Skip to content
Tailscale partner

Tailscale for Business

Tailscale gives your people secure access to the office, the server and each other from anywhere, without an exposed VPN box waiting to be attacked. GravIT is a Tailscale partner: we design it, deploy it, manage it and put the licensing on the same bill as the rest of your IT.

The problem with the old way in

Most remote access still works the way it did fifteen years ago: a VPN appliance on the office internet connection, a port open to the world, and client software staff wrestle with from the kitchen table. That open port is one of the first things attackers scan for (VPN appliances have had a rough few years of serious vulnerabilities), and once someone is through it, a flat network usually lets them see everything.

Tailscale inverts that. Nothing is exposed to the internet at all. Each device (laptop, server, phone) joins a private network by proving who it is, and traffic runs directly between devices, encrypted end to end. Access is per person and per rule: the bookkeeper reaches the finance share, the field techs reach the job system, and neither can wander anywhere else.

Where it earns its keep

  • Hybrid and remote staff. The office server and files, reachable from home or the ute, with the same Microsoft 365 sign-in and MFA they already use.
  • More than one site. Offices, depots and workshops joined into one network without dedicated links or a rack of firewalls to keep in sync.
  • Reaching a private server. A tidy way into a hosted or on-premise server without exposing it to the internet.
  • Third parties, on a leash. An accountant, a software vendor or a contractor gets access to exactly one system, for exactly as long as needed, and switching them off is one click rather than a password change everyone shares the pain of.
  • Retiring an old VPN. The most common job: the appliance is end-of-life, the renewal quote is offensive, and this is the better answer.

What we do, as a partner

  1. 1Design. Who needs to reach what, written down as rules rather than tribal knowledge. This is the step that makes it zero trust.
  2. 2Deploy. Devices enrolled, the server published to the people entitled to it, Microsoft 365 sign-in wired up so MFA and offboarding carry over automatically.
  3. 3Licensing. Supplied by us, on the same bill as the rest of your IT: one supplier, one number to call.
  4. 4Manage. New starters added, leavers removed, rules kept matching reality as the business changes. The part a subscription alone never does.

The honest fit: if nobody works remotely, you have one site and no server, you do not need this, and we will say so. It also is not a fix for a messy network on its own: the access rules are only as good as the thinking behind them, which is why the design step comes first.

What's included

  • Access design: who reaches what
  • Deployment across devices and sites
  • Microsoft 365 single sign-on & MFA
  • Licensing on your GravIT bill
  • Third-party access, tightly scoped
  • Ongoing management and support
FAQ

Frequently asked questions

What is Tailscale, in plain English?

A private network between your devices (the office server, the laptops, the machine at home) that works wherever they are. Each device proves its identity, traffic between them is encrypted end to end, and nothing sits exposed on the open internet waiting to be found. It is the job a VPN was meant to do, without the appliance, the port forwarding or the client software people fight.

Is it a VPN?

It replaces one, and most businesses meet it that way. The difference is architecture: a traditional VPN funnels everyone through one box with an open port on the internet, and once inside you can usually see everything. Tailscale connects device to device, there is no open port, and each person can reach exactly what the rules say they can, which is the “zero trust” everyone keeps hearing about, done simply.

Does our data pass through Tailscale's servers?

Traffic goes directly between your devices wherever the networks allow, encrypted end to end. Tailscale's own service coordinates the keys and identities; where two devices genuinely cannot reach each other directly a relay passes the encrypted traffic along without being able to read it. Either way, nobody in the middle, including Tailscale and including us, can see the contents.

Does it work with our Microsoft 365 sign-in?

Yes, and that is one of the best things about it: staff sign in to the network with the same Microsoft 365 identity they already use, so multi-factor authentication and conditional access apply, and switching someone off in 365 switches them off the network too. One front door, not two.

Do we need to replace our firewall or internet?

No. Tailscale runs alongside what you have, with no appliance to buy and no carrier change. It usually means retiring an ageing VPN appliance rather than installing a new one.

What does GravIT being a Tailscale partner actually mean?

We are in Tailscale's partner program for managed service providers, which means we design, deploy and manage it for clients rather than only recommending it, and we supply the licensing on the same bill as the rest of your IT. You get one local team accountable for the network working, not a subscription and best wishes.

What does it cost?

Licensing is per user alongside your other subscriptions, and setup is quoted to your situation. A two-site business with a server and a dozen remote laptops is a known-size job. Call 03 5280 8088 and we will size it.

Tailscale instead of the old VPN box

Tell us what it is and who uses it. We will tell you straight whether Tailscale is the better answer, and what the switch involves.