Teleport
开源基础设施身份平台,拿下强势企业客户标识,但 2022 年独角兽估值已经过时。
Teleport 产品深度和企业客户验证都真实存在;但 2022 年独角兽估值已经陈旧、当前 ARR 未核实,加上许可与采购摩擦风险,投资判断仍受约束。
封面要素
公司概况
Teleport 是一家成立于 2015 年的私有基础设施身份公司,把服务器、Kubernetes 集群、数据库、Web 应用、机器和 AI 代理的访问与策略统一起来。公司从开源访问项目长成多模块商业平台,覆盖 Zero Trust Access、Machine and Workload Identity、Identity Governance、Identity Security,以及 Beams 代理运行时。Teleport 已在三轮已披露融资中募资 $165M,2022 年 5 月估值达到 $1.1B,并在科技、金融科技和受监管基础设施领域有强势具名客户背书,但当前财务画像仍大多未披露。
- 成立时间
- 2015-01-01
- 创始人
- Ev Kontsevoy, Alexander Klizhentas, Taylor Wakefield
- 创立地点
- Oakland, California, USA
- 总部
- Oakland, California, USA
- 产品
- 基于证书的基础设施身份平台,覆盖 SSH、Kubernetes、数据库、Web 应用、Windows / RDP、MCP 服务器、机器身份和 AI 代理运行时。
- 客户
- 中端市场和企业级工程、平台、安全、金融科技及受监管基础设施团队。
- 商业模式
- 按用量计费的企业 SaaS 和自托管软件,按月活跃用户、机器 / 工作负载身份和受保护资源变现;免费社区层只面向较小公司。
- 阶段
- Series C private
- 融资情况
- 2022 年 5 月以 $1.1B 估值完成 $110M Series C;已披露融资总额 $165M;此后无已验证新融资轮。
执行摘要
主要优势
- 基于证书的统一访问架构覆盖 SSH、Kubernetes、数据库、Web 应用和机器身份。
- 开源分发和庞大 GitHub 足迹支撑了强开发者可信度。
- 已披露蓝筹客户包括 Nasdaq、DoorDash、IBM Instana、Carta、Samsung、Elastic 和 Snowflake。
- Kleiner Perkins、S28、Bessemer 和 Insight 组成的强投资人组合支撑品类创建。
- 新的 AI-agent 身份和 Beams 定位若能落地采用,可能打开额外增长楔子。
主要风险
- $1.1B Series C 估值已经陈旧,相比 2026 年公开身份和 PAM 可比公司显得偏贵。
- 唯一当前 ARR 数字(2024 年 $49M)来自第三方估计,并非公司确认数据。
- 2024 年 6 月社区许可证变更可能削弱自下而上转化和社区好感。
- 公开资料支持其拥有 FedRAMP 合规工具,但未验证 Teleport Cloud 本身获得 FedRAMP 授权。
- 大型竞争对手和云原生替代方案可以打包相邻身份与特权访问能力。
未决问题
- 当前 ARR、毛利率、烧钱速度、现金跑道和 NRR 均未公开披露。
- 600+ 客户数字由公司自述,尚未独立验证。
- 可访问公开资料仍无法确认 Teleport Cloud 的 FedRAMP 授权状态。
- 除已宣布投资人外,股权结构条款、清算优先权和董事会构成仍属私密。
- 二级市场定价或任何 2022 年后更新估值证据均未公开。
目录
01公司概览
1.1 身份、使命、产品和总部
Teleport 自称「AI Infrastructure Identity Company」,总部位于加利福尼亚州奥克兰 Franklin St 2100 号 Suite 400,邮编 94612。公司为基础设施改造身份、访问和策略,把产品定位成一个平台:既提升工程速度,也增强对身份攻击的韧性。公司最初注册为 Gravitational Inc.,2021 年更名为 Teleport,并从 gravitational.com 迁至 goteleport.com;宣布更名的博客明确称,Teleport 产品已成为公司的主要重心。法律实体在包签名证书上仍保留 Gravitational Inc. 公司名(Apple Developer ID QH8AA5B8UP Gravitational Inc.),证明公司延续性。 Teleport 将产品描述为统一身份层,用证书颁发机构模型取代服务器(SSH)、Kubernetes、数据库、RDP、Web 应用和 MCP 服务器之间碎片化的访问管理系统;该模型为请求者身份签发短期凭证。该架构与 NIST SP 800-207 Zero Trust Architecture 框架一致:零信任消除基于网络位置的隐式信任,并要求每次请求都认证和授权。公开定价页显示,收入模型按用量计费,计量口径包括 Monthly Active Users(MAU)、Machine and Workload Identities(MWI)和 Teleport Protected Resources(TPR)。Community Edition 对员工少于 100 人且年收入低于 $10M 的公司免费,Enterprise Edition 则需要商业接洽。公司为私有企业;未公开收入、利润率、现金或烧钱数据。[CO001, CO002, CO003, CO004, CO005, CO006]
| 指标 | 数值 / 状态 | 日期 | 置信度 | 缺口 |
|---|---|---|---|---|
| 创立年份 | 2015 | 2015 | 高 | |
| 法定名称 | Gravitational Inc.(以 Teleport 名义经营) | 2021 | 高 | |
| 总部 | 2100 Franklin St Suite 400,Oakland,CA 94612(总部地址) | 2026-06 | 高 | |
| 阶段 | 私有 / Series C | 2022-05 | 高 | |
| 最新估值(USD B) | 1.1 | 2022-05 | 中 | 2022 年后融资未确认;估值标记已过时约 4 年 |
| Series A 融资额(USD M) | 25 | 2019(约) | 高 | 博客未说明准确日期 |
| Series B 融资额(USD M) | 30 | 2021 | 高 | |
| Series C 融资额(USD M) | 110 | 2022-05 | 高 | |
| 已披露融资总额(USD M) | 165 | 2022-05 | 高 | |
| 2024 ARR(USD M,估算) | ~49(GetLatka,未确认) | 2024-12 | 低 | 未验证的第三方估算;公司未确认 |
| 员工数(估算) | ~246(GetLatka,2025 年 11 月) | 2025-11 | 低 | 估算值;未披露官方员工数 |
| GitHub stars | 15000+ | 2024-06 | 中 | 截至社区许可博客发布时;可能已增长 |
| 具名客户 | 600+ | 2026-06 | 中 | 公司表述;总数没有第三方验证 |
| 收入模式 | 基于用量(MAU / MWI / TPR) | 2026-06 | 高 | |
| 源代码许可 | AGPLv3(未变) | 2024-06 | 高 | |
| 二进制 / 镜像许可 | 商业许可(自 Teleport 16 起限制大型公司) | 2024-06 | 高 | |
| FedRAMP 状态 | 仅 FIPS / 合规工具——未确认 SaaS ATO | 2026-06 | 中 | 没有 Teleport Cloud ATO 的公开证据 |
除标注为估算外,所有财务数字均为公司披露数据。GetLatka ARR 和员工数是第三方估算,未经独立确认。估值为 2022 年 Series C 标记;没有可用更新。
[CO001, CO004, CO014, CO015, CO016, CO018]公开可支撑的 KPI 显示,这是一家资本充足、企业 logo 强的私营公司;但关键财务指标仍未确认,估值标记已过时四年。
ARR 和员工数是 GetLatka 第三方估算;其他所有数值来自已披露的公司或投资者材料。
[CO014, CO015, CO016, CO017, CO018, CO020]1.2 创始人、领导层和关键人物集中度
Teleport 由三位联合创始人于 2015 年创立。三人在 Rackspace 收购 Mailgun 后于 Rackspace 共事,Mailgun 是他们此前打造的开发者邮件基础设施创业公司。Ev Kontsevoy 担任 CEO,是公司最主要的公开声音。Alexander Klizhentas(Sasha)担任 CTO。Taylor Wakefield 担任 COO。截至本次报告日期,Teleport 关于页面确认三人仍在活跃高管岗位。创始团队共同具备云基础设施和开发者工具背景,这是公开来源中最清晰的创始人—市场匹配信号。 创始团队之外的领导层包括 CRO Jeff Bunten 和 CMO Diana Jovin,二人均出现在外部媒体报道中。Jovin 于 2026 年 4 月在 RSAC 被引用,新闻室也称其为 CMO。Bunten 在关于页面列为 CRO。关键人物风险不低:Kontsevoy 签署了三次融资公告,是 Agentic Identity Framework 发布和 Fortune Cyber 60 公告中的具名发言人,也出现在每一次主要外部访谈中。除融资轮中提到的投资人外,公司未公开更多董事会成员。[CO007, CO008, CO009, CO010, CO011, CO012]
| 人员 | 职位 | 背景 | 创始人-市场契合 / 职能覆盖 | 关键人物依赖 |
|---|---|---|---|---|
| Ev Kontsevoy | 联合创始人兼 CEO | 联合创立 Mailgun(被 Rackspace 收购);在 Rackspace 搭建云基础设施 | 深厚基础设施和开发者工具背景;主导三轮融资 | 关键——融资、公开战略和外部发言人角色均集中于其身上 |
| Alexander Klizhentas | 联合创始人兼 CTO | 与 Kontsevoy 联合创立 Mailgun;具备分布式系统和安全工程背景 | 负责开源核心和企业产品架构的技术领导 | 高——技术路线图和架构决策 |
| Taylor Wakefield | 联合创始人兼 COO | 联合创立 Mailgun;具备 GTM 和运营领导背景 | 运营规模化;与 Kontsevoy 共同领导商业执行 | 中——支持 CEO,但分担运营权重,降低单点风险 |
| Jeff Bunten | CRO | 企业销售领导背景;Series C 后加入以扩展商业打法 | 企业收入增长;负责销售和渠道 | 中——面向外部的收入负责人,但向创始人负责 |
| Diana Jovin | CMO | 网络安全营销背景;RSAC 2026 被引用 | 品牌、需求生成,以及 AI 基础设施身份叙事的产品营销 | 低——营销职能;市场上可替换 |
除已具名投资人董事会成员(Mary D'Onofrio / Bessemer;Matt Koran / Insight observer)外,董事会构成未披露。公开材料中没有出现独立董事姓名。
[CO007, CO008, CO009, CO010, CO011, CO012]1.3 融资历史、估值和资本结构
Teleport 已披露三轮融资,总额 $165M。首轮是 Kleiner Perkins 领投的 $25M Series A,公司当时仍以 Gravitational 名义运营,并在公司博客上宣布。Series A 博客列出早期客户 NASDAQ、Splunk、TicketMaster、Mulesoft 和 Samsung,并称公司近期已实现盈利。随后是 2021 年由 S28 Capital 和 Kleiner Perkins 领投的 $30M Series B;该轮发生在一个季度之后,当季净新增 ARR 同比增长 5x,总 ARR 较 2020 年 Q2 增长 2.5x,说明公司收入正从较小基数快速放大。公司当时未披露 ARR 金额。 最大一轮是 2022 年 5 月宣布的 $110M Series C,由 Bessemer Venture Partners 领投,Insight Venture Partners 参投,估值 $1.1B。Bessemer 投资博客(bvp.com)和 Teleport 公告博客均确认该估值。Series C 当时披露总 ARR 同比增长 2.8x、净新增 ARR 增长 4.5x,距离 Series B 不到一年。Bessemer 的 Mary D'Onofrio 加入董事会;Insight 的 Matt Koran 担任董事会观察员。未发现 2022 年 5 月之后后续融资轮的公开证据。因此,截至本次报告日期,$1.1B 估值标记已有约四年,私募市场环境也已明显变化。 第三方数据聚合商 GetLatka 在 2025 年快照中称 Teleport 两轮融资共 $140M,这与公司披露的三轮 $165M 不一致。GetLatka 还估算公司 2024 年收入为 $49M,2025 年底员工数约 246 人;这些数字是未经确认的第三方估算,不应视为已验证财务数据。[CO013, CO014, CO015, CO016, CO017, CO018]
| 利益相关方 | 角色 | 投资 / 参与 | 控制权或经济重要性 | 尽调问题 |
|---|---|---|---|---|
| Kleiner Perkins | 领投 Series A;共同领投 Series B | $25M Series A + 参与 $30M Series B | 最早机构支持者;董事会席位有暗示,但 Series C 后未确认 | 确认当前董事席位或观察员身份,以及持股比例 |
| S28 Capital | 与 Kleiner Perkins 共同领投 Series B | $30M Series B 共同领投方 | Series B 领投方;Series C 后股份可能被稀释 | 确认当前持股比例及任何治理权利 |
| Bessemer Venture Partners | 领投 Series C | $110M Series C;Mary D'Onofrio 加入董事会 | 最大已披露外部投资人;轮次时确认当前董事席位 | 确认董事会构成和 Series C 后当前持股比例 |
| Insight Venture Partners | 参与 Series C | 重要参与 $110M Series C;Matt Koran 任董事会观察员 | Series C 参与方;轮次日期拥有董事会观察员权利 | 确认观察员身份和当前持股比例 |
| Ev Kontsevoy / Klizhentas / Wakefield | 创始管理团队 | 创始股权;未披露买断或二级交易 | 可能为控股股东;内部股权结构未知 | 从公司法律顾问处取得 cap table,以确认所有权和稀释 |
| 员工股权持有人 | 现任和前员工 | 标准股权授予;期权池规模未知 | 集体激励机制;期权池悬挂影响稀释测算 | 向公司索取期权池规模和归属计划数据 |
| S28 Capital 跟投 | 潜在跟投投资人 | Series C 后未确认;没有跟投公开证据 | 未知;未披露 2022 年后融资 | 索取最新 cap table,以及已行使的任何 ROFR 或 pro-rata 权利 |
股权结构表为私有;所有持股均根据公开融资披露推断,可能不能反映 Series C 后的二级交易或授予。GetLatka 显示 2 轮融资共 $140M,与披露的 3 轮共 $165M 不一致。
[CO014, CO015, CO016, CO017, CO018, CO019]Teleport 的公开记录从 2015 年创立开始,经过 2022 年 $1.1B Series C,延伸到 2026 年 AI agent 产品扩张;其中 2024 年许可证变化是最不利的经营里程碑。
Series A 日期为近似值(2019 年由 KP perspectives 文章推断;确切交割月份未在已审阅来源中确认)。其他所有日期均来自官方公告。
[CO013, CO014, CO015, CO016, CO025, CO027]1.4 里程碑、规模和产品演进
Teleport 的里程碑显示,公司用约十年时间从面向开发者的访问工具,走向完整基础设施身份平台。开源 Teleport 项目于 2016 年在 GitHub 以 AGPLv3 许可证公开;到 2024 年 6 月社区许可证博客发布时,仓库已累计超过 15,000 颗星。公司在连续几个大版本中加入 Kubernetes 访问、数据库访问(PostgreSQL、MongoDB、MySQL)、Windows RDP 访问,最近又加入 MCP 服务器访问。Teleport 16(2024 年 6 月)和 Teleport 17(2024 年 10 月)是最近两个主要版本,Teleport 已改用每年一个主要版本的发布节奏。 官方材料中的具名客户标识包括 NASDAQ、Snowflake、DoorDash、IBM(Instana)、Carta、GoTo、Exness、KnowBe4、Turo、Gladly、ThredUP、ExtraHop 等。案例研究页面列出十余个详细案例,招聘页面称「全球超过 600 家客户」。公司在 2025 年和 2026 年获得 Fortune Cyber 60 榜单(2025 年 10 月)和 Citizens Securities Cyber 66 榜单(2026 年 4 月)认可。2026 年 1 月,Teleport 发布 Agentic Identity Framework,这是一条面向生产基础设施中 AI 代理安全的 AI 路线图。2026 年 6 月,Teleport 宣布 Beams,这是在 beams.run 为 AI 代理提供可信运行时的新产品。[CO024, CO025, CO026, CO027, CO028, CO029]
| 日期 | 事件 | 类型 | 金额 / 估值 / 状态 | 参与方 | 含义 |
|---|---|---|---|---|---|
| 2015 | Gravitational Inc. 成立;Teleport 项目启动 | 创立 | $0 融资 | Ev Kontsevoy、Alexander Klizhentas、Taylor Wakefield 三位创始人 | 将多云基础设施访问识别为创始问题 |
| 2016 | Teleport 在 GitHub 以 AGPLv3 开源 | 产品 | 到 2024 年 GitHub stars 15,000+ | Gravitational 团队 | 开源采用策略;社区增长成为竞争护城河 |
| 2016-2018 | 早期客户基础——NASDAQ、Splunk、Samsung 在 Series A 被点名 | 规模 | Gravitational | 机构资本进入前已获得企业 logo;证明企业需求 | |
| 2019(约) | 由 Kleiner Perkins 领投的 Series A 完成 | 融资 | 融资 $25M;KP 领投 | Kleiner Perkins(Bucky Moore) | 首笔机构资本;公司此前不久已达到盈利 |
| 2021 | 由 S28 Capital 和 Kleiner Perkins 领投的 Series B 完成 | 融资 | 融资 $30M;ARR 较 2020 年 Q2 同比 2.5 倍 | S28 Capital、Kleiner Perkins;引用 Bucky Moore 发言 | ARR 三倍增长轨迹获确认;随该轮推出数据库访问(MongoDB) |
| 2021 | Gravitational 正式更名为 Teleport;迁至 goteleport.com | 治理 | Gravitational / Teleport 领导层 | 品牌围绕产品名统一;公司实体仍为 Gravitational Inc. | |
| 2022-05 | 由 Bessemer Venture Partners 领投的 Series C 完成 | 融资 | 融资 $110M;估值 $1.1B | Bessemer(Mary D'Onofrio)、Insight(Matt Koran 观察员) | 独角兽里程碑;轮次时 ARR 同比 2.8 倍;最后已知外部估值 |
| 2024-06 | Teleport 16 发布;社区二进制许可改为商业许可 | 产品 | Teleport 团队 | 编译二进制 / 镜像受商业许可限制;AGPLv3 源代码不变 | |
| 2025-10-30 | 入选 2026 Fortune Cyber 60 榜单 | 监管 / 认可 | Fortune / Lightspeed / AWS | 第三方增长认可;新闻稿引用 600+ 客户 | |
| 2026-01-27 | Agentic Identity Framework 发布 | 产品 | Teleport;Ev Kontsevoy 声明 | AI-first 身份路线图;将 Teleport 定位于 agentic AI 基础设施安全 | |
| 2026-04-07 | 入选 Citizens Securities Cyber 66 榜单 | 监管 / 认可 | Citizens Securities 网络安全研究团队 | 同行认可其为最热门私有网络安全公司;AI 身份角度被强调 | |
| 2026-06 | Beams 在 beams.run 启动公测 | 产品 | Teleport | 面向 AI agent 基础设施的独立产品;把 TAM 从人类 / 机器身份扩展出去 |
没有月 / 日的日期是根据博客文章推算的近似值。Series A 日期根据 KP perspectives 文章推断;准确月份未确认。2022 年 5 月 Series C 后未确认任何融资事件。
[CO013, CO014, CO015, CO016, CO024, CO025]Teleport 的开源社区和企业客户群共同喂给基于用量的收入引擎,但过时的 2022 年估值标记、受限社区许可证,以及未确认的 FedRAMP ATO 缺口构成约束。
[CO001, CO006, CO014, CO015, CO016, CO024]1.5 许可证变更、FedRAMP 定位缺口和负面信号
近期最重大的负面进展是 2024 年 6 月社区许可证变更。从 Teleport 16 开始,公司将编译后的 Community Edition 二进制文件和容器镜像从 Apache 2.0 改为商业许可证。新许可证只允许员工少于 100 人且年收入低于 $10M 的公司免费商业使用。源代码仓库的 AGPLv3 许可证未变,意味着大公司仍可从源码编译,但下载预构建二进制文件的便利性现在受限。这一动作与其他 open-core 公司保护社区变现的做法一致,但也清楚收紧了社区产品,一些用户和企业对此有批评。 FedRAMP 方面,Teleport 公开文档和营销材料称产品可帮助客户满足 FedRAMP 合规要求。Teleport Enterprise 构建使用通过 FIPS 140 验证的加密模块编译,FedRAMP 文档页说明 Teleport 如何帮助实现具体 FedRAMP 控制项。不过,公开语料中没有证据确认 Teleport 自身云服务已获得 FedRAMP Authorization To Operate(ATO)。Teleport 的 FedRAMP 定位是合规赋能工具,而不是获得 FedRAMP 授权的服务提供商。联邦买家可能预期 SaaS 本身具备 ATO,因此该缺口重要。 第三方评论平台上的负面产品信号也值得注意。PeerSpot 评论者提到初始设置复杂、RBAC 配置困难,以及与 SIEM 和监控工具集成有挑战。StrongDM 的竞品对比页面声称,Teleport 基于代理的架构要求代理以 root 身份运行在每台被监控服务器上,创造新的攻击面;同一页面还称 Teleport Cloud 存在可靠性问题,包括更新期间宕机。这些说法来自竞争供应商,应批判性阅读,但它们代表了买家评估时会考虑的弱点类别。[CO033, CO034, CO035, CO036, CO037, CO039]
1.6 图表
02市场分析
2.1 市场范围、相邻领域和替代品
Teleport 自身定位和产品架构决定了市场边界:比传统特权访问管理更宽,但比整个零信任堆栈更窄。公司称自己是 AI Infrastructure Identity 公司,销售基于证书的访问,覆盖 SSH、Kubernetes、数据库、Windows、内部 Web 应用、机器身份和 AI 相关基础设施工作流。因此,可纳入的支出是基础设施访问控制平面:特权访问、工作负载身份、访问审计,以及面向合规的基础设施访问现代化。即使这些预算有时影响交易,也不足以把广义员工 IAM、客户身份、端点安全、SIEM 或通用 AI 应用支出计入核心市场价值。现状替代品仍然很多——VPN、堡垒机、长期密钥、数据库密码、云原生单点 IAM 和手工审计工作流都在争同一件事。StrongDM 的负面竞品视角在这里有用,因为它认为 Teleport 对现代云资产仍是点状方案,而非通用访问平台;这是真实约束,会压住夸大的 TAM 叙事。[CM001, CM002, CM003, CM004, CM005, CM006]
| 细分 / 类别 | 纳入支出 | 排除支出 | 主要买方 | 与 Teleport 的相关性 |
|---|---|---|---|---|
| 面向基础设施的特权访问管理 | 特权会话控制、即时访问、审计、数据库和服务器访问代理 | 通用员工 SSO、消费者身份、非特权应用登录 | CISO / 安全工程 | 核心窄口径市场视角,最接近付费控制预算 |
| 零信任基础设施访问 | 面向 SSH、Kubernetes、数据库、RDP、内部 Web 应用的身份感知访问和策略执行 | 与基础设施访问工作流无关的端点、网络和数据控制 | 安全架构 / 平台工程 | 更宽但仍相关的相邻市场视角 |
| 机器与工作负载身份 | 为 bot、服务、CI-CD 和基础设施工作负载签发证书 | 与访问工作流无关的通用密钥管理或 PKI 支出 | 平台工程 / 安全平台 | 高相关性,因为 Teleport 直接变现 MWI |
| 与访问绑定的合规和审计自动化 | FedRAMP、SOC 2、证据采集、会话录制、访问审查支持 | 完整 GRC 套件支出、外部审计费用、广义合规咨询 | 安全 / 合规 / 公共部门项目负责人 | 扩大合同价值的相邻项,但不应作为独立 TAM 计算 |
| AI agent 身份与访问控制 | 面向 agentic 基础设施动作和 MCP 关联工作流的身份、授权和审计 | 通用 AI 模型训练、应用层 copilots,以及非基础设施 AI 工具 | 安全平台 / AI 平台负责人 | Teleport 定位中的新兴扩张向量 |
| Workforce IAM / CIAM / 端点或 SIEM 工具 | 仅纳入直接触达基础设施身份的管理员访问切片 | 常规员工 SSO、客户身份、端点防护、通用日志分析 | CIO / IAM / IT 运营 | 相邻,但大多排除在 Teleport 核心市场规模之外 |
边界表把可变现的基础设施身份控制平面,与更广义的身份、端点和分析类别区分开;后者可能影响交易,但不应计入核心 TAM。
[CM001, CM002, CM004, CM005, CM006, CM007]2.2 规模测算视角和估算差异
规模证据支持分层看法,而不是单一醒目的 TAM。Precedence Research 的狭义 PAM 视角认为 2025 年市场为 $4.50 billion;两个更宽的零信任估算则把市场放在 2024 年约 $36.96 billion、2025 年 $40.01 billion,长期预测明显更高。Teleport 可能位于这些视角之间,因为它解决特权基础设施访问和身份控制,但无法捕获广义零信任研究中包含的所有网络、端点、数据和应用控制支出。类别语言也仍在稳定:Bessemer 将基础设施访问描述为一个新产品类别,这解释了为什么分析师覆盖跨越多个重叠定义,而非一套固定分类法。需求信号足以支撑真实市场,而不只是概念。Teleport 报告有 600 多家客户,2026 年调研和 2026 年新闻室证据显示 AI 驱动的身份担忧正在快速上升。即便如此,公开证据仍无法隔离精确的 Teleport SAM 或 SOM,因为客户组合、合同价值和部署分布均未披露,而且一个 Fortune Business Insights PAM 来源返回的内容完全错误。[CM009, CM010, CM011, CM012, CM013, CM014]
| 发布方 | 基准年份 | 市场范围 | 数值(USD B) | CAGR(%) | 方法论 | 置信度 | 局限 |
|---|---|---|---|---|---|---|---|
| Precedence Research | 2025 | 特权访问管理 | 4.5 | 23.4 | 全球分析师市场模型,含 2034 年预测 | 中 | 范围窄于 Teleport 的完整产品足迹,且供应商方法论不完全透明 |
| Grand View Research(存档) | 2025 | 特权访问管理 | 保留的类别列表作为类别覆盖证据 | 低 | 保留来源未能为本轮提供清晰的公开头部数字 | ||
| Fortune Business Insights | 2026 | 特权访问管理 | 尝试用于三角校验的来源 | 低 | URL 返回了无关的农业内容,因此 PAM 估算不可用 | ||
| Grand View Research(存档) | 2024 | 零信任安全 | 36.96 | 16.6 | 到 2030 年的宽口径零信任市场估算 | 中 | 覆盖的控制范围比单纯基础设施访问更宽 |
| Precedence Research | 2025 | 零信任安全 | 40.01 | 16.39 | 到 2035 年的宽口径零信任市场估算 | 中 | 可作为 TAM 上限参考,但口径太宽,不能当作 Teleport SAM |
| Teleport Infrastructure Identity Survey | 2026 | AI 身份需求代理指标 | 衡量企业 AI 项目强度和准备度的调研 | 中 | 需求信号,不是直接的市场规模估算 |
Null 值标记的是用于三角校验或限制分析、但在保留证据集中无法恢复市场规模数字的来源。
[CM009, CM010, CM011, CM012, CM015, CM018]Teleport 处在狭义 PAM 核心与广义 zero-trust 天花板之间;新兴 AI 身份层又在可触达的中间层里抬高紧迫性。
分层边界是基于产品范围和标准映射的分析综合;只有外层市场参考点来自已发布的分析师数字。
[CM013, CM014, CM015, CM017]已发布市场参考从狭义 PAM 当前价值一路覆盖到广义 zero-trust 远期预测,说明单一 TAM 数字会夸大精确度。
区间端点使用已发布的当前和长期数字,单位为十亿美元;中点值是展示辅助,不是新的有来源市场估算。
[CM009, CM010, CM011, CM012, CM016, CM018]2.3 买家类型、预算归属和采用路径
Teleport 的买家地图是跨职能的,因为产品把安全、平台和合规工作流压缩到同一个访问层。日常用户通常是平台工程师、SRE 或 DevOps 团队、安全工程师、基础设施管理员,以及数据库或 Kubernetes 运维人员。预算归属取决于采购触发点。安全主导的交易常落在 CISO 组织;平台主导的推广可由工程基础设施团队负责;合规主导的公共部门或受监管企业交易往往会拉入 GRC 相关方,因为 FedRAMP 和 SOC 2 取证与访问控制同样重要。定价也强化了这种共享所有权:Teleport 按月活跃用户和机器 / 工作负载身份收费,因此商业模型随身份采用扩张,而不是绑定一个固定设备部署规模。开发者主导评估仍然重要,因为开源仓库有超过 15,000 颗星,但企业转化似乎在受监管和云原生组织中最强,包括大型金融服务买家。最弱契合点是遗留系统较重的混合环境,买家更看重广泛协议覆盖和更简单迁移,而不是 Teleport 的云原生深度。[CM019, CM020, CM021, CM022, CM023, CM024]
| 细分市场 | 买方角色 | 用户 | 付款方 | 预算负责人 | 采用触发点 |
|---|---|---|---|---|---|
| 受监管的云企业 | CISO 或安全平台负责人 | 平台工程师、安全工程师、数据库 / Kubernetes 管理员 | 安全预算 | 安全组织,与平台团队协作 | 需要用可审计、基于证书的控制替代 VPN 或堡垒机访问 |
| 联邦或公共部门承包商 | 合规负责人加安全架构 | 处理受监管工作负载的管理员和运营人员 | 安全与合规项目预算 | 对授权证据负责的项目负责人 | FedRAMP 证据、FIPS 要求,以及集中式会话审计需求 |
| 平台原生的中端 SaaS | 平台工程负责人 | SRE、DevOps、开发者 | 工程基础设施预算 | 平台工程 | 希望在不保留长期密钥的情况下统一 SSH、Kubernetes 和数据库访问 |
| AI 原生基础设施团队 | 安全平台负责人或 AI 平台负责人 | Agent 构建者、MLOps、平台工程师 | 安全与平台共享预算 | 跨职能的安全 / 平台负责人 | 需要把非人类身份、授权和审计分配给 agent 或 MCP 工作流 |
| 传统系统负担重的混合企业 | IT 基础设施或访问管理负责人 | 跨传统与现代混合系统的管理员 | 中央 IT 或安全预算 | 往往共享或存在争夺 | 迁移压力存在,但如果协议覆盖和传统系统支持比云原生深度更关键,采用速度会放慢 |
买方地图基于 Teleport 定价、合规用例、产品范围和客户画像证据推断可能的预算归属,而非已披露的赢单率数据。
[CM019, CM020, CM021, CM022, CM023, CM024]安全、平台、合规和 AI 相关方都会参与,但占比随细分市场和触发因素而变。
矩阵单元格是基于产品范围、定价、合规用例、社区信号和竞争对手负面定位综合出的定性权重,不是披露的细分收入组合。
[CM020, CM021, CM022, CM024, CM025, CM026]2.4 监管、AI、云和安全驱动因素
标准、合规压力、云复杂度和新的 AI 代理风险共同把需求向前拉。NIST SP 800-207 给零信任正式架构定义,CISA 的 Zero Trust Maturity Model 又把该架构落实到五大支柱和三项跨领域能力,为围绕身份的基础设施控制预算提供正当性。当这些抽象框架转化为具体 FedRAMP 和 SOC 2 访问控制要求时,Teleport 受益,尤其因为它记录了 FIPS 140 支持和控制项映射。AI 是更尖锐的近期催化剂。Teleport 2026 年调研称,92% 受访者有近期 AI 计划,79% 正在评估或部署 agentic AI,只有 13% 觉得准备极充分,60% 已发生或怀疑发生 AI 相关事件。另一组 2026 年新闻室数据称,73% 网络安全领导者正在听到企业对 AI 代理安全的提问。与此同时,多云蔓延和云时代向统一控制平面的更广泛迁移也支撑类别。主要采用阻力不是没有需求,而是切换成本:买家仍要拆掉存量方案、重构访问路径,并判断 Teleport 的现代云强项是否足以压过遗留覆盖担忧。[CM027, CM028, CM029, CM030, CM031, CM032]
| 因素 | 方向 | 类型 | 时间 | 影响 | 尽调问题 |
|---|---|---|---|---|---|
| NIST 和 CISA 零信任框架 | 正向 | 监管 / 标准 | 现在 | 为以身份为中心的访问控制提供持久的架构语言和预算正当性 | 询问多少 pipeline 明确映射到联邦或企业零信任项目 |
| FedRAMP 和 FIPS 访问控制证据 | 正向 | 合规 | 现在 | 提升与受监管买方和公共部门承包商的契合度 | 要求提供受监管行业收入占比,以及交易中复用控制映射的证据 |
| SOC 2 基础设施访问要求 | 正向 | 合规 | 现在 | 把安全和审计利益相关方拉进采购流程 | 询问 SOC 2 驱动的赢单是否带来溢价,还是只是转化更快 |
| AI 项目强度和 AI agent 安全担忧 | 正向 | 市场需求 | 现在至 24 个月 | 将 Teleport 从人类访问扩展到机器和 agent 身份预算 | 要求拆分核心访问交易与 AI 身份附加项的 pipeline |
| 多云与开放控制平面复杂度 | 正向 | 技术 | 12 至 36 个月 | 支撑统一访问平面,而不是一堆点状凭证 | 询问 Teleport 在单云与多云环境中的赢单差异 |
| 基于用量的 MAU 和 MWI 定价 | 混合 | 商业 | 现在 | 可降低进入门槛,但预算增长取决于身份扩张和定价透明度 | 要求按用户身份与机器身份拆分 cohort 扩张数据 |
| VPN、PAM、IAM 和审计工作流带来的 incumbent 切换成本 | 负向 | 运营 | 现在 | 拉长销售周期,并抬高价值证明门槛 | 询问中位部署时间、迁移服务使用情况和竞争替换数据 |
| 传统系统覆盖批评 | 负向 | 竞争 | 12 至 24 个月 | 缩窄在异构环境中的适配面,并支撑竞争对手的反向叙事 | 要求按环境复杂度提供赢亏数据,以及协议覆盖路线图 |
表格同时列出正负因素,因为市场采用取决于预算生成和迁移摩擦;时间判断是方向性,不是公司发布的预测。
[CM027, CM028, CM029, CM030, CM031, CM032]多数 Teleport 评估似乎从风险或合规触发开始,先进入范围明确的试点,再推进更广的身份扩张。
采用顺序是从合规定位、定价结构、客户证明和竞争约束中综合出的模式;它不是已披露的漏斗转化图。
[CM028, CM030, CM032, CM034, CM035, CM036]2.5 采用障碍、尽调缺口和矛盾证据
市场分析最大约束不是需求弱,而是精度弱。公开来源无法隔离 Teleport 可寻址支出中有多少来自受监管企业、公共部门承包商、AI 原生团队或既有客户扩张。最近一次已披露融资事件仍是 2022 年 5 月以 $1.1 billion 估值完成的 Series C,因此外界正用一个过时资本市场锚点解读快速变化的类别。已发布市场估算方向上有用,但方法论并不一致,因为 PAM 和零信任报告使用不同范围定义,而且可访问的 Fortune Business Insights PAM URL 返回了无关农业内容,而不是可用市场页面。Teleport 自有材料在产品广度和合规对齐上很丰富,但不披露公开赢单率、部署周期、流失率、ACV,或自托管与云交易的拆分。因此,对需求方向可以有合理信心;但在管理层提供分部收入和转化证据前,对可变现份额和高效捕获的信心要低得多。[CM037, CM038, CM039, CM040, CM041, CM042]
2.6 图表
03竞争格局
3.1 格局
Teleport 的竞争集合比传统密码库 PAM 更宽。最接近的阵营包括 CyberArk、BeyondTrust、Delinea 等老牌套件;StrongDM、HashiCorp Boundary 等现代基础设施访问挑战者;以及来自 Okta 的相邻竞争,Okta 可以把既有员工身份关系延伸到特权服务器访问。Bessemer 对基础设施访问的定义解释了为什么买家不会只在一个框里评估 Teleport:实际任务横跨服务器、集群、数据库,以及越来越多由 AI 操作的基础设施工作流,包含连接、认证、授权和审计。独立对比与评论网站也强化了这份活跃买家候选名单。这个市场因此不是赢家通吃的功能竞赛,而是广义企业既有厂商、云原生专家和身份平台捆绑方之间的分层竞争;Teleport 在买家想要一个现代控制平面,而不是遗留密码库加点状代理时最强。[CP015, CP016, CP017, CP041, CP042]
| 竞争对手 | 类别 | 规模 | 目标细分市场 | 差异化 | 关键限制 |
|---|---|---|---|---|---|
| Teleport | 基础设施身份 / 现代 PAM | 私营;另有披露显示 GitHub star 超过 15,000,客户超过 600 家 | 云原生企业、受监管基础设施团队、平台工程 | 统一 CA + 代理架构,覆盖 SSH、Kubernetes、数据库、RDP、工作负载和 AI agent | 传统系统负担重的环境可能更偏好更宽的协议覆盖和更简单的迁移叙事 |
| CyberArk | 传统企业 PAM | $20.63B 市值;$1.30B TTM 收入 | 大型混合企业和受监管安全团队 | 统一 PAM 平台、零长期特权定位、强合规与审计姿态 | 较重的传统企业销售动作,可能不如 Teleport 贴近开发者 |
| BeyondTrust | 传统 PAM / 特权远程访问 | 大型 incumbent 厂商;公开语料更强调 Gartner 地位,而非当前财务数据 | 企业安全、第三方 / 供应商访问、混合 IT | 最小特权叙事、凭证注入、VPN 替代、供应商特权访问 | 保留证据集中较少看到 Teleport 式统一云原生控制平面的证据 |
| Delinea | 传统 PAM / 密钥库 | 私营厂商;保留证据集未公开量化规模 | 宽口径企业 PAM 买方,尤其是密钥库和轮换用例 | 快速部署表述、发现、密码轮换、会话监控、AI 会话分析 | 私营财务可见度薄,架构仍更接近经典密钥管理 |
| StrongDM | 云原生挑战者 / 访问代理 | 私营厂商,现归入 Delinea;直接攻击式营销可见 | 需要现代与传统访问覆盖的混合企业 | Identity Firewall 叙事、持续授权、完整会话可见性、更宽的协议 / 认证方法覆盖 | 保留证据高度依赖竞争对手叙事;公开定价和规模信息稀少 |
| HashiCorp Boundary | 感知身份的访问代理 | HashiCorp 支持的产品,拥有大型相邻社区 | 已使用 HashiCorp 身份和基础设施栈的平台团队 | SSO 加上通过 Vault 提供的动态凭证,用于最小特权访问 | 在数据库、合规打包和 AI 身份上的产品面比 Teleport 窄 |
| Okta | IAM 相邻的特权访问 | $20.65B 市值;$2.91B TTM 收入 | 现有 Okta 身份客户向服务器访问延伸 | 从员工身份交叉销售、消除静态凭证、SSH/RDP 会话录制 | 面向 Kubernetes、数据库和更广访问代理的基础设施深度比 Teleport 窄 |
覆盖范围有意不完整:它聚焦截至 2026 年 6 月,最可能出现在 Teleport 买方 PAM 和基础设施身份评估中的直接及相邻厂商,而非每一个长尾管理员访问或云原生点工具。
[CP015, CP017, CP041, CP042]这个序数地图展示哪些厂商既具备现代 zero-credential 姿态,又拥有最强企业分发杠杆。
轴向分数是有证据支撑的序数判断,来自上市公司规模、安装基数线索、架构定位和产品页主张;它们不是市场份额测算。
[CP004, CP005, CP010, CP012, CP014, CP021]3.2 老牌 PAM
CyberArk、BeyondTrust 和 Delinea 仍定义市场中的既有厂商一端,因为它们把特权访问卖给广义企业和混合环境,而不只是卖给绿地云团队。CyberArk 官方定位强调单一 PAM 平台、降低网络风险、审计与合规结果,以及跨混合环境的零常驻特权访问。BeyondTrust 讲述类似故事,围绕最小权限、凭证注入和特权远程访问,可消除对 VPN 和已知凭证的需求。Delinea 的 Secret Server 仍锚定凭证库、发现、密码轮换和会话监控,并在其上叠加新的 AI 驱动会话分析表述。这些供应商都没有把自己营销成 Teleport 式开放基础设施身份平台,但重叠已经足够实质,Teleport 必须靠现代环境中的架构简洁性取胜,而不能假设既有厂商被困在旧密码库工作流里。[CP004, CP005, CP006, CP007, CP024, CP025]
3.3 云原生挑战者
StrongDM、HashiCorp Boundary 和 Okta 重要,是因为它们从三个不同角度攻击 Teleport。StrongDM 在现代基础设施访问上正面竞争,但它把自己包装成更适合混合环境:支持更多遗留系统和认证方法,也不要求 Teleport 那套精确的纯证书运行模型。Boundary 范围更窄,但技术上重要:身份感知代理加 Vault 集成,让它在已标准化 HashiCorp 工具的团队中有可信度。Okta 从 IAM 相邻路线切入市场,把 SSO、临时服务器访问和会话录制延伸到 Linux 与 Windows 基础设施,面向已经信任 Okta 作为身份控制平面的客户。这些挑战者共同说明,Teleport 不能只靠云原生品牌;每个对手都带来不同分发机制,从平台相邻、直接攻击广告,到捆绑式交叉销售。[CP008, CP009, CP010, CP012, CP013, CP014]
| 厂商 | 定价模型 | 计费单位 | 关键能力 | 定价透明度 | 明显缺口 |
|---|---|---|---|---|---|
| Teleport | 自助标价加企业打包 | 月活用户和机器 / 工作负载身份 | 统一访问、审计、机器身份、身份安全、agentic 身份附加项 | 相对同行较高 | 实际折扣、企业最低消费和附加率未公开披露 |
| CyberArk | 销售主导的企业合同 | 保留证据集未公开自定义报价 / 合同范围 | 统一 PAM、零长期特权、审计 / 合规、混合访问 | 低 | 缺少公开标价;难以与 Teleport 做 TCO 对比 |
| BeyondTrust | 销售主导的企业合同 | 保留证据集未公开自定义报价 / 部署范围 | 最小特权、PRA、凭证注入、供应商访问 | 低 | 保留语料未显示公开单位定价或部署最低要求 |
| Delinea | 销售主导的企业合同 | 保留证据集未公开自定义报价 / vault 或模块范围 | 密钥库、发现、轮换、会话监控、AI 会话分析 | 低 | 私营定价和打包细节仍然稀少 |
| StrongDM | Delinea 收购后的销售主导打包 | 保留证据集未公开自定义报价 / 用户-资源范围 | Identity Firewall、持续授权、会话可见性、宽协议覆盖 | 低 | 对比型信息很多,但可比标价细节很少 |
| Okta | 平台捆绑或附加销售动作 | 保留证据集未公开自定义报价 / 席位范围 | 特权服务器访问、零长期特权、SSH/RDP 录制、SSO 延伸 | 低 | 公开产品页面看不清可能的捆绑经济性 |
| HashiCorp Boundary | 开源 / 企业混合打包 | 开源加商业条款,保留证据集未公开 | 感知身份代理、SSO、通过 Vault 提供动态凭证、会话管理 | 中低 | 公开保留来源对架构的解释比商业条款更清楚 |
该表比较的是打包姿态和透明度,而不是实际价格领先性,因为保留证据集中多数竞争对手没有发布可一一对照的公开费率。
[CP027, CP028, CP029, CP038]3.4 Teleport 差异化
Teleport 最清晰的差异化是结构性的,不是表面的。它的 Auth Service 充当用户、机器和资源的证书颁发机构,Proxy Service 则在 SSH、Kubernetes、数据库、RDP、Web 应用和机器身份之间代理访问,不依赖长期共享凭证。Teleport 因此能销售一种访问平面:认证、授权和审计统一在一起,而不是由密码库、跳板机、VPN 和分散策略引擎拼接。公司也在向外扩张:近期版本强调 IdP 攻陷缓解、更宽的身份安全层、机器和工作负载身份,以及面向 AI 系统的新 Agentic Identity Framework。这些动作扩大了 Teleport 想拥有的类别。代价是,2024 年社区许可证变更后,Teleport 旧有开源发现优势不再那么干净,因此架构一致性比单纯社区好感更重要。[CP001, CP002, CP003, CP018, CP019, CP020]
| 能力 | Teleport | CyberArk | BeyondTrust | Delinea | StrongDM | Okta | HashiCorp Boundary |
|---|---|---|---|---|---|---|---|
| 基于证书的认证 | 是——覆盖用户、主机和工作负载的核心架构 | 部分——支持临时模型,但官方叙事是更宽的 PAM | 部分——最小特权和 PRA,但不是 CA 优先叙事 | 部分——保留证据集显示其先从密钥库出发,不是 CA 优先 | 部分——在多种认证方法中支持基于证书的认证 | 部分——为服务器访问移除静态 SSH key / 密码 | 部分——感知身份的代理,配合外部认证和动态凭证 |
| 临时特权 | 是——短期证书和即时访问 | 是——零长期特权定位 | 是——特权远程访问和最小特权 | 部分——会话控制和轮换,但 ZSP 叙事不够明确 | 是——持续策略执行,无长期特权 | 是——服务器零长期特权 | 是——通过 Vault 动态凭证实现最小特权访问 |
| 会话录制 | 是——命令、视频和审计录制 | 是——PAM 审计 / 合规核心 | 是——安全远程访问和会话监控 | 是——内置会话监控 | 是——完整会话可见性 | 是——通过 SSH 和 RDP 录制特权访问 | 是——录制并管理特权会话 |
| Kubernetes 支持 | 是——一等访问路径 | 保留证据集未知 | 保留证据集未知 | 保留证据集未知 | 保留证据集未知 | 保留证据集没有公开证据 | 保留证据集没有公开证据 |
| 数据库访问 | 是——SQL 和 NoSQL 通过 Teleport 代理接入 | 部分——强调多云 / 混合 PAM,保留证据集未突出数据库细节 | 保留证据集未知 | 保留证据集未知 | 保留证据集未知 | 保留证据集没有公开证据 | 保留证据集没有公开证据 |
| AI / agentic 身份 | 是——Agentic Identity Framework 和 Beams | 保留证据集没有公开证据 | 保留证据集没有公开证据 | 部分——AI 驱动的会话分析表述 | 是——首页展示 agentic AI 身份信息 | 保留证据集没有公开证据 | 保留证据集没有公开证据 |
| 开源分发 | 部分——源码可用,但编译产物对较大公司有商业限制 | 否 | 否 | 否 | 保留证据集没有公开证据 | 否 | 部分——有开源渊源,文档导向明显 |
| 云原生架构 | 是——面向现代基础设施的统一 CA / 代理平面 | 部分——强调混合和多云 PAM | 部分——强调远程访问和供应商 PAM | 部分——强调密钥库和自动化 | 是——现代访问控制平面和自适应控制 | 部分——把身份云延伸到服务器 | 是——面向云基础设施的感知身份代理 |
单元格只限于保留来源能证明的能力;未知表示已审阅语料不足以支撑更强判断,并不代表该厂商没有该功能。
[CP001, CP004, CP006, CP007, CP009, CP012]Teleport 在现代基础设施资源类型广度上领先;incumbent 和邻近玩家则在企业分发或特定特权访问工作流上最强。
矩阵值仅反映留存来源直接支持的能力;部分或否往往意味着证据更窄或不够明确,而非确定缺少功能。
[CP001, CP004, CP006, CP009, CP013, CP021]3.5 护城河风险
Teleport 确实有切换成本潜力,但护城河有条件,并非不可攻破。一旦客户把审计日志、证书签发、访问工作流和合规证据标准化到一个平台,替换就会带来运营痛感。这种机制也利好既有厂商,所以即便市场现代化,CyberArk 和 BeyondTrust 仍能防守账户。Teleport 还面临三项直接风险。第一,CyberArk、Okta 等大型上市可比公司拥有大得多的资产负债表和装机基础,有空间捆绑或折扣。第二,StrongDM 围绕遗留契合度和 root-agent 架构的负面信息,给混合环境买家提供了具体反方论点。第三,公开客户评论证据支持多于敌意,但保留下来的样本仍缺少大规模上线痛点,投资人无法获得决定性证据来证明 Teleport 部署模型能在保守企业中无摩擦扩张。[CP023, CP024, CP025, CP029, CP031, CP032]
| 护城河主张 | 支撑证据 | 威胁 | 严重性 | 缓解 / 尽调问题 |
|---|---|---|---|---|
| 统一基础设施身份平面 | Teleport CA + 代理架构把多类资源纳入同一套审计模型 | CyberArk、BeyondTrust 和 Okta 继续增加零长期特权和会话能力 | 高 | 要求按资源类型提供赢亏数据,并证明统一架构能缩短部署或降低管理员负担 |
| 开发者主导发现与开源拉动 | 公共 repo 规模和早期社区根基带来认知 | 社区许可证限制削弱自下而上的好感,也让 Boundary 这类开放血统更有吸引力 | 高 | 索取社区漏斗、自助转化,以及 v16 之后贡献或采用趋势 |
| 贴合现代云原生 | Teleport 和 StrongDM 都围绕现代基础设施工作流优化 | 在混合环境里,StrongDM 会拿传统覆盖面和 root-agent 架构攻击 Teleport | 高 | 索取协议路线图、部署加固证据,以及传统负载较重客户的赢亏拆分 |
| 合规与信任姿态 | 安全审计发布和身份安全文档支撑企业信任 | 既有厂商已经掌握大型合规关系,还能捆绑相邻控制项 | 中 | 索取受监管行业的企业客户访谈,以及控制项层面的替换案例 |
| AI 与机器身份扩张 | Teleport 现在主推 Agentic Identity Framework、Beams 和机器 / 工作负载身份 | 竞争对手可能很快补上 agentic 功能,而当前市场需求仍在形成 | 中 | 索取 AI 与非人类身份模块的 attach rate、pipeline 和商业化证据 |
| 推出后的切换成本累积 | 一旦部署,策略、审计、证书签发和访问工作流会嵌入组织流程 | 在 Teleport 站稳前,大型上市可比公司拥有更强分销和折扣能力 | 高 | 索取中位 time-to-value、续约或扩张数据,以及相对 CyberArk 或 Okta 的竞争替换证据 |
风险登记表聚焦护城河耐久性,而不是泛化产品风险;严重性反映竞争压力,并非量化概率模型。
[CP023, CP024, CP025, CP035, CP036, CP037]一组紧凑指标,显示 Teleport 哪里最强,以及大型对手仍在哪里占优。
[CP018, CP021, CP022, CP035, CP036, CP037]04财务
4.1 商业模型、收入结构和客户基础
Teleport 的商业模型按用量计费且多产品。定价页披露三项计费指标:Zero Trust Access 和 Identity Governance 模块的 Monthly Active Users(MAU),Machine and Workload Identity 模块的 Machine / Workload Identities(MWI),以及 Identity Security 的 Teleport Protected Resources(TPR)。未公开标价;所有定价都需要与销售团队商业接洽。Enterprise Edition 支持云、本地部署(标准和 FIPS)、多区域高可用和混合部署模式。Beams AI 代理运行时产品于 2026 年 6 月进入公开测试版,尚未公开定价。 Community Edition 免费层——自 2024 年 6 月许可证变更后,面向员工少于 100 人且年收入低于 $10M 的公司——有意把客户增长转化为商业升级触发器。客户案例显示企业部署广度:GoTo(印度尼西亚最大数字平台,管理复杂基础设施上的多云访问)、Exness(安全要求严格的受监管全球交易公司)、Gladly(有 SOC 2 合规要求的 SaaS 平台)和 ExtraHop(聚焦安全的云网络检测公司)。每个案例代表不同垂直行业和合规姿态。招聘页面称,截至 2025 年 10 月,全球客户超过 600 家。 公开材料中可见的收入驱动因素包括:(1)随着基础设施规模扩大,MAU、MWI 和 TPR 指标增长,不必重新谈判即可带来用量扩张;(2)公司跨过 100 名员工或 $10M AR 门槛后,从社区版转向企业版;(3)客户采用 Identity Governance、Identity Security 和 AI 代理身份模块,带来多模块加购;(4)通过 Beams 和 Machine Workload Identity 模块切入 AI 代理市场机会。会话录制、数据库访问和 MCP 服务器访问也在合规敏感行业创造加购。[CI001, CI014, CI015, CI016, CI033, CI034]
| 收入流 | 机制 | 计费指标 | 当前状态 | 收入质量 | 尽调要求 |
|---|---|---|---|---|---|
| Zero Trust Access(人类) | 按用量计费 SaaS —— 人类用户和受保护资源 | MAU 和 TPR | 已上线 —— Enterprise Edition;Community 对小公司免费 | 模型清晰度好;未披露 ARPU | 提供混合 MAU ARPU 和同比扩张率 |
| 机器与工作负载身份 | 按用量计费 SaaS —— 非人类和 AI agent 身份 | MWI | 已上线 —— 独立模块;AI agent 需求在增长 | 增长潜力高;AI agent 浪潮拉动 MWI 需求 | 提供 MWI 数量和净新增 MWI 增长率 |
| Identity Governance | 按用量计费 SaaS —— 人类访问上的治理层 | MAU | 已上线 —— 向现有人类访问客户 upsell | 有 upsell 潜力;未披露 attach rate 或 ASP 提升 | 提供 cross-sell attach rate 和收入贡献 |
| Identity Security | 按用量计费 SaaS —— 影子访问发现与异常 | TPR | 已上线 —— 向现有客户 upsell | 合规驱动需求;单独定价层级 | 提供合规驱动模块的收入占比 |
| Beams AI Agent Runtimes | 新兴 —— AI agent 基础设施运行时 | 未知(beta) | 2026 年 6 月公开 beta;尚未定价 | 尚未验证;现在做收入建模太早 | 确认定价和已签署的 beta 承诺 |
| Community-to-Enterprise 转化 | 100 名员工和 $10M AR 的许可证门槛 | 转化事件 | 自 Teleport 16(2024 年 6 月)起生效 | 可能是新增 ARR 驱动因素;无转化率数据 | 提供月度 cohort 转化数据 |
所有收入流均由公开定价页、文档和博客文章推断。公司未披露按收入流或模块划分的官方 ARR。Beams 产品仍处 beta,未披露定价。
[CI001, CI014, CI015, CI016, CI033]| 维度 | Teleport(私有) | CyberArk CYBR(上市) | Okta OKTA(上市) |
|---|---|---|---|
| 定价模型 | 按用量计费(MAU / MWI / TPR);无公开标价 | 订阅 + 用量;按用户和按资源 | 订阅;按用户和按服务 |
| 企业定价披露 | 仅联系销售;无标价 | 部分公开;合同金额不公开 | 部分公开;企业层级不公开 |
| 社区 / 免费层 | 是 —— 公司 <100 名员工、<$10M AR | 无显著免费层 | 无显著免费层 |
| 2024 年收入(USD) | ~$49M(GetLatka 估算;未确认) | $1.00B(SEC 文件披露) | $2.61B(SEC 文件披露) |
| 市值 / 估值(USD) | $1.1B(2022 年 5 月标记;已滞后约 4 年) | $20.63B(2026 年 6 月) | $20.65B(2026 年 6 月) |
| 隐含收入倍数 | ~22x ARR(按 GetLatka 估算) | ~15.9x 收入(2026 年 6 月) | ~7.1x 收入(2026 年 6 月) |
Teleport 数据仅来自公司披露或 GetLatka 估算。CyberArk 和 Okta 数据来自 companiesmarketcap.com(来源为公开 SEC 文件)。Teleport 估值采用 2022 年 Series C 标记。
[CI002, CI009, CI010, CI015]Teleport 通过社区到企业的漏斗和多模块追加销售,把基础设施需求转成按用量计费的收入,但部署规模与留存毛利率之间的关系完全不透明。
仅为定性桥接;没有公开定价、ARPU 或毛利率数据。$49M ARR 是 GetLatka 的未经确认第三方估计。
[CI001, CI016, CI033, CI039]4.2 收入和 ARR 估算——完全未经验证的图景
Teleport 不披露任何财务数据。唯一公开 ARR 估算来自第三方数据聚合商 GetLatka,后者报告 Teleport 在 2024 年 12 月达到 $49M 收入。GetLatka 还估算截至 2025 年底员工数约 246 人。这些数字未得到 Teleport、任何投资人或任何独立来源确认。GetLatka 自己的融资摘要显示 2 轮共 $140M,与公司披露的 3 轮 $165M 不一致,进一步削弱了对该数据集完整性的信心。 从融资公告披露的 ARR 增长率倒推:Series C 博客(2022 年 5 月)报告总 ARR 同比增长 2.8x、净新增 ARR 同比增长 4.5x;Series B 博客(2021 年)报告总 ARR 较 2020 年 Q2 同比增长 2.5x、净新增 ARR 同比增长 5x。如果这些增长率正确,且公司按 Series B 时期披露所称正走向 2021 年收入三倍增长,那么 Series C 交割时隐含 ARR 约为 $17–20M。从该水平增长到 2024 年 $49M,意味着融资后 CAGR 约 22%,较 Series C 前轨迹明显减速。没有管理层数据无法确认这一点,但它与 2022–2024 年更广泛 SaaS 市场放缓方向一致。 GTM 效率指标完全缺失。公开资料没有销售周期长度、CAC、回本期或 quota 达成数据。GTM 有效性的最佳代理是客户数轨迹(2025 年提到 600+)和具名客户标识质量,但没有进一步数据,二者都无法转化为单客户收入或扩张率。[CI002, CI003, CI005, CI006, CI012, CI013]
| 指标 | 数值 | 日期 / 期间 | 置信度 | 来源 | 缺口说明 |
|---|---|---|---|---|---|
| ARR(估算) | ~$49M | 2024-12 | 低 | GetLatka(第三方;未确认) | 未经公司或独立来源验证 |
| Series B 时 ARR 增长 | 2.5x YoY | 2021 | 中 | Teleport Series B 博客(官方) | 未说明绝对 ARR 美元金额 |
| Series C 时 ARR 增长 | 2.8x YoY | 2022-05 | 中 | Teleport Series C 博客(官方)+ BVP 投资博客 | 未说明绝对 ARR 美元金额 |
| Series C 交割时估算 ARR(推导) | ~$17–20M(推断) | 2022-05 | 低 | 由 GetLatka $49M 和隐含 CAGR 推断 | 未确认;计算假设 2022–2024 年持平 |
| Series C 后隐含 CAGR | ~22% / 年(推断) | 2022–2024 | 低 | 由估算 ARR 路径推导 | 较 Series C 前增长轨迹减速 |
| 人均 ARR(估算) | ~$199K | 2024/2025 | 低 | 由 GetLatka ARR 和员工数估算推导 | 双重估算;仅作方向参考 |
| ARR / 已融资本比率 | ~0.30x | 2024-12 | 低 | 由 GetLatka ARR / 已披露融资 $165M 推导 | 低于高效 SaaS 0.5–1.0x 基准 |
| 毛利率 | 未披露 | unknown | 无公开来源 | 阻断性缺口;没有披露无法承销 | |
| 净收入留存(NRR) | 未披露 | unknown | 无公开来源 | 估值关键项;扩张率未知 |
所有财务指标要么是公司引用的增长率(仅百分比),要么是 GetLatka 第三方估算。任何期间都没有审计或管理层提供的财务数据。公开来源完全看不到 NRR 和毛利率。
[CI002, CI003, CI004, CI005, CI006, CI024]公开证据支持可信的基础设施需求信号和按用量扩张逻辑,但在量化 CAC、NRR 和毛利率之前就完全断裂。
定性桥接使用公开需求信号和客户案例研究证据。ARR 和单位经济数字不可得。
[CI002, CI004, CI005, CI020, CI034, CI035]4.3 估值和上市可比公司倍数
Teleport 唯一外部估值数据点是 2022 年 5 月 Series C 的 $1.1B 标记。截至 2026 年 6 月,该标记已有约四年,且未更新。按 GetLatka 估算的 $49M ARR,隐含收入倍数约 22.4x——显著高于 2026 年中可比上市网络安全公司的交易水平。 CyberArk Software(CYBR)是特权访问管理领域最接近的上市可比公司,截至 2026 年 6 月市值约 $20.63B,TTM 收入约 $1.30B,隐含收入倍数约 15.9x。CyberArk 收入从 2022 年约 $590M 增至 2025 年 TTM $1.30B,约三年增长 2.2x。Okta(OKTA)是最接近的身份与访问管理可比公司,截至 2026 年 6 月市值约 $20.65B,TTM 收入约 $2.91B,隐含约 7.1x。Okta 收入同期从 $1.85B 增至 $2.91B(增长 1.6x)。两家公司收入规模都远高于 Teleport 的估算 ARR。 按这两家上市同行收入倍数中点(约 11x)计算,$49M ARR 对应 Teleport 企业价值约 $540M,远低于 $1.1B 标记。即使按 CyberArk 15.9x 倍数,隐含价值也约 $779M。2022 年 5 月 Series C 交割时,CyberArk 自身以约 $5.27B 市值对应 $590M 收入(约 9x),Okta 以约 $10.94B 对应 $1.85B 收入(约 6x),说明 Teleport 22x+ 的隐含倍数在发行时已经约为可比区间的 2x。2022 年后市场调整之下,2022 年标记中隐含的私募市场溢价可能进一步侵蚀。[CI007, CI008, CI009, CI010, CI011, CI026]
| 轮次 | 日期 | 金额(USD M) | 领投方 | 估值(USD M) | 含义 |
|---|---|---|---|---|---|
| Series A | 2019(约) | 25 | Kleiner Perkins(Bucky Moore) | 未说明 | 公司称接近盈利;NASDAQ、Splunk、Samsung 被列为客户 |
| Series B | 2021 | 30 | S28 Capital 和 Kleiner Perkins | 未说明 | ARR 同比 2.5x;Series B 博客称 2021 年收入有望翻三倍 |
| Series C | 2022-05 | 110 | Bessemer Venture Partners 与 Insight Venture Partners | 1100 | ARR 同比 2.8x;最后一次已知外部估值;截至运行日已滞后约 4 年 |
| Series C 后 | 无证据 | Unknown | 未识别 | Unknown | 2022 年 5 月后无公开融资事件;股权结构不公开 |
所有轮次数据来自 Teleport 官方博客文章及 Bessemer / Kleiner Perkins 投资人发布内容。GetLatka 显示 2 轮共 $140M,缺失 Series A;与已披露 $165M 不一致,降低了对 GetLatka 数据完整性的信心。EDGAR 中未找到任何轮次的 SEC Form D。
[CI005, CI006, CI013, CI022, CI023, CI030]将 2026 年中公开同业倍数套用到 GetLatka 的 $49M ARR 估计后,多数情景下得到的估值区间都低于 2022 年 5 月的 $1.1B 标记。
所有情景都将 companiesmarketcap.com 的 2026 年 6 月公开市场收入倍数,套用到 GetLatka 未确认的 $49M ARR 估计。这些是说明性敏感性区间,不是正式估值。$75M ARR 情景是假设,未获得任何公开来源支持。
[CI007, CI008, CI009, CI010, CI011, CI037]4.4 成本结构、资本充足性和财务结论
Teleport 的成本结构在公开材料中完全不透明。没有 COGS 拆分、毛利率、基础设施成本或人员费用数据。最佳参照是上市网络安全 SaaS 同行,基础设施导向产品的毛利率通常在 65–75%。如果 Teleport 毛利率处于该区间,$49M ARR 可产生 $32–37M 毛利润——足以作为基础,但仍必须支撑持续产品投入、G&A 和销售成本,而这些成本没有披露。 资本充足性同样不透明。公司已在三轮披露融资中募资 $165M,最近一轮是 2022 年 5 月 $110M Series C。此后未公开确认新融资。按 Teleport 阶段公司的行业典型现金消耗率,Series C 资金可支撑三到五年运营,具体取决于烧钱纪律——这说明公司可能不急需新资本,但没有真实资产负债表数据,这完全是推测。未披露债务、信贷额度或项目融资。 财务结论是混合的。需求信号真实:600+ 企业客户、受监管行业客户标识和 Fortune Cyber 60 认可,都说明公司有活跃 GTM。收入模型也适合先落地再扩张。不过,承销案例被基本不透明性卡住:没有经验证 ARR、没有毛利率、没有 NRR、没有烧钱率、没有当前估值。2022 年标记隐含的倍数在当前上市市场可比公司面前难以辩护。任何接近 $1.1B 标记的投资,都需要更新的 409A 或数据室披露,才能解决核心估值问题。[CI019, CI020, CI021, CI022, CI023, CI024]
| 缺口 | 缺失内容 | 重要性 | 严重性 | 尽调路径 |
|---|---|---|---|---|
| 收入 / ARR(实际) | 管理层披露的 ARR,并按模块和 cohort 拆分 | GetLatka $49M 未确认;无法建立收入模型 | 阻断 | 索取包含 ARR bridge 和 cohort 分析的财务数据室 |
| 毛利率 | COGS 拆分 —— 基础设施托管、SRE 支持成本 | 毛利率决定真实单位经济和估值底线 | 阻断 | 向 CFO 索取包含 COGS 的 P&L 和 SaaS Metrics 快照 |
| 净收入留存(NRR) | 各 cohort 按模块拆分的扩张减流失率 | NRR 超过 120% 才能支撑溢价倍数;基线未知 | 阻断 | 索取回溯到 2021 年的月度 cohort 扩张和流失 |
| 烧钱速度与 runway | 最近季度末月度现金消耗和现金余额 | 不知道公司何时需要资本,就无法评估财务风险 | 阻断 | 向 CFO 索取现金头寸和 12 个月现金预测 |
| GTM 效率指标 | CAC 回收期、quota attainment 和销售周期长度 | 没有 GTM 效率数据,无法承销销售可扩展性 | 重大 | 索取 SaaS Metrics deck 或等效管理层材料 |
所有缺口都是私营公司标准数据室请求。缺少这些数据不代表经营承压——私营公司通常如此。若要做有意义的股权投资或二级交易,公司必须在尽调中披露这些数据。
[CI012, CI013, CI025, CI030]从资本、收入、成本和竞争定位四个维度评估 Teleport 的财务透明度;由于其私营公司属性,多数单元格评级为低或未知。
矩阵评估是基于运行日期公开证据做出的定性判断。管理层 data room 中的真实财务数据会实质性改变这一评估。
[CI009, CI010, CI012, CI025, CI026, CI027]4.5 图表
05产品与技术
5.1 产品定义和模块地图
Teleport 是证书颁发机构(CA)和身份感知访问代理,支持 SSH、RDP、HTTPS、Kubernetes API,以及多种 SQL 和 NoSQL 数据库协议。产品以单一 Go 二进制文件分发,把认证、授权、审计和隧道放在一个可部署单元里。Teleport 为主机和用户运行内部 Certificate Authorities;每个身份——人、机器或 AI——获得短期证书,而非长期凭证,从架构层面消除密钥蔓延。 产品套件现在覆盖五个品牌化产品支柱:Zero Trust Access(SSH、Kubernetes、数据库、RDP、Web 应用)、Machine & Workload Identity(非人服务凭证)、Identity Governance、Identity Security(访问分析和威胁检测),以及 Agentic Identity Framework(AI 代理身份 + Beams 运行时)。功能矩阵区分 Enterprise Cloud、Enterprise Self-Hosted 和 Community Edition,Beams 可信运行时仅限 Enterprise Cloud。历史上每四个月发布一个主要版本;版本 18(当前)于 2025 年 7 月到来,版本 19.0 已规划。2024 年 6 月社区许可证变更,限制员工超过 100 人或 AR 超过 $10 M 的公司使用编译二进制文件,这一变化对生态影响持久。[CE001, CE002, CE003, CE004, CE005, CE006]
| 模块 / 产品 | 主要用户 | 状态 / 成熟度 | 差异化 | 尽调缺口 |
|---|---|---|---|---|
| Zero Trust Access — SSH | 工程师 / 管理员 | GA,已在大型企业生产环境使用 | 仅证书认证、无 SSH key;按会话审计日志 | 相比 StrongDM,传统协议支持存在缺口 |
| Zero Trust Access — Kubernetes | 平台 / DevOps 工程师 | GA | kubectl 证书注入;按 pod RBAC;kubectl exec 会话录制 | Agent 在节点上以 root 运行 —— 增加攻击面 |
| Zero Trust Access — Databases | DBA / 开发者 | GA;PostgreSQL、MySQL、MongoDB、CockroachDB 等 | 协议级访问控制,无需改客户端配置 | 各版本完整 DB 协议覆盖清单未公开列举 |
| 零信任访问 — Windows / RDP | IT 管理员 / 工程师 | GA;通过 Teleport Web UI 的无 agent RDP | 无需单独 RDP 客户端;屏幕级会话录制 | PeerSpot 用户指出剪贴板访问是安全缺口 |
| 零信任访问 — Web 应用 | 工程师 / 内部用户 | GA | 基于身份访问和审计事件的 HTTPS 代理 | 未公开详述各身份提供商的 SSO 深度 |
| 零信任访问 — MCP 服务器 | AI 开发者 / 平台团队 | GA(Community 和 Enterprise) | 一等 MCP 纳管;按工具审计事件 | 运营成熟度和生产规模未验证 |
| Machine & Workload Identity | 服务 / CI-CD / 工作负载 | GA | tbot 签发短期证书;无常驻服务密钥 | SPIFFE/SVID 互操作深度未被外部完整记录 |
| Identity Governance | 安全 / 合规团队 | GA(Enterprise) | 访问列表、嵌套组、JIT 访问请求、ChatOps 集成 | Nested Access Lists 在 v17 引入 —— 成熟度仍新 |
| Identity Security | CISO / 安全分析师 | GA(Enterprise) | Crown Jewels 监控、SQL 编辑器访问查询、异常告警 | 未披露 AI 告警模型准确率和误报率 |
| Beams — Agentic Runtime | AI 开发者 / 平台团队 | 公开 beta(仅 Enterprise Cloud),2026 年 6 月 | Firecracker VM 隔离、LLM Proxy、Delegated Identity | 仅 beta;GA 时间线未披露;仅 Cloud 限制自托管部署 |
成熟度评级基于 Teleport 官方功能矩阵和发布说明。Community Edition 缺口在适用处标注。
[CE001, CE002, CE003, CE004, CE005, CE006]五个产品支柱叠在统一的 Auth 和 Proxy 控制平面之上。
[CE001, CE002, CE003, CE004, CE005, CE006]5.2 架构和运行模型
Teleport 控制平面由两项标准服务组成:Auth Service(集群 CA、配置存储和审计日志收集器)与 Proxy Service(公网入口和反向隧道枢纽)。两项服务彼此之间无状态,通过 gRPC 通信,并可水平扩展以实现高可用。在 Teleport Cloud 上,两项服务均由 Teleport Inc. 全托管;在 Enterprise Self-Hosted 中,客户在自有基础设施上运行它们。 资源接入有三条路径:Teleport Agents(以守护进程部署在目标机器上,并反向隧道回 Proxy)、部分协议的无代理模式,以及 Machine & Workload Identity tokens(基于 tbot 的工作负载短期证书)。认证流程跨协议一致:用户(或机器)运行 tsh login,获得客户端证书,随后 SSH、Kubernetes、数据库、RDP 和 MCP 代理接受该证书,无需重新认证。会话录制可在节点或代理层配置,可同步或异步,并捕获 SSH 与 Kubernetes 的完整 PTY 输出、桌面会话屏幕内容,以及数据库会话查询流。 StrongDM 的竞争分析指出,Teleport agents 在目标服务器上以 root 身份运行,增加额外攻击面;该公司还批评其遗留协议支持有限、云可靠性间歇性不足。PeerSpot 用户也独立指出,RBAC 复杂、初始设置负担重,以及 RDP 会话中的剪贴板访问安全,是实际摩擦点。[CE010, CE011, CE012, CE013, CE014, CE015]
| 层 / 组件 | 角色 | 依赖 | 风险 |
|---|---|---|---|
| Auth Service | 内部 CA;配置存储;审计日志收集器 | 需要持久化后端(etcd、DynamoDB、Postgres 或 Teleport Cloud 存储) | 未配置 HA 时会成为单点故障;密钥轮换政策必须实际演练 |
| Proxy Service | 面向公网入口;反向隧道中枢;Web UI 服务器 | 通过 gRPC 连接 Auth Service;所有协议经 443 端口做 TLS 路由 | StrongDM 称其云可靠性有问题,更新期间停机最长可达 6 小时 |
| Teleport Agent | 运行在目标节点上;通过反向隧道把流量送回 Proxy | 目标 OS(Linux/Windows);多数模式需要 root 级访问 | 以 root 运行 Agent 会放大每台接入主机的攻击面 |
| tbot(MWI agent) | 为工作负载签发并续期短期证书 | Teleport Auth Service;兼容 SPIFFE 的证书格式 | 如果进程隔离较弱,tbot 凭证可能暴露 |
| Certificate Authorities | 签发主机和用户证书;支撑零信任集群成员资格 | Hardware Security Module 可选;FIPS 使用 BoringCrypto | CA 一旦被攻破,整个集群都会失效;需要自动化轮换 |
| Session Recording Store | 捕获 PTY、屏幕、查询流;审计记录防篡改 | S3 兼容对象存储或 Teleport Cloud 存储 | 用户可尝试用编码隐藏 PTY 命令(文档已披露的风险) |
| Identity Security Analytics | 用 SQL 编辑器查询访问图;Crown Jewels 监控;AI 异常检测 | 摄取 Okta、AWS、GitHub 日志,以及 Teleport 审计流 | AI 告警准确性尚无独立验证 |
| Beams Runtime(beta) | 每个 agent 会话一个 Firecracker microVM;LLM Proxy;Delegated Identity | OpenAI / Anthropic 推理端点;Teleport 身份层 | beta;仅限 Enterprise Cloud;GA 时间未披露 |
架构基于 Teleport 官方文档和功能矩阵;StrongDM 的说法来自竞争对手,可能带有偏向。
[CE010, CE011, CE014, CE015, CE016, CE017]用户或机器如何认证并获得受保护资源的访问权。
[CE010, CE011, CE012, CE013]5.3 Agentic Identity 与 Machine & Workload Identity
Teleport Machine & Workload Identity(MWI)用与人类访问相同的证书模型,为非人服务账户提供身份。服务通过 tbot 认证,接收短期 X.509 或 SSH 证书,再用这些证书授权访问数据库、Kubernetes 集群、内部 API 和 MCP 服务器——全部记录到同一条审计轨迹里。这为人和机器创建了单一身份网络,而不是另起一套密钥管理系统。 2026 年 1 月发布的 Agentic Identity Framework 把该模型延伸到 AI 代理。它定义四层:身份(加密代理证书)、访问(通过 Teleport proxy 执行 RBAC / ABAC)、安全(行为监控和锁定)以及调度(Kubernetes 和 Temporal 的编排模式)。2026 年 6 月 Beams 公开测试版增加两项具体能力:LLM Proxy(位于代理与推理端点之间,记录每个请求 / 响应,并执行每个 Beam 的允许列表)和 Delegated Identity(允许人类或编排器为一个代理会话分配最小权限)。每个 Beam 在 Firecracker microVM 中运行,具备临时存储、注入身份、虚拟网络,以及约 24 小时的会话绑定生命周期。Beams 目前仅限 Enterprise Cloud,处于公开测试版——尚未正式可用。[CE020, CE021, CE022, CE023, CE024, CE025]
| 用户任务 | 不用 Teleport 的当前工作流 | Teleport 方案 | 已说明的可量化收益 | 限制 / 缺口 |
|---|---|---|---|---|
| 工程师 SSH 访问云主机 | 分发 SSH keypair;手工轮换;无中央审计 | tsh login → 短期证书 → ssh user@host;自动审计日志 | 消除常驻 SSH key;访问耗时下降 80%(公司声称) | Agent 必须在目标上以 root 运行;传统 OS 支持有限 |
| Kubernetes 集群访问 | kubectl 使用长期 kubeconfig token;每个集群单独 RBAC | Teleport 将证书注入 kubeconfig;集中 RBAC;按查询审计 | 所有 k8s 集群单点 SSO;按 exec 会话录制 | Agent footprint 增加运维复杂度 |
| 数据库访问(Postgres/MySQL) | 直接 DB 凭证;共享密码;无查询审计 | Teleport DB 代理;短期证书;查询级审计日志 | 开发者笔记本上没有 DB 凭证 | 并非所有版本都支持所有 DB 引擎 |
| Windows 桌面(RDP) | 单独 RDP 客户端;VPN + RDP 凭证存储在笔记本上 | 通过 Teleport Web UI 的浏览器 RDP;无需 RDP 客户端 | 屏幕捕获会话录制;无需 VPN | 用户评论提到剪贴板安全担忧 |
| AI agent 访问基础设施 | Agent 用静态 API key 和未检查权限冒充用户 | tbot 给 agent 签发自己的证书;代理侧执行 RBAC;查询被记录 | 100% 可审计的 agentic 工作流(公司声称) | Beams 仍处公开 beta;不支持自托管 Beams |
| FedRAMP / 合规审计 | 在 VPN、bastion 和云 IAM 之间手工收集日志 | Teleport 原生覆盖 AC-02、AC-03、AC-07、AU-02、AU-12 等 | 加速 FedRAMP-Moderate ATO;FIPS 140-3 验证模块 | FedRAMP ATO 时点取决于客户完整技术栈 |
除非另有说明,收益陈述均为公司声称;没有独立量化。
[CE010, CE012, CE013, CE014, CE015, CE029]Agentic Identity Framework 组件与外部服务之间的依赖关系。
[CE020, CE021, CE022, CE023, CE024, CE025]5.4 信任、合规和路线图
Teleport Enterprise 包含通过 FIPS 140 验证的加密模块。版本 17.7.3+ 和 18.0.0+ 使用 BoringCrypto CMVP certificate #4735(FIPS 140-3);更早版本使用 certificate #4407(FIPS 140-2)。这让 Teleport 成为 FedRAMP-Moderate 授权的可行加速器,因为它原生覆盖 AC-02 到 AU-12 及其他 NIST SP 800-53 控制项。Teleport 还记录了 SOC 2 在九个控制类别中的四项覆盖(CC6、CC6 physical、CC7、CC8)。Cure53 于 2019 年进行的独立安全审计未发现严重漏洞;roles API 中一个高危目录遍历问题已在同一版本修复。 发布节奏为每年一个主要版本(从四个月节奏切换而来);版本 18 是当前受支持版本(EOL 2027 年 8 月),版本 17 是稳定受支持版本(EOL 2026 年 8 月)。即将到来的路线图事项包括 Linux Desktop Access(到 Linux 主机的远程会话)、Windows RDP 的目录共享增强,以及 Identity Security 中 AI 总结的会话录制。从版本 16(2024 年 6 月)开始的社区许可证变更,是最重大的持续信任风险:员工超过 100 人或 AR 超过 $10 M 的公司使用编译二进制文件、容器镜像和 AMI,不再适用 Apache 许可证。源代码仍是 AGPLv3,但多数企业使用编译产物,因此商业限制成为事实许可证。[CE029, CE030, CE031, CE032, CE033, CE034]
| 控制 / 认证 | 状态 | 范围 | 缺口 / 注意事项 |
|---|---|---|---|
| FIPS 140-3(BoringCrypto | 生效 | Teleport Enterprise v18+ 编译二进制文件 | 仅 Enterprise 构建;Community Edition 不符合 FIPS |
| FIPS 140-2(BoringCrypto | 旧版本生效(17.7.3 之前) | Teleport Enterprise v16–17 系列 | 正被 FIPS 140-3 模块取代 |
| FedRAMP 覆盖(AC、AU 控制) | 通过 FIPS 构建 + RBAC + 审计日志支持 | 基础设施访问控制;不是完整 ATO | 客户必须自行取得 ATO;Teleport 只是赋能组件 |
| SOC 2(CC6、CC7、CC8) | 有文档化映射 | Enterprise Edition;九类控制中的四类 | Community Edition 不提供 SOC 2 合规功能 |
| 第三方安全审计(Cure53) | 2019 年完成;未发现严重漏洞 | 全量源代码审计;一个高严重性问题在同一版本修复 | 审计停留在 2019 年;未披露更新的公开第三方审计 |
| Apple 代码签名 | 生效(Developer ID QH8AA5B8UP,Gravitational Inc.) | macOS 包和二进制文件 | 证书 2026-07-27 到期;续期状态未公开确认 |
| Community Edition 商业许可证(v16+) | 2024 年 6 月起生效 | 员工 100+ 或 AR $10 M+ 的公司必须购买 Enterprise | 许可证变化扰动开源生态;AGPLv3 源码仍可用 |
| 会话录制安全(PTY 混淆风险) | 官方文档披露的限制 | SSH 和 Kubernetes 会话 | 用户可编码命令来隐藏活动;BPF Enhanced Recording 可缓解 |
合规状态反映公开文档中的官方说法和链接的 CMVP 证书;2019 年后未见独立第三方验证。
[CE029, CE030, CE031, CE032, CE033, CE034]| 日期 / 版本 | 功能 / 里程碑 | 状态 | 影响 | 来源 |
|---|---|---|---|---|
| 2025 年 7 月(v18.0.0) | Teleport 18 当前版本;AWS IAM Identity Center preview | 已发布;EOL 2027 年 8 月 | 核心 GA 版本;为 2026 年产品路线图打底 | 官方文档 |
| 2024 年 11 月(v17.0.0) | Teleport 17 稳定版;Identity Security Crown Jewels;Nested Access Lists | 已发布;EOL 2026 年 8 月 | Crown Jewels 和 Nested Access Lists 是新功能;成熟度仍在形成 | 官方博客 |
| 2024 年 6 月(v16.0.0) | Teleport 16;社区许可证商业限制;IdP 加固 | 已发布 | Community Edition 现在限制企业使用;生态影响仍在发酵 | 官方博客 + 社区许可证公告 |
| 2026 年 1 月 | 发布 Agentic Identity Framework;四层 AI 安全路线图 | 已宣布 | 定义 AI agent 架构;商业化实现仍在推进 | 新闻稿 |
| 2026 年 6 月 | Beams 公测 — Firecracker VM 中的 LLM Proxy 和 Delegated Identity | 公测(仅限 Enterprise Cloud) | GA 时间未披露;自托管客户无法参与 beta | 新闻稿 |
| 2026 年 7 月 6 日当周(v18.10.0) | 补丁周期继续;18.10.0 计划云端推出 | 已计划 | 证实主版本内维持四个月补丁节奏 | 官方 upcoming-releases 文档 |
| 未来(v19.0.0) | Linux Desktop Access;多目录 Windows RDP;AI 总结的会话录制 | 路线图中;日期未披露 | Linux desktop 扩大 RDP 覆盖;AI 摘要缩短调查时间 | 官方 upcoming-releases 文档 |
日期基于官方发布公告和文档;Beams GA 时间未公开披露。
[CE034, CE035, CE036, CE037, CE008, CE026]Teleport 关键能力领域的成熟度与竞争差异化。
成熟度评级来自官方文档和功能矩阵;竞争差异化是作者基于架构分析和竞品对比做出的评估。
[CE001, CE003, CE005, CE006, CE020, CE025]5.5 图表
06客户
6.1 客户分层和购买画像
Teleport 的买方主要是中大型企业里的工程团队或平台安全团队,技术、金融服务和全球数字平台公司尤其典型。采购决策通常由基础设施工程负责人(工程副总裁、平台工程师、CISO)推动,DevOps 和 SRE 团队是核心用户。官方客户页和案例研究呈现出一致模式:企业希望用基于证书的基础设施访问,替代 VPN 加共享凭证的做法。 公开案例覆盖的垂直行业包括金融科技(Carta、Exness)、全球 SaaS 平台(GoTo、Gladly)、网络检测(ExtraHop)和企业可观测性(IBM Instana)。Series A 融资公告点名 Nasdaq(证券交易所)、Splunk(SIEM / 可观测性)、TicketMaster(现场娱乐)、Mulesoft(API 集成)和 Samsung(消费电子);Series C 则明确点名 Nasdaq、DoorDash 和 Snowflake。Fortune Cyber 60 新闻稿(2025 年 10 月)称,「超过 600 家公司,包括五大金融服务公司中的三家,以及 AI 研究、算力和云领域的领导者」依赖 Teleport——这是迄今最宽泛的客户基数表述,但来自公司自身。 地域上,客户高度集中在北美和全球科技公司,GoTo 总部在东南亚(印度尼西亚),Exness 则在全球金融市场运营。公司规模从成长阶段企业(Series B 时期客户)到大型上市企业(Nasdaq、Samsung、IBM)不等。Community Edition 为小型公司和员工少于 100 人或年收入低于 $10 M 的团队提供获客入口;一旦触及商业许可门槛,就转入 Enterprise 销售。[CU001, CU002, CU003, CU004, CU005, CU006]
| 客群 | 买方 / 用户 | 主要用例 | 公开规模 / 证明 | 缺口 |
|---|---|---|---|---|
| 技术原生企业(fintech/SaaS/cloud) | VP Engineering / CISO / Platform 团队 | 基于证书的 SSH、K8s、DB 访问;合规(SOC 2、ISO 27001) | Carta、Exness、Gladly、ExtraHop、GoTo 在案例研究中确认 | NRR、合同规模、流失未披露 |
| 全球数字平台(电商、出行、游戏) | Platform/SRE 工程师 | 统一多云访问;Kubernetes 私有集群访问 | GoTo(东南亚平台)、Rush Street Interactive(游戏)、Turo(汽车共享) | 未披露部署规模指标 |
| 企业可观测性 / 基础设施工具厂商 | Cloud Architect / Infrastructure 团队 | 安全访问云原生可观测性工具;合规证明 | IBM Instana(IBM 旗下);ExtraHop;KnowBe4 | 只有 IBM Instana 有详细案例研究 |
| 金融服务 / 证券交易所 | 安全 / 合规团队 | FedRAMP-ready;监管合规所需审计日志 | Nasdaq 在 Series A 和 C 中被点名;「前 5 大金融服务公司中 3 家」(Fortune Cyber 60) | NVIDIA 未验证;缺少单家金融公司的案例研究 |
| Startup / SMB 社区(低于门槛) | Dev / DevOps 工程师 | 员工少于 100 人 / AR 低于 $10 M 的公司可用免费 Community Edition | 15,000+ GitHub stars;广泛开源采用信号 | Community-to-Enterprise 转化率未知 |
分群基于公开案例研究、融资博客点名客户和官方新闻稿。各客群收入或席位集中度未公开披露。
[CU001, CU002, CU003, CU004, CU005, CU010]典型企业客户如何发现、评估、部署并扩展 Teleport。
[CU001, CU002, CU003, CU030, CU031]6.2 采用轨迹与规模信号
Teleport 最权威的客户数量表述来自 2025 年 10 月 Fortune Cyber 60 新闻稿:「超过 600 家公司,包括五大金融服务公司中的三家,以及 AI 研究、算力和云领域的领导者,依赖 Teleport。」该说法由公司发布,无法独立审计。更早的里程碑包括 Series A 博客所称从「少数早期采用者」发展到「全球最大、最具创新性的公司中的一批」客户组合,以及 Series C 披露的「净新增 ARR 同比增长 4.5 倍」。Getlatka 数据库(截至 2025 年 11 月)报告年收入约 $49 M、员工约 246 人,符合中端 SaaS 规模。 案例研究页面公开列出至少 15 个具名客户——GoTo、Exness、Gladly、ExtraHop、IBM Instana、Carta、KnowBe4、Turo、Rush Street Interactive、Buyers Edge、ThredUP、Qwilt、Mapgears、ECMWF、Flywheel——另有更多匿名描述。客户类型横跨北美 SaaS、全球金融科技、游戏、电商、生物医学研究和气象基础设施。部署深度看起来很深:Exness 称通过 Teleport 管理「横跨本地和云端的数百个 Kubernetes 集群」;GoTo 则称 Teleport 为其庞大基础设施管理「跨多个云服务商」的访问。 Teleport 已连续多年入选 Fortune Cyber 60,并在 Citizens Cyber 66 2026 年 4 月报告中被认定为「收入类别跃迁者」,显示业务势头仍在。独立收入数据有限;Getlatka 的 $49 M 估算未经验证。NVIDIA 出现在部分非官方 logo 墙上,但没有任何官方新闻稿或案例研究确认——此处视为缺口。[CU010, CU011, CU012, CU013, CU014, CU015]
| 里程碑 / 指标 | 数值 | 日期 / 来源 | 置信度 | 缺口 |
|---|---|---|---|---|
| 点名客户数(官方表述) | >600 companies | 2025 年 10 月(Fortune Cyber 60 新闻稿) | 低-中(公司表述;未独立验证) | 无独立审计;Teleport 自述 |
| 净新增 ARR 增长(Series C 时期) | 4.5x YoY 净新增 ARR;2.8x total ARR YoY | 2022 年 3 月(Series C 博客) | 中(历史数据;与披露融资相符) | 2022 年后未更新;当前增长率未知 |
| 收入估计(独立) | 2024 年年收入约 $49 M | 2025 年 11 月(Getlatka) | 低(估计;方法未披露) | 独立估计;Teleport 未确认 |
| 官方页面上的点名案例研究 | 15+ 个点名客户故事 | 2026 年 6 月(Teleport 案例研究页) | 高(直接观察) | 企业客户样本;不代表完整客户基础 |
| GitHub stars(开源采用信号) | >15,000 stars | 2024 年 6 月(社区许可证公告) | 中(公司表述;当前数量未重新抓取) | 截至 runDate,GitHub star 数未独立重新抓取 |
| 被认定为「revenue category mover」 | Citizens Cyber 66 2026 认可 | 2026 年 4 月(Citizens Securities 报告) | 中(独立分析机构认可) | 报告全文未公开 |
| 员工数 | ~246 employees | 2025 年 11 月(Getlatka) | 低(估计) | 第三方估计;Teleport 未确认 |
数值来自公开来源;NRR、GRR、logo 数和 ARR 均为私有数据。Getlatka 收入和员工数估计未经验证,属于第三方数据。
[CU010, CU011, CU012, CU013, CU014, CU016]从开源社区到企业客户的估计转化阶段。
阶段规模为估计;只有 GitHub stars 数和 600+ 家企业数据由公司正式表述。社区到企业的转化率未公开披露。
[CU010, CU013, CU014]6.3 具名客户证明与案例质量
六个客户在 goteleport.com 上有深入、公开的案例研究,均确认生产环境使用: **IBM Instana**(2020 年被 IBM 收购):云架构师 Hunter Madison 用 Teleport 替代 VPN 加共享凭证来访问 Dropwizard,并表示这是他主导 Teleport 迁移的第三家公司。引述:「这是我做这件事的第三家公司,让 Teleport 发挥作用,给我们能力去改善安全态势。」确认生产使用;信息独立且具体。 **Carta**(金融科技,估值 $7 B+):将 Teleport 与 Okta 集成,用于 Kubernetes 和数据库 RBAC、带细粒度审计的基于角色访问策略,以及更顺畅的开发者入职 / 离职流程。确认用于 SOC 2 / ISO 27001 合规。已在规模化生产环境使用。 **GoTo**(东南亚最大数字平台,已上市):用 Teleport 替代自研工具,管理私有 Kubernetes 集群(「我们所有 Kubernetes 集群都是私有的——也就是说无法被公开访问」)。多云规模的生产部署;由合规驱动(上市公司)。 **Exness**(全球金融科技,受监管金融服务):称「Teleport 是评估过的方案中唯一满足所有要求的一个」,包括全自动化、GitOps 就绪、SSO 和机器身份。生产环境覆盖数百个 Kubernetes 集群。确认满足 PCI DSS、SOC 2 和 ISO 27001。 **Gladly**(SaaS CX 平台):用 Teleport 作为 RBAC 的证书颁发机构,替代静态 SSH 密钥。确认无密钥服务器访问用于合规和基于证据的安全审计。 **ExtraHop**(网络检测与响应):用 Teleport 保障基于身份的 SSH 和 Kubernetes 访问,覆盖半打 Kubernetes 集群,每个集群运行数百个独立节点。 官方新闻稿验证过的 logo 包括 Nasdaq、DoorDash、Snowflake、Splunk、TicketMaster、Mulesoft、Samsung(Series A / C 博客)。Square、Elastic 和 Bloomberg 出现在官方客户页上,但缺少单独案例研究。NVIDIA 未在官方来源中验证。[CU019, CU020, CU021, CU022, CU023, CU024]
| 客户 | 行业 | 部署确认 | 成果 / 引语 | 验证状态 | 来源 |
|---|---|---|---|---|---|
| IBM Instana | 企业可观测性(IBM 子公司) | 生产环境 — Kubernetes、数据库、SSH | 这是我在第三家公司推动 Teleport 落地 | 已验证:goteleport.com 官方案例研究 | 官方案例研究 |
| Carta | Fintech(cap table 管理) | 生产环境 — Kubernetes RBAC、数据库、Okta SSO 集成 | SOC 2/ISO 27001 合规;开发者入职改善 | 已验证:goteleport.com 官方案例研究 | 官方案例研究 |
| GoTo | 东南亚数字平台(公开上市) | 生产环境 — 私有 Kubernetes 集群、多云 | Teleport 完全契合我们对私有 K8s 访问的要求 | 已验证:goteleport.com 官方案例研究 | 官方案例研究 |
| Exness | 全球 fintech / 交易技术(受监管) | 生产环境 — 数百个 K8s 集群、数据库、SSH、Web 应用 | Teleport 是评估方案中唯一满足所有要求的解决方案 | 已验证:goteleport.com 官方案例研究 | 官方案例研究 |
| Gladly | SaaS 客户体验平台 | 生产环境 — 无密钥 SSH 访问、RBAC、合规审计 | 会话录制作为合规审计证据 | 已验证:goteleport.com 官方案例研究 | 官方案例研究 |
| ExtraHop | 网络检测与响应(网络安全) | 生产环境 — 6 个 K8s 集群,每个数百节点 | 所有 K8s API 查询和 SSH 命令均采用基于身份的授权 | 已验证:goteleport.com 官方案例研究 | 官方案例研究 |
| Nasdaq | 证券交易所(金融市场) | 已声明客户(无单独案例研究) | Series A 博客和 Series C Bessemer 引语中点名为客户 | 已验证:官方博客文章 | Series A 博客;Series C 博客 |
| DoorDash | 外卖平台 | 已声明客户(无单独案例研究) | Bessemer 在 Series C 投资博客中点名 | 已验证:官方 Series C 博客 | Series C 博客 |
| Snowflake | 云数据平台 | 已声明客户(无单独案例研究) | Bessemer 在 Series C 投资博客中点名 | 已验证:官方 Series C 博客 | Series C 博客 |
| Splunk | SIEM / 可观测性(现属 Cisco) | 已声明客户(无单独案例研究) | Series A 博客中点名 | 已验证:官方 Series A 博客 | Series A 博客 |
| Samsung | 消费电子 / 全球企业 | 已声明客户(无单独案例研究) | Series A 博客中点名 | 已验证:官方 Series A 博客 | Series A 博客 |
| NVIDIA | AI 计算 / 半导体 | 未确认 | 未在任何官方新闻稿或案例研究中找到 | 未验证:不在官方来源中 | 缺口 — 无来源 |
验证状态看客户名称是否出现在 Teleport 发布的官方来源(案例研究、博客、新闻稿)。「未验证」指名称只出现在第三方或社区列表中,未出现在官方来源中。NVIDIA 是已记录缺口。
[CU019, CU020, CU021, CU022, CU023, CU024]公开客户证明在关键维度上的质量与深度。
评分反映作者对公开可得证据的评估;没有案例研究的客户仅限于具名参考。
[CU019, CU020, CU021, CU022, CU023, CU024]6.4 留存、扩张与集中度风险
Teleport 不公开披露 NRR、GRR、logo 流失或续约率。Series C 博客提到 ARR 同比增长 2.8 倍、净新增 ARR 增长 4.5 倍,符合来自现有客户的强扩张特征,但这些数字来自 2022 年,如今已是历史数据。PeerSpot 用户称 Teleport「通过集中访问控制改变了我们的工作流」,多位评论者把它描述为替代传统 SSH 密钥流程的粘性工具——两者都指向较高切换成本。 Exness(数百个 Kubernetes 集群)、GoTo(多云、多垂直)和 ExtraHop(数百个独立节点)的企业部署深度,说明 Teleport 已嵌入基础设施,形成有意义的切换成本。IBM Instana 的云架构师明确提到,这是他在不同公司推动的第三次 Teleport 部署,是顾问驱动重复采用的强信号。 扩张风险:StrongDM 的竞争批评认为,Teleport 缺少传统协议支持和 SIEM 集成,这可能限制其向混合传统 / 云环境客户扩张。社区许可变更(v16+)限制了大型公司的免费社区层,可能增加社区漏斗转商业扩张的摩擦。集中度是实质风险:公开具名客户明显偏向金融科技和云基础设施里的技术原生公司;医疗、制造、政府和零售行业在公开证据中代表性不足。Fortune Cyber 60 提到「五大金融服务公司中的三家」,说明单一垂直行业集中度显著。[CU029, CU030, CU031, CU032, CU033, CU034]
| 信号 | 证据 | 置信度 | 限制 |
|---|---|---|---|
| 顾问驱动的重复部署 | IBM Instana 的云架构师确认,已在不同公司第三次部署 Teleport | 高 | 仅引用单一个人;不是代表性样本 |
| 深度基础设施集成(切换成本) | Exness — 数百个 K8s 集群;GoTo — 多云;ExtraHop — 数百节点 | 高 | 深度指标来自案例研究推断;不是汇总留存数据 |
| 社区生态黏性(开源) | 15,000+ GitHub stars;社区论坛持续活跃 | 中 | stars 是滞后指标;当前活跃度未单独衡量 |
| 正面用户评价(PeerSpot) | 被描述为稳健、安全、提升生产力;替代传统工具 | 中 | PeerSpot 评价数量未披露;样本可能经过筛选 |
| NRR / GRR(量化) | 未披露 | 低(不可得) | 关键留存指标;公开信息中没有可用 proxy |
| 合同长度 / 续约率 | 未披露 | 低(不可得) | 未公开披露合同条款或续约基准 |
| 流失信号(负面) | StrongDM 称 Teleport Cloud 有可靠性问题;PeerSpot 评价提到部署摩擦 | 中 | 竞品批评可能有偏见;但 PeerSpot 评价来自独立用户 |
留存证据偏定性且间接。量化 NRR、GRR 和续约数据均未公开。顾问驱动的重复部署是较强定性信号,但只来自一名顾问。
[CU019, CU029, CU030, CU031, CU032, CU033]| 风险因素 | 证据 | 严重性 | 尽调问题 |
|---|---|---|---|
| 垂直行业集中(科技 - 金融) | 公开点名客户高度集中在金融科技、云和 SaaS;未见医疗和制造业 | 重大 | 要求提供各垂直行业 ARR 拆分 |
| 金融服务集中 | 五大金融服务公司中有三家被点名;Nasdaq 是唯一被点名的金融交易所 | 重大 | 要求提供前 10 大客户集中度,占 ARR 比例 |
| 社区版到企业版转化摩擦 | v16+ 许可变更限制员工超过 100 人 / 年收入 $10 M 的社区用户 | 重大 | 衡量 v16 后社区版 → 企业版转化率变化 |
| NVIDIA 标识未经验证 | 未在 Teleport 官方来源中找到 NVIDIA;可能出现在非官方标识墙上 | 轻微 | 确认 NVIDIA 是否为活跃企业客户 |
| 竞争流失风险(传统协议) | StrongDM 称 Teleport 缺少传统协议支持;这会限制其在混合环境中的扩张 | 重大 | 要求提供涉及传统系统交易的竞争胜负数据 |
| 自托管客户升级路径 | Beams 和部分 Identity Security 功能仅限 Cloud;自托管客户可能落后 | 轻微 | 询问企业客户中自托管与 Cloud 的拆分 |
集中度风险来自公开点名客户证据的推断;私有 ARR 集中度数据不可得。
[CU034, CU035, CU036, CU037, CU038, CU039]从关键维度看六个案例客户的定性留存信号强度。
评分为 0-100 的定性判断,依据公开案例研究证据;目前没有公开的量化 NRR 或续约数据。
[CU019, CU020, CU021, CU022, CU023, CU024]6.5 图表与证据
07风险
7.1 许可变更与开源社区风险
2024 年 6 月,Teleport 从 v16 开始把 Community Edition 编译产物从 Apache 2.0 迁至商业许可,制造了一个自伤型信任风险。该政策适用于员工 100 人及以上或年收入至少 $10 million 的公司,也禁止转售或嵌入 Community Edition 产物。这个变化很关键,因为 Teleport 很大一部分类别信誉来自开发者采用;公告发布时,项目已有超过 15,000 个 GitHub stars。源代码仍然可用,但大多数企业实际消费的是二进制文件、镜像或 AMI,因此即使仓库保持公开,商业限制也改变了开发者的真实体验。由此产生的风险不只是社交媒体反弹。它会激励 fork,削弱自下而上的布道,复杂化旧 Apache 许可构建的升级路径,并招致批评:Teleport 已不再像 Open Source Initiative 定义下的常规基础设施开源项目那样行事。[CR001, CR002, CR003, CR004, CR005, CR006]
| 规则 / 许可 / 案例 | 司法辖区 | 状态 | 可能性 | 严重性 | 缓释措施 | 剩余敞口 | 尽调路径 |
|---|---|---|---|---|---|---|---|
| Teleport v16 Community Edition 商业许可 | 全球商业使用 | 2024 年 6 月起对较大公司生效,并禁止转售 / 嵌入 | 高 | 高 | 清晰的商业升级路径和源码可得性降低短期混乱 | 高,因为信任受损和分叉动机仍在 | 审查许可文本、SKU 执行机制和客户升级政策 |
| Open Source Initiative 开源定义 | 全球开源规范 | 限制使用的商业条款不符合 OSI 开源标准 | 高 | 中 | Teleport 仍可维护公共仓库和社区文档 | 高,因为开发者观感可能不会很快恢复 | 要求提供关于 OSS 定位和社区沟通的法律备忘录 |
| Teleport Cloud FedRAMP 授权状态 | 美国公共部门 | 文档描述可加速客户合规;未找到 Teleport Cloud 公开授权 | 中 | 高 | 启用 FIPS 的构建和控制映射支持客户 ATO 工作 | 中到高,因为采购团队可能预期供应商已有授权 | 确认是否存在任何云服务授权包,以及谁拥有边界控制责任 |
| FIPS 140-3 加密边界表述 | 美国受监管买家 | 使用 BoringCrypto 证书 | 低 | 中 | 官方版本指引缩窄获批部署范围 | 低到中,因为版本漂移仍可能造成合规错误 | 核验目标客户使用的准确构建版本和销售话术 |
| 旧版 Apache 许可工件来源 | 现有企业用户 | 旧版本仍沿用此前条款,但升级路径改变经济性和义务 | 中 | 中 | 固定版本并审查合同可降低意外 | 中,因为混合版本资产可能带来法律和运营摩擦 | 梳理哪些客户依赖 v16 前工件及计划迁移时间 |
各行聚焦公开法律和合规问题,这些问题可能改变采购、升级或社区结果;不能替代合同审查。
[CR001, CR002, CR004, CR007, CR016, CR017]在可见公开缓释因素之后,Teleport 主要剩余风险类别的相对位置。
[CR006, CR014, CR018, CR026, CR033, CR041]7.2 自托管复杂性与运营风险
Teleport 的架构带来强控制和审计收益,但也把运营负担推给客户,可能演变为投资风险。StrongDM 的竞争材料称,Teleport agent 在目标服务器上以 root 运行,形成有意义的特权攻击面;他们还把 Teleport 描述为潜在单点故障,前提是控制平面没有按高可用设计。这些说法带有方向性,并非中立评价,但与客户评论中的证据相吻合:大型部署配置和运营都可能复杂。自托管模式要求客户自行负责 auth 和 proxy 组件的基础设施容量、补丁、升级顺序、灾难恢复和宕机预案。Teleport 发布过安全审计材料并支持 FIPS 140-3,这些确实是缓释因素,但无法抹掉架构脆弱性或实施复杂度。FedRAMP 又增加一层:Teleport 文档说明客户如何用产品满足控制族要求,但公开材料没有显示 Teleport Cloud 自身持有 FedRAMP 授权,这会在公共部门销售周期中制造混淆。[CR010, CR011, CR012, CR013, CR014, CR015]
| 故障模式 | 可能性 | 严重性 | 缓释成熟度 | 剩余敞口 | 未解决缺口 |
|---|---|---|---|---|---|
| 以 root 运行的特权代理会成为托管服务器上的额外攻击面 | 中 | 高 | 中 | 在敏感环境中,除非拿出加固证据,否则敞口仍高 | 需要加固指引、事件历史和客户安全审查结果 |
| HA 设计不当时,认证 / 代理控制平面宕机会阻断基础设施访问 | 中 | 高 | 中 | 高,因为访问中断会打到关键业务流程 | 需要可用性历史、参考架构和故障切换测试证据 |
| 自托管部署会累积补丁、升级和灾难恢复负担 | 高 | 中 | 中 | 对精简客户团队而言为中到高 | 需要支持负载指标、HA runbook 和版本升级失败数据 |
| 传统协议或认证支持有限,缩窄其在混合资产中的适配面 | 中 | 中 | 低 | 中,因为竞品能赢下混合环境交易 | 需要详细协议覆盖矩阵和按环境拆分的胜负数据 |
| 企业 RBAC 和部署复杂度拖慢初始 rollout | 高 | 中 | 中 | 中,因为复杂度损害价值兑现速度 | 需要实施周期、服务 attach rate,以及按部署规模拆分的评价情绪 |
| FedRAMP 营销被误读为 Teleport Cloud 已获服务级授权 | 中 | 高 | 低到中 | 中,因为公共部门尽调可能在后期卡住 | 需要明确销售话术、异议处理和授权边界文档 |
运营风险来自架构和部署负担,而不是当前语料中有具体已披露事件的证据。
[CR010, CR011, CR012, CR013, CR014, CR015]7.3 竞争压力与市场集中风险
Teleport 所处赛道有吸引力,但有吸引力的赛道会吸引更大、资金更充足的对手。2026 年 6 月,CyberArk 和 Okta 的市值均超过 $20 billion,收入基数也明显大于 Teleport 的估算规模,因此更有空间捆绑特权访问、吸收产品重叠,并在企业销售上压过 Teleport。StrongDM 攻击 Teleport 的传统系统覆盖和运营简单性;这很重要,因为许多企业访问资产是混合形态,而非云原生。HashiCorp Boundary 仍是一个带开源根基的身份感知代理替代方案;AWS、Google Cloud 和 Microsoft 也都提供原生 IAM 与特权访问功能,对只用云的买家可能已经足够。 Teleport 的 600 多家客户,以及登上 2026 Fortune Cyber 60 和 Citizens Cyber 66 榜单的具名认可,证明了真实市场牵引力,但也提高了门槛:一旦供应商进入顶级企业评估,功能缺口、打包摩擦和许可信任问题,都会被拿来与资金更充足的平台比较,而不是与没有既有供应商的空白局面比较。[CR019, CR020, CR021, CR022, CR023, CR024]
| 竞品 / 依赖 | 类型 | 竞争威胁 / 失败情景 | 严重性 | 缓释措施 | 剩余敞口 |
|---|---|---|---|---|---|
| CyberArk | 既有 PAM 套件 | 借规模、广泛企业关系和大产品面打包挤压 Teleport | 高 | 用开发者体验和现代基础设施工作流做差异化 | 高 |
| Okta Privileged Access | 身份平台邻近产品 | 把 PAM 扩进既有 IAM 客群,挤压独立需求 | 高 | 靠基础设施深度、会话录制,以及覆盖 SSH/Kubernetes/数据库的平台宽度取胜 | 高 |
| StrongDM | 直接现代访问竞品 | 以更简单部署和更广协议覆盖的定位,赢下混合或传统客户 | 中 | 补强传统支持证据和自托管运营清晰度 | 中 |
| HashiCorp Boundary | 开源风格替代方案 | 吸引想要身份感知代理、但不愿承担 Teleport 新商业许可包袱的买家 | 中 | 强调更宽产品面和企业控制能力 | 中 |
| AWS/GCP/Azure 原生 IAM 和 PIM 工具 | 云平台依赖 | 纯云团队认为原生控制已经够用,避免再引入一个控制平面 | 中 | 聚焦多云、混合、审计和即时访问工作流 | 中 |
| 开源善意和社区渠道 | 生态依赖 | 许可不信任削弱推荐、贡献者和低摩擦采用 | 高 | 用透明路线图和公平打包重建信任 | 高 |
本登记表混合列出具名竞品和生态依赖,因为 Teleport 的风险一部分是产品功能战,一部分是分发信任战。
[CR020, CR021, CR022, CR023, CR024, CR025]结合规模、相邻业务和替代风险,给出指示性竞争压力评分。
评分为序数型威胁分数,综合规模、捆绑能力和基于适配度的替代风险;它们不是市场份额估算。
[CR020, CR021, CR022, CR023, CR024, CR026]7.4 财务不透明与估值风险
Teleport 的财务争议更多来自可见度缺失,而不是可见弱点。公开融资历史清楚到 2022 年 3 月 Series C:Teleport 宣布由 Bessemer Venture Partners 领投,以 $1.1 billion 估值融资 $110 million,Series A、B、C 累计融资约 $140 million。看不清的是当前规模、利润率结构、现金效率和盈利能力。来源集合中唯一 ARR 数字是 GetLatka 对 2024 年 $49 million 的估算,且 Teleport 未验证。若该数字方向正确,最后披露估值意味着约 22 倍 ARR 倍数;对一家没有公开增长耐久性证明的私有基础设施公司而言,这个要求很高。给定材料中没有更新融资可见,投资者只能围绕一个已过时四年的价格锚承销。旧估值、估算 ARR 和缺失的单位经济数据叠加,使下行更难量化,也让资源更强的上市可比公司对市场情绪有更大影响。[CR028, CR029, CR030, CR031, CR032, CR033]
7.5 人员、执行与战略风险
Teleport 现在的战略风险来自两线作战:既要守住成熟的基础设施访问业务,又要扩张到 agentic AI identity。领导层集中度值得注意:Ev Kovyrin、Sasha Klizhentas 和 Taylor Wakefield 仍分别担任 CEO、CTO 和 COO,处在产品、工程和运营执行的中心。已审阅的公开材料没有披露继任计划、更广的管理梯队深度或当前员工数,外部难以判断管理冗余。与此同时,Teleport 已把自己重塑为 AI Infrastructure Identity Company,2026 年 1 月发布 Agentic Identity Framework,2026 年 6 月推出 Beams 公测。这些动作可能带来真实上行,但也引入路线图复杂性、支持负担,以及围绕委托权限、审计覆盖和 agent 运行时隔离的治理问题。核心风险不是公司不该向 AI 相邻领域扩张;而是在变现和控制成熟前,投资者仍需要证据证明新打法强化了既有访问业务,而不是分散注意力。[CR035, CR036, CR037, CR038, CR039, CR040]
| 角色 / 职能 | 依赖或缺口 | 可能性 | 严重性 | 缓释措施 | 尽调路径 |
|---|---|---|---|---|---|
| 创始领导层 | 三名联合创始人仍支撑战略、工程方向和运营 | 中 | 高 | 创始人经验丰富,且仍保持公开活跃 | 要求提供组织架构、授权管理层和继任规划材料 |
| 合规与公共部门 GTM | FedRAMP 定位要求边界责任和买家教育必须精确 | 中 | 高 | FIPS 支持和官方控制映射有帮助 | 要求提供公共部门 pipeline、异议日志和授权责任矩阵 |
| Agentic 产品团队 | AI 身份扩张可能稀释核心 PAM 执行注意力 | 中 | 高 | 复用核心平台的证书、审计和策略原语 | 要求提供 Beams 的路线图人员拆分和 GA 就绪标准 |
| SRE 与客户成功 | 自托管复杂度可能增加支持负担并拖慢续约 | 高 | 中 | 参考架构和托管云产品可降低痛感 | 要求按部署模式提供支持比例、升级指标和续约数据 |
| 财务与规划 | 未公开盈利、烧钱或增长披露,限制外部信心 | 中 | 中 | 既有蓝筹投资人提供一定信号价值 | 要求提供董事会包指标、当前 ARR、烧钱和 runway 假设 |
Teleport 现在同时横跨核心访问安全、受监管买家销售和新的 AI runtime 动作,人才风险因此抬高。
[CR035, CR036, CR037, CR038, CR039, CR042]| 风险 | 可监测触发器 | 阈值 / 事件 | 行动含义 |
|---|---|---|---|
| 许可 / 社区反弹 | 有意义的分叉牵引,或大型企业围绕 v16 许可提出重大异议 | 因 Community Edition 不再被视为开源,导致漏斗顶部流失或具名交易受阻 | 下调增长效率和生态护城河假设,重新承销 |
| FedRAMP 模糊性 | 公共部门尽调要求供应商授权证据 | Teleport 无法展示清晰服务边界语言或任何供应商授权包 | 推迟政府扩张承销,并升级合规审查 |
| 控制平面韧性 | 参考架构和宕机证据 | 自托管或云运营拿不出有说服力的 HA、DR 或可用性证据 | 将架构脆弱性视为关键任务部署的负面论点 |
| 财务不透明 | 当前 ARR、烧钱和毛利包 | 管理层无法把 2024 年估计值与当前运营指标对齐 | 下调估值,并要求更宽的下行情景 |
| AI 转向执行 | Beams beta 转化和治理里程碑 | 到下一次尽调里程碑仍无清晰采用、GA 路径或策略控制 | 将 AI 上行视为免费期权,而非承载价值的核心论点 |
| 竞争替代 | 胜负和续约数据 | 面对 StrongDM、Okta 或 CyberArk,传统支持或打包驱动的流失上升 | 下调定价权假设和销售效率预期 |
这些触发器刻意设计成可监测项,方便尽调区分可修复的披露缺口和需要停止或重定价的结构性理由。
[CR031, CR033, CR041, CR043, CR044, CR045]Teleport 的许可、架构和战略风险如何传导到增长与估值。
[CR008, CR011, CR018, CR026, CR033, CR037]7.6 图表与证据
08估值
8.1 投资正论与反论
投资正论首先来自市场结构和定位,而不是当前财务披露。Teleport 面向特权访问管理和零信任访问销售,这两类安全预算即使在软件支出放缓时仍具战略重要性。Precedence Research 估算 PAM 2025 年规模为 $4.50B,CAGR 为 23.4%;零信任市场更大,规模 $40.01B,CAGR 为 16.39%。Teleport 还受益于开发者驱动分发:开源仓库建立了广泛认知,公司声称拥有 600+ 客户,官方引用强调五大金融服务公司中的三家采用。投资人阵容——Bessemer、Insight、Kleiner Perkins 和 S28——增加可信度;2026 年 Agentic Identity Framework / Beams 重新定位,也提供了一个可讲通的叙事:从传统人类特权访问扩张到机器和 AI agent 身份。反论比普通后期软件尽调备忘录更强,因为关键承销变量仍未公开验证。GetLatka 未确认的 2024 年 $49M ARR 估算,是唯一当前收入锚;若采用该数字,相对过时的 2022 年 3 月 $1.1B Series C 标记,隐含约 22.4 倍 EV / ARR。这个水平高于 CyberArk 约 15.8 倍的经验证公开倍数,也远高于 Okta 约 7.1 倍。竞争并非理论风险:CyberArk、Okta、BeyondTrust、StrongDM 和 Boundary 都在定义相邻的基础设施访问问题。2024 年社区许可变更也可能削弱最初让 Teleport 差异化的自下而上开源漏斗。最后,Teleport Cloud 缺少 FedRAMP 授权压窄了近期联邦市场上行,而 2022 年以来没有新一级融资、IPO 申报或公开流动性信号来重置估值预期。[CV010, CV011, CV012, CV016, CV017, CV019]
| 方向 | 论点 | 证据锚点 | 什么会改变判断 |
|---|---|---|---|
| 正方 | PAM 和零信任市场规模大且仍在扩张,足以支撑长期品类增长。 | 2025 年 PAM 为 $4.50B;2025 年零信任为 $40.01B。 | 市场增长明显放缓,或 Teleport 无法把 TAM 转化为经验证的 ARR 增长。 |
| 正方 | 开源分发、GitHub 牵引和 600+ 客户表明产品相关性有韧性。 | GitHub stars 和企业客户声明支撑认知度与采用。 | 若出现社区下滑、转化疲弱或重大客户流失证据,该论点会削弱。 |
| 正方 | Bessemer、Insight、Kleiner Perkins 和 S28 让投资团在后续融资或退出上具备可信度。 | Series A/B/C 披露和投资人评论。 | 如果下一轮持平 / 下行,或内部人不愿支持流程,投资团实力的重要性会下降。 |
| 正方 | 2026 年 AI agent 身份重新定位可能把 Teleport 从经典人类特权访问扩到更大边界。 | Agentic Identity Framework 和 Beams 发布。 | 如果 Beams 无法变现,或只停留在 demo 叙事,溢价应消失。 |
| 反方 | 唯一公开 ARR 锚点是未经确认的 $49M 估计,对应约 ~22.4x 的偏贵倍数。 | GetLatka 加 Series C 估值测算。 | 经验证 ARR 明显高于 $70M 且增长强劲,才能缩窄估值担忧。 |
| 反方 | CyberArk、Okta、BeyondTrust、StrongDM 和 Boundary 都压制可实现倍数。 | 公开可比公司数据和竞品产品页。 | 若 Teleport 在功能和增长上拉开清晰差距,溢价才可能重新成立。 |
| 反方 | CE 许可变更可能削弱自下而上的社区驱动获客。 | 官方许可变更公告和 GitHub / 社区语境。 | 如果变更后转化效率和自助 pipeline 仍强,风险会下降。 |
| 反方 | 缺少 FedRAMP,且没有公开 IPO 或二级交易信号,降低近期可选性。 | 面向 FedRAMP 的材料但无授权,再加上后续无融资 / IPO 标记。 | 授权进展或正式融资 / 退出流程会改善风险调整后的判断。 |
论点只围绕估值相关性展开;不是通用品质打分卡。
[CV010, CV011, CV012, CV016, CV017, CV019]公开证据支持产品相关性,但不足以在旧估值点上形成干净的承销判断。
[CV010, CV011, CV012, CV019, CV024, CV025]8.2 估值背景与可比公司组
Teleport 唯一披露的估值标记是 2022 年 3 月 Series C:由 Bessemer Venture Partners 领投、Insight Venture Partners 参与,以 $1.1B 投后估值融资 $110M。2021 年 Series B 增加 $30M,2020 年 Series A 增加 $25M,因此披露的累计一级资本约 $140M。官方新闻室没有宣布后续一级融资、二级报价、IPO 申报或其他公开标记,投资者只能用一个过时四年的价格,对照 2026 年软件可比公司环境来评估。关键问题不是 $1.1B 在 2022 年不可能;而是当前公开证据没有确认足以支撑今天维持该标记的经营规模。GetLatka 估算 2024 ARR 为 $49M,但它明确只是估算的单一来源数据点,并非公司披露。若该估算方向正确,过时估值隐含约 22.4 倍 EV / ARR。CyberArk 是最接近的公开 PAM 锚,市值约 $20.63B、TTM 收入 $1.30B,约 15.8 倍。Okta 是更广义的身份平台,如今也销售特权访问,交易倍数接近 7.1 倍。这些公开倍数并非完全一一对应,但确实建立了估值重力:Teleport 需要证明 ARR 显著高于 $49M、当下增长远快于公开可验证水平,或拥有持久的 AI 身份溢价,才配得上旧私有市场标记。没有这些证明,估值看起来是昂贵,而不只是溢价。[CV001, CV002, CV003, CV004, CV005, CV006]
| 可比对象 | 类别 | Revenue/ARR 指标 | 倍数 / 估值 | 状态 | 与 Teleport 的相关性 | 局限 |
|---|---|---|---|---|---|---|
| Teleport(上一轮标记) | 私有基础设施安全 | 估算 ARR $49M(2024 GetLatka) | $1.1B / 约 22.4x ARR | 过时的私募轮估值标记 | 直接标的;显示今天必须证明什么 | ARR 未确认,估值标记停留在 2022 年 3 月 |
| CyberArk | 上市 PAM 龙头 | TTM 收入 $1.30B(2026 年 6 月) | ~15.8x 收入 | 当前上市可比公司 | 最接近且透明的 PAM 估值锚 | 规模更大、披露为上市公司口径,产品广度也更成熟 |
| Okta | 带 PAM 的上市身份平台 | TTM 收入 $2.91B(2026 年 6 月) | ~7.1x 收入 | 当前上市可比公司 | 展示带 PAM 邻近属性的身份市场估值底线 | 类别更宽,利润率 / 增长组合不同 |
| 私有安全 SaaS 参考区间 | 私有增长参考 | $40M-$60M ARR | ~8x-15x ARR | 示意性私募区间 | 有助于约束基准情景下的私募定价 | 区间是背景参照,不是单一可交易资产 |
| 高增长溢价区间 | 私有上行参考 | ARR 增长经验证 >50% | ~15x-25x ARR | 示意性上行区间 | 显示溢价标记要守住所需的门槛 | 需要验证增长,且披露通常要好于 Teleport 目前公开水平 |
表内混合了直接上市可比公司与参考区间,因为 Teleport 后续融资或可靠的私募二级市场标记均未公开。收入和 ARR 数据具有特定时点属性,且未按净现金调整。
[CV006, CV007, CV008, CV025, CV039, CV041]基于 $49M ARR 估算,在选定收入倍数下推导隐含企业价值。
数值四舍五入到最接近的百万位,并仅把单一来源的 $49M ARR 估算作为敏感性锚点。
[CV005, CV006, CV025, CV041]8.3 情景分析与敏感性
情景区间主要取决于经验证收入规模和增长耐久性,而不是表格模型复杂度。牛市情景中,Teleport 的 AI Infrastructure Identity 重新定位奏效,Beams 成为可信的 agent 身份切入点,ARR 从 2024 年 $49M 估算起,以每年 35% 以上复合增长,到 2027 年约 $85M。套用 15 倍倍数——大致是透明公开 PAM 锚的高端,而不是激进 AI 泡沫倍数——得到约 $1.28B,只比旧标记略高。这是可接受但不惊艳的后期上行情景。基准情景假设产品仍相关、客户质量扎实,但增长回落到每年约 25%。到 2027 年 ARR 约 $73M。按 10 倍至 12 倍,对应健康但不亢奋的安全软件倍数区间,隐含价值约 $730M 至 $875M。熊市情景假设许可过渡拖慢开发者驱动获客,竞争者压迫定价,AI 重新定位兑现慢于叙事;在年增长低于 15% 时,ARR 仅约 $60M,6 倍至 8 倍区间隐含 $360M 至 $480M。换句话说,大多数现实路径都需要优于公开证据的增长证明,或更低入场价,风险调整后回报才有吸引力。[CV031, CV032, CV033, CV034, CV038, CV039]
| 情景 | 关键假设 | 2027E ARR | 适用倍数 | 隐含估值 USD | 概率信号 |
|---|---|---|---|---|---|
| 牛市 | AI 身份产品跑出牵引力,增长维持在 35% 以上,客户质量撑得起溢价倍数。 | $85M | 15x | $1.28B | 上行情景;需要验证增长,并跑通 AI 变现 |
| 基准 | 核心访问平台仍有相关性,增长放缓至约 25%,且未出现重大利润率冲击。 | $73M | 10x-12x | $730M-$875M | 按现有证据最可能成立 |
| 熊市 | 许可证逆风、可比公司压力、扩张放缓,把增长压在约 15%,可比估值容忍度下降。 | $60M | 6x-8x | $360M-$480M | 若当前叙事跑在基本面前面,就是下行情景 |
ARR 情景由 GetLatka 对 2024 年 $49M 的估算推导,应视为示意,而非公司指引。
[CV031, CV032, CV033, CV034, CV039, CV041]牛市、基准和熊市价值区间显示,旧估值点附近几乎没有安全边际。
区间是基于 $49M ARR 估算和选定可比公司区间推导的情景输出;它们不是管理层指引。
[CV031, CV032, CV033, CV034]8.4 退出准备度与最终尽调要求
退出准备度喜忧参半。积极一面是,创始团队仍然可见,公司继续推出产品,投资人联盟也足够深,可以支持战略出售或后续 IPO 尝试。最可能的战略收购方是已经触达身份、PAM 或零信任工作流的大型安全或基础设施厂商,例如 CyberArk、Palo Alto Networks、Cisco 或 Microsoft。话虽如此,公开记录中没有任何迹象显示 Teleport 当前处在 IPO 路径上,也没有披露的流动性机制为后期持有人重置价格发现。因此,战略退出论点只是一种可能性,不是估值托底。尽调负担很高,因为缺失证据正好落在估值应当锚定的位置:2024 和 2025 年经验证 ARR、当前增长率、净收入留存、毛利率、burn、股权结构优先权,以及 CE 许可变更对新 logo 生成的实际影响。联邦市场扩张也是门槛项,因为 Teleport 讨论了面向 FedRAMP 的用例,但 Teleport Cloud 没有公开授权。因此,谨慎投资者应把它视为依赖 data room 的决策,而不是单靠叙事动能就能形成确信的一轮。[CV020, CV035, CV036, CV037, CV042, CV044]
| 触发器 | 阈值 / 事件 | 对投资论点的传导 | 行动含义 |
|---|---|---|---|
| ARR 验证失败 | 已验证 ARR 显著低于 $49M,或 2025 年 ARR 未显示可信增长 | 入场倍数升至远高于本已昂贵的上市和私募参考点 | 暂停,或把价格重估至低于过时的 $1.1B 标记 |
| 增长质量不及预期 | 当前 YoY 增长低于 25%,或 NRR 低于 100% | 基准情景过于乐观,倍数支撑被压缩 | 从继续研究转为回避,除非价格重置 |
| 毛利率偏弱 | 毛利率低于软件式门槛,或烧钱结构性偏重 | AI 或基础设施叙事未能转化为有吸引力的 SaaS 经济性 | 要求完全不同的估值框架,或放弃 |
| 许可证变化伤害漏斗 | CE 转换后,社区驱动管线明显下滑 | 自下而上的差异化和资本效率一起走弱 | 下调长期增长假设和 CAC 效率 |
| 联邦就绪停滞 | Teleport Cloud 在目标垂直战略中没有可信的 FedRAMP 路径 | 政府和受监管 TAM 叙事比宣传更有限 | 从市场规模和情景区间中剔除联邦上行 |
这些是投前承诺触发器,不是投后经营 KPI。
[CV016, CV024, CV035, CV036, CV040, CV048]| 主题 | 缺失证据 | 重要性 | 负责人 / 尽调路径 |
|---|---|---|---|
| ARR 验证 | 2024 年和 2025 年经审计或 CFO 证明的 ARR,以及客户桥接 | 当前公开锚点来自单一来源估算 | 财务资料室与客户 cohort 复核 |
| 增长和留存 | 当前 YoY 增长、NRR、流失率和扩张 cohort | 溢价倍数逻辑取决于经验证的增长质量 | CFO 材料、董事会材料和 cohort 分析 |
| 经济性 | 毛利率、烧钱、runway 和销售效率 | 没有单位经济性,入场价格无法做压力测试 | 财务工作流和管理层访谈 |
| 股权结构 | 优先权堆栈、反稀释条款和清算权 | 即便企业价值增长,优先权悬垂也可能损害回报 | 公司法律顾问与融资文件审查 |
| 许可证变化影响 | CE 转换前后的管线构成 | 社区动作变化可能改写 CAC 和转化假设 | 与产品和销售负责人复核 GTM 分析 |
| FedRAMP 路线图 | 授权计划、时间表,以及 go-to-market 对联邦买家的依赖 | 没有执行路径,就不能把政府 TAM 完整计入 | 安全 / 合规复核和联邦管线尽调 |
每项问题都直接对应一个目前在公开材料中不透明的估值变量。
[CV024, CV035, CV036, CV042, CV043, CV048]8.5 建议与证据评估
建议为继续研究,置信度中等,风险评级高,估值立场为昂贵。Teleport 看起来具备战略相关性、客户验证和强投资人背书,但投委会不需要判断公司是否优秀;真正要判断的是今天的入场价格是否站得住。基于当前公开证据,答案是否定的。2022 年 $1.1B 标记只有在几个假设下才能辩护:当前 ARR 明显高于唯一的 GetLatka 估算;Series C 以来未公开披露的增长率仍然较高;或存在公共可比公司尚未验证的高溢价 AI 身份估值体系。证据基础方向上有用,但不完整。官方来源强力支持融资历史、客户信号和产品叙事,公开可比公司也提供了干净基准,显示经验证行业倍数低于 Teleport 隐含的估算倍数。缺的是把叙事转化为价格的核心财务披露。只有当 Teleport 能验证 ARR 高于约 $70M、显示 NRR 高于 100%、确认当前同比增长不低于 25%、提供毛利率和 burn 可见度,并证明政府市场准备度进展或具体退出时间表时,建议才应上调。在此之前,它仍是一家有前景但估值风险需要承销的公司。[CV005, CV006, CV024, CV025, CV032, CV034]
| 维度 | 评估 | 理由 |
|---|---|---|
| 推荐 | 继续研究 | 公开证据方向上偏正面,但不足以承销 $1.1B 估值标记。 |
| 置信度 | 中 | 融资历史和可比公司清晰,但 ARR 和当前增长没有公司确认。 |
| 风险评级 | 高 | 估值过期、ARR 未确认、竞争压力和无公开盈利数据共同抬高下行风险。 |
| 估值立场 | 偏贵 | 未确认 ARR 下约 ~22.4x,高于 CyberArk 经验证的约 ~15.8x 公开收入倍数。 |
| 决策含义 | 等待财务验证 | 推进前需核验 ARR、增长、NRR、利润率和 cap table 可见度。 |
评估基于 2026-06-20 可得公开证据,并仅将 GetLatka 未确认的 $49M ARR 估计作为工作锚点。
[CV004, CV005, CV006, CV024, CV025]可供投委会使用的评分,在市场质量、证据质量和估值支撑之间做权衡。
[CV012, CV019, CV024, CV025, CV035, CV042]8.6 图表与证据
免责声明
本报告基于公开信息;在 Teleport 未披露当前指标处,报告纳入了已清楚标注的第三方估算。
证据索引
| 编号 | 陈述 | 可信度 | 来源 |
|---|---|---|---|
| CO001 | Teleport is headquartered at 2100 Franklin St, Suite 400, Oakland, California 94612 and describes itself as the AI Infrastructure Identity Company. | 高 | SO001, SO002 |
| CO002 | The company was originally incorporated as Gravitational Inc. and officially renamed itself Teleport in 2021, moving to the goteleport.com domain. | 中 | SO006 |
| CO003 | Teleport's corporate signing certificates still use "Developer ID QH8AA5B8UP Gravitational Inc." confirming the legal entity is still Gravitational Inc. | 中 | SO002 |
| CO004 | Teleport was founded in 2015 by Ev Kontsevoy, Alexander Klizhentas, and Taylor Wakefield. | 高 | SO003, SO019 |
| CO005 | Teleport's pricing is usage-based, metered by Monthly Active Users, Machine and Workload Identities, and Teleport Protected Resources. | 中 | SO010 |
| CO006 | Teleport Community Edition is free only for companies with fewer than 100 employees and annual revenue under $10M; larger companies must purchase Enterprise Edition. | 高 | SO007, SO010 |
| CO007 | Ev Kontsevoy serves as Co-founder and CEO, Alexander Klizhentas as Co-founder and CTO, and Taylor Wakefield as Co-founder and COO, all of whom are listed on the Teleport about page as of June 2026. | 高 | SO002, SO008 |
| CO008 | Jeff Bunten is listed as CRO and Diana Jovin as CMO on the Teleport about page. | 中 | SO002, SO028 |
| CO009 | All three co-founders previously worked together at Rackspace after that company acquired Mailgun, a developer email infrastructure startup they had built. | 中 | SO019 |
| CO010 | Ev Kontsevoy is the named author or spokesperson for all three fundraising blog posts, the Agentic Identity Framework launch, and the Fortune Cyber 60 press release. | 中 | SO003, SO004, SO005, SO013, SO011 |
| CO011 | No independent director names or full board composition have been disclosed by Teleport in public materials as of June 2026. | 低 | |
| CO012 | Mary D'Onofrio from Bessemer Venture Partners joined the Teleport board at the Series C close; Matt Koran from Insight joined as a board observer. | 中 | SO003 |
| CO013 | Teleport raised a $25M Series A led by Kleiner Perkins; the company had reached profitability before the round and named NASDAQ, Splunk, TicketMaster, Mulesoft, and Samsung as customers. | 高 | SO005, SO019 |
| CO014 | Teleport raised a $30M Series B led by S28 Capital and Kleiner Perkins in 2021, following a quarter with net new ARR up 5x and total ARR up 2.5x year-over-year versus Q2 2020. | 中 | SO004 |
| CO015 | Teleport raised a $110M Series C led by Bessemer Venture Partners at a $1.1B valuation in May 2022, with net new ARR up 4.5x and total ARR up 2.8x year-over-year at the time of the round. | 高 | SO003, SO018 |
| CO016 | Total disclosed funding for Teleport across all three rounds is $165M. | 高 | SO003, SO004, SO005 |
| CO017 | GetLatka reported that Teleport raised $140M across 2 rounds, which diverges from the company-disclosed $165M across 3 rounds, suggesting GetLatka missed the Series A. | 低 | SO020 |
| CO018 | No publicly available evidence of a Teleport funding round after the May 2022 Series C has been identified, and no SEC Form D filings for Gravitational Inc. or Teleport Inc. were found in EDGAR searches. | 中 | SO003, SO004, SO005 |
| CO019 | The $1.1B Series C valuation mark is approximately four years old as of June 2026, and private-market conditions tightened materially in 2022–2024. | 中 | SO003 |
| CO020 | GetLatka estimated Teleport's 2024 revenue at $49M, describing this as the revenue milestone the company hit in December 2024; this is a third-party estimate not confirmed by Teleport. | 低 | SO020 |
| CO021 | GetLatka reported Teleport employs approximately 246 people as of late 2025; this is an unverified third-party estimate. | 低 | SO020 |
| CO022 | Teleport's Series A blog stated the company had recently reached profitability before the round; no current profitability data is disclosed. | 中 | SO005 |
| CO023 | The Teleport careers page and press release state that more than 600 companies depend on Teleport as of October 2025. | 中 | SO008, SO011 |
| CO024 | Named customers from Teleport public materials include NASDAQ, Snowflake, DoorDash, IBM (Instana), Carta, GoTo, Exness, KnowBe4, Turo, Gladly, ThredUP, ExtraHop, and Rush Street Interactive. | 中 | SO009, SO015, SO016 |
| CO025 | The Teleport open-source GitHub repository had over 15,000 GitHub stars as of the June 2024 community license blog post. | 中 | SO007, SO023 |
| CO026 | The Teleport open-source project has been on GitHub under the AGPLv3 license since 2015 and supports SSH, Kubernetes, databases, RDP, web applications, and MCP servers. | 中 | SO023, SO007 |
| CO027 | Teleport releases major product versions on approximately a four-month cycle; Teleport 16 was released in June 2024 and Teleport 17 in October 2024. | 中 | SO007 |
| CO028 | Teleport was named to the 2026 Fortune Cyber 60 list in October 2025, recognizing rapid growth and commitment to delivering identity security solutions. | 中 | SO011 |
| CO029 | Teleport was named to the Citizens Securities 2026 Cyber 66 list in April 2026, recognizing it as one of the hottest privately held cybersecurity companies. | 中 | SO012 |
| CO030 | Teleport's Agentic Identity Framework was announced on January 27, 2026, providing a roadmap for deploying autonomous AI agents in production infrastructure with cryptographic identity. | 中 | SO013 |
| CO031 | Beams (beams.run) entered public beta in June 2026 as a Teleport product providing trusted runtimes for AI agents, running each agent in isolated Firecracker VMs with built-in identity and no secrets. | 中 | SO024, SO027 |
| CO032 | Teleport's 2026 Infrastructure Identity Survey of 200+ infrastructure leaders found that 79% were evaluating or deploying agentic AI and 69% said AI adoption required significant changes to identity management. | 中 | SO025 |
| CO033 | Starting with Teleport 16 in June 2024, compiled Community Edition binaries and container images were moved from the Apache 2.0 license to a commercial license; the AGPLv3 source code repository was not changed. | 中 | SO007 |
| CO034 | Teleport's FedRAMP documentation describes how Teleport FIPS mode can help customers achieve FedRAMP authorization, but does not represent a FedRAMP ATO for Teleport's own SaaS. | 中 | SO014, SO026 |
| CO035 | No public evidence confirms that Teleport's own cloud service has received a FedRAMP Authorization To Operate (ATO) from the FedRAMP Program Management Office. | 中 | |
| CO036 | PeerSpot reviewers cite initial setup complexity, RBAC configuration difficulty, SIEM integration gaps, and pricing concerns for large companies as key areas for improvement. | 中 | SO022 |
| CO037 | StrongDM's competitor comparison page claims Teleport's agents run as root on every monitored server and that Teleport Cloud experiences availability issues during updates. | 低 | SO021 |
| CO038 | Teleport's product secures SSH, Kubernetes, databases, RDP, web applications, and MCP servers through a certificate-authority model that issues short-lived credentials. | 中 | SO023, SO001 |
| CO039 | Teleport conducted a security audit by Cure53 in 2019, resulting in no critical vulnerabilities found; the company has committed to regular third-party security audits. | 中 | SO017 |
| CO040 | The global PAM market was estimated at $4.5B in 2025 and is projected to grow to $29.88B by 2034 at a 23.4% CAGR according to Precedence Research. | 中 | SO029 |
| CO041 | Teleport's competitive context includes public cybersecurity companies such as CyberArk (market cap ~$20B, revenue ~$1B in 2024) and Okta (market cap ~$20B, revenue ~$2.9B in 2025), both of which are substantially larger by revenue than Teleport's estimated ARR. | 低 | SO029 |
| CO043 | NIST SP 800-207 (2020) defines zero trust architecture as eliminating implicit trust based on network location and requiring per-request authentication and authorization — the framework Teleport's products implement for infrastructure access. | 中 | SO030 |
| CO042 | The Bessemer BVP investment blog described Teleport as "the easiest, most secure way to access infrastructure" and noted that 2021 saw a 50% increase in attacks on corporate networks. | 中 | SO018 |
| CM001 | Teleport positions itself as an AI Infrastructure Identity company spanning human, machine, and AI identities. | 中 | SM001, SM015 |
| CM002 | Teleport's published product scope covers SSH, Kubernetes, databases, Windows, web apps, machine identities, and related infrastructure workflows. | 中 | SM024, SM028 |
| CM003 | Bessemer described infrastructure access as a new and exciting product category when explaining its Teleport investment. | 中 | SM012 |
| CM004 | A disciplined Teleport market definition should include privileged infrastructure access, workload identity, audit, and compliance-linked access modernization spend. | 中 | SM024, SM028, SM006 |
| CM005 | A disciplined Teleport market definition should exclude most workforce IAM, CIAM, endpoint, SIEM, and non-infrastructure AI application spend. | 中 | SM024, SM028, SM007 |
| CM006 | VPNs, bastions, long-lived credentials, cloud-native point IAM, and manual audit workflows remain status-quo substitutes for Teleport. | 中 | SM024, SM015 |
| CM007 | FedRAMP, SOC 2, and access-audit use cases expand Teleport's commercial relevance without turning the company into a full GRC or broader identity vendor. | 中 | SM016, SM017, SM018 |
| CM008 | StrongDM argues that Teleport is a point solution for modern cloud architecture and lacks broader legacy-system fit. | 低 | SM029 |
| CM009 | Precedence Research values the global privileged access management market at $4.50 billion in 2025 and forecasts $29.88 billion by 2034. | 中 | SM009 |
| CM010 | Archived Grand View Research evidence values the global zero-trust security market at $36.96 billion in 2024 with a 16.6% CAGR through 2030. | 中 | SM010 |
| CM011 | Precedence Research values the global zero-trust security market at $40.01 billion in 2025 and forecasts $182.59 billion by 2035. | 中 | SM011 |
| CM012 | Published market estimates diverge because PAM and zero-trust reports use overlapping but not identical scope definitions and forecast windows. | 中 | SM009, SM010, SM011 |
| CM013 | Teleport's practical TAM sits between narrow PAM and broad zero-trust security because the product spans infrastructure access and identity but not every control category inside zero trust. | 中 | SM001, SM024, SM028 |
| CM014 | The market taxonomy around infrastructure identity is still forming rather than universally settled. | 中 | SM012 |
| CM015 | AI adoption expands Teleport's SAM because 92% of survey respondents report near-term AI initiatives and 79% are evaluating or deploying agentic AI. | 中 | SM003 |
| CM016 | Enterprise preparedness lags AI adoption because only 13% of respondents feel extremely prepared and 60% have had or suspect AI-related incidents. | 中 | SM003 |
| CM017 | Teleport reports more than 600 customers, including three of the top five financial services firms, which demonstrates real market adoption but not precise share. | 高 | SM004, SM027 |
| CM018 | The retained Fortune Business Insights PAM URL could not be used for triangulation because it returned unrelated agricultural content instead of PAM analysis. | 中 | SM026 |
| CM019 | Teleport's primary operational users are platform engineers, security engineers, infrastructure admins, and Kubernetes or database operators. | 中 | SM024, SM028 |
| CM020 | Budget ownership commonly sits with either the security organization or platform engineering, depending on whether the trigger is control posture or operational fragmentation. | 中 | SM022, SM023 |
| CM021 | Teleport's MAU and MWI pricing model ties commercial expansion to identity adoption rather than to a fixed appliance or seat bundle. | 中 | SM022 |
| CM022 | Compliance-led deals pull in public-sector or regulated-program owners because Teleport markets FedRAMP and FIPS alignment as part of the value proposition. | 中 | SM016, SM018, SM019 |
| CM023 | SOC 2-oriented buyers use Teleport as infrastructure access control rather than as a general-purpose compliance platform. | 中 | SM017, SM023 |
| CM024 | The public GitHub repository has more than 15,000 stars, which supports developer-led awareness and evaluation. | 中 | SM025 |
| CM025 | Teleport's disclosed customer proof is strongest in large regulated enterprises, including major financial-services institutions. | 中 | SM004, SM023 |
| CM026 | Legacy-heavy hybrid enterprises are less naturally aligned with Teleport when broad protocol coverage is prioritized over cloud-native depth. | 低 | SM029 |
| CM027 | Zero trust has both a formal standards anchor in NIST SP 800-207 and an operational maturity framework in CISA's Zero Trust Maturity Model. | 高 | SM006, SM007 |
| CM028 | Teleport links its infrastructure-access controls to FedRAMP and SOC 2 requirements, which turns compliance from an adjacency into a concrete demand driver. | 中 | SM016, SM017, SM018 |
| CM029 | Teleport reports that 73% of cybersecurity leaders are hearing enterprise customer questions about AI agent security. | 中 | SM005 |
| CM030 | Teleport's 2026 survey says 92% of respondents have near-term AI initiatives and 79% are evaluating or deploying agentic AI. | 中 | SM003 |
| CM031 | Investor and cloud-market commentary from BVP and Kleiner Perkins supports the view that multi-cloud complexity and AI are reinforcing demand for unified infrastructure control planes. | 中 | SM012, SM013, SM014 |
| CM032 | Usage-based MAU and MWI pricing can reduce initial adoption friction while making long-run spend dependent on identity growth. | 中 | SM022, SM003 |
| CM033 | Fortune Cyber 60 and Cyber 66 recognition strengthen Teleport's category legitimacy with enterprise buyers. | 中 | SM004, SM005 |
| CM034 | Switching costs remain material because buyers must unwind incumbent access workflows and test whether Teleport's strengths offset migration burden and coverage gaps. | 中 | SM024, SM029 |
| CM035 | Teleport documents support for FIPS 140 cryptographic modules, which materially improves fit for regulated and public-sector access programs. | 高 | SM016, SM018 |
| CM036 | Demand is structurally strongest in regulated and cloud-native environments and weaker in legacy-dense estates. | 中 | SM023, SM024, SM029 |
| CM037 | Public evidence does not isolate Teleport's SAM or SOM by segment, geography, deployment model, or average contract value. | 中 | SM021, SM022, SM023 |
| CM038 | Market-sizing evidence is directionally useful but methodologically inconsistent because the sources blend narrow PAM and broad zero-trust definitions. | 中 | SM009, SM011, SM026 |
| CM039 | The Fortune Business Insights page failure is a genuine research limitation rather than a minor formatting issue because it removes one potential triangulation point. | 中 | SM026 |
| CM040 | Teleport's public materials are richer on product breadth and compliance mapping than on win rates, deployment duration, churn, or segment economics. | 中 | SM001, SM023, SM027 |
| CM041 | Adverse competitor framing that Teleport is a point solution for modern cloud estates is relevant when testing whether the company can claim a broad cross-environment market. | 低 | SM029 |
| CM042 | The market thesis is stronger on demand direction than on precise monetizable share until management discloses segment-level revenue and expansion evidence. | 中 | SM003, SM004, SM022 |
| CM043 | Teleport's last disclosed financing event remains the May 2022 Series C of $110 million at a $1.1 billion valuation, leaving public market interpretation anchored to stale capital data. | 高 | SM002, SM012 |
| CM044 | Teleport also frames automation of identity and access evidence collection as a FedRAMP acceleration vector, which broadens the compliance-driven budget conversation. | 中 | SM019, SM020 |
| CM045 | Archived Grand View coverage shows that privileged access management is tracked as a standalone analyst category even though not every retained source yielded usable public figures. | 中 | SM008, SM026 |
| CP001 | Teleport's core product is a certificate-authority and proxy architecture that issues short-lived credentials and brokers access across multiple infrastructure resource types. | 中 | SP016, SP017, SP021 |
| CP002 | Teleport's current platform scope now spans zero trust access, machine and workload identity, identity security, and an explicit agentic identity layer. | 高 | SP021, SP022, SP024, SP025, SP031 |
| CP003 | Recent Teleport releases have added IdP-compromise mitigations, a broader identity-security layer, and agentic-identity packaging, showing product expansion beyond classic SSH access. | 中 | SP018, SP019, SP022 |
| CP004 | CyberArk presents PAM as a unified platform for controlling elevated access and explicitly markets zero-standing-privilege access in hybrid and multicloud environments. | 高 | SP002, SP003 |
| CP005 | CyberArk's public-company scale was about $20.63 billion in market cap and $1.30 billion in trailing revenue as of June 2026. | 中 | SP012, SP013 |
| CP006 | BeyondTrust competes on least privilege, credential injection, secure remote access, and vendor privileged access rather than on a developer-led infrastructure identity narrative. | 中 | SP004, SP005 |
| CP007 | Delinea Secret Server remains centered on vaulting, discovery, password rotation, session monitoring, and AI-driven session analysis. | 中 | SP006 |
| CP008 | StrongDM is now positioned inside Delinea through the publicly announced acquisition, tightening the overlap between cloud-native access brokering and incumbent PAM suites. | 中 | SP001, SP006 |
| CP009 | StrongDM markets continuous policy enforcement, full session visibility, and no standing privileges on top of an Identity Firewall foundation. | 中 | SP001 |
| CP010 | StrongDM's direct comparison page explicitly says Teleport lacks support for legacy systems and some authentication protocols and that Teleport agents running as root create an additional attack surface. | 中 | SP026 |
| CP011 | PeerSpot reviewers praise Teleport for centralized access control, role-based permissions, smoother SSH key management, and strong visibility during incidents. | 中 | SP009 |
| CP012 | HashiCorp Boundary is an identity-aware proxy that integrates with external identity providers and HashiCorp Vault to deliver single sign-on and dynamic credentials for least-privileged access. | 中 | SP008 |
| CP013 | Okta Privileged Access extends Okta's identity platform into Linux and Windows server access with zero-standing-privilege framing and recorded SSH or RDP sessions. | 中 | SP007 |
| CP014 | Okta's public scale was about $20.65 billion in market cap and $2.91 billion in trailing revenue as of June 2026. | 中 | SP014, SP015 |
| CP015 | The main buyer consideration set around Teleport includes CyberArk, BeyondTrust, Delinea, StrongDM, Okta, and Boundary rather than only one-for-one open-source lookalikes. | 中 | SP010, SP011, SP027 |
| CP016 | Teleport competes in a broader infrastructure-identity category that combines connectivity, authentication, authorization, and audit across multi-cloud infrastructure workflows. | 高 | SP027, SP028 |
| CP017 | Because competitors span incumbent PAM suites, cloud-native access brokers, and IAM adjacency, Teleport is being evaluated across both direct and adjacent budget lines. | 中 | SP010, SP011, SP027 |
| CP018 | Teleport's historical open-source distribution and public repository still create awareness advantages relative to fully proprietary incumbents. | 中 | SP023, SP030 |
| CP019 | The June 2024 community-license change reduced Teleport's practical open-source advantage because larger companies can no longer freely use compiled Community Edition artifacts. | 中 | SP023 |
| CP020 | Teleport backs its trust story with a published security audit and explicit identity-security documentation, which matters in enterprise infrastructure-access evaluations. | 高 | SP020, SP021 |
| CP021 | Teleport's architecture supports certificate-based access across SSH, RDP, Kubernetes, databases, and machine or workload identities, reducing long-lived secret sprawl. | 中 | SP016, SP017, SP025 |
| CP022 | Teleport's Agentic Identity Framework and machine-identity products widen competition into non-human identity and AI-operated infrastructure workflows. | 高 | SP022, SP024, SP025 |
| CP023 | StrongDM's critique implies that Teleport's certificate-centric design is strongest in modern estates and potentially weaker in legacy-heavy environments. | 中 | SP026, SP016 |
| CP024 | CyberArk and BeyondTrust can credibly encroach on Teleport's cloud-native accounts because both market least-privilege, secure remote access, and zero-standing-privilege outcomes rather than only password vaulting. | 中 | SP003, SP005 |
| CP025 | PAM switching costs accumulate through vaulted credentials, policy engines, approval workflows, session archives, and compliance evidence that buyers do not want to rebuild. | 高 | SP002, SP003, SP004, SP005, SP006 |
| CP026 | HashiCorp Boundary has narrower public product breadth than Teleport in the retained set, but its Vault integration gives it real leverage inside existing HashiCorp-oriented platform teams. | 中 | SP008 |
| CP027 | Teleport is more transparent on list pricing and edition boundaries than most direct competitors because the company publishes pricing and feature segmentation publicly. | 高 | SP029, SP031 |
| CP028 | CyberArk, BeyondTrust, Delinea, StrongDM, Okta, and Boundary generally use sales-led or quote-led packaging in the retained evidence set, limiting public apples-to-apples pricing comparison. | 中 | SP001, SP003, SP005, SP006, SP007, SP008 |
| CP029 | Public retained pricing evidence is enough to compare transparency and packaging posture, but not enough to prove Teleport is absolutely cheaper than strong alternatives after discounting or bundling. | 中 | SP029, SP003, SP005, SP006, SP007, SP008 |
| CP030 | Teleport's differentiation is architectural unification: one access plane for authentication, authorization, and audit across modern infrastructure resources. | 中 | SP016, SP017, SP021 |
| CP031 | The retained independent review set is more supportive than hostile: public review evidence highlights ease of deployment and security visibility more than onboarding pain. | 中 | SP009 |
| CP032 | PeerSpot reviewers describe Teleport adoption in workflow terms: centralize access control, improve visibility during incidents, and replace ad hoc SSH key handling with more consistent policy. | 中 | SP009 |
| CP033 | Delinea's acquisition of StrongDM raises the competitive ceiling against Teleport because a modern access-broker story can now be paired with a larger incumbent PAM relationship base. | 中 | SP001, SP006 |
| CP034 | Okta competes less as a deep infrastructure specialist than as an adjacency play that can bundle privileged server access into an existing identity-cloud relationship. | 中 | SP007, SP014, SP015 |
| CP035 | Teleport faces a major scale asymmetry because CyberArk and Okta each exceed $20 billion in market cap, giving them greater room to bundle, cross-sell, and absorb overlap. | 中 | SP012, SP013, SP014, SP015 |
| CP036 | Adverse competitive evidence against Teleport is concentrated on legacy coverage and root-agent architecture rather than on an absence of core session-control or audit capabilities. | 中 | SP026, SP009 |
| CP037 | Teleport's community-license change weakens its competitive contrast versus open-source-oriented alternatives because buyers must now separate source availability from binary-use rights. | 中 | SP023, SP030 |
| CP038 | Comparable public pricing remains structurally incomplete because most rivals do not publish equivalent seat, workload, or contract-unit pricing in the retained set. | 中 | SP001, SP003, SP005, SP006, SP007, SP008 |
| CP039 | The retained 2026 freshness evidence is uneven across the field: Teleport and Delinea or StrongDM show visible 2026 signals, but equivalent 2026 update detail for CyberArk, BeyondTrust, Okta, and Boundary is thin. | 中 | SP001, SP022 |
| CP040 | Teleport's resource-type breadth still exceeds what the retained Okta and Boundary sources show, especially for Kubernetes, databases, machine identity, and AI-oriented access control. | 中 | SP007, SP008, SP021, SP024, SP025, SP031 |
| CP041 | The market remains segmented rather than fully converged, so Teleport's competitive success depends on winning the right estate profile rather than being universal across all privileged-access jobs. | 中 | SP010, SP011, SP026, SP027 |
| CP042 | Incumbent PAM vendors skew toward broad hybrid-enterprise security buyers, while Teleport, StrongDM, and Boundary skew toward platform teams and Okta sells into its existing IAM base. | 中 | SP001, SP003, SP005, SP007, SP008, SP016 |
| CI001 | Teleport's pricing is usage-based, metered by Monthly Active Users, Machine and Workload Identities, and Teleport Protected Resources; no public list price is stated and all pricing requires commercial engagement with the sales team. | 中 | SI013 |
| CI002 | GetLatka estimated Teleport's 2024 revenue at $49M, describing it as a December 2024 milestone; this is an unconfirmed third-party estimate not corroborated by any official source. | 低 | SI012 |
| CI003 | No Teleport revenue estimate more recent than GetLatka's 2024 snapshot has been found in public sources; Teleport's 2025-2026 recognition press releases do not include revenue data. | 中 | SI012, SI015 |
| CI004 | At $49M estimated ARR and ~246 estimated employees, the implied ARR-per-employee ratio is approximately $199K, consistent with mid-stage infrastructure SaaS but below top-decile benchmarks. | 低 | SI012 |
| CI005 | The Teleport Series C blog (May 2022) reported total ARR up 2.8x and net new ARR up 4.5x year-over-year at the time of the round; Bessemer's investment blog confirmed this growth trajectory. | 高 | SI015, SI014 |
| CI006 | The Teleport Series B blog (2021) reported total ARR up 2.5x and net new ARR up 5x year-over-year versus Q2 2020. | 中 | SI016 |
| CI007 | At GetLatka's $49M ARR estimate, the $1.1B Series C valuation implies a revenue multiple of approximately 22.4x ARR — materially above where public cybersecurity peers traded in mid-2026. | 低 | SI012, SI015 |
| CI008 | The $1.1B Series C valuation from May 2022 has not been refreshed by any public subsequent financing event, secondary transaction, or management disclosure, making it approximately four years stale. | 中 | SI015 |
| CI009 | CyberArk Software had a market cap of approximately $20.63B and TTM revenue of approximately $1.30B as of June 2026, implying a revenue multiple of approximately 15.9x. | 高 | SI019, SI011 |
| CI010 | Okta had a market cap of approximately $20.65B and TTM revenue of approximately $2.91B as of June 2026, implying a revenue multiple of approximately 7.1x. | 高 | SI021, SI011 |
| CI011 | Applying the midpoint of CyberArk's and Okta's mid-2026 public revenue multiples (~11x) to Teleport's $49M estimated ARR produces an implied enterprise value of approximately $540M, well below the $1.1B 2022 mark. | 低 | SI019, SI021, SI012 |
| CI012 | Teleport discloses no official revenue, gross margin, burn rate, or cash position data in any public-facing materials; the company is not required to file financial statements as a private entity. | 中 | SI015, SI013 |
| CI013 | No SEC Form D or other federal securities registration filing has been found for Gravitational Inc. or Teleport Inc. on EDGAR, preventing independent verification of investor ownership stakes. | 中 | SI011 |
| CI014 | Teleport has four commercial billing modules: Zero Trust Access (MAU/TPR), Machine and Workload Identity (MWI), Identity Governance (MAU), and Identity Security (TPR) — each a separate upsell opportunity with its own billing metric. | 中 | SI013 |
| CI015 | Teleport Enterprise Edition requires commercial contact for all pricing; no public list price is disclosed for any product tier or module. | 中 | SI013 |
| CI016 | The June 2024 community license change restricts compiled Community Edition use to companies with fewer than 100 employees and less than $10M AR, creating a commercial conversion gate for mid-market growth. | 中 | SI018 |
| CI017 | Teleport's Beams AI agent runtime and the Machine/Workload Identity module (docs/ai-agents-mwi) confirm the platform is actively building for AI agent identity as a production revenue surface, with agents receiving unique cryptographic identity enforced at access time. | 中 | SI005, SI010 |
| CI018 | GetLatka's funding summary for Teleport shows $140M across 2 rounds, diverging from the company-disclosed $165M across 3 rounds, suggesting GetLatka missed the Series A or has incomplete sourcing. | 低 | SI012 |
| CI019 | No SEC Form D or equivalent state securities filing was publicly identified for Gravitational/Teleport, consistent with the company relying on state-level exemptions or other non-federal registration paths for its three private placement rounds. | 中 | SI011 |
| CI020 | The PAM market was estimated at $4.5B in 2025 and projected to reach $29.88B by 2034 at a CAGR of 23.4% per Precedence Research, providing a strong market tailwind for Teleport. | 中 | SI026, SI027 |
| CI021 | The PAM market's 23.4% CAGR implies the market nearly doubles every 3.5 years, providing strong tailwinds for Teleport across the infrastructure PAM and zero-trust identity segments. | 中 | SI026 |
| CI022 | Bessemer Venture Partners' investment thesis for the Series C framed Teleport as "the defining solution" to infrastructure access, citing a 50% increase in corporate network attacks in 2021. | 中 | SI014 |
| CI023 | Insight Venture Partners participated significantly in the $110M Series C, with Matt Koran joining the board as an observer; no post-Series C investor update is publicly available. | 中 | SI015 |
| CI024 | At $49M estimated ARR and $165M total raised, Teleport's implied capital efficiency (ARR / capital raised) is approximately 0.30 — below the commonly cited efficient SaaS benchmark of 0.5–1.0. | 低 | SI012, SI015, SI016, SI017 |
| CI025 | The key outstanding financial gaps for Teleport include audited ARR, gross margin, NRR, burn rate, cash balance, option pool size, and current cap table — none of which are publicly available. | 中 | |
| CI026 | CyberArk revenue grew from approximately $590M in 2022 to $1.30B TTM in 2025, a 2.2x increase in roughly three years. | 高 | SI020, SI011 |
| CI027 | Okta revenue grew from approximately $1.85B in 2022 to $2.91B TTM in 2026, a 1.6x increase in roughly four years. | 高 | SI022, SI011 |
| CI028 | Teleport disclosed total funding of $165M across three rounds: $25M Series A, $30M Series B, and $110M Series C. | 高 | SI015, SI016, SI017 |
| CI029 | PeerSpot reviews highlight pricing concerns for large companies and initial setup complexity as recurring Teleport complaints, indicating enterprise price sensitivity is an active competitive dynamic. | 中 | SI023, SI024 |
| CI030 | No public evidence of secondary market transactions, tender offers, or equity pricing events involving Teleport has been identified since the May 2022 Series C. | 中 | SI015 |
| CI031 | StrongDM's competitor comparison page claims Teleport Cloud has reliability issues and that its agent- based architecture creates new security exposures; these claims originate from a direct competitor and must be weighed accordingly. | 低 | SI024 |
| CI032 | Kleiner Perkins' Series A investment thesis (2019) described Gravitational as solving a once-in-a-decade opportunity in multi-cloud infrastructure — an early validation of the market thesis that Teleport's subsequent growth appears to confirm. | 中 | SI025 |
| CI033 | Teleport's MAU/MWI/TPR billing model creates natural revenue expansion as customers add infrastructure resources, without requiring re-negotiation of the commercial relationship. | 中 | SI013 |
| CI034 | The GoTo case study shows Teleport securing multi-cloud infrastructure for Indonesia's largest digital platform, illustrating the revenue expansion potential as large enterprises add workloads and users. | 中 | SI001 |
| CI035 | The Exness and Gladly case studies show Teleport serving regulated financial services and compliance- driven SaaS customers, segments where infrastructure identity tooling typically commands premium pricing. | 中 | SI002, SI003 |
| CI036 | If Teleport's ARR at the Series C close was approximately $17–20M (implied by the 2.8x growth cited) and grew to $49M by 2024, the post-fundraising CAGR was approximately 22%, significantly below the pre-Series-C rates. | 低 | SI015, SI012 |
| CI037 | At the Series C close in May 2022, CyberArk traded at approximately $5.27B market cap on ~$590M revenue (~9x) and Okta at ~$10.94B on $1.85B revenue (~6x), suggesting Teleport's ~22x implied multiple was already ~2x the comparable range at issuance. | 低 | SI019, SI021, SI015 |
| CI038 | Teleport's machine workload identity documentation for AI agents (ai-agents-mwi) confirms the platform issues each AI agent its own cryptographic identity, with deterministic access enforcement — a capability that underpins the Machine/Workload Identity revenue module. | 中 | SI005 |
| CI039 | Teleport's session recording architecture captures complete pseudo-terminal output for SSH sessions and database session events, providing compliance audit evidence that drives adoption in regulated industries. | 中 | SI007, SI006 |
| CE001 | Teleport is a certificate authority and identity-aware access proxy that implements SSH, RDP, HTTPS, Kubernetes API, and SQL/NoSQL database protocols, distributed as a single Go binary. | 中 | SE011, SE036 |
| CE002 | Teleport's product suite includes five pillars: Zero Trust Access, Machine & Workload Identity, Identity Governance, Identity Security, and the Agentic Identity Framework. | 中 | SE019, SE001 |
| CE003 | The Zero Trust Access product covers SSH, Kubernetes, databases, Windows/RDP, internal web apps, and MCP servers. | 中 | SE019, SE011, SE036, SE055, SE058 |
| CE004 | MCP server access is available in Community Edition, Enterprise Self-Hosted, and Enterprise Cloud, with per-tool audit events for MCP requests. | 中 | SE019, SE022 |
| CE005 | The Teleport feature matrix distinguishes Enterprise Cloud, Enterprise Self-Hosted, and Community Edition, with Beams trusted runtimes exclusive to Enterprise Cloud. | 中 | SE019, SE012 |
| CE006 | Identity Security provides SQL-editor access queries, Crown Jewels monitoring for critical assets, anomaly alerting, and integration with Okta, AWS, and GitHub audit logs. | 中 | SE023, SE010 |
| CE007 | Teleport pricing is usage-based across four billing metrics: Monthly Active Users, Machine/Workload Identity users, and Teleport Protected Resources, with no publicly listed list prices. | 中 | SE012 |
| CE008 | Teleport's Agentic Identity Framework was announced January 27, 2026, defining a four-layer architecture (identity, access, security, scheduling) for securing AI agents in production. | 中 | SE030, SE033 |
| CE009 | Teleport's 2026 Infrastructure Identity Survey of 200+ infrastructure leaders found 92% have near-term AI initiatives in infrastructure and only 13% feel extremely prepared. | 中 | SE032 |
| CE010 | The Teleport control plane consists of the Auth Service (CA, config store, audit log) and Proxy Service (public entry point, reverse-tunnel hub, Web UI), both communicating via gRPC. | 中 | SE017, SE018 |
| CE011 | The Auth Service is the only Teleport component that must be connected to a persistent backend (etcd, DynamoDB, Postgres, or Teleport Cloud storage); all other services are stateless. | 中 | SE018, SE017 |
| CE012 | Teleport authentication flow: user runs tsh login, receives a client certificate from the Auth Service, and that certificate is automatically accepted by SSH, kubectl, psql, and other CLI tools. | 中 | SE011, SE017 |
| CE013 | Teleport integrates with enterprise SSO providers including Okta, GitHub, Google Workspace, and Active Directory for identity provider authentication. | 中 | SE011, SE025 |
| CE014 | Teleport's Proxy Service implements an SSH server; Teleport Agents establish reverse tunnels to the Proxy to receive traffic from the public internet without exposing private resources. | 中 | SE017, SE018 |
| CE015 | Teleport can be deployed as Cloud (fully managed), on-premises, on-premises FIPS, multi-region high availability, hybrid, or edge; deployment type does not affect billing metrics except for multi-region HA. | 中 | SE012 |
| CE016 | StrongDM claims Teleport agents run as root on every enrolled server, creating a new attack vector; agentless mode is available but offers limited features without RBAC or granular auditing. | 中 | SE043 |
| CE017 | Session recording in Teleport supports four configurations (node-sync, node, proxy-sync, proxy) and captures PTY output for SSH and Kubernetes, screen content for desktop, and query streams for databases. | 中 | SE024 |
| CE018 | Teleport's official session recording documentation discloses that users can conceal terminal commands by encoding them (e.g., base64) or running scripts from disk, with BPF Enhanced Session Recording as a mitigation. | 中 | SE024 |
| CE019 | StrongDM claims Teleport Cloud is unreliable and that updates can cause access downtime of up to six hours; Teleport does not publish a public uptime SLA or incident history. | 低 | SE043 |
| CE020 | Machine & Workload Identity uses tbot to issue short-lived X.509 or SSH certificates to non-human workloads, eliminating standing service secrets. | 中 | SE020, SE034 |
| CE021 | AI agents secured with Machine & Workload Identity receive their own cryptographic identity and operate under RBAC/ABAC enforcement at both network and protocol level, with all actions logged. | 中 | SE034, SE033 |
| CE022 | The Agentic Identity Framework is organized into four layers: identity (cryptographic agent certificates), access (RBAC/ABAC via Teleport proxy), security (behavioral monitoring), and scheduling (Kubernetes/Temporal orchestration patterns). | 中 | SE033, SE030 |
| CE023 | Beams is described as a trusted ephemeral runtime for AI agents; each Beam runs in a Firecracker microVM with ephemeral storage, injected identity, and a session-bound lifecycle of approximately 24 hours. | 中 | SE035, SE019 |
| CE024 | The LLM Proxy sits between an AI agent and its inference endpoint, logging every request and response to the Teleport audit trail and enforcing per-Beam allowlists for which inference endpoints agents can reach. | 中 | SE031, SE035 |
| CE025 | Delegated Identity allows a human operator or orchestrator to define and assign least-privilege permissions to an agent session, and was launched as part of the Beams public beta in June 2026. | 中 | SE031 |
| CE026 | Beams trusted runtimes are currently in public beta and are available only to Enterprise Cloud customers; Enterprise Self-Hosted and Community Edition deployments do not have access to Beams. | 高 | SE019, SE031 |
| CE027 | Beams includes built-in inference proxy support for OpenAI and Anthropic endpoints, with an option to bring your own inference endpoint. | 高 | SE035, SE019 |
| CE028 | The 2026 Citizens Securities Cyber 66 report survey found 73% of cybersecurity leaders are seeing enterprise customers ask how their platforms can help secure AI agents, with identity topping the list of security pain points. | 中 | SE053 |
| CE029 | Teleport Enterprise versions 17.7.3+ and 18.0.0+ include FIPS 140-3 validated cryptographic modules using BoringCrypto CMVP certificate | 中 | SE025 |
| CE030 | Teleport's FedRAMP documentation covers AC-02, AC-03, AC-07, AC-08, AC-10, AC-12, AU-02, AU-03, AU-09, AU-10, and AU-12 NIST SP 800-53 controls, supporting FedRAMP-Moderate authorization. | 中 | SE025, SE054 |
| CE031 | Teleport documents SOC 2 coverage across four of nine control categories: CC6 (control activities), CC6 (physical/logical access), CC7 (system operations), and CC8 (change management). | 中 | SE026 |
| CE032 | A Cure53 security audit of Teleport in 2019 found no critical vulnerabilities; one high-severity directory-traversal issue in the roles API was patched in the same release (v2.6.0). | 中 | SE029 |
| CE033 | No public third-party security audit of Teleport more recent than 2019 has been disclosed; the Cure53 audit covered source code version 2.x, not current v17/v18. | 中 | SE029 |
| CE034 | Teleport releases one major version per year with 24-month support; version 18 (current) was released July 2025 with EOL August 2027; version 17 (stable) EOL August 2026. | 中 | SE027 |
| CE035 | Starting with Teleport 16 (June 2024), compiled Community Edition binaries, container images, and AMIs are licensed under a commercial license restricting companies with 100+ employees or $10 M+ annual revenue. | 中 | SE008, SE009 |
| CE036 | The Teleport open-source repository on GitHub remains AGPLv3; documentation and client library code remain Apache 2.0; only compiled artifacts switched to the commercial license in June 2024. | 高 | SE008, SE036 |
| CE037 | Teleport's product roadmap includes Linux Desktop Access (remote sessions to Linux hosts), multiple-directory sharing for Windows RDP, and AI-summarized session recordings in Identity Security. | 中 | SE027 |
| CE038 | The Teleport GitHub open-source repository has over 15,000 GitHub stars (stated at time of community-license announcement) and is written in Go; Teleport maintains Apple code-signing and RPM/Debian signing keys published on the security page. | 中 | SE008, SE036, SE056, SE057 |
| CE039 | PeerSpot user reviews identify Teleport's initial setup and RBAC configuration complexity, SIEM integration limitations, clipboard security risk in RDP, and pricing concerns for large companies as the primary improvement areas. | 中 | SE052 |
| CE040 | NIST SP 800-207 and CISA Zero Trust Maturity Model provide regulatory frameworks for zero-trust access controls that Teleport's architecture is designed to satisfy. | 中 | SE041, SE042 |
| CE041 | Teleport Identity Governance adds access lists, access requests, approval workflows, and SCIM-driven lifecycle controls on top of the core access plane. | 中 | SE059, SE019 |
| CE042 | The Teleport Proxy Service provides the public-facing web UI, single sign-on entry point, and reverse-tunnel transport that connects users to private resources through the control plane. | 中 | SE017, SE060 |
| CE043 | Teleport authentication issues short-lived certificates to human users, services, and AI agents after they authenticate through local accounts or external identity providers with MFA. | 中 | SE017, SE061 |
| CE044 | Teleport agents are deployed onto protected infrastructure and can join clusters through multiple join methods, allowing SSH, Kubernetes, application, and database traffic to traverse the identity-aware proxy. | 中 | SE017, SE062 |
| CE045 | The tsh client is Teleport's command-line workflow surface for user logins, certificate retrieval, and protocol-specific sessions, complementing the browser UI and Teleport Connect desktop app. | 中 | SE018, SE063 |
| CU001 | Teleport's buyer persona is primarily engineering or platform-security teams at mid-to-large enterprises in technology, fintech, and global digital platforms. | 中 | SU001, SU002, SU003 |
| CU002 | Teleport's public case studies span verticals including fintech (Carta, Exness), Southeast Asia digital platform (GoTo), SaaS CX (Gladly), network detection (ExtraHop), and enterprise observability (IBM Instana). | 中 | SU001, SU002, SU003, SU006, SU007 |
| CU003 | The Series A announcement named Nasdaq, Splunk, TicketMaster, Mulesoft, and Samsung as early major customers. | 高 | SU008, SU022 |
| CU004 | The Series C announcement named Nasdaq, DoorDash, and Snowflake as flagship customer logos, cited by Bessemer lead investor Mary D'Onofrio. | 高 | SU009, SU013 |
| CU005 | The Community Edition provides a top-of-funnel acquisition channel for companies with fewer than 100 employees or less than $10 M AR; larger companies must purchase Enterprise licenses. | 高 | SU018, SU009 |
| CU006 | GoTo (Southeast Asia's largest digital platform, publicly listed) is a confirmed production customer; all of GoTo's Kubernetes clusters are private and Teleport was selected for secure private access. | 中 | SU002 |
| CU007 | Exness is a global fintech and trading technology company regulated under PCI DSS, SOC 2, and ISO 27001; it selected Teleport after evaluating multiple solutions and states it was the only solution meeting all requirements. | 中 | SU003 |
| CU008 | Teleport's case study page as of June 2026 lists at least 15 named customer stories including KnowBe4, Turo, Exness, Rush Street Interactive, GoTo, Carta, Buyers Edge, ExtraHop, IBM Instana, ThredUP, Qwilt, Mapgears, ECMWF, Flywheel, and Gladly. | 中 | SU001 |
| CU009 | Teleport customer geographies include North America (Carta, ExtraHop, Gladly), Southeast Asia (GoTo), global fintech (Exness), and IBM (global enterprise). | 中 | SU001, SU002, SU003 |
| CU010 | An October 2025 Fortune Cyber 60 press release by Teleport states that 'more than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport.' | 中 | SU011 |
| CU011 | The 600+ customer count from the October 2025 Fortune Cyber 60 press release is company-stated and has not been independently verified by any third-party analyst or database. | 中 | SU011, SU017 |
| CU012 | At the time of the Series C in March 2022, Teleport reported net-new ARR growth of 4.5x and total ARR growth of 2.8x year over year. | 中 | SU009, SU013 |
| CU013 | The Teleport open-source repository on GitHub has over 15,000 GitHub stars, as stated at the time of the June 2024 community license announcement. | 中 | SU018, SU014 |
| CU014 | Teleport was recognized as a 'revenue category mover' in the Citizens Securities Cyber 66 April 2026 report, indicating continued business momentum. | 中 | SU012, SU024 |
| CU015 | Series B materials stated Teleport included a major stock exchange, the biggest crypto exchanges, large gaming and e-commerce platforms among its customers at the time of the September 2021 funding. | 中 | SU010 |
| CU016 | Getlatka estimates Teleport generated approximately $49 M in annual revenue in 2024, with approximately 246 employees as of November 2025; these are unverified third-party estimates. | 低 | SU017 |
| CU017 | The PAM market including infrastructure access is dominated by BFSI (banking, financial services, insurance) verticals which account for approximately 29% of market share, consistent with Teleport's heavy financial services customer concentration. | 中 | SU019 |
| CU018 | Teleport's Fortune Cyber 60 press release specifically notes 'three of the top five financial services firms' as customers, indicating significant financial-sector concentration. | 中 | SU011 |
| CU019 | IBM Instana's Cloud Architect Hunter Madison states this is his third Teleport deployment across different companies, confirming advisor-driven repeat adoption as a retention signal. | 中 | SU006 |
| CU020 | IBM Instana uses Teleport to manage secure access to Dropwizard tooling and replaced a combination of VPNs and shared credentials; the case study confirms production deployment at IBM-scale. | 中 | SU006 |
| CU021 | Carta integrated Teleport with Okta for Kubernetes and database RBAC, enabling streamlined developer onboarding/offboarding and fine-grained auditing for SOC 2 and ISO 27001 compliance. | 中 | SU007 |
| CU022 | GoTo adopted Teleport for all private Kubernetes clusters across its multi-cloud infrastructure, replacing an in-house access tool that became too complex to maintain as GoTo scaled across business verticals. | 中 | SU002 |
| CU023 | Exness operates hundreds of Kubernetes clusters across on-premises and cloud environments; Teleport was selected as the only solution meeting its requirements for automation, GitOps readiness, SSO, and machine identity. | 中 | SU003 |
| CU024 | Gladly uses Teleport as a certificate authority for RBAC rather than static SSH keys, and uses session recording as compliance evidence for security auditors and privacy-conscious customers. | 中 | SU004 |
| CU025 | ExtraHop secured six Kubernetes clusters each running hundreds of individually spun-up nodes with Teleport, replacing hardcoded and shared secrets that were creating compliance and audit gaps. | 中 | SU005 |
| CU026 | Nasdaq is a confirmed named customer cited in both the Series A announcement and in Bessemer's Series C investment statement. | 高 | SU008, SU009, SU013 |
| CU027 | DoorDash and Snowflake are confirmed named customers cited by Bessemer Venture Partners in the Series C investment announcement. | 高 | SU009, SU013 |
| CU028 | Splunk, TicketMaster, Mulesoft, and Samsung are confirmed named customers cited in the Series A funding announcement. | 中 | SU008 |
| CU029 | PeerSpot users describe Teleport as significantly improving workflow by centralizing access control and reducing manual SSH key management, indicating high stickiness once deployed. | 中 | SU023 |
| CU030 | The depth of enterprise deployments at Exness (hundreds of K8s clusters), GoTo (multi-cloud), and ExtraHop (hundreds of nodes per cluster) creates significant infrastructure integration depth and high switching costs. | 中 | SU002, SU003, SU005 |
| CU031 | Teleport does not publicly disclose NRR, GRR, logo churn, or contract renewal rates; no third-party database has independently verified these metrics. | 中 | SU017, SU009 |
| CU032 | PeerSpot reviews identify initial setup complexity, RBAC configuration difficulty, and pricing concerns as friction points that could limit adoption or cause attrition. | 中 | SU023, SU015 |
| CU033 | StrongDM's competitive analysis claims Teleport lacks legacy-protocol support, limiting expansion in mixed legacy/cloud environments, which is a potential barrier to enterprise-wide adoption. | 低 | SU020 |
| CU034 | Publicly named customers are concentrated in tech-native companies (SaaS, fintech, cloud platforms); healthcare, manufacturing, government, and retail sectors are not represented in public case studies. | 中 | SU001, SU011 |
| CU035 | Teleport's Fortune Cyber 60 press release notes 'three of the top five financial services firms,' which implies significant revenue concentration in the financial services sector without disclosing individual firm names beyond Nasdaq. | 中 | SU011 |
| CU036 | The community-license change starting with Teleport v16 (June 2024) restricts the free Community Edition for companies above 100 employees or $10 M AR, potentially reducing the organic community-to-enterprise conversion pipeline. | 中 | SU018, SU009 |
| CU037 | Beams and several Identity Security features are Enterprise Cloud-only; self-hosted customers cannot access these capabilities, creating a two-tier customer experience. | 中 | SU021, SU009 |
| CU038 | NVIDIA does not appear in any official Teleport press release, funding announcement, or case study and should be considered an unverified logo-wall claim rather than a confirmed customer. | 中 | SU008, SU009, SU011 |
| CU039 | Square and Bloomberg appear on the Teleport official customer page as logo references but lack individual case studies confirming production deployment details. | 低 | SU025, SU001 |
| CU040 | The PAM market (of which Teleport participates in the infrastructure access segment) was valued at approximately $4.5 B in 2025 with a projected CAGR of 23.4% to 2034, driven by rising identity-based attacks. | 中 | SU019 |
| CU041 | Teleport's official llms.txt file (June 2026) names Nasdaq, IBM, DoorDash, Elastic, and GoTo as industry-leading organizations that trust Teleport, providing an official customer reference for Elastic beyond the case study list. | 中 | SU027, SU025 |
| CU042 | Teleport's Elasticsearch integration page confirms that Teleport supports database-level RBAC and audit for Elasticsearch as a first-class protected resource, extending enterprise value beyond SSH and Kubernetes. | 中 | SU026 |
| CU043 | Turo publicly references Teleport as an infrastructure-access platform, showing adoption within a large consumer marketplace environment. | 中 | SU029 |
| CU044 | KnowBe4 appears in Teleport's official case study library, extending proof that Teleport is used inside security-focused organizations beyond fintech and cloud-native engineering teams. | 中 | SU030 |
| CU045 | TigerGraph's case study shows Teleport supporting globally distributed access-control requirements, adding a graph-database and analytics workload to the public customer mix. | 中 | SU031 |
| CU046 | ECMWF's public case study shows Teleport being used to secure access to supercomputing clusters, proving demand beyond standard SaaS infrastructure into research and HPC environments. | 中 | SU032 |
| CU047 | Rush Street Interactive's case study adds online gaming and regulated cloud security as another public customer vertical for Teleport. | 中 | SU033 |
| CU048 | Mapgears' case study highlights Teleport's secure SSH access improving customer-support workflows, broadening evidence that Teleport is used for both platform engineering and operational support access. | 中 | SU034 |
| CU049 | thredUP's case study adds retail and Kubernetes-access controls to the public customer proof set for Teleport. | 中 | SU035 |
| CU050 | Qwilt's case study indicates Teleport is used alongside operational tools such as Rundeck and Slack APIs in globally distributed content-delivery environments. | 中 | SU036 |
| CU051 | Flywheel's case study adds biomedical research and compliance-sensitive infrastructure to Teleport's public customer references. | 中 | SU037 |
| CR001 | Teleport announced that Community Edition compiled artifacts moved from Apache 2.0 to a commercial license starting with Teleport v16 in June 2024. | 高 | SR001, SR011 |
| CR002 | The new Community Edition terms apply to companies with at least 100 employees or $10 million of annual revenue and prohibit resale or embedding. | 中 | SR001 |
| CR003 | Teleport's repository remains public, but the practical licensing change is concentrated in binaries, images, and AMIs that many enterprises actually deploy. | 中 | SR001, SR011 |
| CR004 | The Open Source Initiative definition does not treat usage-restricted commercial licenses as open source, so Teleport Community Edition no longer fits the standard OSS definition after v16. | 高 | SR001, SR031 |
| CR005 | Teleport said the project had more than 15000 GitHub stars when it announced the license change, showing that any community backlash touches a large developer audience. | 高 | SR001, SR011 |
| CR006 | Because Teleport historically benefited from developer-led adoption, the new licensing gate can weaken bottom-up enterprise pipeline and increase willingness to test alternatives. | 中 | SR001, SR011, SR025 |
| CR007 | Enterprises that standardized on Apache-era Teleport builds face artifact-provenance and upgrade-review risk when moving into the v16+ commercial-license regime. | 中 | SR001, SR010 |
| CR008 | License-driven community distrust creates credible fork and ecosystem-goodwill risk because users who want open-source-style access controls now have clearer incentive to evaluate substitutes. | 中 | SR001, SR022, SR025 |
| CR009 | The licensing change may improve monetization conversion, but it also introduces a reputational overhang that investors must treat as a structural distribution risk rather than as a one-time announcement artifact. | 中 | SR001, SR013 |
| CR010 | StrongDM's comparison page says Teleport agents run as root on target servers, which increases the privileged software footprint on managed infrastructure. | 中 | SR016 |
| CR011 | StrongDM also frames Teleport as a potential single point of failure when the control plane is unavailable, making high-availability design mission critical. | 中 | SR016 |
| CR012 | StrongDM positions broader legacy access support as a competitive advantage over Teleport, implying fit risk in hybrid estates with older protocols or workflows. | 中 | SR016, SR017 |
| CR013 | PeerSpot review evidence points to deployment and RBAC complexity in larger environments, reinforcing the view that Teleport can be operationally heavy to roll out. | 中 | SR023, SR024 |
| CR014 | Teleport's self-hosted model requires customers to own infrastructure, patching, upgrades, and resilience planning for auth and proxy services. | 中 | SR006, SR010 |
| CR015 | Teleport published an independent Cure53 security audit and disclosed remediation of the single high-severity issue found, indicating some security-process maturity. | 中 | SR009 |
| CR016 | Teleport documents FIPS 140-3 support through BoringCrypto CMVP certificate #4735 in builds from v17.7.3+ and v18.0.0+, which is a meaningful compliance mitigant for regulated buyers. | 高 | SR006, SR007 |
| CR017 | Teleport's official materials explain how customers can meet FedRAMP control requirements with the product, but the reviewed public corpus does not show Teleport Cloud itself having a FedRAMP authorization. | 高 | SR006, SR008 |
| CR018 | That FedRAMP boundary ambiguity can create procurement friction because public-sector buyers may incorrectly assume vendor-service authorization rather than customer-system control mapping. | 中 | SR006, SR008, SR014, SR015 |
| CR019 | The PAM market is large and growing, which attracts incumbents and increases the probability of sustained competitive pressure around Teleport's core category. | 中 | SR030 |
| CR020 | CyberArk carried an approximately $20.63 billion market capitalization and $1.30 billion of TTM revenue in June 2026. | 中 | SR026, SR027 |
| CR021 | Okta carried an approximately $20.65 billion market capitalization and $2.91 billion of TTM revenue in June 2026 while marketing a Privileged Access product. | 高 | SR021, SR028, SR029 |
| CR022 | StrongDM explicitly attacks Teleport on legacy support, operational simplicity, and architecture footprint, showing that those are active competitive battlegrounds rather than hypothetical weaknesses. | 中 | SR016 |
| CR023 | HashiCorp Boundary provides an identity-aware proxy alternative with open-source roots, making it a credible option for buyers who want a different trust or packaging model. | 中 | SR022 |
| CR024 | Cloud-native IAM and privileged-identity features from AWS, Google Cloud, and Microsoft can be good enough substitutes for customers whose estates stay mostly within one cloud. | 中 | SR014, SR015, SR021 |
| CR025 | Teleport says it serves more than 600 customers including three of the top five financial services firms, showing real traction but also confirming that it competes in demanding enterprise evaluations. | 高 | SR005, SR033, SR034 |
| CR026 | Competitive pressure can slow sales cycles or compress pricing because larger rivals can bundle adjacent identity or security products and smaller rivals can exploit Teleport's license and complexity narrative. | 中 | SR016, SR020, SR021, SR024 |
| CR027 | Recent 2026 recognition on the Fortune Cyber 60 and Citizens Cyber 66 lists strengthens Teleport's visibility but does not remove feature-parity or platform-bundling risk. | 高 | SR033, SR034 |
| CR028 | Teleport publicly disclosed funding of $25 million in Series A, $30 million in Series B, and $110 million in Series C for roughly $140 million raised in total. | 高 | SR002, SR003, SR004 |
| CR029 | Teleport's Series C was announced in March 2022 at a $1.1 billion valuation led by Bessemer Venture Partners, and no newer round is visible in the provided source corpus. | 高 | SR002, SR012 |
| CR030 | The only ARR figure in the reviewed source set is GetLatka's estimate of $49 million for 2024, which should be treated as external and unverified. | 低 | SR032 |
| CR031 | If the $49 million ARR estimate were directionally correct, Teleport's last disclosed $1.1 billion valuation would imply an ARR multiple of roughly 22 times. | 低 | SR002, SR032 |
| CR032 | The current public evidence set does not disclose profitability, burn, gross margin, net retention, or cash runway. | 中 | SR002, SR005, SR032 |
| CR033 | A four-year-stale private valuation anchor combined with limited current financial disclosure creates meaningful financing and mark risk for investors entering today. | 中 | SR012, SR013, SR030, SR032 |
| CR034 | Public competitors such as CyberArk and Okta have vastly larger visible revenue bases and organizational resources than Teleport. | 中 | SR020, SR021, SR026, SR027, SR028, SR029 |
| CR035 | Teleport's official about materials identify Ev Kovyrin as CEO, Sasha Klizhentas as CTO, and Taylor Wakefield as COO, concentrating visible leadership around three co-founders. | 中 | SR005 |
| CR036 | The reviewed public corpus does not disclose a formal succession plan, management bench map, or employee-count update for Teleport. | 中 | SR005 |
| CR037 | Teleport has repositioned itself around AI infrastructure identity, expanding the company story beyond core privileged access and zero-trust access. | 高 | SR035, SR036 |
| CR038 | Teleport announced the Agentic Identity Framework in January 2026, showing that the company is actively investing in a still-emerging control plane for AI agents. | 中 | SR035 |
| CR039 | Beams launched in public beta in June 2026, which means product maturity, adoption proof, and support economics are still early. | 中 | SR036 |
| CR040 | Because Beams is early stage and cloud-oriented, some security-sensitive or self-hosted buyers may wait for broader maturity before treating it as production infrastructure. | 中 | SR010, SR036 |
| CR041 | Delegating infrastructure access to AI agents introduces governance questions around delegated permissions, tool-use boundaries, audit scope, and runtime isolation even when core human access controls are mature. | 中 | SR014, SR015, SR035, SR036 |
| CR042 | Teleport's compliance posture and enterprise traction help credibility, but simultaneously executing core PAM growth and a new AI-runtime motion increases roadmap complexity. | 中 | SR016, SR025, SR033, SR034, SR035 |
| CR043 | The three diligence topics most likely to change underwriting outcomes quickly are license transition exposure, FedRAMP authorization ambiguity, and current financial proof. | 中 | SR001, SR006, SR008, SR032 |
| CR044 | Practical kill criteria include unresolved v16 licensing objections, inability to prove HA resilience, failure to reconcile present commercial metrics, or over-rotation into AI before core PAM economics are proven. | 中 | SR001, SR006, SR016, SR032, SR036 |
| CR045 | The highest-value next diligence package is a legal memo on licensing, a resilience package for control-plane uptime, a precise regulated-cloud posture statement, and current board-level financial metrics. | 中 | SR001, SR006, SR008, SR023, SR032 |
| CR046 | AWS Systems Manager Session Manager offers a managed shell-access path for AWS-centric estates, reducing the need for a separate third-party infrastructure-access layer in simpler deployments. | 中 | SR037 |
| CR047 | Azure Bastion provides Microsoft-native browser and RDP or SSH access into private Azure resources, narrowing Teleport's differentiation for Azure-concentrated customers. | 中 | SR038 |
| CR048 | Google Cloud Identity-Aware Proxy offers an identity-aware control point for Google-hosted applications and VM access, making single-cloud substitution a real risk for parts of Teleport's workload mix. | 中 | SR039 |
| CR049 | Microsoft Entra Privileged Identity Management brings just-in-time privileged access and approval workflows into the Microsoft identity stack, increasing bundling pressure on standalone vendors. | 中 | SR040 |
| CR050 | Teleport's own authorization documentation shows deep RBAC and policy expressiveness, but that same policy depth can increase implementation and change-management complexity in large enterprises. | 中 | SR023, SR041 |
| CR051 | TLS Routing and proxy peering expand Teleport's network flexibility for multi-cluster estates, but they also add migration and traffic-management complexity that operators must own. | 中 | SR042, SR043 |
| CV001 | Teleport's last known post-money valuation is $1.1B from the May 2022 Series C. | 高 | SV001, SV008 |
| CV002 | The Series C raised $110M and was led by Bessemer Venture Partners with Insight Venture Partners participating. | 高 | SV001, SV008 |
| CV003 | Teleport has disclosed approximately $165M of total primary capital across Series A, Series B, and Series C. | 高 | SV001, SV002, SV003 |
| CV004 | No new primary equity round has been announced in official Teleport materials since May 2022, making the $1.1B mark more than four years stale as of June 2026. | 中 | SV001, SV030 |
| CV005 | GetLatka estimates Teleport's 2024 ARR at $49M, and that figure is unconfirmed by Teleport. | 低 | SV010 |
| CV006 | Using the $1.1B Series C mark and the $49M GetLatka ARR estimate implies about 22.4x EV/ARR. | 中 | SV001, SV010 |
| CV007 | CyberArk had about $20.63B market capitalization and $1.30B TTM revenue in June 2026, implying roughly 15.8x EV or market cap to revenue. | 中 | SV011, SV012 |
| CV008 | Okta had about $20.65B market capitalization and $2.91B TTM revenue in June 2026, implying roughly 7.1x revenue. | 中 | SV013, SV014 |
| CV009 | CyberArk revenue increased from roughly $0.75B in 2023 to $1.00B in 2024 and to about $1.30B on a TTM basis in 2025-2026, indicating about 30% year-over-year growth. | 中 | SV012, SV020 |
| CV010 | The PAM market is sized at $4.50B in 2025 and forecast to grow at 23.4% CAGR to $29.88B by 2034. | 中 | SV015 |
| CV011 | The zero-trust security market is sized at $40.01B in 2025 and forecast to grow at 16.39% CAGR to $182.59B by 2035. | 中 | SV016 |
| CV012 | Teleport says it serves more than 600 customers, including three of the top five financial services firms. | 中 | SV001, SV004 |
| CV013 | Bessemer described Teleport as building the unified access plane for DevOps and infrastructure access. | 中 | SV008 |
| CV014 | Teleport said ARR growth was 2.5x year over year at the time of the Series B raise. | 中 | SV002 |
| CV015 | Teleport said ARR growth was 2.8x year over year at the time of Series C and that net new ARR grew 4.5x. | 中 | SV001 |
| CV016 | The 2024 community-edition license change could reduce bottom-up open-source conversion and alter ARR growth trajectory. | 中 | SV007, SV029 |
| CV017 | StrongDM, BeyondTrust, CyberArk, Okta, and HashiCorp Boundary all compete for privileged or infrastructure access workflows with more capital resources than Teleport. | 中 | SV021, SV022, SV023, SV025, SV026, SV032, SV042, SV043 |
| CV018 | Using the $49M ARR estimate and roughly 246 employees as an unverified headcount proxy implies around $199K ARR per employee. | 低 | SV010, SV039 |
| CV019 | Teleport's Agentic Identity Framework launch and the Beams public beta mark a 2026 AI-agent identity repositioning. | 中 | SV031, SV033, SV034 |
| CV020 | No public secondary pricing source was located in the reviewed materials for Teleport shares as of the run date. | 低 | |
| CV021 | Teleport was named to the Fortune Cyber 60 list and the Citizens Securities Cyber 66 list in 2025-2026, signaling market recognition. | 中 | SV005, SV006 |
| CV022 | Bessemer's State of the Cloud 2024 argues that AI has revived premium private-market software investing and references a $1B AI commitment. | 中 | SV009 |
| CV023 | Bessemer invested in Teleport's Series C alongside Insight Venture Partners. | 高 | SV001, SV008 |
| CV024 | A research-more recommendation is warranted because current public evidence is insufficient to underwrite the $1.1B mark with high confidence. | 中 | SV001, SV010, SV011, SV012, SV013, SV014 |
| CV025 | Teleport at about 22.4x unconfirmed ARR screens expensive relative to CyberArk at roughly 15.8x verified revenue. | 中 | SV001, SV010, SV011, SV012 |
| CV026 | Okta's privileged-access product expands overlap with Teleport and can compress the premium comp set available to the company. | 中 | SV023, SV013, SV014 |
| CV027 | HashiCorp Boundary provides additional infrastructure-access competition and pricing context for Teleport's access plane. | 中 | SV032 |
| CV028 | Third-party market research beyond Precedence also supports a large and growing PAM market opportunity. | 中 | SV018, SV019, SV044, SV045 |
| CV029 | AI-agent identity is an emerging segment without an established public multiple framework, increasing model risk around any premium narrative. | 中 | SV031, SV033, SV034 |
| CV030 | Teleport's Series C was priced during a 2022 software valuation regime that was materially richer than public security-software multiples in 2026. | 中 | SV001, SV009, SV011, SV012, SV013, SV014 |
| CV031 | A bull case with 35% annual growth from the $49M 2024 ARR estimate reaches about $85M ARR by 2027, and at 15x implies roughly $1.28B of value. | 中 | SV010, SV019, SV033, SV034 |
| CV032 | A base case with 25% annual growth from the $49M estimate reaches about $73M ARR by 2027, and at 10x to 12x implies about $730M to $875M. | 中 | SV010, SV009, SV011, SV012, SV013, SV014 |
| CV033 | A bear case with 15% annual growth and license-change headwinds reaches about $60M ARR by 2027, and at 6x to 8x implies about $360M to $480M. | 中 | SV007, SV010, SV009 |
| CV034 | The stale $1.1B mark sits about 26% to 50% above the base-case implied valuation range. | 中 | SV001, SV010, SV009 |
| CV035 | Reviewed public sources do not disclose Teleport profitability, gross margin, NRR, or burn rate. | 低 | SV004, SV010, SV030 |
| CV036 | The absence of public FedRAMP authorization for Teleport Cloud limits near-term federal and highly regulated cloud TAM capture. | 中 | SV040, SV041 |
| CV037 | Teleport's investor syndicate includes Bessemer, Insight, Kleiner Perkins, and S28, which supports exit credibility even though it does not validate price. | 中 | SV001, SV002, SV003, SV024 |
| CV038 | Teleport has raised about 2.9 times as much capital as its estimated 2024 ARR. | 中 | SV001, SV002, SV003, SV010 |
| CV039 | High-growth security and infrastructure software companies can command roughly 15x to 25x ARR when growth is verified and sustained above 50% year over year. | 中 | SV009, SV011, SV012 |
| CV040 | Teleport's disclosed 2.8x ARR growth at Series C is historical rather than current, so present growth remains unverified. | 中 | SV001, SV010 |
| CV041 | For security software at roughly $40M to $60M ARR, a more defensible present-day private-market band is about 8x to 15x ARR unless growth is exceptional and verified. | 中 | SV009, SV011, SV012, SV013, SV014 |
| CV042 | The absence of a new funding round since 2022 and no public IPO announcement increase liquidity risk for late-stage investors. | 中 | SV001, SV030 |
| CV043 | The CE license change could raise customer acquisition costs if fewer community users convert through the old open-source funnel. | 中 | SV007, SV029 |
| CV044 | A strategic acquisition by a larger security or platform vendor is a viable exit path given Teleport's category position and customer footprint. | 中 | SV021, SV022, SV023, SV037 |
| CV045 | GetLatka labels its Teleport ARR figure as estimated, leaving a single-source dependency for public revenue analysis. | 中 | SV010 |
| CV046 | Teleport's GitHub repository has well over 15,000 stars, supporting the view that developer awareness remains meaningful. | 中 | SV029 |
| CV047 | Multiple official case studies across IBM Instana, Carta, GoTo, and Exness support Teleport's enterprise adoption narrative. | 中 | SV035, SV036, SV037, SV038, SV046, SV047 |
| CV048 | Public materials do not disclose liquidation preferences, anti-dilution terms, or cap-table structure, so entry discipline must assume unknown preference overhang. | 低 | SV001, SV002, SV003, SV030 |
| CV049 | Stock Analysis revenue pages reinforce that CyberArk and Okta are already multi-hundred-million to multi-billion-dollar revenue businesses, making them more mature public comp anchors than Teleport. | 中 | SV049, SV050 |
| CV050 | Stock Analysis overview pages provide continuous public-market price discovery for CYBR and OKTA, highlighting how much stronger public valuation transparency is than Teleport's stale private mark. | 中 | SV051, SV052 |
| CV051 | Macrotrends' long-run Okta price-to-sales history underlines that public identity-software multiples have already compressed from earlier peak periods. | 中 | SV048 |
| CV052 | The gap between public-market price discovery for Okta and CyberArk and Teleport's unrefreshed 2022 private mark increases valuation-risk for any new investor entering today. | 中 | SV048, SV051, SV052 |
| CV053 | Additional public-comp data sources from Stock Analysis and Macrotrends all point investors back to the same conclusion: Teleport needs fresh ARR proof before its 2022 unicorn valuation can be defended confidently. | 中 | SV048, SV049, SV050, SV051, SV052 |
| CV054 | Yahoo Finance and Nasdaq both maintain live Okta market pages, underscoring that public peers benefit from continuous price discovery that Teleport does not have. | 中 | SV053, SV054 |
| CV055 | The presence of multiple independent market-data venues for Okta reinforces that public-comp valuation evidence is more current and auditable than Teleport's stale private mark. | 中 | SV052, SV053, SV054 |
| 编号 | 出版方 | 标题 | 引文 |
|---|---|---|---|
| SO001 | Teleport | Teleport: Unified Identity Securing Classic & AI Infrastructure | Teleport unifies identities — humans, machines, and AI — with strong identity implementation to speed up engineering, improve resiliency against identity-based attacks, and control AI in production infrastructure. |
| SO002 | Teleport | About Us | Teleport | Global Headquarters 2100 Franklin St, Suite 400, Oakland, CA 94612. Ev Kontsevoy — Co-founder and CEO; Alexander Klizhentas — Co-founder and CTO; Taylor Wakefield — Co-founder and COO. |
| SO003 | Teleport | Teleport Raises $110 Million Series C at $1.1 Billion Valuation | Teleport has just secured $110M in Series C funding … started with my co-founders Sasha Klizhentas and Taylor Wakefield in 2015. The new round values the company at $1.1 billion. |
| SO004 | Teleport | Teleport raises $30MM in series-B and launches secure access for MongoDB | Secured $30M in Series B funding … net new annual recurring revenue up 5x and total annual recurring revenue up 2.5x, compared to the second quarter of 2020. |
| SO005 | Teleport | Announcing our Series A | We have closed a $25MM Series A funding round led by Kleiner Perkins … customer base has exploded … including NASDAQ, Splunk, TicketMaster, Mulesoft and Samsung. We were recently able to reach profitability. |
| SO006 | Teleport | Gravitational Changes Name to Teleport | Today we are officially announcing that Gravitational is becoming Teleport … moving from gravitational.com to https://goteleport.com. |
| SO007 | Teleport | Teleport Community Edition will adopt a commercial license starting with version 16 | Starting with the June release of Teleport 16, we are switching Teleport Community Edition to a commercial license … Companies may use Teleport Community Edition on the condition they have less than 100 employees and less than $10MM in annual revenue. |
| SO008 | Teleport | Teleport Careers | Solving big problems across multiple domains for the world's most innovative companies … more than 600 customers around the globe. |
| SO009 | Teleport | Case Studies — Secure Infrastructure Access at Leading Companies | KnowBe4, Turo, Exness, Rush Street Interactive, GoTo, Carta, NASDAQ, Buyers Edge, ExtraHop, IBM Instana, ThredUP, Qwilt, Mapgears, ECMWF, Flywheel, Gladly — and many more. |
| SO010 | Teleport | Teleport Pricing | |
| SO011 | Teleport | Teleport named to 2026 Fortune Cyber 60 List | More than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport. |
| SO012 | Teleport | Teleport Named to Citizens Securities' 2026 Cyber 66 List | Teleport has been named to the Citizens Securities 2026 Cyber 66 … recognizes the most notable privately held cybersecurity companies. 73% of cybersecurity leaders are already seeing enterprise customers ask how their platforms can help secure AI agents. |
| SO013 | Teleport | Teleport Introduces Agentic Identity Framework | Teleport today announced the Teleport Agentic Identity Framework, an AI-centered framework that provides organizations with a clear roadmap for securely deploying agentic AI in production cloud and on-premises environments. |
| SO014 | Teleport | FedRAMP Compliance for Infrastructure Access | Teleport provides the foundation to meet FedRAMP requirements … This includes support for the Federal Information Processing Standard FIPS 140 … This document explains how Teleport FIPS mode works and how it can help your company to become FedRAMP authorized. |
| SO015 | Teleport | IBM Instana implements streamlined access control, visibility and compliance with Teleport | |
| SO016 | Teleport | Carta's Win/Win: Implementing Robust Security Controls while Improving Developer Productivity | |
| SO017 | Teleport | Teleport Security Audit by Cure53 — No Critical Vulnerabilities Found | No critical vulnerabilities have been discovered … The results of this second-run Cure53 security assessment of the latest release of the Teleport software … are once again very positive. |
| SO018 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Bessemer Growth leads the $110 million Series C. We believe Teleport will be the defining solution to this emerging massive problem, granting infrastructure access seamlessly without compromising security. |
| SO019 | Kleiner Perkins | Gravitational — Pulling Us Toward an Open and Multi-Cloud Future | Ev, Sasha, and Taylor identified this tension during the formative period of the cloud era while working at Rackspace via the acquisition of their first startup, Mailgun. |
| SO020 | GetLatka | Teleport — Company Financial Data and Metrics | In 2024, Teleport's revenue reached $49M … Teleport employs approximately 246 people as of 2026 … Teleport raised $140M in total funding across 2 rounds. |
| SO021 | StrongDM | StrongDM vs. Teleport — Comparison and Alternatives | The Teleport agents run as root in every server you want to audit, creating a new attack vector and a new surface to protect. Teleport cloud is unreliable and availability numbers are inaccurate. |
| SO022 | PeerSpot | Teleport Reviews — User Feedback and Ratings | Teleport requires improvements in initial setup and RBAC complexity. Integration with SIEM and monitoring tools could be enhanced. Pricing concerns affect large companies. |
| SO023 | GitHub (Gravitational) | gravitational/teleport — Open-Source Repository | Teleport provides connectivity, authentication, access controls and audit for infrastructure … SSH nodes, Kubernetes clusters, PostgreSQL, MongoDB, CockroachDB and MySQL databases, MCP, Internal Web apps, Windows Hosts. |
| SO024 | Teleport (Beams) | Beams — Trusted Runtimes for Infrastructure Agents | Beams runs each agent in an isolated Firecracker VM with built-in identity. Connected to your infrastructure and inference services — no secrets, no IAM wrestling. |
| SO025 | Teleport | The 2026 Infrastructure Identity Survey — State of AI Adoption | 79% are evaluating/deploying agentic AI … only 13% feel extremely prepared … 60% have had or suspect an AI-related security incident. |
| SO026 | Teleport | FedRAMP Compliance with Teleport — Use Cases | |
| SO027 | Teleport | Teleport Debuts Delegated Agentic Identity and LLM Proxy in Beams Public Beta | |
| SO028 | Teleport | Teleport Newsroom — Latest News and Press Releases | |
| SO029 | Precedence Research | Privileged Access Management Market Size to Hit USD 29.88 Bn by 2034 | The global privileged access management market size is accounted at USD 4.50 billion in 2025 and is predicted to increase … to approximately USD 29.88 billion by 2034, expanding at a CAGR of 23.40%. |
| SO030 | NIST | Zero Trust Architecture — NIST Special Publication 800-207 | Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location … Authentication and authorization are discrete functions performed before a session to an enterprise resource is established. |
| SM001 | Teleport | Teleport homepage | AI Infrastructure Identity Company |
| SM002 | Teleport | Teleport raises Series C | $110 million Series C financing at a $1.1 billion valuation |
| SM003 | Teleport | Infrastructure Identity Survey 2026 | 92% have near-term AI initiatives and only 13% feel extremely prepared |
| SM004 | Teleport | Teleport named to 2026 Fortune Cyber 60 list | 600+ customers including three of the top five financial services firms |
| SM005 | Teleport | Teleport named 2026 Cyber 66 hottest privately held cybersecurity companies | 73% of cybersecurity leaders see enterprise customers asking about AI agent security |
| SM006 | NIST | Zero Trust Architecture (SP 800-207) | Zero trust provides a collection of concepts and ideas designed to minimize uncertainty in enforcing accurate, least privilege per-request access decisions. |
| SM007 | CISA | Zero Trust Maturity Model | Five pillars plus three cross-cutting capabilities structure federal zero-trust implementation. |
| SM008 | Grand View Research (archived) | Privileged Access Management market report archive | |
| SM009 | Precedence Research | Privileged Access Management market | The global privileged access management market size was valued at USD 4.50 billion in 2025 and is projected to reach USD 29.88 billion by 2034. |
| SM010 | Grand View Research (archived) | Zero Trust Security market report archive | The global zero trust security market size was valued at USD 36.96 billion in 2024 and is expected to grow at a CAGR of 16.6% from 2025 to 2030. |
| SM011 | Precedence Research | Zero Trust Security market | The global zero trust security market size is calculated at USD 40.01 billion in 2025 and is forecasted to hit around USD 182.59 billion by 2035. |
| SM012 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Infrastructure access is a new and exciting product category. |
| SM013 | Bessemer Venture Partners | State of the Cloud 2024 | |
| SM014 | Kleiner Perkins | Gravitational: Pulling Us Toward an Open and Multi-Cloud Future | |
| SM015 | Teleport | Identity Security | |
| SM016 | Teleport | FedRAMP compliance documentation | Teleport provides support for FIPS 140 cryptographic modules. |
| SM017 | Teleport | SOC 2 compliance documentation | |
| SM018 | Teleport | FedRAMP compliance use case | |
| SM019 | Teleport | Accelerate FedRAMP compliance | |
| SM020 | Teleport | Automating identity access for FedRAMP 20x | |
| SM021 | GetLatka | goteleport.com company profile | |
| SM022 | Teleport | Pricing | |
| SM023 | Teleport | Case studies | |
| SM024 | Teleport | How it works | |
| SM025 | GitHub | gravitational/teleport repository | 15,000+ stars |
| SM026 | Fortune Business Insights | Privileged Access Management market page returned unrelated agricultural content | Retained URL returned content about agricultural microbials rather than privileged access management. |
| SM027 | Teleport | Newsroom | |
| SM028 | Teleport | Feature matrix | |
| SM029 | StrongDM | StrongDM vs Teleport | Teleport is a point solution for modern cloud architecture. |
| SP001 | StrongDM | StrongDM homepage | |
| SP002 | CyberArk | What is Privileged Access Management (PAM)? | |
| SP003 | CyberArk | Privileged Access Manager | |
| SP004 | BeyondTrust | Privileged Access Management (PAM) glossary | |
| SP005 | BeyondTrust | Privileged Remote Access | |
| SP006 | Delinea | Secret Server | |
| SP007 | Okta | Okta Privileged Access | |
| SP008 | HashiCorp | What is Boundary? | |
| SP009 | PeerSpot | Teleport Reviews | |
| SP010 | PeerSpot | Teleport Alternatives and Competitors | |
| SP011 | Slashdot | Teleport Alternatives | |
| SP012 | CompaniesMarketCap | CyberArk market cap | |
| SP013 | CompaniesMarketCap | CyberArk revenue | |
| SP014 | CompaniesMarketCap | Okta market cap | |
| SP015 | CompaniesMarketCap | Okta revenue | |
| SP016 | Teleport | Reference Architecture | |
| SP017 | Teleport | Core Concepts | |
| SP018 | Teleport | Teleport 16 | |
| SP019 | Teleport | Teleport 17 | |
| SP020 | Teleport | Teleport Security Audit | |
| SP021 | Teleport | Identity Security | |
| SP022 | Teleport | Teleport Introduces Agentic Identity Framework | |
| SP023 | Teleport | Teleport Community License | |
| SP024 | Teleport | Agentic Identity Framework docs | |
| SP025 | Teleport | Machine & Workload Identity | |
| SP026 | StrongDM | StrongDM vs Teleport | |
| SP027 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | |
| SP028 | Teleport | Gravitational is Teleport | |
| SP029 | Teleport | Pricing | |
| SP030 | GitHub | gravitational/teleport repository | |
| SP031 | Teleport | Feature Matrix | |
| SI001 | Teleport | GoTo Secures and Simplifies Cloud Access with Teleport | GoTo streamlines multi-cloud access management and enhances security across their infrastructure with Teleport. |
| SI002 | Teleport | Exness Elevates Global Kubernetes and Infrastructure Security with Teleport | Exness is one of the world's largest trading technology companies … As a regulated financial services provider, Exness treats security as a core business priority. |
| SI003 | Teleport | Secure Cloud Infrastructure Access with Teleport: A Gladly Case Study | Gladly selected Teleport to secure the cloud-native infrastructure … meeting international compliance requirements. |
| SI004 | Teleport | ExtraHop Secures Access with Identity to Kubernetes and Server Infrastructure | ExtraHop used Teleport to secure access to their servers and Kubernetes clusters without sacrificing speed … an identity-based approach to authorizing each developer. |
| SI005 | Teleport | Machine and Workload Identity — AI Agent Use Cases | Teleport enables you to enforce access and privileges for agents. Security must be enforced deterministically; AI agents cannot be trusted to follow high-level instructions like "don't delete production". Teleport solves this by issuing each agent its own identity. |
| SI006 | Teleport | Database Access — Enroll Resources | |
| SI007 | Teleport | Teleport Session Recording Architecture | Teleport captures the entire pseudo-terminal (PTY) output of the session. The intention is for session recording to document what a user saw when they ran a session. |
| SI008 | Teleport | Teleport LLMs.txt — Company and Product Summary | Teleport, the AI Infrastructure Identity Company, establishes a unified identity layer for infrastructure — humans, machines, workloads, and AI agents — secured cryptographically. Headquartered in Oakland, CA, Teleport operates globally. |
| SI009 | Teleport | Elasticsearch RBAC and Auditing with Teleport | |
| SI010 | Teleport | MCP Servers — Enroll Resources | |
| SI011 | U.S. Securities and Exchange Commission (EDGAR) | CyberArk Software Ltd. Form 20-F Annual Report (Fiscal Year 2024) | |
| SI012 | GetLatka | Teleport — Company Financial Data and Metrics | In 2024, Teleport's revenue reached $49M … Teleport employs approximately 246 people as of 2026 … Teleport raised $140M in total funding across 2 rounds. |
| SI013 | Teleport | Teleport Pricing | |
| SI014 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Bessemer Growth leads the $110 million Series C. We believe Teleport will be the defining solution … granting infrastructure access seamlessly without compromising security. |
| SI015 | Teleport | Teleport Raises $110 Million Series C at $1.1 Billion Valuation | Teleport has just secured $110M in Series C funding … net new annual recurring revenue up 4.5x and total annual recurring revenue up 2.8x year over year. The new round values the company at $1.1 billion. |
| SI016 | Teleport | Teleport raises $30MM in series-B and launches secure access for MongoDB | Net new annual recurring revenue up 5x and total annual recurring revenue up 2.5x, compared to the second quarter of 2020. |
| SI017 | Teleport | Announcing our Series A | We have closed a $25MM Series A funding round led by Kleiner Perkins … We were recently able to reach profitability. |
| SI018 | Teleport | Teleport Community Edition will adopt a commercial license starting with version 16 | Companies may use Teleport Community Edition on the condition they have less than 100 employees and less than $10MM in annual revenue. |
| SI019 | CompaniesMarketCap | CyberArk Software (CYBR) — Market Capitalization | As of June 2026 CyberArk Software has a market cap of $20.63 Billion USD. |
| SI020 | CompaniesMarketCap | CyberArk Software (CYBR) — Revenue | CyberArk Software's current revenue (TTM) is $1.30 Billion USD. In 2024 the company made a revenue of $1.00 Billion USD. |
| SI021 | CompaniesMarketCap | Okta (OKTA) — Market Capitalization | As of June 2026 Okta has a market cap of $20.65 Billion USD. |
| SI022 | CompaniesMarketCap | Okta (OKTA) — Revenue | Okta's current revenue (TTM) is $2.91 Billion USD. In 2025 the company made a revenue of $2.91 Billion USD an increase over the revenue in the year 2024 that were of $2.61 Billion USD. |
| SI023 | PeerSpot | Teleport Reviews — User Feedback and Ratings | Pricing concerns affect large companies … Teleport requires improvements in initial setup and RBAC complexity. |
| SI024 | StrongDM | StrongDM vs. Teleport — Comparison and Alternatives | The Teleport agents run as root in every server you want to audit, creating a new attack vector … Pricing concerns affect large companies. |
| SI025 | Kleiner Perkins | Gravitational — Pulling Us Toward an Open and Multi-Cloud Future | |
| SI026 | Precedence Research | Privileged Access Management Market Size to Hit USD 29.88 Bn by 2034 | The global privileged access management market size is accounted at USD 4.50 billion in 2025 and is predicted to increase … to approximately USD 29.88 billion by 2034, expanding at a CAGR of 23.40%. |
| SI027 | NIST | Zero Trust Architecture — NIST Special Publication 800-207 | |
| SE001 | Teleport | Teleport: Unified Identity Securing Classic & AI Infrastructure | Teleport unifies identities — humans, machines, and AI — with strong identity implementation to speed up engineering, improve resiliency against identity-based attacks, and control AI in production infrastructure. |
| SE008 | Teleport | Teleport Community Edition will adopt a commercial license starting with version 16 | Starting with the June release of Teleport 16, we are switching Teleport Community Edition to a commercial license with new restrictions |
| SE009 | Teleport | Introducing Teleport 16 - Enhanced Security and Usability with New Features | |
| SE010 | Teleport | Introducing Teleport 17 - Enhanced Security and Usability with New Features | |
| SE011 | Teleport | Teleport Explained: Concepts & Architecture Guide | Teleport is a certificate authority and identity-aware access proxy that implements protocols such as SSH, RDP, HTTPS, Kubernetes API, and a variety of SQL and NoSQL database protocols. |
| SE012 | Teleport | Teleport Pricing | |
| SE017 | Teleport | Teleport Reference Architecture | |
| SE018 | Teleport | Teleport Core Concepts | |
| SE019 | Teleport | Teleport Feature Matrix | The Teleport Agentic Identity Framework combines Teleport identity, access, governance, and monitoring capabilities to secure AI agents and the infrastructure they access. |
| SE020 | Teleport | Machine & Workload Identity Documentation | |
| SE022 | Teleport | MCP Server Access Documentation | |
| SE023 | Teleport | Teleport Identity Security Documentation | |
| SE024 | Teleport | Session Recording Architecture | |
| SE025 | Teleport | FedRAMP Compliance with Teleport | Teleport releases from 17.7.3+ and 18.0.0+ use BoringCrypto tag fips-20220613 (CMVP certificate #4735, FIPS 140-3) |
| SE026 | Teleport | SOC 2 Compliance with Teleport | |
| SE027 | Teleport | Teleport Upcoming Releases | |
| SE028 | Teleport | Identity Security Blog Post | |
| SE029 | Teleport | Teleport Security Audit by Cure53 | No critical vulnerabilities have been discovered. One high vulnerability was found: The roles API of the auth server allow directory traversal. |
| SE030 | Teleport | Teleport Introduces Agentic Identity Framework | |
| SE031 | Teleport | Beams LLM Proxy and Delegated Identity Public Beta | Two foundational identity concepts — controlling the scope of agent roles and constraining what they can access — now have a production implementation in Beams |
| SE032 | Teleport | 2026 Infrastructure Identity Survey: State of AI Adoption | 92% have near-term AI initiatives in infrastructure... but only 13% feel extremely prepared |
| SE033 | Teleport | Agentic Identity Framework Documentation | |
| SE034 | Teleport | AI Agents with Machine & Workload Identity | |
| SE035 | Beams (Teleport) | Beams — Trusted Runtimes for Infrastructure Agents | Beams runs each agent in an isolated Firecracker VM with built-in identity. Connected to your infrastructure and inference services — no secrets, no IAM wrestling. |
| SE036 | GitHub (gravitational/teleport) | Teleport Open Source Repository | Teleport is a single Go binary that integrates with multiple protocols and cloud services |
| SE041 | NIST | Zero Trust Architecture (SP 800-207) | |
| SE042 | CISA | Zero Trust Maturity Model | |
| SE043 | StrongDM | StrongDM vs Teleport Comparison | The Teleport agents run as root in every server you want to audit, creating a new attack vector and a new surface to protect... Teleport cloud is unreliable and availability numbers are inaccurate. |
| SE051 | HashiCorp | What is Boundary? | |
| SE052 | PeerSpot | Teleport Reviews | I rate it a seven because, as I mentioned, there is a security threat regarding clipboard access. |
| SE054 | Teleport | FedRAMP Compliance Use Case | |
| SE053 | Teleport | Teleport Named to Citizens Securities 2026 Cyber 66 | 73% of cybersecurity leaders are already seeing enterprise customers ask how their platforms can help secure AI agents |
| SE037 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Teleport will be the defining solution to this emerging massive problem, granting infrastructure access seamlessly without compromising security. |
| SE039 | Kleiner Perkins | Gravitational: Pulling Us Toward an Open and Multi-Cloud Future | |
| SE055 | Teleport | Teleport Database Access Documentation | |
| SE056 | Teleport | Teleport Security Page — Code Signing and Certificates | |
| SE057 | Teleport | Teleport Blog | |
| SE058 | Teleport | Elasticsearch Database Access — Self-Hosted Enrollment | |
| SE059 | Teleport | Teleport Identity Governance | |
| SE060 | Teleport | Teleport Proxy Service | |
| SE061 | Teleport | Teleport Authentication | |
| SE062 | Teleport | Deploying Teleport Agents | |
| SE063 | Teleport | Teleport tsh Client Documentation | |
| SU001 | Teleport | Teleport Customer Case Studies | When security and a frictionless engineering experience matter, the most innovative companies in the world trust Teleport for Infrastructure Identity. |
| SU002 | Teleport | GoTo Customer Case Study | All our Kubernetes clusters are private—meaning they can't be accessed publicly, both for the data plane and control plane. We needed a mechanism to securely expose this to developers, and Teleport fit our requirements perfectly. |
| SU003 | Teleport | Exness Customer Case Study | Teleport was the only evaluated solution that met every requirement. |
| SU004 | Teleport | Gladly Customer Case Study | |
| SU005 | Teleport | ExtraHop Customer Case Study | |
| SU006 | Teleport | IBM Instana Customer Case Study | This is company number three I've done this at, to have Teleport in play to give us the ability to go and help our security posture |
| SU007 | Teleport | Carta Customer Case Study | |
| SU008 | Teleport | Announcing our Series A | our customer base has exploded from a handful of early adopters to an impressive portfolio of some of the world's largest and most innovative companies, including NASDAQ, Splunk, TicketMaster, Mulesoft and Samsung. |
| SU009 | Teleport | Teleport Raises $110 Million Series C at $1.1 Billion Valuation | fantastic logos like Nasdaq, Doordash, and Snowflake, make Teleport a category-defining company |
| SU010 | Teleport | Teleport Raises $30M in Series B | |
| SU011 | Teleport | Teleport Named to 2026 Fortune Cyber 60 | More than 600 companies, including three of the top five financial services firms and the leaders in AI research, compute, and cloud, depend on Teleport to reduce risk and simplify access. |
| SU012 | Teleport | Teleport Newsroom | |
| SU013 | Bessemer Venture Partners | Investing in Teleport and the Unified Access Plane | Its secretless security model and focus on developer productivity, along with fantastic logos like Nasdaq, Doordash, and Snowflake, make Teleport a category-defining company |
| SU014 | GitHub (gravitational/teleport) | Teleport Open Source Repository | |
| SU015 | PeerSpot | Teleport Alternatives and Competitors | |
| SU016 | Slashdot | Best Teleport Alternatives in 2026 | |
| SU017 | Latka (getlatka.com) | Teleport Revenue and Company Data | In 2024, Teleport's revenue reached $49M. Since its launch in 2015, Teleport has shown consistent revenue growth. |
| SU018 | Teleport | Teleport Community Edition License Change | |
| SU019 | Precedence Research | Privileged Access Management Market Report 2025-2034 | |
| SU020 | StrongDM | StrongDM vs Teleport Comparison | Teleport only supports more modern systems that will allow their certificate-based authentication. |
| SU021 | Teleport | 2026 Infrastructure Identity Survey | |
| SU022 | Kleiner Perkins | Gravitational: Pulling Us Toward an Open and Multi-Cloud Future | |
| SU023 | PeerSpot | Teleport Reviews | Teleport changed our workflow by centralizing access control and reducing manual SSH key management. |
| SU024 | Teleport | Teleport Named Citizens Securities 2026 Cyber 66 | recognized in the Cyber 66 report as a revenue category mover, reflecting continued business momentum |
| SU025 | Teleport | Teleport About Page | |
| SU026 | Teleport | Teleport Elasticsearch Integration | |
| SU027 | Teleport | Teleport LLMs.txt — AI Infrastructure Identity Company | trusted by industry-leading organizations including Nasdaq, IBM, Doordash, Elastic, and GoTo |
| SU028 | Fortune Business Insights | Privileged Access Management Market Size and Growth Report | |
| SU029 | Teleport | Turo Streamlines Infrastructure Access with Teleport | |
| SU030 | Teleport | KnowBe4 Case Study | |
| SU031 | Teleport | How TigerGraph Enhances Global Access Control with Teleport | |
| SU032 | Teleport | ECMWF Secure Access to Supercomputing Clusters with Teleport | |
| SU033 | Teleport | RSI Levels Up Cloud Security with Teleport Infrastructure Identity | |
| SU034 | Teleport | Mapgears Boosts Customer Support with Teleport's Secure SSH Access | |
| SU035 | Teleport | Securing Kubernetes Access with thredUP | |
| SU036 | Teleport | Enhance Global Content Delivery with Teleport, Rundeck and Slack APIs | |
| SU037 | Teleport | Secure Biomedical Research Compliance with Flywheel and Teleport Access | |
| SR001 | Teleport | A new commercial license for Teleport Community Edition | |
| SR002 | Teleport | Teleport raises $110M in Series C funding | |
| SR003 | Teleport | Gravitational raises Series A funding | |
| SR004 | Teleport | Teleport raises Series B funding | |
| SR005 | Teleport | About Teleport | |
| SR006 | Teleport Docs | FedRAMP compliance framework | |
| SR007 | Teleport Docs | SOC 2 compliance framework | |
| SR008 | Teleport | FedRAMP compliance use case | |
| SR009 | Teleport | Teleport security audit | |
| SR010 | Teleport | Teleport pricing | |
| SR011 | GitHub | gravitational/teleport | |
| SR012 | Bessemer Venture Partners | Investing in Teleport and the unified access plane | |
| SR013 | Bessemer Venture Partners | State of the Cloud 2024 | |
| SR014 | NIST | Zero Trust Architecture | |
| SR015 | CISA | Zero Trust Maturity Model | |
| SR016 | StrongDM | StrongDM vs Teleport | |
| SR017 | StrongDM | StrongDM homepage | |
| SR018 | CyberArk | What is Privileged Access Management? | |
| SR019 | CyberArk | Privileged Access Manager | |
| SR020 | BeyondTrust | Privileged Access Management (PAM) | |
| SR021 | Okta | Okta Privileged Access | |
| SR022 | HashiCorp | What is Boundary? | |
| SR023 | PeerSpot | Teleport reviews | |
| SR024 | PeerSpot | Teleport alternatives and competitors | |
| SR025 | Slashdot | Teleport alternatives | |
| SR026 | CompaniesMarketCap | CyberArk market cap | |
| SR027 | CompaniesMarketCap | CyberArk revenue | |
| SR028 | CompaniesMarketCap | Okta market cap | |
| SR029 | CompaniesMarketCap | Okta revenue | |
| SR030 | Precedence Research | Privileged Access Management market | |
| SR031 | Open Source Initiative | The Open Source Definition | |
| SR032 | GetLatka | Teleport company profile | |
| SR033 | Teleport | Teleport named to 2026 Fortune Cyber 60 list | |
| SR034 | Teleport | Teleport named to 2026 Cyber 66 | |
| SR035 | Teleport Docs | Agentic Identity Framework | |
| SR036 | Beams | Beams homepage | |
| SR037 | AWS | AWS Systems Manager Session Manager | |
| SR038 | Microsoft | What is Azure Bastion? | |
| SR039 | Google Cloud | Identity-Aware Proxy overview | |
| SR040 | Microsoft | What is Privileged Identity Management? | |
| SR041 | Teleport Docs | Teleport Authorization | |
| SR042 | Teleport Docs | TLS Routing | |
| SR043 | Teleport Docs | Proxy Peering Migration | |
| SV001 | Teleport | Teleport raises $110M in Series C funding | |
| SV002 | Teleport | Teleport raises $30M in Series B funding | |
| SV003 | Teleport | Gravitational raises Series A funding | |
| SV004 | Teleport | About Teleport | |
| SV005 | Teleport | Teleport named to the 2026 Fortune Cyber 60 list | |
| SV006 | Teleport | Teleport named to the 2026 Cyber 66 hottest privately held cybersecurity companies | |
| SV007 | Teleport | A new commercial license for Teleport Community Edition | |
| SV008 | Bessemer Venture Partners | Investing in Teleport and the unified access plane | |
| SV009 | Bessemer Venture Partners | State of the Cloud 2024 | |
| SV010 | GetLatka | Teleport company profile and estimated revenue | |
| SV011 | CompaniesMarketCap | CyberArk market capitalization | |
| SV012 | CompaniesMarketCap | CyberArk revenue history | |
| SV013 | CompaniesMarketCap | Okta market capitalization | |
| SV014 | CompaniesMarketCap | Okta revenue history | |
| SV015 | Precedence Research | Privileged Access Management Market | |
| SV016 | Precedence Research | Zero Trust Security Market | |
| SV017 | Grand View Research via Internet Archive | Zero Trust Security Market Report (archived) | |
| SV018 | Grand View Research via Internet Archive | Privileged Access Management Market Report (archived) | |
| SV019 | Fortune Business Insights | Privileged Access Management Market | |
| SV020 | Securities and Exchange Commission | CyberArk Software Ltd. EDGAR company filings | |
| SV021 | CyberArk | What is Privileged Access Management? | |
| SV022 | CyberArk | CyberArk Privileged Access Manager | |
| SV023 | Okta | Okta Privileged Access | |
| SV024 | Kleiner Perkins | Gravitational: pulling us toward an open and multi-cloud future | |
| SV025 | StrongDM | StrongDM vs Teleport | |
| SV026 | PeerSpot | Teleport alternatives and competitors | |
| SV027 | Slashdot | Teleport alternatives | |
| SV028 | Teleport | Infrastructure Identity Survey 2026 | |
| SV029 | GitHub | gravitational/teleport repository | |
| SV030 | Teleport | Teleport newsroom | |
| SV031 | Beams | Beams | |
| SV032 | HashiCorp | What is Boundary? | |
| SV033 | Teleport | Teleport introduces Agentic Identity Framework | |
| SV034 | Teleport | Beams LLM proxy with delegated identity | |
| SV035 | Teleport | IBM Instana case study | |
| SV036 | Teleport | Carta case study | |
| SV037 | Teleport | GoTo case study | |
| SV038 | Teleport | Exness case study | |
| SV039 | Teleport | Careers at Teleport | |
| SV040 | Teleport | Accelerate FedRAMP compliance | |
| SV041 | Teleport | Automating identity and access for FedRAMP 20x | |
| SV042 | BeyondTrust | BeyondTrust Privileged Remote Access | |
| SV043 | Delinea | Secret Server | |
| SV044 | Grand View Research | Privileged Access Management Market Report | |
| SV045 | Grand View Research | Zero Trust Security Market Report | |
| SV046 | Teleport | Gladly case study | |
| SV047 | Teleport | ExtraHop case study | |
| SV048 | Macrotrends | Okta price to sales ratio | |
| SV049 | Stock Analysis | CyberArk Software revenue | |
| SV050 | Stock Analysis | Okta revenue | |
| SV051 | Stock Analysis | CyberArk Software stock price and overview | |
| SV052 | Stock Analysis | Okta stock price and overview | |
| SV053 | Yahoo Finance | Okta stock price, news, quote and history | |
| SV054 | Nasdaq | OKTA stock page |