,最可能出现在 Teleport 买方 PAM 和基础设施身份评估中的直接及相邻厂商,而非每一个长尾管理员访问或云原生点工具。

[CP015, CP017, CP041, CP042]
FP001: 竞争定位地图

这个序数地图展示哪些厂商既具备现代 zero-credential 姿态,又拥有最强企业分发杠杆。

轴向分数是有证据支撑的序数判断,来自上市公司规模、安装基数线索、架构定位和产品页主张;它们不是市场份额测算。

[CP004, CP005, CP010, CP012, CP014, CP021]

3.2 老牌 PAM

CyberArk、BeyondTrust 和 Delinea 仍定义市场中的既有厂商一端,因为它们把特权访问卖给广义企业和混合环境,而不只是卖给绿地云团队。CyberArk 官方定位强调单一 PAM 平台、降低网络风险、审计与合规结果,以及跨混合环境的零常驻特权访问。BeyondTrust 讲述类似故事,围绕最小权限、凭证注入和特权远程访问,可消除对 VPN 和已知凭证的需求。Delinea 的 Secret Server 仍锚定凭证库、发现、密码轮换和会话监控,并在其上叠加新的 AI 驱动会话分析表述。这些供应商都没有把自己营销成 Teleport 式开放基础设施身份平台,但重叠已经足够实质,Teleport 必须靠现代环境中的架构简洁性取胜,而不能假设既有厂商被困在旧密码库工作流里。[CP004, CP005, CP006, CP007, CP024, CP025]

3.3 云原生挑战者

StrongDM、HashiCorp Boundary 和 Okta 重要,是因为它们从三个不同角度攻击 Teleport。StrongDM 在现代基础设施访问上正面竞争,但它把自己包装成更适合混合环境:支持更多遗留系统和认证方法,也不要求 Teleport 那套精确的纯证书运行模型。Boundary 范围更窄,但技术上重要:身份感知代理加 Vault 集成,让它在已标准化 HashiCorp 工具的团队中有可信度。Okta 从 IAM 相邻路线切入市场,把 SSO、临时服务器访问和会话录制延伸到 Linux 与 Windows 基础设施,面向已经信任 Okta 作为身份控制平面的客户。这些挑战者共同说明,Teleport 不能只靠云原生品牌;每个对手都带来不同分发机制,从平台相邻、直接攻击广告,到捆绑式交叉销售。[CP008, CP009, CP010, CP012, CP013, CP014]

定价 / 打包对比
厂商定价模型计费单位关键能力定价透明度明显缺口
Teleport自助标价加企业打包月活用户和机器 / 工作负载身份统一访问、审计、机器身份、身份安全、agentic 身份附加项相对同行较高实际折扣、企业最低消费和附加率未公开披露
CyberArk销售主导的企业合同保留证据集未公开自定义报价 / 合同范围统一 PAM、零长期特权、审计 / 合规、混合访问缺少公开标价;难以与 Teleport 做 TCO 对比
BeyondTrust销售主导的企业合同保留证据集未公开自定义报价 / 部署范围最小特权、PRA、凭证注入、供应商访问保留语料未显示公开单位定价或部署最低要求
Delinea销售主导的企业合同保留证据集未公开自定义报价 / vault 或模块范围密钥库、发现、轮换、会话监控、AI 会话分析私营定价和打包细节仍然稀少
StrongDMDelinea 收购后的销售主导打包保留证据集未公开自定义报价 / 用户-资源范围Identity Firewall、持续授权、会话可见性、宽协议覆盖对比型信息很多,但可比标价细节很少
Okta平台捆绑或附加销售动作保留证据集未公开自定义报价 / 席位范围特权服务器访问、零长期特权、SSH/RDP 录制、SSO 延伸公开产品页面看不清可能的捆绑经济性
HashiCorp Boundary开源 / 企业混合打包开源加商业条款,保留证据集未公开感知身份代理、SSO、通过 Vault 提供动态凭证、会话管理中低公开保留来源对架构的解释比商业条款更清楚

该表比较的是打包姿态和透明度,而不是实际价格领先性,因为保留证据集中多数竞争对手没有发布可一一对照的公开费率。

[CP027, CP028, CP029, CP038]

3.4 Teleport 差异化

Teleport 最清晰的差异化是结构性的,不是表面的。它的 Auth Service 充当用户、机器和资源的证书颁发机构,Proxy Service 则在 SSH、Kubernetes、数据库、RDP、Web 应用和机器身份之间代理访问,不依赖长期共享凭证。Teleport 因此能销售一种访问平面:认证、授权和审计统一在一起,而不是由密码库、跳板机、VPN 和分散策略引擎拼接。公司也在向外扩张:近期版本强调 IdP 攻陷缓解、更宽的身份安全层、机器和工作负载身份,以及面向 AI 系统的新 Agentic Identity Framework。这些动作扩大了 Teleport 想拥有的类别。代价是,2024 年社区许可证变更后,Teleport 旧有开源发现优势不再那么干净,因此架构一致性比单纯社区好感更重要。[CP001, CP002, CP003, CP018, CP019, CP020]

功能 / 能力矩阵
能力TeleportCyberArkBeyondTrustDelineaStrongDMOktaHashiCorp Boundary
基于证书的认证是——覆盖用户、主机和工作负载的核心架构部分——支持临时模型,但官方叙事是更宽的 PAM部分——最小特权和 PRA,但不是 CA 优先叙事部分——保留证据集显示其先从密钥库出发,不是 CA 优先部分——在多种认证方法中支持基于证书的认证部分——为服务器访问移除静态 SSH key / 密码部分——感知身份的代理,配合外部认证和动态凭证
临时特权是——短期证书和即时访问是——零长期特权定位是——特权远程访问和最小特权部分——会话控制和轮换,但 ZSP 叙事不够明确是——持续策略执行,无长期特权是——服务器零长期特权是——通过 Vault 动态凭证实现最小特权访问
会话录制是——命令、视频和审计录制是——PAM 审计 / 合规核心是——安全远程访问和会话监控是——内置会话监控是——完整会话可见性是——通过 SSH 和 RDP 录制特权访问是——录制并管理特权会话
Kubernetes 支持是——一等访问路径保留证据集未知保留证据集未知保留证据集未知保留证据集未知保留证据集没有公开证据保留证据集没有公开证据
数据库访问是——SQL 和 NoSQL 通过 Teleport 代理接入部分——强调多云 / 混合 PAM,保留证据集未突出数据库细节保留证据集未知保留证据集未知保留证据集未知保留证据集没有公开证据保留证据集没有公开证据
AI / agentic 身份是——Agentic Identity Framework 和 Beams保留证据集没有公开证据保留证据集没有公开证据部分——AI 驱动的会话分析表述是——首页展示 agentic AI 身份信息保留证据集没有公开证据保留证据集没有公开证据
开源分发部分——源码可用,但编译产物对较大公司有商业限制保留证据集没有公开证据部分——有开源渊源,文档导向明显
云原生架构是——面向现代基础设施的统一 CA / 代理平面部分——强调混合和多云 PAM部分——强调远程访问和供应商 PAM部分——强调密钥库和自动化是——现代访问控制平面和自适应控制部分——把身份云延伸到服务器是——面向云基础设施的感知身份代理

单元格只限于保留来源能证明的能力;未知表示已审阅语料不足以支撑更强判断,并不代表该厂商没有该功能。

[CP001, CP004, CP006, CP007, CP009, CP012]
FP002: 功能广度 / 能力地图

Teleport 在现代基础设施资源类型广度上领先;incumbent 和邻近玩家则在企业分发或特定特权访问工作流上最强。

矩阵值仅反映留存来源直接支持的能力;部分或否往往意味着证据更窄或不够明确,而非确定缺少功能。

[CP001, CP004, CP006, CP009, CP013, CP021]

3.5 护城河风险

Teleport 确实有切换成本潜力,但护城河有条件,并非不可攻破。一旦客户把审计日志、证书签发、访问工作流和合规证据标准化到一个平台,替换就会带来运营痛感。这种机制也利好既有厂商,所以即便市场现代化,CyberArk 和 BeyondTrust 仍能防守账户。Teleport 还面临三项直接风险。第一,CyberArk、Okta 等大型上市可比公司拥有大得多的资产负债表和装机基础,有空间捆绑或折扣。第二,StrongDM 围绕遗留契合度和 root-agent 架构的负面信息,给混合环境买家提供了具体反方论点。第三,公开客户评论证据支持多于敌意,但保留下来的样本仍缺少大规模上线痛点,投资人无法获得决定性证据来证明 Teleport 部署模型能在保守企业中无摩擦扩张。[CP023, CP024, CP025, CP029, CP031, CP032]

护城河耐久度 / 竞争风险登记
护城河主张支撑证据威胁严重性缓解 / 尽调问题
统一基础设施身份平面Teleport CA + 代理架构把多类资源纳入同一套审计模型CyberArk、BeyondTrust 和 Okta 继续增加零长期特权和会话能力要求按资源类型提供赢亏数据,并证明统一架构能缩短部署或降低管理员负担
开发者主导发现与开源拉动公共 repo 规模和早期社区根基带来认知社区许可证限制削弱自下而上的好感,也让 Boundary 这类开放血统更有吸引力索取社区漏斗、自助转化,以及 v16 之后贡献或采用趋势
贴合现代云原生Teleport 和 StrongDM 都围绕现代基础设施工作流优化在混合环境里,StrongDM 会拿传统覆盖面和 root-agent 架构攻击 Teleport索取协议路线图、部署加固证据,以及传统负载较重客户的赢亏拆分
合规与信任姿态安全审计发布和身份安全文档支撑企业信任既有厂商已经掌握大型合规关系,还能捆绑相邻控制项索取受监管行业的企业客户访谈,以及控制项层面的替换案例
AI 与机器身份扩张Teleport 现在主推 Agentic Identity Framework、Beams 和机器 / 工作负载身份竞争对手可能很快补上 agentic 功能,而当前市场需求仍在形成索取 AI 与非人类身份模块的 attach rate、pipeline 和商业化证据
推出后的切换成本累积一旦部署,策略、审计、证书签发和访问工作流会嵌入组织流程在 Teleport 站稳前,大型上市可比公司拥有更强分销和折扣能力索取中位 time-to-value、续约或扩张数据,以及相对 CyberArk 或 Okta 的竞争替换证据

风险登记表聚焦护城河耐久性,而不是泛化产品风险;严重性反映竞争压力,并非量化概率模型。

[CP023, CP024, CP025, CP035, CP036, CP037]
FP003: 护城河 / 就绪度 KPI

一组紧凑指标,显示 Teleport 哪里最强,以及大型对手仍在哪里占优。

[CP018, CP021, CP022, CP035, CP036, CP037]
Chapter 04

04财务

4.1 商业模型、收入结构和客户基础

Teleport 的商业模型按用量计费且多产品。定价页披露三项计费指标:Zero Trust Access 和 Identity Governance 模块的 Monthly Active Users(MAU),Machine and Workload Identity 模块的 Machine / Workload Identities(MWI),以及 Identity Security 的 Teleport Protected Resources(TPR)。未公开标价;所有定价都需要与销售团队商业接洽。Enterprise Edition 支持云、本地部署(标准和 FIPS)、多区域高可用和混合部署模式。Beams AI 代理运行时产品于 2026 年 6 月进入公开测试版,尚未公开定价。 Community Edition 免费层——自 2024 年 6 月许可证变更后,面向员工少于 100 人且年收入低于 $10M 的公司——有意把客户增长转化为商业升级触发器。客户案例显示企业部署广度:GoTo(印度尼西亚最大数字平台,管理复杂基础设施上的多云访问)、Exness(安全要求严格的受监管全球交易公司)、Gladly(有 SOC 2 合规要求的 SaaS 平台)和 ExtraHop(聚焦安全的云网络检测公司)。每个案例代表不同垂直行业和合规姿态。招聘页面称,截至 2025 年 10 月,全球客户超过 600 家。 公开材料中可见的收入驱动因素包括:(1)随着基础设施规模扩大,MAU、MWI 和 TPR 指标增长,不必重新谈判即可带来用量扩张;(2)公司跨过 100 名员工或 $10M AR 门槛后,从社区版转向企业版;(3)客户采用 Identity Governance、Identity Security 和 AI 代理身份模块,带来多模块加购;(4)通过 Beams 和 Machine Workload Identity 模块切入 AI 代理市场机会。会话录制、数据库访问和 MCP 服务器访问也在合规敏感行业创造加购。[CI001, CI014, CI015, CI016, CI033, CI034]

收入流表
收入流机制计费指标当前状态收入质量尽调要求
Zero Trust Access(人类)按用量计费 SaaS —— 人类用户和受保护资源MAU 和 TPR已上线 —— Enterprise Edition;Community 对小公司免费模型清晰度好;未披露 ARPU提供混合 MAU ARPU 和同比扩张率
机器与工作负载身份按用量计费 SaaS —— 非人类和 AI agent 身份MWI已上线 —— 独立模块;AI agent 需求在增长增长潜力高;AI agent 浪潮拉动 MWI 需求提供 MWI 数量和净新增 MWI 增长率
Identity Governance按用量计费 SaaS —— 人类访问上的治理层MAU已上线 —— 向现有人类访问客户 upsell有 upsell 潜力;未披露 attach rate 或 ASP 提升提供 cross-sell attach rate 和收入贡献
Identity Security按用量计费 SaaS —— 影子访问发现与异常TPR已上线 —— 向现有客户 upsell合规驱动需求;单独定价层级提供合规驱动模块的收入占比
Beams AI Agent Runtimes新兴 —— AI agent 基础设施运行时未知(beta)2026 年 6 月公开 beta;尚未定价尚未验证;现在做收入建模太早确认定价和已签署的 beta 承诺
Community-to-Enterprise 转化100 名员工和 $10M AR 的许可证门槛转化事件自 Teleport 16(2024 年 6 月)起生效可能是新增 ARR 驱动因素;无转化率数据提供月度 cohort 转化数据

所有收入流均由公开定价页、文档和博客文章推断。公司未披露按收入流或模块划分的官方 ARR。Beams 产品仍处 beta,未披露定价。

[CI001, CI014, CI015, CI016, CI033]
定价与商业化对比
维度Teleport(私有)CyberArk CYBR(上市)Okta OKTA(上市)
定价模型按用量计费(MAU / MWI / TPR);无公开标价订阅 + 用量;按用户和按资源订阅;按用户和按服务
企业定价披露仅联系销售;无标价部分公开;合同金额不公开部分公开;企业层级不公开
社区 / 免费层是 —— 公司 <100 名员工、<$10M AR无显著免费层无显著免费层
2024 年收入(USD)~$49M(GetLatka 估算;未确认)$1.00B(SEC 文件披露)$2.61B(SEC 文件披露)
市值 / 估值(USD)$1.1B(2022 年 5 月标记;已滞后约 4 年)$20.63B(2026 年 6 月)$20.65B(2026 年 6 月)
隐含收入倍数~22x ARR(按 GetLatka 估算)~15.9x 收入(2026 年 6 月)~7.1x 收入(2026 年 6 月)

Teleport 数据仅来自公司披露或 GetLatka 估算。CyberArk 和 Okta 数据来自 companiesmarketcap.com(来源为公开 SEC 文件)。Teleport 估值采用 2022 年 Series C 标记。

[CI002, CI009, CI010, CI015]
FI001: 收入模型桥

Teleport 通过社区到企业的漏斗和多模块追加销售,把基础设施需求转成按用量计费的收入,但部署规模与留存毛利率之间的关系完全不透明。

仅为定性桥接;没有公开定价、ARPU 或毛利率数据。$49M ARR 是 GetLatka 的未经确认第三方估计。

[CI001, CI016, CI033, CI039]

4.2 收入和 ARR 估算——完全未经验证的图景

Teleport 不披露任何财务数据。唯一公开 ARR 估算来自第三方数据聚合商 GetLatka,后者报告 Teleport 在 2024 年 12 月达到 $49M 收入。GetLatka 还估算截至 2025 年底员工数约 246 人。这些数字未得到 Teleport、任何投资人或任何独立来源确认。GetLatka 自己的融资摘要显示 2 轮共 $140M,与公司披露的 3 轮 $165M 不一致,进一步削弱了对该数据集完整性的信心。 从融资公告披露的 ARR 增长率倒推:Series C 博客(2022 年 5 月)报告总 ARR 同比增长 2.8x、净新增 ARR 同比增长 4.5x;Series B 博客(2021 年)报告总 ARR 较 2020 年 Q2 同比增长 2.5x、净新增 ARR 同比增长 5x。如果这些增长率正确,且公司按 Series B 时期披露所称正走向 2021 年收入三倍增长,那么 Series C 交割时隐含 ARR 约为 $17–20M。从该水平增长到 2024 年 $49M,意味着融资后 CAGR 约 22%,较 Series C 前轨迹明显减速。没有管理层数据无法确认这一点,但它与 2022–2024 年更广泛 SaaS 市场放缓方向一致。 GTM 效率指标完全缺失。公开资料没有销售周期长度、CAC、回本期或 quota 达成数据。GTM 有效性的最佳代理是客户数轨迹(2025 年提到 600+)和具名客户标识质量,但没有进一步数据,二者都无法转化为单客户收入或扩张率。[CI002, CI003, CI005, CI006, CI012, CI013]

单位经济与 ARR 分析表
指标数值日期 / 期间置信度来源缺口说明
ARR(估算)~$49M2024-12GetLatka(第三方;未确认)未经公司或独立来源验证
Series B 时 ARR 增长2.5x YoY2021Teleport Series B 博客(官方)未说明绝对 ARR 美元金额
Series C 时 ARR 增长2.8x YoY2022-05Teleport Series C 博客(官方)+ BVP 投资博客未说明绝对 ARR 美元金额
Series C 交割时估算 ARR(推导)~$17–20M(推断)2022-05由 GetLatka $49M 和隐含 CAGR 推断未确认;计算假设 2022–2024 年持平
Series C 后隐含 CAGR~22% / 年(推断)2022–2024由估算 ARR 路径推导较 Series C 前增长轨迹减速
人均 ARR(估算)~$199K2024/2025由 GetLatka ARR 和员工数估算推导双重估算;仅作方向参考
ARR / 已融资本比率~0.30x2024-12由 GetLatka ARR / 已披露融资 $165M 推导低于高效 SaaS 0.5–1.0x 基准
毛利率未披露unknown无公开来源阻断性缺口;没有披露无法承销
净收入留存(NRR)未披露unknown无公开来源估值关键项;扩张率未知

所有财务指标要么是公司引用的增长率(仅百分比),要么是 GetLatka 第三方估算。任何期间都没有审计或管理层提供的财务数据。公开来源完全看不到 NRR 和毛利率。

[CI002, CI003, CI004, CI005, CI006, CI024]
FI002: 单位经济桥

公开证据支持可信的基础设施需求信号和按用量扩张逻辑,但在量化 CAC、NRR 和毛利率之前就完全断裂。

定性桥接使用公开需求信号和客户案例研究证据。ARR 和单位经济数字不可得。

[CI002, CI004, CI005, CI020, CI034, CI035]

4.3 估值和上市可比公司倍数

Teleport 唯一外部估值数据点是 2022 年 5 月 Series C 的 $1.1B 标记。截至 2026 年 6 月,该标记已有约四年,且未更新。按 GetLatka 估算的 $49M ARR,隐含收入倍数约 22.4x——显著高于 2026 年中可比上市网络安全公司的交易水平。 CyberArk Software(CYBR)是特权访问管理领域最接近的上市可比公司,截至 2026 年 6 月市值约 $20.63B,TTM 收入约 $1.30B,隐含收入倍数约 15.9x。CyberArk 收入从 2022 年约 $590M 增至 2025 年 TTM $1.30B,约三年增长 2.2x。Okta(OKTA)是最接近的身份与访问管理可比公司,截至 2026 年 6 月市值约 $20.65B,TTM 收入约 $2.91B,隐含约 7.1x。Okta 收入同期从 $1.85B 增至 $2.91B(增长 1.6x)。两家公司收入规模都远高于 Teleport 的估算 ARR。 按这两家上市同行收入倍数中点(约 11x)计算,$49M ARR 对应 Teleport 企业价值约 $540M,远低于 $1.1B 标记。即使按 CyberArk 15.9x 倍数,隐含价值也约 $779M。2022 年 5 月 Series C 交割时,CyberArk 自身以约 $5.27B 市值对应 $590M 收入(约 9x),Okta 以约 $10.94B 对应 $1.85B 收入(约 6x),说明 Teleport 22x+ 的隐含倍数在发行时已经约为可比区间的 2x。2022 年后市场调整之下,2022 年标记中隐含的私募市场溢价可能进一步侵蚀。[CI007, CI008, CI009, CI010, CI011, CI026]

资本充足性与投资人结构表
轮次日期金额(USD M)领投方估值(USD M)含义
Series A2019(约)25Kleiner Perkins(Bucky Moore)未说明公司称接近盈利;NASDAQ、Splunk、Samsung 被列为客户
Series B202130S28 Capital 和 Kleiner Perkins未说明ARR 同比 2.5x;Series B 博客称 2021 年收入有望翻三倍
Series C2022-05110Bessemer Venture Partners 与 Insight Venture Partners1100ARR 同比 2.8x;最后一次已知外部估值;截至运行日已滞后约 4 年
Series C 后无证据Unknown未识别Unknown2022 年 5 月后无公开融资事件;股权结构不公开

所有轮次数据来自 Teleport 官方博客文章及 Bessemer / Kleiner Perkins 投资人发布内容。GetLatka 显示 2 轮共 $140M,缺失 Series A;与已披露 $165M 不一致,降低了对 GetLatka 数据完整性的信心。EDGAR 中未找到任何轮次的 SEC Form D。

[CI005, CI006, CI013, CI022, CI023, CI030]
FI003: 财务估计区间——估值情景

将 2026 年中公开同业倍数套用到 GetLatka 的 $49M ARR 估计后,多数情景下得到的估值区间都低于 2022 年 5 月的 $1.1B 标记。

所有情景都将 companiesmarketcap.com 的 2026 年 6 月公开市场收入倍数,套用到 GetLatka 未确认的 $49M ARR 估计。这些是说明性敏感性区间,不是正式估值。$75M ARR 情景是假设,未获得任何公开来源支持。

[CI007, CI008, CI009, CI010, CI011, CI037]

4.4 成本结构、资本充足性和财务结论

Teleport 的成本结构在公开材料中完全不透明。没有 COGS 拆分、毛利率、基础设施成本或人员费用数据。最佳参照是上市网络安全 SaaS 同行,基础设施导向产品的毛利率通常在 65–75%。如果 Teleport 毛利率处于该区间,$49M ARR 可产生 $32–37M 毛利润——足以作为基础,但仍必须支撑持续产品投入、G&A 和销售成本,而这些成本没有披露。 资本充足性同样不透明。公司已在三轮披露融资中募资 $165M,最近一轮是 2022 年 5 月 $110M Series C。此后未公开确认新融资。按 Teleport 阶段公司的行业典型现金消耗率,Series C 资金可支撑三到五年运营,具体取决于烧钱纪律——这说明公司可能不急需新资本,但没有真实资产负债表数据,这完全是推测。未披露债务、信贷额度或项目融资。 财务结论是混合的。需求信号真实:600+ 企业客户、受监管行业客户标识和 Fortune Cyber 60 认可,都说明公司有活跃 GTM。收入模型也适合先落地再扩张。不过,承销案例被基本不透明性卡住:没有经验证 ARR、没有毛利率、没有 NRR、没有烧钱率、没有当前估值。2022 年标记隐含的倍数在当前上市市场可比公司面前难以辩护。任何接近 $1.1B 标记的投资,都需要更新的 409A 或数据室披露,才能解决核心估值问题。[CI019, CI020, CI021, CI022, CI023, CI024]

公开财务缺口表
缺口缺失内容重要性严重性尽调路径
收入 / ARR(实际)管理层披露的 ARR,并按模块和 cohort 拆分GetLatka $49M 未确认;无法建立收入模型阻断索取包含 ARR bridge 和 cohort 分析的财务数据室
毛利率COGS 拆分 —— 基础设施托管、SRE 支持成本毛利率决定真实单位经济和估值底线阻断向 CFO 索取包含 COGS 的 P&L 和 SaaS Metrics 快照
净收入留存(NRR)各 cohort 按模块拆分的扩张减流失率NRR 超过 120% 才能支撑溢价倍数;基线未知阻断索取回溯到 2021 年的月度 cohort 扩张和流失
烧钱速度与 runway最近季度末月度现金消耗和现金余额不知道公司何时需要资本,就无法评估财务风险阻断向 CFO 索取现金头寸和 12 个月现金预测
GTM 效率指标CAC 回收期、quota attainment 和销售周期长度没有 GTM 效率数据,无法承销销售可扩展性重大索取 SaaS Metrics deck 或等效管理层材料

所有缺口都是私营公司标准数据室请求。缺少这些数据不代表经营承压——私营公司通常如此。若要做有意义的股权投资或二级交易,公司必须在尽调中披露这些数据。

[CI012, CI013, CI025, CI030]
FI004: 财务可观察性矩阵

从资本、收入、成本和竞争定位四个维度评估 Teleport 的财务透明度;由于其私营公司属性,多数单元格评级为低或未知。

矩阵评估是基于运行日期公开证据做出的定性判断。管理层 data room 中的真实财务数据会实质性改变这一评估。

[CI009, CI010, CI012, CI025, CI026, CI027]

4.5 图表

Chapter 05

05产品与技术

5.1 产品定义和模块地图

Teleport 是证书颁发机构(CA)和身份感知访问代理,支持 SSH、RDP、HTTPS、Kubernetes API,以及多种 SQL 和 NoSQL 数据库协议。产品以单一 Go 二进制文件分发,把认证、授权、审计和隧道放在一个可部署单元里。Teleport 为主机和用户运行内部 Certificate Authorities;每个身份——人、机器或 AI——获得短期证书,而非长期凭证,从架构层面消除密钥蔓延。 产品套件现在覆盖五个品牌化产品支柱:Zero Trust Access(SSH、Kubernetes、数据库、RDP、Web 应用)、Machine & Workload Identity(非人服务凭证)、Identity Governance、Identity Security(访问分析和威胁检测),以及 Agentic Identity Framework(AI 代理身份 + Beams 运行时)。功能矩阵区分 Enterprise Cloud、Enterprise Self-Hosted 和 Community Edition,Beams 可信运行时仅限 Enterprise Cloud。历史上每四个月发布一个主要版本;版本 18(当前)于 2025 年 7 月到来,版本 19.0 已规划。2024 年 6 月社区许可证变更,限制员工超过 100 人或 AR 超过 $10 M 的公司使用编译二进制文件,这一变化对生态影响持久。[CE001, CE002, CE003, CE004, CE005, CE006]

产品模块 / 资产矩阵
模块 / 产品主要用户状态 / 成熟度差异化尽调缺口
Zero Trust Access — SSH工程师 / 管理员GA,已在大型企业生产环境使用仅证书认证、无 SSH key;按会话审计日志相比 StrongDM,传统协议支持存在缺口
Zero Trust Access — Kubernetes平台 / DevOps 工程师GAkubectl 证书注入;按 pod RBAC;kubectl exec 会话录制Agent 在节点上以 root 运行 —— 增加攻击面
Zero Trust Access — DatabasesDBA / 开发者GA;PostgreSQL、MySQL、MongoDB、CockroachDB 等协议级访问控制,无需改客户端配置各版本完整 DB 协议覆盖清单未公开列举
零信任访问 — Windows / RDPIT 管理员 / 工程师GA;通过 Teleport Web UI 的无 agent RDP无需单独 RDP 客户端;屏幕级会话录制PeerSpot 用户指出剪贴板访问是安全缺口
零信任访问 — Web 应用工程师 / 内部用户GA基于身份访问和审计事件的 HTTPS 代理未公开详述各身份提供商的 SSO 深度
零信任访问 — MCP 服务器AI 开发者 / 平台团队GA(Community 和 Enterprise)一等 MCP 纳管;按工具审计事件运营成熟度和生产规模未验证
Machine & Workload Identity服务 / CI-CD / 工作负载GAtbot 签发短期证书;无常驻服务密钥SPIFFE/SVID 互操作深度未被外部完整记录
Identity Governance安全 / 合规团队GA(Enterprise)访问列表、嵌套组、JIT 访问请求、ChatOps 集成Nested Access Lists 在 v17 引入 —— 成熟度仍新
Identity SecurityCISO / 安全分析师GA(Enterprise)Crown Jewels 监控、SQL 编辑器访问查询、异常告警未披露 AI 告警模型准确率和误报率
Beams — Agentic RuntimeAI 开发者 / 平台团队公开 beta(仅 Enterprise Cloud),2026 年 6 月Firecracker VM 隔离、LLM Proxy、Delegated Identity仅 beta;GA 时间线未披露;仅 Cloud 限制自托管部署

成熟度评级基于 Teleport 官方功能矩阵和发布说明。Community Edition 缺口在适用处标注。

[CE001, CE002, CE003, CE004, CE005, CE006]
FE001: Teleport Infrastructure Identity Platform——产品架构栈

五个产品支柱叠在统一的 Auth 和 Proxy 控制平面之上。

[CE001, CE002, CE003, CE004, CE005, CE006]

5.2 架构和运行模型

Teleport 控制平面由两项标准服务组成:Auth Service(集群 CA、配置存储和审计日志收集器)与 Proxy Service(公网入口和反向隧道枢纽)。两项服务彼此之间无状态,通过 gRPC 通信,并可水平扩展以实现高可用。在 Teleport Cloud 上,两项服务均由 Teleport Inc. 全托管;在 Enterprise Self-Hosted 中,客户在自有基础设施上运行它们。 资源接入有三条路径:Teleport Agents(以守护进程部署在目标机器上,并反向隧道回 Proxy)、部分协议的无代理模式,以及 Machine & Workload Identity tokens(基于 tbot 的工作负载短期证书)。认证流程跨协议一致:用户(或机器)运行 tsh login,获得客户端证书,随后 SSH、Kubernetes、数据库、RDP 和 MCP 代理接受该证书,无需重新认证。会话录制可在节点或代理层配置,可同步或异步,并捕获 SSH 与 Kubernetes 的完整 PTY 输出、桌面会话屏幕内容,以及数据库会话查询流。 StrongDM 的竞争分析指出,Teleport agents 在目标服务器上以 root 身份运行,增加额外攻击面;该公司还批评其遗留协议支持有限、云可靠性间歇性不足。PeerSpot 用户也独立指出,RBAC 复杂、初始设置负担重,以及 RDP 会话中的剪贴板访问安全,是实际摩擦点。[CE010, CE011, CE012, CE013, CE014, CE015]

技术 / 运行架构表
层 / 组件角色依赖风险
Auth Service内部 CA;配置存储;审计日志收集器需要持久化后端(etcd、DynamoDB、Postgres 或 Teleport Cloud 存储)未配置 HA 时会成为单点故障;密钥轮换政策必须实际演练
Proxy Service面向公网入口;反向隧道中枢;Web UI 服务器通过 gRPC 连接 Auth Service;所有协议经 443 端口做 TLS 路由StrongDM 称其云可靠性有问题,更新期间停机最长可达 6 小时
Teleport Agent运行在目标节点上;通过反向隧道把流量送回 Proxy目标 OS(Linux/Windows);多数模式需要 root 级访问以 root 运行 Agent 会放大每台接入主机的攻击面
tbot(MWI agent)为工作负载签发并续期短期证书Teleport Auth Service;兼容 SPIFFE 的证书格式如果进程隔离较弱,tbot 凭证可能暴露
Certificate Authorities签发主机和用户证书;支撑零信任集群成员资格Hardware Security Module 可选;FIPS 使用 BoringCryptoCA 一旦被攻破,整个集群都会失效;需要自动化轮换
Session Recording Store捕获 PTY、屏幕、查询流;审计记录防篡改S3 兼容对象存储或 Teleport Cloud 存储用户可尝试用编码隐藏 PTY 命令(文档已披露的风险)
Identity Security Analytics用 SQL 编辑器查询访问图;Crown Jewels 监控;AI 异常检测摄取 Okta、AWS、GitHub 日志,以及 Teleport 审计流AI 告警准确性尚无独立验证
Beams Runtime(beta)每个 agent 会话一个 Firecracker microVM;LLM Proxy;Delegated IdentityOpenAI / Anthropic 推理端点;Teleport 身份层beta;仅限 Enterprise Cloud;GA 时间未披露

架构基于 Teleport 官方文档和功能矩阵;StrongDM 的说法来自竞争对手,可能带有偏向。

[CE010, CE011, CE014, CE015, CE016, CE017]
FE002: Teleport 认证流程

用户或机器如何认证并获得受保护资源的访问权。

[CE010, CE011, CE012, CE013]

5.3 Agentic Identity 与 Machine & Workload Identity

Teleport Machine & Workload Identity(MWI)用与人类访问相同的证书模型,为非人服务账户提供身份。服务通过 tbot 认证,接收短期 X.509 或 SSH 证书,再用这些证书授权访问数据库、Kubernetes 集群、内部 API 和 MCP 服务器——全部记录到同一条审计轨迹里。这为人和机器创建了单一身份网络,而不是另起一套密钥管理系统。 2026 年 1 月发布的 Agentic Identity Framework 把该模型延伸到 AI 代理。它定义四层:身份(加密代理证书)、访问(通过 Teleport proxy 执行 RBAC / ABAC)、安全(行为监控和锁定)以及调度(Kubernetes 和 Temporal 的编排模式)。2026 年 6 月 Beams 公开测试版增加两项具体能力:LLM Proxy(位于代理与推理端点之间,记录每个请求 / 响应,并执行每个 Beam 的允许列表)和 Delegated Identity(允许人类或编排器为一个代理会话分配最小权限)。每个 Beam 在 Firecracker microVM 中运行,具备临时存储、注入身份、虚拟网络,以及约 24 小时的会话绑定生命周期。Beams 目前仅限 Enterprise Cloud,处于公开测试版——尚未正式可用。[CE020, CE021, CE022, CE023, CE024, CE025]

工作流 / 用例表
用户任务不用 Teleport 的当前工作流Teleport 方案已说明的可量化收益限制 / 缺口
工程师 SSH 访问云主机分发 SSH keypair;手工轮换;无中央审计tsh login → 短期证书 → ssh user@host;自动审计日志消除常驻 SSH key;访问耗时下降 80%(公司声称)Agent 必须在目标上以 root 运行;传统 OS 支持有限
Kubernetes 集群访问kubectl 使用长期 kubeconfig token;每个集群单独 RBACTeleport 将证书注入 kubeconfig;集中 RBAC;按查询审计所有 k8s 集群单点 SSO;按 exec 会话录制Agent footprint 增加运维复杂度
数据库访问(Postgres/MySQL)直接 DB 凭证;共享密码;无查询审计Teleport DB 代理;短期证书;查询级审计日志开发者笔记本上没有 DB 凭证并非所有版本都支持所有 DB 引擎
Windows 桌面(RDP)单独 RDP 客户端;VPN + RDP 凭证存储在笔记本上通过 Teleport Web UI 的浏览器 RDP;无需 RDP 客户端屏幕捕获会话录制;无需 VPN用户评论提到剪贴板安全担忧
AI agent 访问基础设施Agent 用静态 API key 和未检查权限冒充用户tbot 给 agent 签发自己的证书;代理侧执行 RBAC;查询被记录100% 可审计的 agentic 工作流(公司声称)Beams 仍处公开 beta;不支持自托管 Beams
FedRAMP / 合规审计在 VPN、bastion 和云 IAM 之间手工收集日志Teleport 原生覆盖 AC-02、AC-03、AC-07、AU-02、AU-12 等加速 FedRAMP-Moderate ATO;FIPS 140-3 验证模块FedRAMP ATO 时点取决于客户完整技术栈

除非另有说明,收益陈述均为公司声称;没有独立量化。

[CE010, CE012, CE013, CE014, CE015, CE029]
FE003: Agentic Identity Framework——关键依赖图

Agentic Identity Framework 组件与外部服务之间的依赖关系。

[CE020, CE021, CE022, CE023, CE024, CE025]

5.4 信任、合规和路线图

Teleport Enterprise 包含通过 FIPS 140 验证的加密模块。版本 17.7.3+ 和 18.0.0+ 使用 BoringCrypto CMVP certificate #4735(FIPS 140-3);更早版本使用 certificate #4407(FIPS 140-2)。这让 Teleport 成为 FedRAMP-Moderate 授权的可行加速器,因为它原生覆盖 AC-02 到 AU-12 及其他 NIST SP 800-53 控制项。Teleport 还记录了 SOC 2 在九个控制类别中的四项覆盖(CC6、CC6 physical、CC7、CC8)。Cure53 于 2019 年进行的独立安全审计未发现严重漏洞;roles API 中一个高危目录遍历问题已在同一版本修复。 发布节奏为每年一个主要版本(从四个月节奏切换而来);版本 18 是当前受支持版本(EOL 2027 年 8 月),版本 17 是稳定受支持版本(EOL 2026 年 8 月)。即将到来的路线图事项包括 Linux Desktop Access(到 Linux 主机的远程会话)、Windows RDP 的目录共享增强,以及 Identity Security 中 AI 总结的会话录制。从版本 16(2024 年 6 月)开始的社区许可证变更,是最重大的持续信任风险:员工超过 100 人或 AR 超过 $10 M 的公司使用编译二进制文件、容器镜像和 AMI,不再适用 Apache 许可证。源代码仍是 AGPLv3,但多数企业使用编译产物,因此商业限制成为事实许可证。[CE029, CE030, CE031, CE032, CE033, CE034]

信任 / 质量 / 合规表
控制 / 认证状态范围缺口 / 注意事项
FIPS 140-3(BoringCrypto生效Teleport Enterprise v18+ 编译二进制文件仅 Enterprise 构建;Community Edition 不符合 FIPS
FIPS 140-2(BoringCrypto旧版本生效(17.7.3 之前)Teleport Enterprise v16–17 系列正被 FIPS 140-3 模块取代
FedRAMP 覆盖(AC、AU 控制)通过 FIPS 构建 + RBAC + 审计日志支持基础设施访问控制;不是完整 ATO客户必须自行取得 ATO;Teleport 只是赋能组件
SOC 2(CC6、CC7、CC8)有文档化映射Enterprise Edition;九类控制中的四类Community Edition 不提供 SOC 2 合规功能
第三方安全审计(Cure53)2019 年完成;未发现严重漏洞全量源代码审计;一个高严重性问题在同一版本修复审计停留在 2019 年;未披露更新的公开第三方审计
Apple 代码签名生效(Developer ID QH8AA5B8UP,Gravitational Inc.)macOS 包和二进制文件证书 2026-07-27 到期;续期状态未公开确认
Community Edition 商业许可证(v16+)2024 年 6 月起生效员工 100+ 或 AR $10 M+ 的公司必须购买 Enterprise许可证变化扰动开源生态;AGPLv3 源码仍可用
会话录制安全(PTY 混淆风险)官方文档披露的限制SSH 和 Kubernetes 会话用户可编码命令来隐藏活动;BPF Enhanced Recording 可缓解

合规状态反映公开文档中的官方说法和链接的 CMVP 证书;2019 年后未见独立第三方验证。

[CE029, CE030, CE031, CE032, CE033, CE034]
路线图 / 发布 / 开发阶段表
日期 / 版本功能 / 里程碑状态影响来源
2025 年 7 月(v18.0.0)Teleport 18 当前版本;AWS IAM Identity Center preview已发布;EOL 2027 年 8 月核心 GA 版本;为 2026 年产品路线图打底官方文档
2024 年 11 月(v17.0.0)Teleport 17 稳定版;Identity Security Crown Jewels;Nested Access Lists已发布;EOL 2026 年 8 月Crown Jewels 和 Nested Access Lists 是新功能;成熟度仍在形成官方博客
2024 年 6 月(v16.0.0)Teleport 16;社区许可证商业限制;IdP 加固已发布Community Edition 现在限制企业使用;生态影响仍在发酵官方博客 + 社区许可证公告
2026 年 1 月发布 Agentic Identity Framework;四层 AI 安全路线图已宣布定义 AI agent 架构;商业化实现仍在推进新闻稿
2026 年 6 月Beams 公测 — Firecracker VM 中的 LLM Proxy 和 Delegated Identity公测(仅限 Enterprise Cloud)GA 时间未披露;自托管客户无法参与 beta新闻稿
2026 年 7 月 6 日当周(v18.10.0)补丁周期继续;18.10.0 计划云端推出已计划证实主版本内维持四个月补丁节奏官方 upcoming-releases 文档
未来(v19.0.0)Linux Desktop Access;多目录 Windows RDP;AI 总结的会话录制路线图中;日期未披露Linux desktop 扩大 RDP 覆盖;AI 摘要缩短调查时间官方 upcoming-releases 文档

日期基于官方发布公告和文档;Beams GA 时间未公开披露。

[CE034, CE035, CE036, CE037, CE008, CE026]
FE004: 产品能力成熟度图

Teleport 关键能力领域的成熟度与竞争差异化。

成熟度评级来自官方文档和功能矩阵;竞争差异化是作者基于架构分析和竞品对比做出的评估。

[CE001, CE003, CE005, CE006, CE020, CE025]

5.5 图表

Chapter 06

06客户

6.1 客户分层和购买画像

Teleport 的买方主要是中大型企业里的工程团队或平台安全团队,技术、金融服务和全球数字平台公司尤其典型。采购决策通常由基础设施工程负责人(工程副总裁、平台工程师、CISO)推动,DevOps 和 SRE 团队是核心用户。官方客户页和案例研究呈现出一致模式:企业希望用基于证书的基础设施访问,替代 VPN 加共享凭证的做法。 公开案例覆盖的垂直行业包括金融科技(Carta、Exness)、全球 SaaS 平台(GoTo、Gladly)、网络检测(ExtraHop)和企业可观测性(IBM Instana)。Series A 融资公告点名 Nasdaq(证券交易所)、Splunk(SIEM / 可观测性)、TicketMaster(现场娱乐)、Mulesoft(API 集成)和 Samsung(消费电子);Series C 则明确点名 Nasdaq、DoorDash 和 Snowflake。Fortune Cyber 60 新闻稿(2025 年 10 月)称,「超过 600 家公司,包括五大金融服务公司中的三家,以及 AI 研究、算力和云领域的领导者」依赖 Teleport——这是迄今最宽泛的客户基数表述,但来自公司自身。 地域上,客户高度集中在北美和全球科技公司,GoTo 总部在东南亚(印度尼西亚),Exness 则在全球金融市场运营。公司规模从成长阶段企业(Series B 时期客户)到大型上市企业(Nasdaq、Samsung、IBM)不等。Community Edition 为小型公司和员工少于 100 人或年收入低于 $10 M 的团队提供获客入口;一旦触及商业许可门槛,就转入 Enterprise 销售。[CU001, CU002, CU003, CU004, CU005, CU006]

客户分群表
客群买方 / 用户主要用例公开规模 / 证明缺口
技术原生企业(fintech/SaaS/cloud)VP Engineering / CISO / Platform 团队基于证书的 SSH、K8s、DB 访问;合规(SOC 2、ISO 27001)Carta、Exness、Gladly、ExtraHop、GoTo 在案例研究中确认NRR、合同规模、流失未披露
全球数字平台(电商、出行、游戏)Platform/SRE 工程师统一多云访问;Kubernetes 私有集群访问GoTo(东南亚平台)、Rush Street Interactive(游戏)、Turo(汽车共享)未披露部署规模指标
企业可观测性 / 基础设施工具厂商Cloud Architect / Infrastructure 团队安全访问云原生可观测性工具;合规证明IBM Instana(IBM 旗下);ExtraHop;KnowBe4只有 IBM Instana 有详细案例研究
金融服务 / 证券交易所安全 / 合规团队FedRAMP-ready;监管合规所需审计日志Nasdaq 在 Series A 和 C 中被点名;「前 5 大金融服务公司中 3 家」(Fortune Cyber 60)NVIDIA 未验证;缺少单家金融公司的案例研究
Startup / SMB 社区(低于门槛)Dev / DevOps 工程师员工少于 100 人 / AR 低于 $10 M 的公司可用免费 Community Edition15,000+ GitHub stars;广泛开源采用信号Community-to-Enterprise 转化率未知

分群基于公开案例研究、融资博客点名客户和官方新闻稿。各客群收入或席位集中度未公开披露。

[CU001, CU002, CU003, CU004, CU005, CU010]
FU001: Teleport 客户旅程图

典型企业客户如何发现、评估、部署并扩展 Teleport。

[CU001, CU002, CU003, CU030, CU031]

6.2 采用轨迹与规模信号

Teleport 最权威的客户数量表述来自 2025 年 10 月 Fortune Cyber 60 新闻稿:「超过 600 家公司,包括五大金融服务公司中的三家,以及 AI 研究、算力和云领域的领导者,依赖 Teleport。」该说法由公司发布,无法独立审计。更早的里程碑包括 Series A 博客所称从「少数早期采用者」发展到「全球最大、最具创新性的公司中的一批」客户组合,以及 Series C 披露的「净新增 ARR 同比增长 4.5 倍」。Getlatka 数据库(截至 2025 年 11 月)报告年收入约 $49 M、员工约 246 人,符合中端 SaaS 规模。 案例研究页面公开列出至少 15 个具名客户——GoTo、Exness、Gladly、ExtraHop、IBM Instana、Carta、KnowBe4、Turo、Rush Street Interactive、Buyers Edge、ThredUP、Qwilt、Mapgears、ECMWF、Flywheel——另有更多匿名描述。客户类型横跨北美 SaaS、全球金融科技、游戏、电商、生物医学研究和气象基础设施。部署深度看起来很深:Exness 称通过 Teleport 管理「横跨本地和云端的数百个 Kubernetes 集群」;GoTo 则称 Teleport 为其庞大基础设施管理「跨多个云服务商」的访问。 Teleport 已连续多年入选 Fortune Cyber 60,并在 Citizens Cyber 66 2026 年 4 月报告中被认定为「收入类别跃迁者」,显示业务势头仍在。独立收入数据有限;Getlatka 的 $49 M 估算未经验证。NVIDIA 出现在部分非官方 logo 墙上,但没有任何官方新闻稿或案例研究确认——此处视为缺口。[CU010, CU011, CU012, CU013, CU014, CU015]

客户增长 / 采用轨迹表
里程碑 / 指标数值日期 / 来源置信度缺口
点名客户数(官方表述)>600 companies2025 年 10 月(Fortune Cyber 60 新闻稿)低-中(公司表述;未独立验证)无独立审计;Teleport 自述
净新增 ARR 增长(Series C 时期)4.5x YoY 净新增 ARR;2.8x total ARR YoY2022 年 3 月(Series C 博客)中(历史数据;与披露融资相符)2022 年后未更新;当前增长率未知
收入估计(独立)2024 年年收入约 $49 M2025 年 11 月(Getlatka)低(估计;方法未披露)独立估计;Teleport 未确认
官方页面上的点名案例研究15+ 个点名客户故事2026 年 6 月(Teleport 案例研究页)高(直接观察)企业客户样本;不代表完整客户基础
GitHub stars(开源采用信号)>15,000 stars2024 年 6 月(社区许可证公告)中(公司表述;当前数量未重新抓取)截至 runDate,GitHub star 数未独立重新抓取
被认定为「revenue category mover」Citizens Cyber 66 2026 认可2026 年 4 月(Citizens Securities 报告)中(独立分析机构认可)报告全文未公开
员工数~246 employees2025 年 11 月(Getlatka)低(估计)第三方估计;Teleport 未确认

数值来自公开来源;NRR、GRR、logo 数和 ARR 均为私有数据。Getlatka 收入和员工数估计未经验证,属于第三方数据。

[CU010, CU011, CU012, CU013, CU014, CU016]
FU002: Teleport 采用漏斗

从开源社区到企业客户的估计转化阶段。

阶段规模为估计;只有 GitHub stars 数和 600+ 家企业数据由公司正式表述。社区到企业的转化率未公开披露。

[CU010, CU013, CU014]

6.3 具名客户证明与案例质量

六个客户在 goteleport.com 上有深入、公开的案例研究,均确认生产环境使用: **IBM Instana**(2020 年被 IBM 收购):云架构师 Hunter Madison 用 Teleport 替代 VPN 加共享凭证来访问 Dropwizard,并表示这是他主导 Teleport 迁移的第三家公司。引述:「这是我做这件事的第三家公司,让 Teleport 发挥作用,给我们能力去改善安全态势。」确认生产使用;信息独立且具体。 **Carta**(金融科技,估值 $7 B+):将 Teleport 与 Okta 集成,用于 Kubernetes 和数据库 RBAC、带细粒度审计的基于角色访问策略,以及更顺畅的开发者入职 / 离职流程。确认用于 SOC 2 / ISO 27001 合规。已在规模化生产环境使用。 **GoTo**(东南亚最大数字平台,已上市):用 Teleport 替代自研工具,管理私有 Kubernetes 集群(「我们所有 Kubernetes 集群都是私有的——也就是说无法被公开访问」)。多云规模的生产部署;由合规驱动(上市公司)。 **Exness**(全球金融科技,受监管金融服务):称「Teleport 是评估过的方案中唯一满足所有要求的一个」,包括全自动化、GitOps 就绪、SSO 和机器身份。生产环境覆盖数百个 Kubernetes 集群。确认满足 PCI DSS、SOC 2 和 ISO 27001。 **Gladly**(SaaS CX 平台):用 Teleport 作为 RBAC 的证书颁发机构,替代静态 SSH 密钥。确认无密钥服务器访问用于合规和基于证据的安全审计。 **ExtraHop**(网络检测与响应):用 Teleport 保障基于身份的 SSH 和 Kubernetes 访问,覆盖半打 Kubernetes 集群,每个集群运行数百个独立节点。 官方新闻稿验证过的 logo 包括 Nasdaq、DoorDash、Snowflake、Splunk、TicketMaster、Mulesoft、Samsung(Series A / C 博客)。Square、Elastic 和 Bloomberg 出现在官方客户页上,但缺少单独案例研究。NVIDIA 未在官方来源中验证。[CU019, CU020, CU021, CU022, CU023, CU024]

点名客户证明表
客户行业部署确认成果 / 引语验证状态来源
IBM Instana企业可观测性(IBM 子公司)生产环境 — Kubernetes、数据库、SSH这是我在第三家公司推动 Teleport 落地已验证:goteleport.com 官方案例研究官方案例研究
CartaFintech(cap table 管理)生产环境 — Kubernetes RBAC、数据库、Okta SSO 集成SOC 2/ISO 27001 合规;开发者入职改善已验证:goteleport.com 官方案例研究官方案例研究
GoTo东南亚数字平台(公开上市)生产环境 — 私有 Kubernetes 集群、多云Teleport 完全契合我们对私有 K8s 访问的要求已验证:goteleport.com 官方案例研究官方案例研究
Exness全球 fintech / 交易技术(受监管)生产环境 — 数百个 K8s 集群、数据库、SSH、Web 应用Teleport 是评估方案中唯一满足所有要求的解决方案已验证:goteleport.com 官方案例研究官方案例研究
GladlySaaS 客户体验平台生产环境 — 无密钥 SSH 访问、RBAC、合规审计会话录制作为合规审计证据已验证:goteleport.com 官方案例研究官方案例研究
ExtraHop网络检测与响应(网络安全)生产环境 — 6 个 K8s 集群,每个数百节点所有 K8s API 查询和 SSH 命令均采用基于身份的授权已验证:goteleport.com 官方案例研究官方案例研究
Nasdaq证券交易所(金融市场)已声明客户(无单独案例研究)Series A 博客和 Series C Bessemer 引语中点名为客户已验证:官方博客文章Series A 博客;Series C 博客
DoorDash外卖平台已声明客户(无单独案例研究)Bessemer 在 Series C 投资博客中点名已验证:官方 Series C 博客Series C 博客
Snowflake云数据平台已声明客户(无单独案例研究)Bessemer 在 Series C 投资博客中点名已验证:官方 Series C 博客Series C 博客
SplunkSIEM / 可观测性(现属 Cisco)已声明客户(无单独案例研究)Series A 博客中点名已验证:官方 Series A 博客Series A 博客
Samsung消费电子 / 全球企业已声明客户(无单独案例研究)Series A 博客中点名已验证:官方 Series A 博客Series A 博客
NVIDIAAI 计算 / 半导体未确认未在任何官方新闻稿或案例研究中找到未验证:不在官方来源中缺口 — 无来源

验证状态看客户名称是否出现在 Teleport 发布的官方来源(案例研究、博客、新闻稿)。「未验证」指名称只出现在第三方或社区列表中,未出现在官方来源中。NVIDIA 是已记录缺口。

[CU019, CU020, CU021, CU022, CU023, CU024]
FU003: 具名客户证明矩阵

公开客户证明在关键维度上的质量与深度。

评分反映作者对公开可得证据的评估;没有案例研究的客户仅限于具名参考。

[CU019, CU020, CU021, CU022, CU023, CU024]

6.4 留存、扩张与集中度风险

Teleport 不公开披露 NRR、GRR、logo 流失或续约率。Series C 博客提到 ARR 同比增长 2.8 倍、净新增 ARR 增长 4.5 倍,符合来自现有客户的强扩张特征,但这些数字来自 2022 年,如今已是历史数据。PeerSpot 用户称 Teleport「通过集中访问控制改变了我们的工作流」,多位评论者把它描述为替代传统 SSH 密钥流程的粘性工具——两者都指向较高切换成本。 Exness(数百个 Kubernetes 集群)、GoTo(多云、多垂直)和 ExtraHop(数百个独立节点)的企业部署深度,说明 Teleport 已嵌入基础设施,形成有意义的切换成本。IBM Instana 的云架构师明确提到,这是他在不同公司推动的第三次 Teleport 部署,是顾问驱动重复采用的强信号。 扩张风险:StrongDM 的竞争批评认为,Teleport 缺少传统协议支持和 SIEM 集成,这可能限制其向混合传统 / 云环境客户扩张。社区许可变更(v16+)限制了大型公司的免费社区层,可能增加社区漏斗转商业扩张的摩擦。集中度是实质风险:公开具名客户明显偏向金融科技和云基础设施里的技术原生公司;医疗、制造、政府和零售行业在公开证据中代表性不足。Fortune Cyber 60 提到「五大金融服务公司中的三家」,说明单一垂直行业集中度显著。[CU029, CU030, CU031, CU032, CU033, CU034]

留存 / 重复使用 / 满意度表
信号证据置信度限制
顾问驱动的重复部署IBM Instana 的云架构师确认,已在不同公司第三次部署 Teleport仅引用单一个人;不是代表性样本
深度基础设施集成(切换成本)Exness — 数百个 K8s 集群;GoTo — 多云;ExtraHop — 数百节点深度指标来自案例研究推断;不是汇总留存数据
社区生态黏性(开源)15,000+ GitHub stars;社区论坛持续活跃stars 是滞后指标;当前活跃度未单独衡量
正面用户评价(PeerSpot)被描述为稳健、安全、提升生产力;替代传统工具PeerSpot 评价数量未披露;样本可能经过筛选
NRR / GRR(量化)未披露低(不可得)关键留存指标;公开信息中没有可用 proxy
合同长度 / 续约率未披露低(不可得)未公开披露合同条款或续约基准
流失信号(负面)StrongDM 称 Teleport Cloud 有可靠性问题;PeerSpot 评价提到部署摩擦竞品批评可能有偏见;但 PeerSpot 评价来自独立用户

留存证据偏定性且间接。量化 NRR、GRR 和续约数据均未公开。顾问驱动的重复部署是较强定性信号,但只来自一名顾问。

[CU019, CU029, CU030, CU031, CU032, CU033]
扩张与集中度风险表
风险因素证据严重性尽调问题
垂直行业集中(科技 - 金融)公开点名客户高度集中在金融科技、云和 SaaS;未见医疗和制造业重大要求提供各垂直行业 ARR 拆分
金融服务集中五大金融服务公司中有三家被点名;Nasdaq 是唯一被点名的金融交易所重大要求提供前 10 大客户集中度,占 ARR 比例
社区版到企业版转化摩擦v16+ 许可变更限制员工超过 100 人 / 年收入 $10 M 的社区用户重大衡量 v16 后社区版 → 企业版转化率变化
NVIDIA 标识未经验证未在 Teleport 官方来源中找到 NVIDIA;可能出现在非官方标识墙上轻微确认 NVIDIA 是否为活跃企业客户
竞争流失风险(传统协议)StrongDM 称 Teleport 缺少传统协议支持;这会限制其在混合环境中的扩张重大要求提供涉及传统系统交易的竞争胜负数据
自托管客户升级路径Beams 和部分 Identity Security 功能仅限 Cloud;自托管客户可能落后轻微询问企业客户中自托管与 Cloud 的拆分

集中度风险来自公开点名客户证据的推断;私有 ARR 集中度数据不可得。

[CU034, CU035, CU036, CU037, CU038, CU039]
FU004: 客户留存与扩张信号分组

从关键维度看六个案例客户的定性留存信号强度。

评分为 0-100 的定性判断,依据公开案例研究证据;目前没有公开的量化 NRR 或续约数据。

[CU019, CU020, CU021, CU022, CU023, CU024]

6.5 图表与证据

Chapter 07

07风险

7.1 许可变更与开源社区风险

2024 年 6 月,Teleport 从 v16 开始把 Community Edition 编译产物从 Apache 2.0 迁至商业许可,制造了一个自伤型信任风险。该政策适用于员工 100 人及以上或年收入至少 $10 million 的公司,也禁止转售或嵌入 Community Edition 产物。这个变化很关键,因为 Teleport 很大一部分类别信誉来自开发者采用;公告发布时,项目已有超过 15,000 个 GitHub stars。源代码仍然可用,但大多数企业实际消费的是二进制文件、镜像或 AMI,因此即使仓库保持公开,商业限制也改变了开发者的真实体验。由此产生的风险不只是社交媒体反弹。它会激励 fork,削弱自下而上的布道,复杂化旧 Apache 许可构建的升级路径,并招致批评:Teleport 已不再像 Open Source Initiative 定义下的常规基础设施开源项目那样行事。[CR001, CR002, CR003, CR004, CR005, CR006]

监管 / 法律风险登记表
规则 / 许可 / 案例司法辖区状态可能性严重性缓释措施剩余敞口尽调路径
Teleport v16 Community Edition 商业许可全球商业使用2024 年 6 月起对较大公司生效,并禁止转售 / 嵌入清晰的商业升级路径和源码可得性降低短期混乱高,因为信任受损和分叉动机仍在审查许可文本、SKU 执行机制和客户升级政策
Open Source Initiative 开源定义全球开源规范限制使用的商业条款不符合 OSI 开源标准Teleport 仍可维护公共仓库和社区文档高,因为开发者观感可能不会很快恢复要求提供关于 OSS 定位和社区沟通的法律备忘录
Teleport Cloud FedRAMP 授权状态美国公共部门文档描述可加速客户合规;未找到 Teleport Cloud 公开授权启用 FIPS 的构建和控制映射支持客户 ATO 工作中到高,因为采购团队可能预期供应商已有授权确认是否存在任何云服务授权包,以及谁拥有边界控制责任
FIPS 140-3 加密边界表述美国受监管买家使用 BoringCrypto 证书官方版本指引缩窄获批部署范围低到中,因为版本漂移仍可能造成合规错误核验目标客户使用的准确构建版本和销售话术
旧版 Apache 许可工件来源现有企业用户旧版本仍沿用此前条款,但升级路径改变经济性和义务固定版本并审查合同可降低意外中,因为混合版本资产可能带来法律和运营摩擦梳理哪些客户依赖 v16 前工件及计划迁移时间

各行聚焦公开法律和合规问题,这些问题可能改变采购、升级或社区结果;不能替代合同审查。

[CR001, CR002, CR004, CR007, CR016, CR017]
FR001: 风险严重度热力图

在可见公开缓释因素之后,Teleport 主要剩余风险类别的相对位置。

[CR006, CR014, CR018, CR026, CR033, CR041]

7.2 自托管复杂性与运营风险

Teleport 的架构带来强控制和审计收益,但也把运营负担推给客户,可能演变为投资风险。StrongDM 的竞争材料称,Teleport agent 在目标服务器上以 root 运行,形成有意义的特权攻击面;他们还把 Teleport 描述为潜在单点故障,前提是控制平面没有按高可用设计。这些说法带有方向性,并非中立评价,但与客户评论中的证据相吻合:大型部署配置和运营都可能复杂。自托管模式要求客户自行负责 auth 和 proxy 组件的基础设施容量、补丁、升级顺序、灾难恢复和宕机预案。Teleport 发布过安全审计材料并支持 FIPS 140-3,这些确实是缓释因素,但无法抹掉架构脆弱性或实施复杂度。FedRAMP 又增加一层:Teleport 文档说明客户如何用产品满足控制族要求,但公开材料没有显示 Teleport Cloud 自身持有 FedRAMP 授权,这会在公共部门销售周期中制造混淆。[CR010, CR011, CR012, CR013, CR014, CR015]

运营与安全风险登记表
故障模式可能性严重性缓释成熟度剩余敞口未解决缺口
以 root 运行的特权代理会成为托管服务器上的额外攻击面在敏感环境中,除非拿出加固证据,否则敞口仍高需要加固指引、事件历史和客户安全审查结果
HA 设计不当时,认证 / 代理控制平面宕机会阻断基础设施访问高,因为访问中断会打到关键业务流程需要可用性历史、参考架构和故障切换测试证据
自托管部署会累积补丁、升级和灾难恢复负担对精简客户团队而言为中到高需要支持负载指标、HA runbook 和版本升级失败数据
传统协议或认证支持有限,缩窄其在混合资产中的适配面中,因为竞品能赢下混合环境交易需要详细协议覆盖矩阵和按环境拆分的胜负数据
企业 RBAC 和部署复杂度拖慢初始 rollout中,因为复杂度损害价值兑现速度需要实施周期、服务 attach rate,以及按部署规模拆分的评价情绪
FedRAMP 营销被误读为 Teleport Cloud 已获服务级授权低到中中,因为公共部门尽调可能在后期卡住需要明确销售话术、异议处理和授权边界文档

运营风险来自架构和部署负担,而不是当前语料中有具体已披露事件的证据。

[CR010, CR011, CR012, CR013, CR014, CR015]

7.3 竞争压力与市场集中风险

Teleport 所处赛道有吸引力,但有吸引力的赛道会吸引更大、资金更充足的对手。2026 年 6 月,CyberArk 和 Okta 的市值均超过 $20 billion,收入基数也明显大于 Teleport 的估算规模,因此更有空间捆绑特权访问、吸收产品重叠,并在企业销售上压过 Teleport。StrongDM 攻击 Teleport 的传统系统覆盖和运营简单性;这很重要,因为许多企业访问资产是混合形态,而非云原生。HashiCorp Boundary 仍是一个带开源根基的身份感知代理替代方案;AWS、Google Cloud 和 Microsoft 也都提供原生 IAM 与特权访问功能,对只用云的买家可能已经足够。 Teleport 的 600 多家客户,以及登上 2026 Fortune Cyber 60 和 Citizens Cyber 66 榜单的具名认可,证明了真实市场牵引力,但也提高了门槛:一旦供应商进入顶级企业评估,功能缺口、打包摩擦和许可信任问题,都会被拿来与资金更充足的平台比较,而不是与没有既有供应商的空白局面比较。[CR019, CR020, CR021, CR022, CR023, CR024]

竞争与依赖风险登记表
竞品 / 依赖类型竞争威胁 / 失败情景严重性缓释措施剩余敞口
CyberArk既有 PAM 套件借规模、广泛企业关系和大产品面打包挤压 Teleport用开发者体验和现代基础设施工作流做差异化
Okta Privileged Access身份平台邻近产品把 PAM 扩进既有 IAM 客群,挤压独立需求靠基础设施深度、会话录制,以及覆盖 SSH/Kubernetes/数据库的平台宽度取胜
StrongDM直接现代访问竞品以更简单部署和更广协议覆盖的定位,赢下混合或传统客户补强传统支持证据和自托管运营清晰度
HashiCorp Boundary开源风格替代方案吸引想要身份感知代理、但不愿承担 Teleport 新商业许可包袱的买家强调更宽产品面和企业控制能力
AWS/GCP/Azure 原生 IAM 和 PIM 工具云平台依赖纯云团队认为原生控制已经够用,避免再引入一个控制平面聚焦多云、混合、审计和即时访问工作流
开源善意和社区渠道生态依赖许可不信任削弱推荐、贡献者和低摩擦采用用透明路线图和公平打包重建信任

本登记表混合列出具名竞品和生态依赖,因为 Teleport 的风险一部分是产品功能战,一部分是分发信任战。

[CR020, CR021, CR022, CR023, CR024, CR025]
FR003: 竞争压力图

结合规模、相邻业务和替代风险,给出指示性竞争压力评分。

评分为序数型威胁分数,综合规模、捆绑能力和基于适配度的替代风险;它们不是市场份额估算。

[CR020, CR021, CR022, CR023, CR024, CR026]

7.4 财务不透明与估值风险

Teleport 的财务争议更多来自可见度缺失,而不是可见弱点。公开融资历史清楚到 2022 年 3 月 Series C:Teleport 宣布由 Bessemer Venture Partners 领投,以 $1.1 billion 估值融资 $110 million,Series A、B、C 累计融资约 $140 million。看不清的是当前规模、利润率结构、现金效率和盈利能力。来源集合中唯一 ARR 数字是 GetLatka 对 2024 年 $49 million 的估算,且 Teleport 未验证。若该数字方向正确,最后披露估值意味着约 22 倍 ARR 倍数;对一家没有公开增长耐久性证明的私有基础设施公司而言,这个要求很高。给定材料中没有更新融资可见,投资者只能围绕一个已过时四年的价格锚承销。旧估值、估算 ARR 和缺失的单位经济数据叠加,使下行更难量化,也让资源更强的上市可比公司对市场情绪有更大影响。[CR028, CR029, CR030, CR031, CR032, CR033]

7.5 人员、执行与战略风险

Teleport 现在的战略风险来自两线作战:既要守住成熟的基础设施访问业务,又要扩张到 agentic AI identity。领导层集中度值得注意:Ev Kovyrin、Sasha Klizhentas 和 Taylor Wakefield 仍分别担任 CEO、CTO 和 COO,处在产品、工程和运营执行的中心。已审阅的公开材料没有披露继任计划、更广的管理梯队深度或当前员工数,外部难以判断管理冗余。与此同时,Teleport 已把自己重塑为 AI Infrastructure Identity Company,2026 年 1 月发布 Agentic Identity Framework,2026 年 6 月推出 Beams 公测。这些动作可能带来真实上行,但也引入路线图复杂性、支持负担,以及围绕委托权限、审计覆盖和 agent 运行时隔离的治理问题。核心风险不是公司不该向 AI 相邻领域扩张;而是在变现和控制成熟前,投资者仍需要证据证明新打法强化了既有访问业务,而不是分散注意力。[CR035, CR036, CR037, CR038, CR039, CR040]

人才与执行风险登记表
角色 / 职能依赖或缺口可能性严重性缓释措施尽调路径
创始领导层三名联合创始人仍支撑战略、工程方向和运营创始人经验丰富,且仍保持公开活跃要求提供组织架构、授权管理层和继任规划材料
合规与公共部门 GTMFedRAMP 定位要求边界责任和买家教育必须精确FIPS 支持和官方控制映射有帮助要求提供公共部门 pipeline、异议日志和授权责任矩阵
Agentic 产品团队AI 身份扩张可能稀释核心 PAM 执行注意力复用核心平台的证书、审计和策略原语要求提供 Beams 的路线图人员拆分和 GA 就绪标准
SRE 与客户成功自托管复杂度可能增加支持负担并拖慢续约参考架构和托管云产品可降低痛感要求按部署模式提供支持比例、升级指标和续约数据
财务与规划未公开盈利、烧钱或增长披露,限制外部信心既有蓝筹投资人提供一定信号价值要求提供董事会包指标、当前 ARR、烧钱和 runway 假设

Teleport 现在同时横跨核心访问安全、受监管买家销售和新的 AI runtime 动作,人才风险因此抬高。

[CR035, CR036, CR037, CR038, CR039, CR042]
否决标准与监测触发器
风险可监测触发器阈值 / 事件行动含义
许可 / 社区反弹有意义的分叉牵引,或大型企业围绕 v16 许可提出重大异议因 Community Edition 不再被视为开源,导致漏斗顶部流失或具名交易受阻下调增长效率和生态护城河假设,重新承销
FedRAMP 模糊性公共部门尽调要求供应商授权证据Teleport 无法展示清晰服务边界语言或任何供应商授权包推迟政府扩张承销,并升级合规审查
控制平面韧性参考架构和宕机证据自托管或云运营拿不出有说服力的 HA、DR 或可用性证据将架构脆弱性视为关键任务部署的负面论点
财务不透明当前 ARR、烧钱和毛利包管理层无法把 2024 年估计值与当前运营指标对齐下调估值,并要求更宽的下行情景
AI 转向执行Beams beta 转化和治理里程碑到下一次尽调里程碑仍无清晰采用、GA 路径或策略控制将 AI 上行视为免费期权,而非承载价值的核心论点
竞争替代胜负和续约数据面对 StrongDM、Okta 或 CyberArk,传统支持或打包驱动的流失上升下调定价权假设和销售效率预期

这些触发器刻意设计成可监测项,方便尽调区分可修复的披露缺口和需要停止或重定价的结构性理由。

[CR031, CR033, CR041, CR043, CR044, CR045]
FR002: 风险传导图

Teleport 的许可、架构和战略风险如何传导到增长与估值。

[CR008, CR011, CR018, CR026, CR033, CR037]

7.6 图表与证据

Chapter 08

08估值

8.1 投资正论与反论

投资正论首先来自市场结构和定位,而不是当前财务披露。Teleport 面向特权访问管理和零信任访问销售,这两类安全预算即使在软件支出放缓时仍具战略重要性。Precedence Research 估算 PAM 2025 年规模为 $4.50B,CAGR 为 23.4%;零信任市场更大,规模 $40.01B,CAGR 为 16.39%。Teleport 还受益于开发者驱动分发:开源仓库建立了广泛认知,公司声称拥有 600+ 客户,官方引用强调五大金融服务公司中的三家采用。投资人阵容——Bessemer、Insight、Kleiner Perkins 和 S28——增加可信度;2026 年 Agentic Identity Framework / Beams 重新定位,也提供了一个可讲通的叙事:从传统人类特权访问扩张到机器和 AI agent 身份。反论比普通后期软件尽调备忘录更强,因为关键承销变量仍未公开验证。GetLatka 未确认的 2024 年 $49M ARR 估算,是唯一当前收入锚;若采用该数字,相对过时的 2022 年 3 月 $1.1B Series C 标记,隐含约 22.4 倍 EV / ARR。这个水平高于 CyberArk 约 15.8 倍的经验证公开倍数,也远高于 Okta 约 7.1 倍。竞争并非理论风险:CyberArk、Okta、BeyondTrust、StrongDM 和 Boundary 都在定义相邻的基础设施访问问题。2024 年社区许可变更也可能削弱最初让 Teleport 差异化的自下而上开源漏斗。最后,Teleport Cloud 缺少 FedRAMP 授权压窄了近期联邦市场上行,而 2022 年以来没有新一级融资、IPO 申报或公开流动性信号来重置估值预期。[CV010, CV011, CV012, CV016, CV017, CV019]

投资论点与反论点
方向论点证据锚点什么会改变判断
正方PAM 和零信任市场规模大且仍在扩张,足以支撑长期品类增长。2025 年 PAM 为 $4.50B;2025 年零信任为 $40.01B。市场增长明显放缓,或 Teleport 无法把 TAM 转化为经验证的 ARR 增长。
正方开源分发、GitHub 牵引和 600+ 客户表明产品相关性有韧性。GitHub stars 和企业客户声明支撑认知度与采用。若出现社区下滑、转化疲弱或重大客户流失证据,该论点会削弱。
正方Bessemer、Insight、Kleiner Perkins 和 S28 让投资团在后续融资或退出上具备可信度。Series A/B/C 披露和投资人评论。如果下一轮持平 / 下行,或内部人不愿支持流程,投资团实力的重要性会下降。
正方2026 年 AI agent 身份重新定位可能把 Teleport 从经典人类特权访问扩到更大边界。Agentic Identity Framework 和 Beams 发布。如果 Beams 无法变现,或只停留在 demo 叙事,溢价应消失。
反方唯一公开 ARR 锚点是未经确认的 $49M 估计,对应约 ~22.4x 的偏贵倍数。GetLatka 加 Series C 估值测算。经验证 ARR 明显高于 $70M 且增长强劲,才能缩窄估值担忧。
反方CyberArk、Okta、BeyondTrust、StrongDM 和 Boundary 都压制可实现倍数。公开可比公司数据和竞品产品页。若 Teleport 在功能和增长上拉开清晰差距,溢价才可能重新成立。
反方CE 许可变更可能削弱自下而上的社区驱动获客。官方许可变更公告和 GitHub / 社区语境。如果变更后转化效率和自助 pipeline 仍强,风险会下降。
反方缺少 FedRAMP,且没有公开 IPO 或二级交易信号,降低近期可选性。面向 FedRAMP 的材料但无授权,再加上后续无融资 / IPO 标记。授权进展或正式融资 / 退出流程会改善风险调整后的判断。

论点只围绕估值相关性展开;不是通用品质打分卡。

[CV010, CV011, CV012, CV016, CV017, CV019]
FV001: 推荐逻辑流

公开证据支持产品相关性,但不足以在旧估值点上形成干净的承销判断。

[CV010, CV011, CV012, CV019, CV024, CV025]

8.2 估值背景与可比公司组

Teleport 唯一披露的估值标记是 2022 年 3 月 Series C:由 Bessemer Venture Partners 领投、Insight Venture Partners 参与,以 $1.1B 投后估值融资 $110M。2021 年 Series B 增加 $30M,2020 年 Series A 增加 $25M,因此披露的累计一级资本约 $140M。官方新闻室没有宣布后续一级融资、二级报价、IPO 申报或其他公开标记,投资者只能用一个过时四年的价格,对照 2026 年软件可比公司环境来评估。关键问题不是 $1.1B 在 2022 年不可能;而是当前公开证据没有确认足以支撑今天维持该标记的经营规模。GetLatka 估算 2024 ARR 为 $49M,但它明确只是估算的单一来源数据点,并非公司披露。若该估算方向正确,过时估值隐含约 22.4 倍 EV / ARR。CyberArk 是最接近的公开 PAM 锚,市值约 $20.63B、TTM 收入 $1.30B,约 15.8 倍。Okta 是更广义的身份平台,如今也销售特权访问,交易倍数接近 7.1 倍。这些公开倍数并非完全一一对应,但确实建立了估值重力:Teleport 需要证明 ARR 显著高于 $49M、当下增长远快于公开可验证水平,或拥有持久的 AI 身份溢价,才配得上旧私有市场标记。没有这些证明,估值看起来是昂贵,而不只是溢价。[CV001, CV002, CV003, CV004, CV005, CV006]

可比估值表
可比对象类别Revenue/ARR 指标倍数 / 估值状态与 Teleport 的相关性局限
Teleport(上一轮标记)私有基础设施安全估算 ARR $49M(2024 GetLatka)$1.1B / 约 22.4x ARR过时的私募轮估值标记直接标的;显示今天必须证明什么ARR 未确认,估值标记停留在 2022 年 3 月
CyberArk上市 PAM 龙头TTM 收入 $1.30B(2026 年 6 月)~15.8x 收入当前上市可比公司最接近且透明的 PAM 估值锚规模更大、披露为上市公司口径,产品广度也更成熟
Okta带 PAM 的上市身份平台TTM 收入 $2.91B(2026 年 6 月)~7.1x 收入当前上市可比公司展示带 PAM 邻近属性的身份市场估值底线类别更宽,利润率 / 增长组合不同
私有安全 SaaS 参考区间私有增长参考$40M-$60M ARR~8x-15x ARR示意性私募区间有助于约束基准情景下的私募定价区间是背景参照,不是单一可交易资产
高增长溢价区间私有上行参考ARR 增长经验证 >50%~15x-25x ARR示意性上行区间显示溢价标记要守住所需的门槛需要验证增长,且披露通常要好于 Teleport 目前公开水平

表内混合了直接上市可比公司与参考区间,因为 Teleport 后续融资或可靠的私募二级市场标记均未公开。收入和 ARR 数据具有特定时点属性,且未按净现金调整。

[CV006, CV007, CV008, CV025, CV039, CV041]
FV002: 估值敏感性条形图

基于 $49M ARR 估算,在选定收入倍数下推导隐含企业价值。

数值四舍五入到最接近的百万位,并仅把单一来源的 $49M ARR 估算作为敏感性锚点。

[CV005, CV006, CV025, CV041]

8.3 情景分析与敏感性

情景区间主要取决于经验证收入规模和增长耐久性,而不是表格模型复杂度。牛市情景中,Teleport 的 AI Infrastructure Identity 重新定位奏效,Beams 成为可信的 agent 身份切入点,ARR 从 2024 年 $49M 估算起,以每年 35% 以上复合增长,到 2027 年约 $85M。套用 15 倍倍数——大致是透明公开 PAM 锚的高端,而不是激进 AI 泡沫倍数——得到约 $1.28B,只比旧标记略高。这是可接受但不惊艳的后期上行情景。基准情景假设产品仍相关、客户质量扎实,但增长回落到每年约 25%。到 2027 年 ARR 约 $73M。按 10 倍至 12 倍,对应健康但不亢奋的安全软件倍数区间,隐含价值约 $730M 至 $875M。熊市情景假设许可过渡拖慢开发者驱动获客,竞争者压迫定价,AI 重新定位兑现慢于叙事;在年增长低于 15% 时,ARR 仅约 $60M,6 倍至 8 倍区间隐含 $360M 至 $480M。换句话说,大多数现实路径都需要优于公开证据的增长证明,或更低入场价,风险调整后回报才有吸引力。[CV031, CV032, CV033, CV034, CV038, CV039]

牛市 / 基准 / 熊市情景分析
情景关键假设2027E ARR适用倍数隐含估值 USD概率信号
牛市AI 身份产品跑出牵引力,增长维持在 35% 以上,客户质量撑得起溢价倍数。$85M15x$1.28B上行情景;需要验证增长,并跑通 AI 变现
基准核心访问平台仍有相关性,增长放缓至约 25%,且未出现重大利润率冲击。$73M10x-12x$730M-$875M按现有证据最可能成立
熊市许可证逆风、可比公司压力、扩张放缓,把增长压在约 15%,可比估值容忍度下降。$60M6x-8x$360M-$480M若当前叙事跑在基本面前面,就是下行情景

ARR 情景由 GetLatka 对 2024 年 $49M 的估算推导,应视为示意,而非公司指引。

[CV031, CV032, CV033, CV034, CV039, CV041]
FV003: 估值 / 回报区间

牛市、基准和熊市价值区间显示,旧估值点附近几乎没有安全边际。

区间是基于 $49M ARR 估算和选定可比公司区间推导的情景输出;它们不是管理层指引。

[CV031, CV032, CV033, CV034]

8.4 退出准备度与最终尽调要求

退出准备度喜忧参半。积极一面是,创始团队仍然可见,公司继续推出产品,投资人联盟也足够深,可以支持战略出售或后续 IPO 尝试。最可能的战略收购方是已经触达身份、PAM 或零信任工作流的大型安全或基础设施厂商,例如 CyberArk、Palo Alto Networks、Cisco 或 Microsoft。话虽如此,公开记录中没有任何迹象显示 Teleport 当前处在 IPO 路径上,也没有披露的流动性机制为后期持有人重置价格发现。因此,战略退出论点只是一种可能性,不是估值托底。尽调负担很高,因为缺失证据正好落在估值应当锚定的位置:2024 和 2025 年经验证 ARR、当前增长率、净收入留存、毛利率、burn、股权结构优先权,以及 CE 许可变更对新 logo 生成的实际影响。联邦市场扩张也是门槛项,因为 Teleport 讨论了面向 FedRAMP 的用例,但 Teleport Cloud 没有公开授权。因此,谨慎投资者应把它视为依赖 data room 的决策,而不是单靠叙事动能就能形成确信的一轮。[CV020, CV035, CV036, CV037, CV042, CV044]

推翻论点与止损触发器
触发器阈值 / 事件对投资论点的传导行动含义
ARR 验证失败已验证 ARR 显著低于 $49M,或 2025 年 ARR 未显示可信增长入场倍数升至远高于本已昂贵的上市和私募参考点暂停,或把价格重估至低于过时的 $1.1B 标记
增长质量不及预期当前 YoY 增长低于 25%,或 NRR 低于 100%基准情景过于乐观,倍数支撑被压缩从继续研究转为回避,除非价格重置
毛利率偏弱毛利率低于软件式门槛,或烧钱结构性偏重AI 或基础设施叙事未能转化为有吸引力的 SaaS 经济性要求完全不同的估值框架,或放弃
许可证变化伤害漏斗CE 转换后,社区驱动管线明显下滑自下而上的差异化和资本效率一起走弱下调长期增长假设和 CAC 效率
联邦就绪停滞Teleport Cloud 在目标垂直战略中没有可信的 FedRAMP 路径政府和受监管 TAM 叙事比宣传更有限从市场规模和情景区间中剔除联邦上行

这些是投前承诺触发器,不是投后经营 KPI。

[CV016, CV024, CV035, CV036, CV040, CV048]
最终尽调问题清单
主题缺失证据重要性负责人 / 尽调路径
ARR 验证2024 年和 2025 年经审计或 CFO 证明的 ARR,以及客户桥接当前公开锚点来自单一来源估算财务资料室与客户 cohort 复核
增长和留存当前 YoY 增长、NRR、流失率和扩张 cohort溢价倍数逻辑取决于经验证的增长质量CFO 材料、董事会材料和 cohort 分析
经济性毛利率、烧钱、runway 和销售效率没有单位经济性,入场价格无法做压力测试财务工作流和管理层访谈
股权结构优先权堆栈、反稀释条款和清算权即便企业价值增长,优先权悬垂也可能损害回报公司法律顾问与融资文件审查
许可证变化影响CE 转换前后的管线构成社区动作变化可能改写 CAC 和转化假设与产品和销售负责人复核 GTM 分析
FedRAMP 路线图授权计划、时间表,以及 go-to-market 对联邦买家的依赖没有执行路径,就不能把政府 TAM 完整计入安全 / 合规复核和联邦管线尽调

每项问题都直接对应一个目前在公开材料中不透明的估值变量。

[CV024, CV035, CV036, CV042, CV043, CV048]

8.5 建议与证据评估

建议为继续研究,置信度中等,风险评级高,估值立场为昂贵。Teleport 看起来具备战略相关性、客户验证和强投资人背书,但投委会不需要判断公司是否优秀;真正要判断的是今天的入场价格是否站得住。基于当前公开证据,答案是否定的。2022 年 $1.1B 标记只有在几个假设下才能辩护:当前 ARR 明显高于唯一的 GetLatka 估算;Series C 以来未公开披露的增长率仍然较高;或存在公共可比公司尚未验证的高溢价 AI 身份估值体系。证据基础方向上有用,但不完整。官方来源强力支持融资历史、客户信号和产品叙事,公开可比公司也提供了干净基准,显示经验证行业倍数低于 Teleport 隐含的估算倍数。缺的是把叙事转化为价格的核心财务披露。只有当 Teleport 能验证 ARR 高于约 $70M、显示 NRR 高于 100%、确认当前同比增长不低于 25%、提供毛利率和 burn 可见度,并证明政府市场准备度进展或具体退出时间表时,建议才应上调。在此之前,它仍是一家有前景但估值风险需要承销的公司。[CV005, CV006, CV024, CV025, CV032, CV034]

推荐结论摘要
维度评估理由
推荐继续研究公开证据方向上偏正面,但不足以承销 $1.1B 估值标记。
置信度融资历史和可比公司清晰,但 ARR 和当前增长没有公司确认。
风险评级估值过期、ARR 未确认、竞争压力和无公开盈利数据共同抬高下行风险。
估值立场偏贵未确认 ARR 下约 ~22.4x,高于 CyberArk 经验证的约 ~15.8x 公开收入倍数。
决策含义等待财务验证推进前需核验 ARR、增长、NRR、利润率和 cap table 可见度。

评估基于 2026-06-20 可得公开证据,并仅将 GetLatka 未确认的 $49M ARR 估计作为工作锚点。

[CV004, CV005, CV006, CV024, CV025]
FV004: 投资 KPI 评分卡

可供投委会使用的评分,在市场质量、证据质量和估值支撑之间做权衡。

[CV012, CV019, CV024, CV025, CV035, CV042]

8.6 图表与证据

免责声明

本报告基于公开信息;在 Teleport 未披露当前指标处,报告纳入了已清楚标注的第三方估算。

证据索引

结论
编号陈述可信度来源
CO001 Teleport is headquartered at 2100 Franklin St, Suite 400, Oakland, California 94612 and describes itself as the AI Infrastructure Identity Company. SO001, SO002
CO002 The company was originally incorporated as Gravitational Inc. and officially renamed itself Teleport in 2021, moving to the goteleport.com domain. SO006
CO003 Teleport's corporate signing certificates still use "Developer ID QH8AA5B8UP Gravitational Inc." confirming the legal entity is still Gravitational Inc. SO002
CO004 Teleport was founded in 2015 by Ev Kontsevoy, Alexander Klizhentas, and Taylor Wakefield. SO003, SO019
CO005 Teleport's pricing is usage-based, metered by Monthly Active Users, Machine and Workload Identities, and Teleport Protected Resources. SO010
CO006 Teleport Community Edition is free only for companies with fewer than 100 employees and annual revenue under $10M; larger companies must purchase Enterprise Edition. SO007, SO010
CO007 Ev Kontsevoy serves as Co-founder and CEO, Alexander Klizhentas as Co-founder and CTO, and Taylor Wakefield as Co-founder and COO, all of whom are listed on the Teleport about page as of June 2026. SO002, SO008
CO008 Jeff Bunten is listed as CRO and Diana Jovin as CMO on the Teleport about page. SO002, SO028
CO009 All three co-founders previously worked together at Rackspace after that company acquired Mailgun, a developer email infrastructure startup they had built. SO019
CO010 Ev Kontsevoy is the named author or spokesperson for all three fundraising blog posts, the Agentic Identity Framework launch, and the Fortune Cyber 60 press release. SO003, SO004, SO005, SO013, SO011
CO011 No independent director names or full board composition have been disclosed by Teleport in public materials as of June 2026.
CO012 Mary D'Onofrio from Bessemer Venture Partners joined the Teleport board at the Series C close; Matt Koran from Insight joined as a board observer. SO003
CO013 Teleport raised a $25M Series A led by Kleiner Perkins; the company had reached profitability before the round and named NASDAQ, Splunk, TicketMaster, Mulesoft, and Samsung as customers. SO005, SO019
CO014 Teleport raised a $30M Series B led by S28 Capital and Kleiner Perkins in 2021, following a quarter with net new ARR up 5x and total ARR up 2.5x year-over-year versus Q2 2020. SO004
CO015 Teleport raised a $110M Series C led by Bessemer Venture Partners at a $1.1B valuation in May 2022, with net new ARR up 4.5x and total ARR up 2.8x year-over-year at the time of the round. SO003, SO018
CO016 Total disclosed funding for Teleport across all three rounds is $165M. SO003, SO004, SO005
CO017 GetLatka reported that Teleport raised $140M across 2 rounds, which diverges from the company-disclosed $165M across 3 rounds, suggesting GetLatka missed the Series A. SO020
CO018 No publicly available evidence of a Teleport funding round after the May 2022 Series C has been identified, and no SEC Form D filings for Gravitational Inc. or Teleport Inc. were found in EDGAR searches. SO003, SO004, SO005
CO019 The $1.1B Series C valuation mark is approximately four years old as of June 2026, and private-market conditions tightened materially in 2022–2024. SO003
CO020 GetLatka estimated Teleport's 2024 revenue at $49M, describing this as the revenue milestone the company hit in December 2024; this is a third-party estimate not confirmed by Teleport. SO020
CO021 GetLatka reported Teleport employs approximately 246 people as of late 2025; this is an unverified third-party estimate. SO020
CO022 Teleport's Series A blog stated the company had recently reached profitability before the round; no current profitability data is disclosed. SO005
CO023 The Teleport careers page and press release state that more than 600 companies depend on Teleport as of October 2025. SO008, SO011
CO024 Named customers from Teleport public materials include NASDAQ, Snowflake, DoorDash, IBM (Instana), Carta, GoTo, Exness, KnowBe4, Turo, Gladly, ThredUP, ExtraHop, and Rush Street Interactive. SO009, SO015, SO016
CO025 The Teleport open-source GitHub repository had over 15,000 GitHub stars as of the June 2024 community license blog post. SO007, SO023
CO026 The Teleport open-source project has been on GitHub under the AGPLv3 license since 2015 and supports SSH, Kubernetes, databases, RDP, web applications, and MCP servers. SO023, SO007
CO027 Teleport releases major product versions on approximately a four-month cycle; Teleport 16 was released in June 2024 and Teleport 17 in October 2024. SO007
CO028 Teleport was named to the 2026 Fortune Cyber 60 list in October 2025, recognizing rapid growth and commitment to delivering identity security solutions. SO011
CO029 Teleport was named to the Citizens Securities 2026 Cyber 66 list in April 2026, recognizing it as one of the hottest privately held cybersecurity companies. SO012
CO030 Teleport's Agentic Identity Framework was announced on January 27, 2026, providing a roadmap for deploying autonomous AI agents in production infrastructure with cryptographic identity. SO013
CO031 Beams (beams.run) entered public beta in June 2026 as a Teleport product providing trusted runtimes for AI agents, running each agent in isolated Firecracker VMs with built-in identity and no secrets. SO024, SO027
CO032 Teleport's 2026 Infrastructure Identity Survey of 200+ infrastructure leaders found that 79% were evaluating or deploying agentic AI and 69% said AI adoption required significant changes to identity management. SO025
CO033 Starting with Teleport 16 in June 2024, compiled Community Edition binaries and container images were moved from the Apache 2.0 license to a commercial license; the AGPLv3 source code repository was not changed. SO007
CO034 Teleport's FedRAMP documentation describes how Teleport FIPS mode can help customers achieve FedRAMP authorization, but does not represent a FedRAMP ATO for Teleport's own SaaS. SO014, SO026
CO035 No public evidence confirms that Teleport's own cloud service has received a FedRAMP Authorization To Operate (ATO) from the FedRAMP Program Management Office.
CO036 PeerSpot reviewers cite initial setup complexity, RBAC configuration difficulty, SIEM integration gaps, and pricing concerns for large companies as key areas for improvement. SO022
CO037 StrongDM's competitor comparison page claims Teleport's agents run as root on every monitored server and that Teleport Cloud experiences availability issues during updates. SO021
CO038 Teleport's product secures SSH, Kubernetes, databases, RDP, web applications, and MCP servers through a certificate-authority model that issues short-lived credentials. SO023, SO001
CO039 Teleport conducted a security audit by Cure53 in 2019, resulting in no critical vulnerabilities found; the company has committed to regular third-party security audits. SO017
CO040 The global PAM market was estimated at $4.5B in 2025 and is projected to grow to $29.88B by 2034 at a 23.4% CAGR according to Precedence Research. SO029
CO041 Teleport's competitive context includes public cybersecurity companies such as CyberArk (market cap ~$20B, revenue ~$1B in 2024) and Okta (market cap ~$20B, revenue ~$2.9B in 2025), both of which are substantially larger by revenue than Teleport's estimated ARR. SO029
CO043 NIST SP 800-207 (2020) defines zero trust architecture as eliminating implicit trust based on network location and requiring per-request authentication and authorization — the framework Teleport's products implement for infrastructure access. SO030
CO042 The Bessemer BVP investment blog described Teleport as "the easiest, most secure way to access infrastructure" and noted that 2021 saw a 50% increase in attacks on corporate networks. SO018
CM001 Teleport positions itself as an AI Infrastructure Identity company spanning human, machine, and AI identities. SM001, SM015
CM002 Teleport's published product scope covers SSH, Kubernetes, databases, Windows, web apps, machine identities, and related infrastructure workflows. SM024, SM028
CM003 Bessemer described infrastructure access as a new and exciting product category when explaining its Teleport investment. SM012
CM004 A disciplined Teleport market definition should include privileged infrastructure access, workload identity, audit, and compliance-linked access modernization spend. SM024, SM028, SM006
CM005 A disciplined Teleport market definition should exclude most workforce IAM, CIAM, endpoint, SIEM, and non-infrastructure AI application spend. SM024, SM028, SM007
CM006 VPNs, bastions, long-lived credentials, cloud-native point IAM, and manual audit workflows remain status-quo substitutes for Teleport. SM024, SM015
CM007 FedRAMP, SOC 2, and access-audit use cases expand Teleport's commercial relevance without turning the company into a full GRC or broader identity vendor. SM016, SM017, SM018
CM008 StrongDM argues that Teleport is a point solution for modern cloud architecture and lacks broader legacy-system fit. SM029
CM009 Precedence Research values the global privileged access management market at $4.50 billion in 2025 and forecasts $29.88 billion by 2034. SM009
CM010 Archived Grand View Research evidence values the global zero-trust security market at $36.96 billion in 2024 with a 16.6% CAGR through 2030. SM010
CM011 Precedence Research values the global zero-trust security market at $40.01 billion in 2025 and forecasts $182.59 billion by 2035. SM011
CM012 Published market estimates diverge because PAM and zero-trust reports use overlapping but not identical scope definitions and forecast windows. SM009, SM010, SM011
CM013 Teleport's practical TAM sits between narrow PAM and broad zero-trust security because the product spans infrastructure access and identity but not every control category inside zero trust. SM001, SM024, SM028
CM014 The market taxonomy around infrastructure identity is still forming rather than universally settled. SM012
CM015 AI adoption expands Teleport's SAM because 92% of survey respondents report near-term AI initiatives and 79% are evaluating or deploying agentic AI. SM003
CM016 Enterprise preparedness lags AI adoption because only 13% of respondents feel extremely prepared and 60% have had or suspect AI-related incidents. SM003
CM017 Teleport reports more than 600 customers, including three of the top five financial services firms, which demonstrates real market adoption but not precise share. SM004, SM027
CM018 The retained Fortune Business Insights PAM URL could not be used for triangulation because it returned unrelated agricultural content instead of PAM analysis. SM026
CM019 Teleport's primary operational users are platform engineers, security engineers, infrastructure admins, and Kubernetes or database operators. SM024, SM028
CM020 Budget ownership commonly sits with either the security organization or platform engineering, depending on whether the trigger is control posture or operational fragmentation. SM022, SM023
CM021 Teleport's MAU and MWI pricing model ties commercial expansion to identity adoption rather than to a fixed appliance or seat bundle. SM022
CM022 Compliance-led deals pull in public-sector or regulated-program owners because Teleport markets FedRAMP and FIPS alignment as part of the value proposition. SM016, SM018, SM019
CM023 SOC 2-oriented buyers use Teleport as infrastructure access control rather than as a general-purpose compliance platform. SM017, SM023
CM024 The public GitHub repository has more than 15,000 stars, which supports developer-led awareness and evaluation. SM025
CM025 Teleport's disclosed customer proof is strongest in large regulated enterprises, including major financial-services institutions. SM004, SM023
CM026 Legacy-heavy hybrid enterprises are less naturally aligned with Teleport when broad protocol coverage is prioritized over cloud-native depth. SM029
CM027 Zero trust has both a formal standards anchor in NIST SP 800-207 and an operational maturity framework in CISA's Zero Trust Maturity Model. SM006, SM007
CM028 Teleport links its infrastructure-access controls to FedRAMP and SOC 2 requirements, which turns compliance from an adjacency into a concrete demand driver. SM016, SM017, SM018
CM029 Teleport reports that 73% of cybersecurity leaders are hearing enterprise customer questions about AI agent security. SM005
CM030 Teleport's 2026 survey says 92% of respondents have near-term AI initiatives and 79% are evaluating or deploying agentic AI. SM003
CM031 Investor and cloud-market commentary from BVP and Kleiner Perkins supports the view that multi-cloud complexity and AI are reinforcing demand for unified infrastructure control planes. SM012, SM013, SM014
CM032 Usage-based MAU and MWI pricing can reduce initial adoption friction while making long-run spend dependent on identity growth. SM022, SM003
CM033 Fortune Cyber 60 and Cyber 66 recognition strengthen Teleport's category legitimacy with enterprise buyers. SM004, SM005
CM034 Switching costs remain material because buyers must unwind incumbent access workflows and test whether Teleport's strengths offset migration burden and coverage gaps. SM024, SM029
CM035 Teleport documents support for FIPS 140 cryptographic modules, which materially improves fit for regulated and public-sector access programs. SM016, SM018
CM036 Demand is structurally strongest in regulated and cloud-native environments and weaker in legacy-dense estates. SM023, SM024, SM029
CM037 Public evidence does not isolate Teleport's SAM or SOM by segment, geography, deployment model, or average contract value. SM021, SM022, SM023
CM038 Market-sizing evidence is directionally useful but methodologically inconsistent because the sources blend narrow PAM and broad zero-trust definitions. SM009, SM011, SM026
CM039 The Fortune Business Insights page failure is a genuine research limitation rather than a minor formatting issue because it removes one potential triangulation point. SM026
CM040 Teleport's public materials are richer on product breadth and compliance mapping than on win rates, deployment duration, churn, or segment economics. SM001, SM023, SM027
CM041 Adverse competitor framing that Teleport is a point solution for modern cloud estates is relevant when testing whether the company can claim a broad cross-environment market. SM029
CM042 The market thesis is stronger on demand direction than on precise monetizable share until management discloses segment-level revenue and expansion evidence. SM003, SM004, SM022
CM043 Teleport's last disclosed financing event remains the May 2022 Series C of $110 million at a $1.1 billion valuation, leaving public market interpretation anchored to stale capital data. SM002, SM012
CM044 Teleport also frames automation of identity and access evidence collection as a FedRAMP acceleration vector, which broadens the compliance-driven budget conversation. SM019, SM020
CM045 Archived Grand View coverage shows that privileged access management is tracked as a standalone analyst category even though not every retained source yielded usable public figures. SM008, SM026
CP001 Teleport's core product is a certificate-authority and proxy architecture that issues short-lived credentials and brokers access across multiple infrastructure resource types. SP016, SP017, SP021
CP002 Teleport's current platform scope now spans zero trust access, machine and workload identity, identity security, and an explicit agentic identity layer. SP021, SP022, SP024, SP025, SP031
CP003 Recent Teleport releases have added IdP-compromise mitigations, a broader identity-security layer, and agentic-identity packaging, showing product expansion beyond classic SSH access. SP018, SP019, SP022
CP004 CyberArk presents PAM as a unified platform for controlling elevated access and explicitly markets zero-standing-privilege access in hybrid and multicloud environments. SP002, SP003
CP005 CyberArk's public-company scale was about $20.63 billion in market cap and $1.30 billion in trailing revenue as of June 2026. SP012, SP013
CP006 BeyondTrust competes on least privilege, credential injection, secure remote access, and vendor privileged access rather than on a developer-led infrastructure identity narrative. SP004, SP005
CP007 Delinea Secret Server remains centered on vaulting, discovery, password rotation, session monitoring, and AI-driven session analysis. SP006
CP008 StrongDM is now positioned inside Delinea through the publicly announced acquisition, tightening the overlap between cloud-native access brokering and incumbent PAM suites. SP001, SP006
CP009 StrongDM markets continuous policy enforcement, full session visibility, and no standing privileges on top of an Identity Firewall foundation. SP001
CP010 StrongDM's direct comparison page explicitly says Teleport lacks support for legacy systems and some authentication protocols and that Teleport agents running as root create an additional attack surface. SP026
CP011 PeerSpot reviewers praise Teleport for centralized access control, role-based permissions, smoother SSH key management, and strong visibility during incidents. SP009
CP012 HashiCorp Boundary is an identity-aware proxy that integrates with external identity providers and HashiCorp Vault to deliver single sign-on and dynamic credentials for least-privileged access. SP008
CP013 Okta Privileged Access extends Okta's identity platform into Linux and Windows server access with zero-standing-privilege framing and recorded SSH or RDP sessions. SP007
CP014 Okta's public scale was about $20.65 billion in market cap and $2.91 billion in trailing revenue as of June 2026. SP014, SP015
CP015 The main buyer consideration set around Teleport includes CyberArk, BeyondTrust, Delinea, StrongDM, Okta, and Boundary rather than only one-for-one open-source lookalikes. SP010, SP011, SP027
CP016 Teleport competes in a broader infrastructure-identity category that combines connectivity, authentication, authorization, and audit across multi-cloud infrastructure workflows. SP027, SP028
CP017 Because competitors span incumbent PAM suites, cloud-native access brokers, and IAM adjacency, Teleport is being evaluated across both direct and adjacent budget lines. SP010, SP011, SP027
CP018 Teleport's historical open-source distribution and public repository still create awareness advantages relative to fully proprietary incumbents. SP023, SP030
CP019 The June 2024 community-license change reduced Teleport's practical open-source advantage because larger companies can no longer freely use compiled Community Edition artifacts. SP023
CP020 Teleport backs its trust story with a published security audit and explicit identity-security documentation, which matters in enterprise infrastructure-access evaluations. SP020, SP021
CP021 Teleport's architecture supports certificate-based access across SSH, RDP, Kubernetes, databases, and machine or workload identities, reducing long-lived secret sprawl. SP016, SP017, SP025
CP022 Teleport's Agentic Identity Framework and machine-identity products widen competition into non-human identity and AI-operated infrastructure workflows. SP022, SP024, SP025
CP023 StrongDM's critique implies that Teleport's certificate-centric design is strongest in modern estates and potentially weaker in legacy-heavy environments. SP026, SP016
CP024 CyberArk and BeyondTrust can credibly encroach on Teleport's cloud-native accounts because both market least-privilege, secure remote access, and zero-standing-privilege outcomes rather than only password vaulting. SP003, SP005
CP025 PAM switching costs accumulate through vaulted credentials, policy engines, approval workflows, session archives, and compliance evidence that buyers do not want to rebuild. SP002, SP003, SP004, SP005, SP006
CP026 HashiCorp Boundary has narrower public product breadth than Teleport in the retained set, but its Vault integration gives it real leverage inside existing HashiCorp-oriented platform teams. SP008
CP027 Teleport is more transparent on list pricing and edition boundaries than most direct competitors because the company publishes pricing and feature segmentation publicly. SP029, SP031
CP028 CyberArk, BeyondTrust, Delinea, StrongDM, Okta, and Boundary generally use sales-led or quote-led packaging in the retained evidence set, limiting public apples-to-apples pricing comparison. SP001, SP003, SP005, SP006, SP007, SP008
CP029 Public retained pricing evidence is enough to compare transparency and packaging posture, but not enough to prove Teleport is absolutely cheaper than strong alternatives after discounting or bundling. SP029, SP003, SP005, SP006, SP007, SP008
CP030 Teleport's differentiation is architectural unification: one access plane for authentication, authorization, and audit across modern infrastructure resources. SP016, SP017, SP021
CP031 The retained independent review set is more supportive than hostile: public review evidence highlights ease of deployment and security visibility more than onboarding pain. SP009
CP032 PeerSpot reviewers describe Teleport adoption in workflow terms: centralize access control, improve visibility during incidents, and replace ad hoc SSH key handling with more consistent policy. SP009
CP033 Delinea's acquisition of StrongDM raises the competitive ceiling against Teleport because a modern access-broker story can now be paired with a larger incumbent PAM relationship base. SP001, SP006
CP034 Okta competes less as a deep infrastructure specialist than as an adjacency play that can bundle privileged server access into an existing identity-cloud relationship. SP007, SP014, SP015
CP035 Teleport faces a major scale asymmetry because CyberArk and Okta each exceed $20 billion in market cap, giving them greater room to bundle, cross-sell, and absorb overlap. SP012, SP013, SP014, SP015
CP036 Adverse competitive evidence against Teleport is concentrated on legacy coverage and root-agent architecture rather than on an absence of core session-control or audit capabilities. SP026, SP009
CP037 Teleport's community-license change weakens its competitive contrast versus open-source-oriented alternatives because buyers must now separate source availability from binary-use rights. SP023, SP030
CP038 Comparable public pricing remains structurally incomplete because most rivals do not publish equivalent seat, workload, or contract-unit pricing in the retained set. SP001, SP003, SP005, SP006, SP007, SP008
CP039 The retained 2026 freshness evidence is uneven across the field: Teleport and Delinea or StrongDM show visible 2026 signals, but equivalent 2026 update detail for CyberArk, BeyondTrust, Okta, and Boundary is thin. SP001, SP022
CP040 Teleport's resource-type breadth still exceeds what the retained Okta and Boundary sources show, especially for Kubernetes, databases, machine identity, and AI-oriented access control. SP007, SP008, SP021, SP024, SP025, SP031
CP041 The market remains segmented rather than fully converged, so Teleport's competitive success depends on winning the right estate profile rather than being universal across all privileged-access jobs. SP010, SP011, SP026, SP027
CP042 Incumbent PAM vendors skew toward broad hybrid-enterprise security buyers, while Teleport, StrongDM, and Boundary skew toward platform teams and Okta sells into its existing IAM base. SP001, SP003, SP005, SP007, SP008, SP016
CI001 Teleport's pricing is usage-based, metered by Monthly Active Users, Machine and Workload Identities, and Teleport Protected Resources; no public list price is stated and all pricing requires commercial engagement with the sales team. SI013
CI002 GetLatka estimated Teleport's 2024 revenue at $49M, describing it as a December 2024 milestone; this is an unconfirmed third-party estimate not corroborated by any official source. SI012
CI003 No Teleport revenue estimate more recent than GetLatka's 2024 snapshot has been found in public sources; Teleport's 2025-2026 recognition press releases do not include revenue data. SI012, SI015
CI004 At $49M estimated ARR and ~246 estimated employees, the implied ARR-per-employee ratio is approximately $199K, consistent with mid-stage infrastructure SaaS but below top-decile benchmarks. SI012
CI005 The Teleport Series C blog (May 2022) reported total ARR up 2.8x and net new ARR up 4.5x year-over-year at the time of the round; Bessemer's investment blog confirmed this growth trajectory. SI015, SI014
CI006 The Teleport Series B blog (2021) reported total ARR up 2.5x and net new ARR up 5x year-over-year versus Q2 2020. SI016
CI007 At GetLatka's $49M ARR estimate, the $1.1B Series C valuation implies a revenue multiple of approximately 22.4x ARR — materially above where public cybersecurity peers traded in mid-2026. SI012, SI015
CI008 The $1.1B Series C valuation from May 2022 has not been refreshed by any public subsequent financing event, secondary transaction, or management disclosure, making it approximately four years stale. SI015
CI009 CyberArk Software had a market cap of approximately $20.63B and TTM revenue of approximately $1.30B as of June 2026, implying a revenue multiple of approximately 15.9x. SI019, SI011
CI010 Okta had a market cap of approximately $20.65B and TTM revenue of approximately $2.91B as of June 2026, implying a revenue multiple of approximately 7.1x. SI021, SI011
CI011 Applying the midpoint of CyberArk's and Okta's mid-2026 public revenue multiples (~11x) to Teleport's $49M estimated ARR produces an implied enterprise value of approximately $540M, well below the $1.1B 2022 mark. SI019, SI021, SI012
CI012 Teleport discloses no official revenue, gross margin, burn rate, or cash position data in any public-facing materials; the company is not required to file financial statements as a private entity. SI015, SI013
CI013 No SEC Form D or other federal securities registration filing has been found for Gravitational Inc. or Teleport Inc. on EDGAR, preventing independent verification of investor ownership stakes. SI011
CI014 Teleport has four commercial billing modules: Zero Trust Access (MAU/TPR), Machine and Workload Identity (MWI), Identity Governance (MAU), and Identity Security (TPR) — each a separate upsell opportunity with its own billing metric. SI013
CI015 Teleport Enterprise Edition requires commercial contact for all pricing; no public list price is disclosed for any product tier or module. SI013
CI016 The June 2024 community license change restricts compiled Community Edition use to companies with fewer than 100 employees and less than $10M AR, creating a commercial conversion gate for mid-market growth. SI018
CI017 Teleport's Beams AI agent runtime and the Machine/Workload Identity module (docs/ai-agents-mwi) confirm the platform is actively building for AI agent identity as a production revenue surface, with agents receiving unique cryptographic identity enforced at access time. SI005, SI010
CI018 GetLatka's funding summary for Teleport shows $140M across 2 rounds, diverging from the company-disclosed $165M across 3 rounds, suggesting GetLatka missed the Series A or has incomplete sourcing. SI012
CI019 No SEC Form D or equivalent state securities filing was publicly identified for Gravitational/Teleport, consistent with the company relying on state-level exemptions or other non-federal registration paths for its three private placement rounds. SI011
CI020 The PAM market was estimated at $4.5B in 2025 and projected to reach $29.88B by 2034 at a CAGR of 23.4% per Precedence Research, providing a strong market tailwind for Teleport. SI026, SI027
CI021 The PAM market's 23.4% CAGR implies the market nearly doubles every 3.5 years, providing strong tailwinds for Teleport across the infrastructure PAM and zero-trust identity segments. SI026
CI022 Bessemer Venture Partners' investment thesis for the Series C framed Teleport as "the defining solution" to infrastructure access, citing a 50% increase in corporate network attacks in 2021. SI014
CI023 Insight Venture Partners participated significantly in the $110M Series C, with Matt Koran joining the board as an observer; no post-Series C investor update is publicly available. SI015
CI024 At $49M estimated ARR and $165M total raised, Teleport's implied capital efficiency (ARR / capital raised) is approximately 0.30 — below the commonly cited efficient SaaS benchmark of 0.5–1.0. SI012, SI015, SI016, SI017
CI025 The key outstanding financial gaps for Teleport include audited ARR, gross margin, NRR, burn rate, cash balance, option pool size, and current cap table — none of which are publicly available.
CI026 CyberArk revenue grew from approximately $590M in 2022 to $1.30B TTM in 2025, a 2.2x increase in roughly three years. SI020, SI011
CI027 Okta revenue grew from approximately $1.85B in 2022 to $2.91B TTM in 2026, a 1.6x increase in roughly four years. SI022, SI011
CI028 Teleport disclosed total funding of $165M across three rounds: $25M Series A, $30M Series B, and $110M Series C. SI015, SI016, SI017
CI029 PeerSpot reviews highlight pricing concerns for large companies and initial setup complexity as recurring Teleport complaints, indicating enterprise price sensitivity is an active competitive dynamic. SI023, SI024
CI030 No public evidence of secondary market transactions, tender offers, or equity pricing events involving Teleport has been identified since the May 2022 Series C. SI015
CI031 StrongDM's competitor comparison page claims Teleport Cloud has reliability issues and that its agent- based architecture creates new security exposures; these claims originate from a direct competitor and must be weighed accordingly. SI024
CI032 Kleiner Perkins' Series A investment thesis (2019) described Gravitational as solving a once-in-a-decade opportunity in multi-cloud infrastructure — an early validation of the market thesis that Teleport's subsequent growth appears to confirm. SI025
CI033 Teleport's MAU/MWI/TPR billing model creates natural revenue expansion as customers add infrastructure resources, without requiring re-negotiation of the commercial relationship. SI013
CI034 The GoTo case study shows Teleport securing multi-cloud infrastructure for Indonesia's largest digital platform, illustrating the revenue expansion potential as large enterprises add workloads and users. SI001
CI035 The Exness and Gladly case studies show Teleport serving regulated financial services and compliance- driven SaaS customers, segments where infrastructure identity tooling typically commands premium pricing. SI002, SI003
CI036 If Teleport's ARR at the Series C close was approximately $17–20M (implied by the 2.8x growth cited) and grew to $49M by 2024, the post-fundraising CAGR was approximately 22%, significantly below the pre-Series-C rates. SI015, SI012
CI037 At the Series C close in May 2022, CyberArk traded at approximately $5.27B market cap on ~$590M revenue (~9x) and Okta at ~$10.94B on $1.85B revenue (~6x), suggesting Teleport's ~22x implied multiple was already ~2x the comparable range at issuance. SI019, SI021, SI015
CI038 Teleport's machine workload identity documentation for AI agents (ai-agents-mwi) confirms the platform issues each AI agent its own cryptographic identity, with deterministic access enforcement — a capability that underpins the Machine/Workload Identity revenue module. SI005
CI039 Teleport's session recording architecture captures complete pseudo-terminal output for SSH sessions and database session events, providing compliance audit evidence that drives adoption in regulated industries. SI007, SI006
CE001 Teleport is a certificate authority and identity-aware access proxy that implements SSH, RDP, HTTPS, Kubernetes API, and SQL/NoSQL database protocols, distributed as a single Go binary. SE011, SE036
CE002 Teleport's product suite includes five pillars: Zero Trust Access, Machine & Workload Identity, Identity Governance, Identity Security, and the Agentic Identity Framework. SE019, SE001
CE003 The Zero Trust Access product covers SSH, Kubernetes, databases, Windows/RDP, internal web apps, and MCP servers. SE019, SE011, SE036, SE055, SE058
CE004 MCP server access is available in Community Edition, Enterprise Self-Hosted, and Enterprise Cloud, with per-tool audit events for MCP requests. SE019, SE022
CE005 The Teleport feature matrix distinguishes Enterprise Cloud, Enterprise Self-Hosted, and Community Edition, with Beams trusted runtimes exclusive to Enterprise Cloud. SE019, SE012
CE006 Identity Security provides SQL-editor access queries, Crown Jewels monitoring for critical assets, anomaly alerting, and integration with Okta, AWS, and GitHub audit logs. SE023, SE010
CE007 Teleport pricing is usage-based across four billing metrics: Monthly Active Users, Machine/Workload Identity users, and Teleport Protected Resources, with no publicly listed list prices. SE012
CE008 Teleport's Agentic Identity Framework was announced January 27, 2026, defining a four-layer architecture (identity, access, security, scheduling) for securing AI agents in production. SE030, SE033
CE009 Teleport's 2026 Infrastructure Identity Survey of 200+ infrastructure leaders found 92% have near-term AI initiatives in infrastructure and only 13% feel extremely prepared. SE032
CE010 The Teleport control plane consists of the Auth Service (CA, config store, audit log) and Proxy Service (public entry point, reverse-tunnel hub, Web UI), both communicating via gRPC. SE017, SE018
CE011 The Auth Service is the only Teleport component that must be connected to a persistent backend (etcd, DynamoDB, Postgres, or Teleport Cloud storage); all other services are stateless. SE018, SE017
CE012 Teleport authentication flow: user runs tsh login, receives a client certificate from the Auth Service, and that certificate is automatically accepted by SSH, kubectl, psql, and other CLI tools. SE011, SE017
CE013 Teleport integrates with enterprise SSO providers including Okta, GitHub, Google Workspace, and Active Directory for identity provider authentication. SE011, SE025
CE014 Teleport's Proxy Service implements an SSH server; Teleport Agents establish reverse tunnels to the Proxy to receive traffic from the public internet without exposing private resources. SE017, SE018
CE015 Teleport can be deployed as Cloud (fully managed), on-premises, on-premises FIPS, multi-region high availability, hybrid, or edge; deployment type does not affect billing metrics except for multi-region HA. SE012
CE016 StrongDM claims Teleport agents run as root on every enrolled server, creating a new attack vector; agentless mode is available but offers limited features without RBAC or granular auditing. SE043
CE017 Session recording in Teleport supports four configurations (node-sync, node, proxy-sync, proxy) and captures PTY output for SSH and Kubernetes, screen content for desktop, and query streams for databases. SE024
CE018 Teleport's official session recording documentation discloses that users can conceal terminal commands by encoding them (e.g., base64) or running scripts from disk, with BPF Enhanced Session Recording as a mitigation. SE024
CE019 StrongDM claims Teleport Cloud is unreliable and that updates can cause access downtime of up to six hours; Teleport does not publish a public uptime SLA or incident history. SE043
CE020 Machine & Workload Identity uses tbot to issue short-lived X.509 or SSH certificates to non-human workloads, eliminating standing service secrets. SE020, SE034
CE021 AI agents secured with Machine & Workload Identity receive their own cryptographic identity and operate under RBAC/ABAC enforcement at both network and protocol level, with all actions logged. SE034, SE033
CE022 The Agentic Identity Framework is organized into four layers: identity (cryptographic agent certificates), access (RBAC/ABAC via Teleport proxy), security (behavioral monitoring), and scheduling (Kubernetes/Temporal orchestration patterns). SE033, SE030
CE023 Beams is described as a trusted ephemeral runtime for AI agents; each Beam runs in a Firecracker microVM with ephemeral storage, injected identity, and a session-bound lifecycle of approximately 24 hours. SE035, SE019
CE024 The LLM Proxy sits between an AI agent and its inference endpoint, logging every request and response to the Teleport audit trail and enforcing per-Beam allowlists for which inference endpoints agents can reach. SE031, SE035
CE025 Delegated Identity allows a human operator or orchestrator to define and assign least-privilege permissions to an agent session, and was launched as part of the Beams public beta in June 2026. SE031
CE026 Beams trusted runtimes are currently in public beta and are available only to Enterprise Cloud customers; Enterprise Self-Hosted and Community Edition deployments do not have access to Beams. SE019, SE031
CE027 Beams includes built-in inference proxy support for OpenAI and Anthropic endpoints, with an option to bring your own inference endpoint. SE035, SE019
CE028 The 2026 Citizens Securities Cyber 66 report survey found 73% of cybersecurity leaders are seeing enterprise customers ask how their platforms can help secure AI agents, with identity topping the list of security pain points. SE053
CE029 Teleport Enterprise versions 17.7.3+ and 18.0.0+ include FIPS 140-3 validated cryptographic modules using BoringCrypto CMVP certificate SE025
CE030 Teleport's FedRAMP documentation covers AC-02, AC-03, AC-07, AC-08, AC-10, AC-12, AU-02, AU-03, AU-09, AU-10, and AU-12 NIST SP 800-53 controls, supporting FedRAMP-Moderate authorization. SE025, SE054
CE031 Teleport documents SOC 2 coverage across four of nine control categories: CC6 (control activities), CC6 (physical/logical access), CC7 (system operations), and CC8 (change management). SE026
CE032 A Cure53 security audit of Teleport in 2019 found no critical vulnerabilities; one high-severity directory-traversal issue in the roles API was patched in the same release (v2.6.0). SE029
CE033 No public third-party security audit of Teleport more recent than 2019 has been disclosed; the Cure53 audit covered source code version 2.x, not current v17/v18. SE029
CE034 Teleport releases one major version per year with 24-month support; version 18 (current) was released July 2025 with EOL August 2027; version 17 (stable) EOL August 2026. SE027
CE035 Starting with Teleport 16 (June 2024), compiled Community Edition binaries, container images, and AMIs are licensed under a commercial license restricting companies with 100+ employees or $10 M+ annual revenue. SE008, SE009
CE036 The Teleport open-source repository on GitHub remains AGPLv3; documentation and client library code remain Apache 2.0; only compiled artifacts switched to the commercial license in June 2024. SE008, SE036
CE037 Teleport's product roadmap includes Linux Desktop Access (remote sessions to Linux hosts), multiple-directory sharing for Windows RDP, and AI-summarized session recordings in Identity Security. SE027
CE038 The Teleport GitHub open-source repository has over 15,000 GitHub stars (stated at time of community-license announcement) and is written in Go; Teleport maintains Apple code-signing and RPM/Debian signing keys published on the security page. SE008, SE036, SE056, SE057
CE039 PeerSpot user reviews identify Teleport's initial setup and RBAC configuration complexity, SIEM integration limitations, clipboard security risk in RDP, and pricing concerns for large companies as the primary improvement areas. SE052
CE040 NIST SP 800-207 and CISA Zero Trust Maturity Model provide regulatory frameworks for zero-trust access controls that Teleport's architecture is designed to satisfy. SE041, SE042
CE041 Teleport Identity Governance adds access lists, access requests, approval workflows, and SCIM-driven lifecycle controls on top of the core access plane. SE059, SE019
CE042 The Teleport Proxy Service provides the public-facing web UI, single sign-on entry point, and reverse-tunnel transport that connects users to private resources through the control plane. SE017, SE060
CE043 Teleport authentication issues short-lived certificates to human users, services, and AI agents after they authenticate through local accounts or external identity providers with MFA. SE017, SE061
CE044 Teleport agents are deployed onto protected infrastructure and can join clusters through multiple join methods, allowing SSH, Kubernetes, application, and database traffic to traverse the identity-aware proxy. SE017, SE062
CE045 The tsh client is Teleport's command-line workflow surface for user logins, certificate retrieval, and protocol-specific sessions, complementing the browser UI and Teleport Connect desktop app. SE018, SE063
CU001 Teleport's buyer persona is primarily engineering or platform-security teams at mid-to-large enterprises in technology, fintech, and global digital platforms. SU001, SU002, SU003
CU002 Teleport's public case studies span verticals including fintech (Carta, Exness), Southeast Asia digital platform (GoTo), SaaS CX (Gladly), network detection (ExtraHop), and enterprise observability (IBM Instana). SU001, SU002, SU003, SU006, SU007
CU003 The Series A announcement named Nasdaq, Splunk, TicketMaster, Mulesoft, and Samsung as early major customers. SU008, SU022
CU004 The Series C announcement named Nasdaq, DoorDash, and Snowflake as flagship customer logos, cited by Bessemer lead investor Mary D'Onofrio. SU009, SU013
CU005 The Community Edition provides a top-of-funnel acquisition channel for companies with fewer than 100 employees or less than $10 M AR; larger companies must purchase Enterprise licenses. SU018, SU009
CU006 GoTo (Southeast Asia's largest digital platform, publicly listed) is a confirmed production customer; all of GoTo's Kubernetes clusters are private and Teleport was selected for secure private access. SU002
CU007 Exness is a global fintech and trading technology company regulated under PCI DSS, SOC 2, and ISO 27001; it selected Teleport after evaluating multiple solutions and states it was the only solution meeting all requirements. SU003
CU008 Teleport's case study page as of June 2026 lists at least 15 named customer stories including KnowBe4, Turo, Exness, Rush Street Interactive, GoTo, Carta, Buyers Edge, ExtraHop, IBM Instana, ThredUP, Qwilt, Mapgears, ECMWF, Flywheel, and Gladly. SU001
CU009 Teleport customer geographies include North America (Carta, ExtraHop, Gladly), Southeast Asia (GoTo), global fintech (Exness), and IBM (global enterprise). SU001, SU002, SU003
CU010 An October 2025 Fortune Cyber 60 press release by Teleport states that 'more than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport.' SU011
CU011 The 600+ customer count from the October 2025 Fortune Cyber 60 press release is company-stated and has not been independently verified by any third-party analyst or database. SU011, SU017
CU012 At the time of the Series C in March 2022, Teleport reported net-new ARR growth of 4.5x and total ARR growth of 2.8x year over year. SU009, SU013
CU013 The Teleport open-source repository on GitHub has over 15,000 GitHub stars, as stated at the time of the June 2024 community license announcement. SU018, SU014
CU014 Teleport was recognized as a 'revenue category mover' in the Citizens Securities Cyber 66 April 2026 report, indicating continued business momentum. SU012, SU024
CU015 Series B materials stated Teleport included a major stock exchange, the biggest crypto exchanges, large gaming and e-commerce platforms among its customers at the time of the September 2021 funding. SU010
CU016 Getlatka estimates Teleport generated approximately $49 M in annual revenue in 2024, with approximately 246 employees as of November 2025; these are unverified third-party estimates. SU017
CU017 The PAM market including infrastructure access is dominated by BFSI (banking, financial services, insurance) verticals which account for approximately 29% of market share, consistent with Teleport's heavy financial services customer concentration. SU019
CU018 Teleport's Fortune Cyber 60 press release specifically notes 'three of the top five financial services firms' as customers, indicating significant financial-sector concentration. SU011
CU019 IBM Instana's Cloud Architect Hunter Madison states this is his third Teleport deployment across different companies, confirming advisor-driven repeat adoption as a retention signal. SU006
CU020 IBM Instana uses Teleport to manage secure access to Dropwizard tooling and replaced a combination of VPNs and shared credentials; the case study confirms production deployment at IBM-scale. SU006
CU021 Carta integrated Teleport with Okta for Kubernetes and database RBAC, enabling streamlined developer onboarding/offboarding and fine-grained auditing for SOC 2 and ISO 27001 compliance. SU007
CU022 GoTo adopted Teleport for all private Kubernetes clusters across its multi-cloud infrastructure, replacing an in-house access tool that became too complex to maintain as GoTo scaled across business verticals. SU002
CU023 Exness operates hundreds of Kubernetes clusters across on-premises and cloud environments; Teleport was selected as the only solution meeting its requirements for automation, GitOps readiness, SSO, and machine identity. SU003
CU024 Gladly uses Teleport as a certificate authority for RBAC rather than static SSH keys, and uses session recording as compliance evidence for security auditors and privacy-conscious customers. SU004
CU025 ExtraHop secured six Kubernetes clusters each running hundreds of individually spun-up nodes with Teleport, replacing hardcoded and shared secrets that were creating compliance and audit gaps. SU005
CU026 Nasdaq is a confirmed named customer cited in both the Series A announcement and in Bessemer's Series C investment statement. SU008, SU009, SU013
CU027 DoorDash and Snowflake are confirmed named customers cited by Bessemer Venture Partners in the Series C investment announcement. SU009, SU013
CU028 Splunk, TicketMaster, Mulesoft, and Samsung are confirmed named customers cited in the Series A funding announcement. SU008
CU029 PeerSpot users describe Teleport as significantly improving workflow by centralizing access control and reducing manual SSH key management, indicating high stickiness once deployed. SU023
CU030 The depth of enterprise deployments at Exness (hundreds of K8s clusters), GoTo (multi-cloud), and ExtraHop (hundreds of nodes per cluster) creates significant infrastructure integration depth and high switching costs. SU002, SU003, SU005
CU031 Teleport does not publicly disclose NRR, GRR, logo churn, or contract renewal rates; no third-party database has independently verified these metrics. SU017, SU009
CU032 PeerSpot reviews identify initial setup complexity, RBAC configuration difficulty, and pricing concerns as friction points that could limit adoption or cause attrition. SU023, SU015
CU033 StrongDM's competitive analysis claims Teleport lacks legacy-protocol support, limiting expansion in mixed legacy/cloud environments, which is a potential barrier to enterprise-wide adoption. SU020
CU034 Publicly named customers are concentrated in tech-native companies (SaaS, fintech, cloud platforms); healthcare, manufacturing, government, and retail sectors are not represented in public case studies. SU001, SU011
CU035 Teleport's Fortune Cyber 60 press release notes 'three of the top five financial services firms,' which implies significant revenue concentration in the financial services sector without disclosing individual firm names beyond Nasdaq. SU011
CU036 The community-license change starting with Teleport v16 (June 2024) restricts the free Community Edition for companies above 100 employees or $10 M AR, potentially reducing the organic community-to-enterprise conversion pipeline. SU018, SU009
CU037 Beams and several Identity Security features are Enterprise Cloud-only; self-hosted customers cannot access these capabilities, creating a two-tier customer experience. SU021, SU009
CU038 NVIDIA does not appear in any official Teleport press release, funding announcement, or case study and should be considered an unverified logo-wall claim rather than a confirmed customer. SU008, SU009, SU011
CU039 Square and Bloomberg appear on the Teleport official customer page as logo references but lack individual case studies confirming production deployment details. SU025, SU001
CU040 The PAM market (of which Teleport participates in the infrastructure access segment) was valued at approximately $4.5 B in 2025 with a projected CAGR of 23.4% to 2034, driven by rising identity-based attacks. SU019
CU041 Teleport's official llms.txt file (June 2026) names Nasdaq, IBM, DoorDash, Elastic, and GoTo as industry-leading organizations that trust Teleport, providing an official customer reference for Elastic beyond the case study list. SU027, SU025
CU042 Teleport's Elasticsearch integration page confirms that Teleport supports database-level RBAC and audit for Elasticsearch as a first-class protected resource, extending enterprise value beyond SSH and Kubernetes. SU026
CU043 Turo publicly references Teleport as an infrastructure-access platform, showing adoption within a large consumer marketplace environment. SU029
CU044 KnowBe4 appears in Teleport's official case study library, extending proof that Teleport is used inside security-focused organizations beyond fintech and cloud-native engineering teams. SU030
CU045 TigerGraph's case study shows Teleport supporting globally distributed access-control requirements, adding a graph-database and analytics workload to the public customer mix. SU031
CU046 ECMWF's public case study shows Teleport being used to secure access to supercomputing clusters, proving demand beyond standard SaaS infrastructure into research and HPC environments. SU032
CU047 Rush Street Interactive's case study adds online gaming and regulated cloud security as another public customer vertical for Teleport. SU033
CU048 Mapgears' case study highlights Teleport's secure SSH access improving customer-support workflows, broadening evidence that Teleport is used for both platform engineering and operational support access. SU034
CU049 thredUP's case study adds retail and Kubernetes-access controls to the public customer proof set for Teleport. SU035
CU050 Qwilt's case study indicates Teleport is used alongside operational tools such as Rundeck and Slack APIs in globally distributed content-delivery environments. SU036
CU051 Flywheel's case study adds biomedical research and compliance-sensitive infrastructure to Teleport's public customer references. SU037
CR001 Teleport announced that Community Edition compiled artifacts moved from Apache 2.0 to a commercial license starting with Teleport v16 in June 2024. SR001, SR011
CR002 The new Community Edition terms apply to companies with at least 100 employees or $10 million of annual revenue and prohibit resale or embedding. SR001
CR003 Teleport's repository remains public, but the practical licensing change is concentrated in binaries, images, and AMIs that many enterprises actually deploy. SR001, SR011
CR004 The Open Source Initiative definition does not treat usage-restricted commercial licenses as open source, so Teleport Community Edition no longer fits the standard OSS definition after v16. SR001, SR031
CR005 Teleport said the project had more than 15000 GitHub stars when it announced the license change, showing that any community backlash touches a large developer audience. SR001, SR011
CR006 Because Teleport historically benefited from developer-led adoption, the new licensing gate can weaken bottom-up enterprise pipeline and increase willingness to test alternatives. SR001, SR011, SR025
CR007 Enterprises that standardized on Apache-era Teleport builds face artifact-provenance and upgrade-review risk when moving into the v16+ commercial-license regime. SR001, SR010
CR008 License-driven community distrust creates credible fork and ecosystem-goodwill risk because users who want open-source-style access controls now have clearer incentive to evaluate substitutes. SR001, SR022, SR025
CR009 The licensing change may improve monetization conversion, but it also introduces a reputational overhang that investors must treat as a structural distribution risk rather than as a one-time announcement artifact. SR001, SR013
CR010 StrongDM's comparison page says Teleport agents run as root on target servers, which increases the privileged software footprint on managed infrastructure. SR016
CR011 StrongDM also frames Teleport as a potential single point of failure when the control plane is unavailable, making high-availability design mission critical. SR016
CR012 StrongDM positions broader legacy access support as a competitive advantage over Teleport, implying fit risk in hybrid estates with older protocols or workflows. SR016, SR017
CR013 PeerSpot review evidence points to deployment and RBAC complexity in larger environments, reinforcing the view that Teleport can be operationally heavy to roll out. SR023, SR024
CR014 Teleport's self-hosted model requires customers to own infrastructure, patching, upgrades, and resilience planning for auth and proxy services. SR006, SR010
CR015 Teleport published an independent Cure53 security audit and disclosed remediation of the single high-severity issue found, indicating some security-process maturity. SR009
CR016 Teleport documents FIPS 140-3 support through BoringCrypto CMVP certificate #4735 in builds from v17.7.3+ and v18.0.0+, which is a meaningful compliance mitigant for regulated buyers. SR006, SR007
CR017 Teleport's official materials explain how customers can meet FedRAMP control requirements with the product, but the reviewed public corpus does not show Teleport Cloud itself having a FedRAMP authorization. SR006, SR008
CR018 That FedRAMP boundary ambiguity can create procurement friction because public-sector buyers may incorrectly assume vendor-service authorization rather than customer-system control mapping. SR006, SR008, SR014, SR015
CR019 The PAM market is large and growing, which attracts incumbents and increases the probability of sustained competitive pressure around Teleport's core category. SR030
CR020 CyberArk carried an approximately $20.63 billion market capitalization and $1.30 billion of TTM revenue in June 2026. SR026, SR027
CR021 Okta carried an approximately $20.65 billion market capitalization and $2.91 billion of TTM revenue in June 2026 while marketing a Privileged Access product. SR021, SR028, SR029
CR022 StrongDM explicitly attacks Teleport on legacy support, operational simplicity, and architecture footprint, showing that those are active competitive battlegrounds rather than hypothetical weaknesses. SR016
CR023 HashiCorp Boundary provides an identity-aware proxy alternative with open-source roots, making it a credible option for buyers who want a different trust or packaging model. SR022
CR024 Cloud-native IAM and privileged-identity features from AWS, Google Cloud, and Microsoft can be good enough substitutes for customers whose estates stay mostly within one cloud. SR014, SR015, SR021
CR025 Teleport says it serves more than 600 customers including three of the top five financial services firms, showing real traction but also confirming that it competes in demanding enterprise evaluations. SR005, SR033, SR034
CR026 Competitive pressure can slow sales cycles or compress pricing because larger rivals can bundle adjacent identity or security products and smaller rivals can exploit Teleport's license and complexity narrative. SR016, SR020, SR021, SR024
CR027 Recent 2026 recognition on the Fortune Cyber 60 and Citizens Cyber 66 lists strengthens Teleport's visibility but does not remove feature-parity or platform-bundling risk. SR033, SR034
CR028 Teleport publicly disclosed funding of $25 million in Series A, $30 million in Series B, and $110 million in Series C for roughly $140 million raised in total. SR002, SR003, SR004
CR029 Teleport's Series C was announced in March 2022 at a $1.1 billion valuation led by Bessemer Venture Partners, and no newer round is visible in the provided source corpus. SR002, SR012
CR030 The only ARR figure in the reviewed source set is GetLatka's estimate of $49 million for 2024, which should be treated as external and unverified. SR032
CR031 If the $49 million ARR estimate were directionally correct, Teleport's last disclosed $1.1 billion valuation would imply an ARR multiple of roughly 22 times. SR002, SR032
CR032 The current public evidence set does not disclose profitability, burn, gross margin, net retention, or cash runway. SR002, SR005, SR032
CR033 A four-year-stale private valuation anchor combined with limited current financial disclosure creates meaningful financing and mark risk for investors entering today. SR012, SR013, SR030, SR032
CR034 Public competitors such as CyberArk and Okta have vastly larger visible revenue bases and organizational resources than Teleport. SR020, SR021, SR026, SR027, SR028, SR029
CR035 Teleport's official about materials identify Ev Kovyrin as CEO, Sasha Klizhentas as CTO, and Taylor Wakefield as COO, concentrating visible leadership around three co-founders. SR005
CR036 The reviewed public corpus does not disclose a formal succession plan, management bench map, or employee-count update for Teleport. SR005
CR037 Teleport has repositioned itself around AI infrastructure identity, expanding the company story beyond core privileged access and zero-trust access. SR035, SR036
CR038 Teleport announced the Agentic Identity Framework in January 2026, showing that the company is actively investing in a still-emerging control plane for AI agents. SR035
CR039 Beams launched in public beta in June 2026, which means product maturity, adoption proof, and support economics are still early. SR036
CR040 Because Beams is early stage and cloud-oriented, some security-sensitive or self-hosted buyers may wait for broader maturity before treating it as production infrastructure. SR010, SR036
CR041 Delegating infrastructure access to AI agents introduces governance questions around delegated permissions, tool-use boundaries, audit scope, and runtime isolation even when core human access controls are mature. SR014, SR015, SR035, SR036
CR042 Teleport's compliance posture and enterprise traction help credibility, but simultaneously executing core PAM growth and a new AI-runtime motion increases roadmap complexity. SR016, SR025, SR033, SR034, SR035
CR043 The three diligence topics most likely to change underwriting outcomes quickly are license transition exposure, FedRAMP authorization ambiguity, and current financial proof. SR001, SR006, SR008, SR032
CR044 Practical kill criteria include unresolved v16 licensing objections, inability to prove HA resilience, failure to reconcile present commercial metrics, or over-rotation into AI before core PAM economics are proven. SR001, SR006, SR016, SR032, SR036
CR045 The highest-value next diligence package is a legal memo on licensing, a resilience package for control-plane uptime, a precise regulated-cloud posture statement, and current board-level financial metrics. SR001, SR006, SR008, SR023, SR032
CR046 AWS Systems Manager Session Manager offers a managed shell-access path for AWS-centric estates, reducing the need for a separate third-party infrastructure-access layer in simpler deployments. SR037
CR047 Azure Bastion provides Microsoft-native browser and RDP or SSH access into private Azure resources, narrowing Teleport's differentiation for Azure-concentrated customers. SR038
CR048 Google Cloud Identity-Aware Proxy offers an identity-aware control point for Google-hosted applications and VM access, making single-cloud substitution a real risk for parts of Teleport's workload mix. SR039
CR049 Microsoft Entra Privileged Identity Management brings just-in-time privileged access and approval workflows into the Microsoft identity stack, increasing bundling pressure on standalone vendors. SR040
CR050 Teleport's own authorization documentation shows deep RBAC and policy expressiveness, but that same policy depth can increase implementation and change-management complexity in large enterprises. SR023, SR041
CR051 TLS Routing and proxy peering expand Teleport's network flexibility for multi-cluster estates, but they also add migration and traffic-management complexity that operators must own. SR042, SR043
CV001 Teleport's last known post-money valuation is $1.1B from the May 2022 Series C. SV001, SV008
CV002 The Series C raised $110M and was led by Bessemer Venture Partners with Insight Venture Partners participating. SV001, SV008
CV003 Teleport has disclosed approximately $165M of total primary capital across Series A, Series B, and Series C. SV001, SV002, SV003
CV004 No new primary equity round has been announced in official Teleport materials since May 2022, making the $1.1B mark more than four years stale as of June 2026. SV001, SV030
CV005 GetLatka estimates Teleport's 2024 ARR at $49M, and that figure is unconfirmed by Teleport. SV010
CV006 Using the $1.1B Series C mark and the $49M GetLatka ARR estimate implies about 22.4x EV/ARR. SV001, SV010
CV007 CyberArk had about $20.63B market capitalization and $1.30B TTM revenue in June 2026, implying roughly 15.8x EV or market cap to revenue. SV011, SV012
CV008 Okta had about $20.65B market capitalization and $2.91B TTM revenue in June 2026, implying roughly 7.1x revenue. SV013, SV014
CV009 CyberArk revenue increased from roughly $0.75B in 2023 to $1.00B in 2024 and to about $1.30B on a TTM basis in 2025-2026, indicating about 30% year-over-year growth. SV012, SV020
CV010 The PAM market is sized at $4.50B in 2025 and forecast to grow at 23.4% CAGR to $29.88B by 2034. SV015
CV011 The zero-trust security market is sized at $40.01B in 2025 and forecast to grow at 16.39% CAGR to $182.59B by 2035. SV016
CV012 Teleport says it serves more than 600 customers, including three of the top five financial services firms. SV001, SV004
CV013 Bessemer described Teleport as building the unified access plane for DevOps and infrastructure access. SV008
CV014 Teleport said ARR growth was 2.5x year over year at the time of the Series B raise. SV002
CV015 Teleport said ARR growth was 2.8x year over year at the time of Series C and that net new ARR grew 4.5x. SV001
CV016 The 2024 community-edition license change could reduce bottom-up open-source conversion and alter ARR growth trajectory. SV007, SV029
CV017 StrongDM, BeyondTrust, CyberArk, Okta, and HashiCorp Boundary all compete for privileged or infrastructure access workflows with more capital resources than Teleport. SV021, SV022, SV023, SV025, SV026, SV032, SV042, SV043
CV018 Using the $49M ARR estimate and roughly 246 employees as an unverified headcount proxy implies around $199K ARR per employee. SV010, SV039
CV019 Teleport's Agentic Identity Framework launch and the Beams public beta mark a 2026 AI-agent identity repositioning. SV031, SV033, SV034
CV020 No public secondary pricing source was located in the reviewed materials for Teleport shares as of the run date.
CV021 Teleport was named to the Fortune Cyber 60 list and the Citizens Securities Cyber 66 list in 2025-2026, signaling market recognition. SV005, SV006
CV022 Bessemer's State of the Cloud 2024 argues that AI has revived premium private-market software investing and references a $1B AI commitment. SV009
CV023 Bessemer invested in Teleport's Series C alongside Insight Venture Partners. SV001, SV008
CV024 A research-more recommendation is warranted because current public evidence is insufficient to underwrite the $1.1B mark with high confidence. SV001, SV010, SV011, SV012, SV013, SV014
CV025 Teleport at about 22.4x unconfirmed ARR screens expensive relative to CyberArk at roughly 15.8x verified revenue. SV001, SV010, SV011, SV012
CV026 Okta's privileged-access product expands overlap with Teleport and can compress the premium comp set available to the company. SV023, SV013, SV014
CV027 HashiCorp Boundary provides additional infrastructure-access competition and pricing context for Teleport's access plane. SV032
CV028 Third-party market research beyond Precedence also supports a large and growing PAM market opportunity. SV018, SV019, SV044, SV045
CV029 AI-agent identity is an emerging segment without an established public multiple framework, increasing model risk around any premium narrative. SV031, SV033, SV034
CV030 Teleport's Series C was priced during a 2022 software valuation regime that was materially richer than public security-software multiples in 2026. SV001, SV009, SV011, SV012, SV013, SV014
CV031 A bull case with 35% annual growth from the $49M 2024 ARR estimate reaches about $85M ARR by 2027, and at 15x implies roughly $1.28B of value. SV010, SV019, SV033, SV034
CV032 A base case with 25% annual growth from the $49M estimate reaches about $73M ARR by 2027, and at 10x to 12x implies about $730M to $875M. SV010, SV009, SV011, SV012, SV013, SV014
CV033 A bear case with 15% annual growth and license-change headwinds reaches about $60M ARR by 2027, and at 6x to 8x implies about $360M to $480M. SV007, SV010, SV009
CV034 The stale $1.1B mark sits about 26% to 50% above the base-case implied valuation range. SV001, SV010, SV009
CV035 Reviewed public sources do not disclose Teleport profitability, gross margin, NRR, or burn rate. SV004, SV010, SV030
CV036 The absence of public FedRAMP authorization for Teleport Cloud limits near-term federal and highly regulated cloud TAM capture. SV040, SV041
CV037 Teleport's investor syndicate includes Bessemer, Insight, Kleiner Perkins, and S28, which supports exit credibility even though it does not validate price. SV001, SV002, SV003, SV024
CV038 Teleport has raised about 2.9 times as much capital as its estimated 2024 ARR. SV001, SV002, SV003, SV010
CV039 High-growth security and infrastructure software companies can command roughly 15x to 25x ARR when growth is verified and sustained above 50% year over year. SV009, SV011, SV012
CV040 Teleport's disclosed 2.8x ARR growth at Series C is historical rather than current, so present growth remains unverified. SV001, SV010
CV041 For security software at roughly $40M to $60M ARR, a more defensible present-day private-market band is about 8x to 15x ARR unless growth is exceptional and verified. SV009, SV011, SV012, SV013, SV014
CV042 The absence of a new funding round since 2022 and no public IPO announcement increase liquidity risk for late-stage investors. SV001, SV030
CV043 The CE license change could raise customer acquisition costs if fewer community users convert through the old open-source funnel. SV007, SV029
CV044 A strategic acquisition by a larger security or platform vendor is a viable exit path given Teleport's category position and customer footprint. SV021, SV022, SV023, SV037
CV045 GetLatka labels its Teleport ARR figure as estimated, leaving a single-source dependency for public revenue analysis. SV010
CV046 Teleport's GitHub repository has well over 15,000 stars, supporting the view that developer awareness remains meaningful. SV029
CV047 Multiple official case studies across IBM Instana, Carta, GoTo, and Exness support Teleport's enterprise adoption narrative. SV035, SV036, SV037, SV038, SV046, SV047
CV048 Public materials do not disclose liquidation preferences, anti-dilution terms, or cap-table structure, so entry discipline must assume unknown preference overhang. SV001, SV002, SV003, SV030
CV049 Stock Analysis revenue pages reinforce that CyberArk and Okta are already multi-hundred-million to multi-billion-dollar revenue businesses, making them more mature public comp anchors than Teleport. SV049, SV050
CV050 Stock Analysis overview pages provide continuous public-market price discovery for CYBR and OKTA, highlighting how much stronger public valuation transparency is than Teleport's stale private mark. SV051, SV052
CV051 Macrotrends' long-run Okta price-to-sales history underlines that public identity-software multiples have already compressed from earlier peak periods. SV048
CV052 The gap between public-market price discovery for Okta and CyberArk and Teleport's unrefreshed 2022 private mark increases valuation-risk for any new investor entering today. SV048, SV051, SV052
CV053 Additional public-comp data sources from Stock Analysis and Macrotrends all point investors back to the same conclusion: Teleport needs fresh ARR proof before its 2022 unicorn valuation can be defended confidently. SV048, SV049, SV050, SV051, SV052
CV054 Yahoo Finance and Nasdaq both maintain live Okta market pages, underscoring that public peers benefit from continuous price discovery that Teleport does not have. SV053, SV054
CV055 The presence of multiple independent market-data venues for Okta reinforces that public-comp valuation evidence is more current and auditable than Teleport's stale private mark. SV052, SV053, SV054
来源
编号出版方标题引文
SO001 Teleport Teleport: Unified Identity Securing Classic & AI Infrastructure Teleport unifies identities — humans, machines, and AI — with strong identity implementation to speed up engineering, improve resiliency against identity-based attacks, and control AI in production infrastructure.
SO002 Teleport About Us | Teleport Global Headquarters 2100 Franklin St, Suite 400, Oakland, CA 94612. Ev Kontsevoy — Co-founder and CEO; Alexander Klizhentas — Co-founder and CTO; Taylor Wakefield — Co-founder and COO.
SO003 Teleport Teleport Raises $110 Million Series C at $1.1 Billion Valuation Teleport has just secured $110M in Series C funding … started with my co-founders Sasha Klizhentas and Taylor Wakefield in 2015. The new round values the company at $1.1 billion.
SO004 Teleport Teleport raises $30MM in series-B and launches secure access for MongoDB Secured $30M in Series B funding … net new annual recurring revenue up 5x and total annual recurring revenue up 2.5x, compared to the second quarter of 2020.
SO005 Teleport Announcing our Series A We have closed a $25MM Series A funding round led by Kleiner Perkins … customer base has exploded … including NASDAQ, Splunk, TicketMaster, Mulesoft and Samsung. We were recently able to reach profitability.
SO006 Teleport Gravitational Changes Name to Teleport Today we are officially announcing that Gravitational is becoming Teleport … moving from gravitational.com to https://goteleport.com.
SO007 Teleport Teleport Community Edition will adopt a commercial license starting with version 16 Starting with the June release of Teleport 16, we are switching Teleport Community Edition to a commercial license … Companies may use Teleport Community Edition on the condition they have less than 100 employees and less than $10MM in annual revenue.
SO008 Teleport Teleport Careers Solving big problems across multiple domains for the world's most innovative companies … more than 600 customers around the globe.
SO009 Teleport Case Studies — Secure Infrastructure Access at Leading Companies KnowBe4, Turo, Exness, Rush Street Interactive, GoTo, Carta, NASDAQ, Buyers Edge, ExtraHop, IBM Instana, ThredUP, Qwilt, Mapgears, ECMWF, Flywheel, Gladly — and many more.
SO010 Teleport Teleport Pricing
SO011 Teleport Teleport named to 2026 Fortune Cyber 60 List More than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport.
SO012 Teleport Teleport Named to Citizens Securities' 2026 Cyber 66 List Teleport has been named to the Citizens Securities 2026 Cyber 66 … recognizes the most notable privately held cybersecurity companies. 73% of cybersecurity leaders are already seeing enterprise customers ask how their platforms can help secure AI agents.
SO013 Teleport Teleport Introduces Agentic Identity Framework Teleport today announced the Teleport Agentic Identity Framework, an AI-centered framework that provides organizations with a clear roadmap for securely deploying agentic AI in production cloud and on-premises environments.
SO014 Teleport FedRAMP Compliance for Infrastructure Access Teleport provides the foundation to meet FedRAMP requirements … This includes support for the Federal Information Processing Standard FIPS 140 … This document explains how Teleport FIPS mode works and how it can help your company to become FedRAMP authorized.
SO015 Teleport IBM Instana implements streamlined access control, visibility and compliance with Teleport
SO016 Teleport Carta's Win/Win: Implementing Robust Security Controls while Improving Developer Productivity
SO017 Teleport Teleport Security Audit by Cure53 — No Critical Vulnerabilities Found No critical vulnerabilities have been discovered … The results of this second-run Cure53 security assessment of the latest release of the Teleport software … are once again very positive.
SO018 Bessemer Venture Partners Investing in Teleport and the Unified Access Plane Bessemer Growth leads the $110 million Series C. We believe Teleport will be the defining solution to this emerging massive problem, granting infrastructure access seamlessly without compromising security.
SO019 Kleiner Perkins Gravitational — Pulling Us Toward an Open and Multi-Cloud Future Ev, Sasha, and Taylor identified this tension during the formative period of the cloud era while working at Rackspace via the acquisition of their first startup, Mailgun.
SO020 GetLatka Teleport — Company Financial Data and Metrics In 2024, Teleport's revenue reached $49M … Teleport employs approximately 246 people as of 2026 … Teleport raised $140M in total funding across 2 rounds.
SO021 StrongDM StrongDM vs. Teleport — Comparison and Alternatives The Teleport agents run as root in every server you want to audit, creating a new attack vector and a new surface to protect. Teleport cloud is unreliable and availability numbers are inaccurate.
SO022 PeerSpot Teleport Reviews — User Feedback and Ratings Teleport requires improvements in initial setup and RBAC complexity. Integration with SIEM and monitoring tools could be enhanced. Pricing concerns affect large companies.
SO023 GitHub (Gravitational) gravitational/teleport — Open-Source Repository Teleport provides connectivity, authentication, access controls and audit for infrastructure … SSH nodes, Kubernetes clusters, PostgreSQL, MongoDB, CockroachDB and MySQL databases, MCP, Internal Web apps, Windows Hosts.
SO024 Teleport (Beams) Beams — Trusted Runtimes for Infrastructure Agents Beams runs each agent in an isolated Firecracker VM with built-in identity. Connected to your infrastructure and inference services — no secrets, no IAM wrestling.
SO025 Teleport The 2026 Infrastructure Identity Survey — State of AI Adoption 79% are evaluating/deploying agentic AI … only 13% feel extremely prepared … 60% have had or suspect an AI-related security incident.
SO026 Teleport FedRAMP Compliance with Teleport — Use Cases
SO027 Teleport Teleport Debuts Delegated Agentic Identity and LLM Proxy in Beams Public Beta
SO028 Teleport Teleport Newsroom — Latest News and Press Releases
SO029 Precedence Research Privileged Access Management Market Size to Hit USD 29.88 Bn by 2034 The global privileged access management market size is accounted at USD 4.50 billion in 2025 and is predicted to increase … to approximately USD 29.88 billion by 2034, expanding at a CAGR of 23.40%.
SO030 NIST Zero Trust Architecture — NIST Special Publication 800-207 Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location … Authentication and authorization are discrete functions performed before a session to an enterprise resource is established.
SM001 Teleport Teleport homepage AI Infrastructure Identity Company
SM002 Teleport Teleport raises Series C $110 million Series C financing at a $1.1 billion valuation
SM003 Teleport Infrastructure Identity Survey 2026 92% have near-term AI initiatives and only 13% feel extremely prepared
SM004 Teleport Teleport named to 2026 Fortune Cyber 60 list 600+ customers including three of the top five financial services firms
SM005 Teleport Teleport named 2026 Cyber 66 hottest privately held cybersecurity companies 73% of cybersecurity leaders see enterprise customers asking about AI agent security
SM006 NIST Zero Trust Architecture (SP 800-207) Zero trust provides a collection of concepts and ideas designed to minimize uncertainty in enforcing accurate, least privilege per-request access decisions.
SM007 CISA Zero Trust Maturity Model Five pillars plus three cross-cutting capabilities structure federal zero-trust implementation.
SM008 Grand View Research (archived) Privileged Access Management market report archive
SM009 Precedence Research Privileged Access Management market The global privileged access management market size was valued at USD 4.50 billion in 2025 and is projected to reach USD 29.88 billion by 2034.
SM010 Grand View Research (archived) Zero Trust Security market report archive The global zero trust security market size was valued at USD 36.96 billion in 2024 and is expected to grow at a CAGR of 16.6% from 2025 to 2030.
SM011 Precedence Research Zero Trust Security market The global zero trust security market size is calculated at USD 40.01 billion in 2025 and is forecasted to hit around USD 182.59 billion by 2035.
SM012 Bessemer Venture Partners Investing in Teleport and the Unified Access Plane Infrastructure access is a new and exciting product category.
SM013 Bessemer Venture Partners State of the Cloud 2024
SM014 Kleiner Perkins Gravitational: Pulling Us Toward an Open and Multi-Cloud Future
SM015 Teleport Identity Security
SM016 Teleport FedRAMP compliance documentation Teleport provides support for FIPS 140 cryptographic modules.
SM017 Teleport SOC 2 compliance documentation
SM018 Teleport FedRAMP compliance use case
SM019 Teleport Accelerate FedRAMP compliance
SM020 Teleport Automating identity access for FedRAMP 20x
SM021 GetLatka goteleport.com company profile
SM022 Teleport Pricing
SM023 Teleport Case studies
SM024 Teleport How it works
SM025 GitHub gravitational/teleport repository 15,000+ stars
SM026 Fortune Business Insights Privileged Access Management market page returned unrelated agricultural content Retained URL returned content about agricultural microbials rather than privileged access management.
SM027 Teleport Newsroom
SM028 Teleport Feature matrix
SM029 StrongDM StrongDM vs Teleport Teleport is a point solution for modern cloud architecture.
SP001 StrongDM StrongDM homepage
SP002 CyberArk What is Privileged Access Management (PAM)?
SP003 CyberArk Privileged Access Manager
SP004 BeyondTrust Privileged Access Management (PAM) glossary
SP005 BeyondTrust Privileged Remote Access
SP006 Delinea Secret Server
SP007 Okta Okta Privileged Access
SP008 HashiCorp What is Boundary?
SP009 PeerSpot Teleport Reviews
SP010 PeerSpot Teleport Alternatives and Competitors
SP011 Slashdot Teleport Alternatives
SP012 CompaniesMarketCap CyberArk market cap
SP013 CompaniesMarketCap CyberArk revenue
SP014 CompaniesMarketCap Okta market cap
SP015 CompaniesMarketCap Okta revenue
SP016 Teleport Reference Architecture
SP017 Teleport Core Concepts
SP018 Teleport Teleport 16
SP019 Teleport Teleport 17
SP020 Teleport Teleport Security Audit
SP021 Teleport Identity Security
SP022 Teleport Teleport Introduces Agentic Identity Framework
SP023 Teleport Teleport Community License
SP024 Teleport Agentic Identity Framework docs
SP025 Teleport Machine & Workload Identity
SP026 StrongDM StrongDM vs Teleport
SP027 Bessemer Venture Partners Investing in Teleport and the Unified Access Plane
SP028 Teleport Gravitational is Teleport
SP029 Teleport Pricing
SP030 GitHub gravitational/teleport repository
SP031 Teleport Feature Matrix
SI001 Teleport GoTo Secures and Simplifies Cloud Access with Teleport GoTo streamlines multi-cloud access management and enhances security across their infrastructure with Teleport.
SI002 Teleport Exness Elevates Global Kubernetes and Infrastructure Security with Teleport Exness is one of the world's largest trading technology companies … As a regulated financial services provider, Exness treats security as a core business priority.
SI003 Teleport Secure Cloud Infrastructure Access with Teleport: A Gladly Case Study Gladly selected Teleport to secure the cloud-native infrastructure … meeting international compliance requirements.
SI004 Teleport ExtraHop Secures Access with Identity to Kubernetes and Server Infrastructure ExtraHop used Teleport to secure access to their servers and Kubernetes clusters without sacrificing speed … an identity-based approach to authorizing each developer.
SI005 Teleport Machine and Workload Identity — AI Agent Use Cases Teleport enables you to enforce access and privileges for agents. Security must be enforced deterministically; AI agents cannot be trusted to follow high-level instructions like "don't delete production". Teleport solves this by issuing each agent its own identity.
SI006 Teleport Database Access — Enroll Resources
SI007 Teleport Teleport Session Recording Architecture Teleport captures the entire pseudo-terminal (PTY) output of the session. The intention is for session recording to document what a user saw when they ran a session.
SI008 Teleport Teleport LLMs.txt — Company and Product Summary Teleport, the AI Infrastructure Identity Company, establishes a unified identity layer for infrastructure — humans, machines, workloads, and AI agents — secured cryptographically. Headquartered in Oakland, CA, Teleport operates globally.
SI009 Teleport Elasticsearch RBAC and Auditing with Teleport
SI010 Teleport MCP Servers — Enroll Resources
SI011 U.S. Securities and Exchange Commission (EDGAR) CyberArk Software Ltd. Form 20-F Annual Report (Fiscal Year 2024)
SI012 GetLatka Teleport — Company Financial Data and Metrics In 2024, Teleport's revenue reached $49M … Teleport employs approximately 246 people as of 2026 … Teleport raised $140M in total funding across 2 rounds.
SI013 Teleport Teleport Pricing
SI014 Bessemer Venture Partners Investing in Teleport and the Unified Access Plane Bessemer Growth leads the $110 million Series C. We believe Teleport will be the defining solution … granting infrastructure access seamlessly without compromising security.
SI015 Teleport Teleport Raises $110 Million Series C at $1.1 Billion Valuation Teleport has just secured $110M in Series C funding … net new annual recurring revenue up 4.5x and total annual recurring revenue up 2.8x year over year. The new round values the company at $1.1 billion.
SI016 Teleport Teleport raises $30MM in series-B and launches secure access for MongoDB Net new annual recurring revenue up 5x and total annual recurring revenue up 2.5x, compared to the second quarter of 2020.
SI017 Teleport Announcing our Series A We have closed a $25MM Series A funding round led by Kleiner Perkins … We were recently able to reach profitability.
SI018 Teleport Teleport Community Edition will adopt a commercial license starting with version 16 Companies may use Teleport Community Edition on the condition they have less than 100 employees and less than $10MM in annual revenue.
SI019 CompaniesMarketCap CyberArk Software (CYBR) — Market Capitalization As of June 2026 CyberArk Software has a market cap of $20.63 Billion USD.
SI020 CompaniesMarketCap CyberArk Software (CYBR) — Revenue CyberArk Software's current revenue (TTM) is $1.30 Billion USD. In 2024 the company made a revenue of $1.00 Billion USD.
SI021 CompaniesMarketCap Okta (OKTA) — Market Capitalization As of June 2026 Okta has a market cap of $20.65 Billion USD.
SI022 CompaniesMarketCap Okta (OKTA) — Revenue Okta's current revenue (TTM) is $2.91 Billion USD. In 2025 the company made a revenue of $2.91 Billion USD an increase over the revenue in the year 2024 that were of $2.61 Billion USD.
SI023 PeerSpot Teleport Reviews — User Feedback and Ratings Pricing concerns affect large companies … Teleport requires improvements in initial setup and RBAC complexity.
SI024 StrongDM StrongDM vs. Teleport — Comparison and Alternatives The Teleport agents run as root in every server you want to audit, creating a new attack vector … Pricing concerns affect large companies.
SI025 Kleiner Perkins Gravitational — Pulling Us Toward an Open and Multi-Cloud Future
SI026 Precedence Research Privileged Access Management Market Size to Hit USD 29.88 Bn by 2034 The global privileged access management market size is accounted at USD 4.50 billion in 2025 and is predicted to increase … to approximately USD 29.88 billion by 2034, expanding at a CAGR of 23.40%.
SI027 NIST Zero Trust Architecture — NIST Special Publication 800-207
SE001 Teleport Teleport: Unified Identity Securing Classic & AI Infrastructure Teleport unifies identities — humans, machines, and AI — with strong identity implementation to speed up engineering, improve resiliency against identity-based attacks, and control AI in production infrastructure.
SE008 Teleport Teleport Community Edition will adopt a commercial license starting with version 16 Starting with the June release of Teleport 16, we are switching Teleport Community Edition to a commercial license with new restrictions
SE009 Teleport Introducing Teleport 16 - Enhanced Security and Usability with New Features
SE010 Teleport Introducing Teleport 17 - Enhanced Security and Usability with New Features
SE011 Teleport Teleport Explained: Concepts & Architecture Guide Teleport is a certificate authority and identity-aware access proxy that implements protocols such as SSH, RDP, HTTPS, Kubernetes API, and a variety of SQL and NoSQL database protocols.
SE012 Teleport Teleport Pricing
SE017 Teleport Teleport Reference Architecture
SE018 Teleport Teleport Core Concepts
SE019 Teleport Teleport Feature Matrix The Teleport Agentic Identity Framework combines Teleport identity, access, governance, and monitoring capabilities to secure AI agents and the infrastructure they access.
SE020 Teleport Machine & Workload Identity Documentation
SE022 Teleport MCP Server Access Documentation
SE023 Teleport Teleport Identity Security Documentation
SE024 Teleport Session Recording Architecture
SE025 Teleport FedRAMP Compliance with Teleport Teleport releases from 17.7.3+ and 18.0.0+ use BoringCrypto tag fips-20220613 (CMVP certificate #4735, FIPS 140-3)
SE026 Teleport SOC 2 Compliance with Teleport
SE027 Teleport Teleport Upcoming Releases
SE028 Teleport Identity Security Blog Post
SE029 Teleport Teleport Security Audit by Cure53 No critical vulnerabilities have been discovered. One high vulnerability was found: The roles API of the auth server allow directory traversal.
SE030 Teleport Teleport Introduces Agentic Identity Framework
SE031 Teleport Beams LLM Proxy and Delegated Identity Public Beta Two foundational identity concepts — controlling the scope of agent roles and constraining what they can access — now have a production implementation in Beams
SE032 Teleport 2026 Infrastructure Identity Survey: State of AI Adoption 92% have near-term AI initiatives in infrastructure... but only 13% feel extremely prepared
SE033 Teleport Agentic Identity Framework Documentation
SE034 Teleport AI Agents with Machine & Workload Identity
SE035 Beams (Teleport) Beams — Trusted Runtimes for Infrastructure Agents Beams runs each agent in an isolated Firecracker VM with built-in identity. Connected to your infrastructure and inference services — no secrets, no IAM wrestling.
SE036 GitHub (gravitational/teleport) Teleport Open Source Repository Teleport is a single Go binary that integrates with multiple protocols and cloud services
SE041 NIST Zero Trust Architecture (SP 800-207)
SE042 CISA Zero Trust Maturity Model
SE043 StrongDM StrongDM vs Teleport Comparison The Teleport agents run as root in every server you want to audit, creating a new attack vector and a new surface to protect... Teleport cloud is unreliable and availability numbers are inaccurate.
SE051 HashiCorp What is Boundary?
SE052 PeerSpot Teleport Reviews I rate it a seven because, as I mentioned, there is a security threat regarding clipboard access.
SE054 Teleport FedRAMP Compliance Use Case
SE053 Teleport Teleport Named to Citizens Securities 2026 Cyber 66 73% of cybersecurity leaders are already seeing enterprise customers ask how their platforms can help secure AI agents
SE037 Bessemer Venture Partners Investing in Teleport and the Unified Access Plane Teleport will be the defining solution to this emerging massive problem, granting infrastructure access seamlessly without compromising security.
SE039 Kleiner Perkins Gravitational: Pulling Us Toward an Open and Multi-Cloud Future
SE055 Teleport Teleport Database Access Documentation
SE056 Teleport Teleport Security Page — Code Signing and Certificates
SE057 Teleport Teleport Blog
SE058 Teleport Elasticsearch Database Access — Self-Hosted Enrollment
SE059 Teleport Teleport Identity Governance
SE060 Teleport Teleport Proxy Service
SE061 Teleport Teleport Authentication
SE062 Teleport Deploying Teleport Agents
SE063 Teleport Teleport tsh Client Documentation
SU001 Teleport Teleport Customer Case Studies When security and a frictionless engineering experience matter, the most innovative companies in the world trust Teleport for Infrastructure Identity.
SU002 Teleport GoTo Customer Case Study All our Kubernetes clusters are private—meaning they can't be accessed publicly, both for the data plane and control plane. We needed a mechanism to securely expose this to developers, and Teleport fit our requirements perfectly.
SU003 Teleport Exness Customer Case Study Teleport was the only evaluated solution that met every requirement.
SU004 Teleport Gladly Customer Case Study
SU005 Teleport ExtraHop Customer Case Study
SU006 Teleport IBM Instana Customer Case Study This is company number three I've done this at, to have Teleport in play to give us the ability to go and help our security posture
SU007 Teleport Carta Customer Case Study
SU008 Teleport Announcing our Series A our customer base has exploded from a handful of early adopters to an impressive portfolio of some of the world's largest and most innovative companies, including NASDAQ, Splunk, TicketMaster, Mulesoft and Samsung.
SU009 Teleport Teleport Raises $110 Million Series C at $1.1 Billion Valuation fantastic logos like Nasdaq, Doordash, and Snowflake, make Teleport a category-defining company
SU010 Teleport Teleport Raises $30M in Series B
SU011 Teleport Teleport Named to 2026 Fortune Cyber 60 More than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport to reduce risk and simplify access.
SU012 Teleport Teleport Newsroom
SU013 Bessemer Venture Partners Investing in Teleport and the Unified Access Plane Its secretless security model and focus on developer productivity, along with fantastic logos like Nasdaq, Doordash, and Snowflake, make Teleport a category-defining company
SU014 GitHub (gravitational/teleport) Teleport Open Source Repository
SU015 PeerSpot Teleport Alternatives and Competitors
SU016 Slashdot Best Teleport Alternatives in 2026
SU017 Latka (getlatka.com) Teleport Revenue and Company Data In 2024, Teleport's revenue reached $49M. Since its launch in 2015, Teleport has shown consistent revenue growth.
SU018 Teleport Teleport Community Edition License Change
SU019 Precedence Research Privileged Access Management Market Report 2025-2034
SU020 StrongDM StrongDM vs Teleport Comparison Teleport only supports more modern systems that will allow their certificate-based authentication.
SU021 Teleport 2026 Infrastructure Identity Survey
SU022 Kleiner Perkins Gravitational: Pulling Us Toward an Open and Multi-Cloud Future
SU023 PeerSpot Teleport Reviews Teleport changed our workflow by centralizing access control and reducing manual SSH key management.
SU024 Teleport Teleport Named Citizens Securities 2026 Cyber 66 recognized in the Cyber 66 report as a revenue category mover, reflecting continued business momentum
SU025 Teleport Teleport About Page
SU026 Teleport Teleport Elasticsearch Integration
SU027 Teleport Teleport LLMs.txt — AI Infrastructure Identity Company trusted by industry-leading organizations including Nasdaq, IBM, Doordash, Elastic, and GoTo
SU028 Fortune Business Insights Privileged Access Management Market Size and Growth Report
SU029 Teleport Turo Streamlines Infrastructure Access with Teleport
SU030 Teleport KnowBe4 Case Study
SU031 Teleport How TigerGraph Enhances Global Access Control with Teleport
SU032 Teleport ECMWF Secure Access to Supercomputing Clusters with Teleport
SU033 Teleport RSI Levels Up Cloud Security with Teleport Infrastructure Identity
SU034 Teleport Mapgears Boosts Customer Support with Teleport's Secure SSH Access
SU035 Teleport Securing Kubernetes Access with thredUP
SU036 Teleport Enhance Global Content Delivery with Teleport, Rundeck and Slack APIs
SU037 Teleport Secure Biomedical Research Compliance with Flywheel and Teleport Access
SR001 Teleport A new commercial license for Teleport Community Edition
SR002 Teleport Teleport raises $110M in Series C funding
SR003 Teleport Gravitational raises Series A funding
SR004 Teleport Teleport raises Series B funding
SR005 Teleport About Teleport
SR006 Teleport Docs FedRAMP compliance framework
SR007 Teleport Docs SOC 2 compliance framework
SR008 Teleport FedRAMP compliance use case
SR009 Teleport Teleport security audit
SR010 Teleport Teleport pricing
SR011 GitHub gravitational/teleport
SR012 Bessemer Venture Partners Investing in Teleport and the unified access plane
SR013 Bessemer Venture Partners State of the Cloud 2024
SR014 NIST Zero Trust Architecture
SR015 CISA Zero Trust Maturity Model
SR016 StrongDM StrongDM vs Teleport
SR017 StrongDM StrongDM homepage
SR018 CyberArk What is Privileged Access Management?
SR019 CyberArk Privileged Access Manager
SR020 BeyondTrust Privileged Access Management (PAM)
SR021 Okta Okta Privileged Access
SR022 HashiCorp What is Boundary?
SR023 PeerSpot Teleport reviews
SR024 PeerSpot Teleport alternatives and competitors
SR025 Slashdot Teleport alternatives
SR026 CompaniesMarketCap CyberArk market cap
SR027 CompaniesMarketCap CyberArk revenue
SR028 CompaniesMarketCap Okta market cap
SR029 CompaniesMarketCap Okta revenue
SR030 Precedence Research Privileged Access Management market
SR031 Open Source Initiative The Open Source Definition
SR032 GetLatka Teleport company profile
SR033 Teleport Teleport named to 2026 Fortune Cyber 60 list
SR034 Teleport Teleport named to 2026 Cyber 66
SR035 Teleport Docs Agentic Identity Framework
SR036 Beams Beams homepage
SR037 AWS AWS Systems Manager Session Manager
SR038 Microsoft What is Azure Bastion?
SR039 Google Cloud Identity-Aware Proxy overview
SR040 Microsoft What is Privileged Identity Management?
SR041 Teleport Docs Teleport Authorization
SR042 Teleport Docs TLS Routing
SR043 Teleport Docs Proxy Peering Migration
SV001 Teleport Teleport raises $110M in Series C funding
SV002 Teleport Teleport raises $30M in Series B funding
SV003 Teleport Gravitational raises Series A funding
SV004 Teleport About Teleport
SV005 Teleport Teleport named to the 2026 Fortune Cyber 60 list
SV006 Teleport Teleport named to the 2026 Cyber 66 hottest privately held cybersecurity companies
SV007 Teleport A new commercial license for Teleport Community Edition
SV008 Bessemer Venture Partners Investing in Teleport and the unified access plane
SV009 Bessemer Venture Partners State of the Cloud 2024
SV010 GetLatka Teleport company profile and estimated revenue
SV011 CompaniesMarketCap CyberArk market capitalization
SV012 CompaniesMarketCap CyberArk revenue history
SV013 CompaniesMarketCap Okta market capitalization
SV014 CompaniesMarketCap Okta revenue history
SV015 Precedence Research Privileged Access Management Market
SV016 Precedence Research Zero Trust Security Market
SV017 Grand View Research via Internet Archive Zero Trust Security Market Report (archived)
SV018 Grand View Research via Internet Archive Privileged Access Management Market Report (archived)
SV019 Fortune Business Insights Privileged Access Management Market
SV020 Securities and Exchange Commission CyberArk Software Ltd. EDGAR company filings
SV021 CyberArk What is Privileged Access Management?
SV022 CyberArk CyberArk Privileged Access Manager
SV023 Okta Okta Privileged Access
SV024 Kleiner Perkins Gravitational: pulling us toward an open and multi-cloud future
SV025 StrongDM StrongDM vs Teleport
SV026 PeerSpot Teleport alternatives and competitors
SV027 Slashdot Teleport alternatives
SV028 Teleport Infrastructure Identity Survey 2026
SV029 GitHub gravitational/teleport repository
SV030 Teleport Teleport newsroom
SV031 Beams Beams
SV032 HashiCorp What is Boundary?
SV033 Teleport Teleport introduces Agentic Identity Framework
SV034 Teleport Beams LLM proxy with delegated identity
SV035 Teleport IBM Instana case study
SV036 Teleport Carta case study
SV037 Teleport GoTo case study
SV038 Teleport Exness case study
SV039 Teleport Careers at Teleport
SV040 Teleport Accelerate FedRAMP compliance
SV041 Teleport Automating identity and access for FedRAMP 20x
SV042 BeyondTrust BeyondTrust Privileged Remote Access
SV043 Delinea Secret Server
SV044 Grand View Research Privileged Access Management Market Report
SV045 Grand View Research Zero Trust Security Market Report
SV046 Teleport Gladly case study
SV047 Teleport ExtraHop case study
SV048 Macrotrends Okta price to sales ratio
SV049 Stock Analysis CyberArk Software revenue
SV050 Stock Analysis Okta revenue
SV051 Stock Analysis CyberArk Software stock price and overview
SV052 Stock Analysis Okta stock price and overview
SV053 Yahoo Finance Okta stock price, news, quote and history
SV054 Nasdaq OKTA stock page