·12 min read·ai-operations · ai-vendor-selection · ai-governance

Ask where your prompts are stored before you buy a gateway

A Tailscale talk says keep AI models, tools, chat and sandbox swappable. Its gateway's Terms say where prompts are hosted. Three owner steps. Not tested by us.

Contents

We suggest three things. Know what you spend on AI, tool by tool. Keep your work in formats that outlive any one model. And if someone pitches you an AI gateway, ask where your prompts and the AI's answers are stored. We are not telling you to install a gateway, and we did not test one. The three steps come from reading a July 2026 conference talk about keeping AI choices open, given by an employee of Tailscale (the company that makes one such gateway), next to Tailscale's own documents and one outside survey.

This is research from public sources, not legal or security advice. We re-read every source below on October 11, 2026, Central time.

#What the talk argued

On July 2, 2026, at the AI Engineer World's Fair in San Francisco, Remy Guercio gave a talk called "An AI Future Without the Lock-In". The conference schedule lists him under Tailscale, as "Strategic Projects". In the talk he says he works on Tailscale's AI gateway, which is called Aperture. So he is describing his employer's product.

His argument has four parts. An AI setup inside a company has four pieces: the model, the data connectors (the tools the AI reads from, often through MCP, a common way for an AI tool to plug into outside data), the chat interface, and the sandbox where an agent runs. His slide lists them as "LLM(s)", "Data Connectors (MCP)", "Interface" and "Sandboxes / Environment". A closing slide reads "ROImaxxing = maximizing choice to prevent lock-in". The idea is to keep a choice open at each piece, with one gateway in the middle that knows who is asking, holds the vendor keys and logs what gets used.

His warning is about what companies do after the first big bill. He says they usually arrive wanting to consolidate on a single vendor, maybe two, and he calls that "maybe not a great idea". A slide reads "After hundreds of conversations" next to a red X and "Consolidating on a single vendor." That is his experience, not a measured share. We read the captions and looked at that slide, and neither gives a count of how many companies wanted to consolidate.

He also says the idea does not depend on his product: "even if you don't use Aperture I do highly recommend you start considering an AI gateway".

#What Tailscale's documents say the gateway does

We have not tested Aperture. Here is what Tailscale's documentation says, as read on October 11, 2026.

  • Who is asking. Aperture asks Tailscale who is on each connection. The docs say this identity "comes from Tailscale's control plane, not from the client".
  • Where the keys sit. The overview page says "API keys stay in the server configuration, never on developer devices." It adds an exception: "With passthrough mode, clients can send their own provider credentials."
  • Budgets. "Admins set user and team spending limits in the Aperture configuration" (Manage AI spending). The dollar amounts are estimates: "Aperture estimates the dollar cost of each LLM request." (Provider configuration)
  • Logs. The captured data includes the "full request and response body". An admin can set how long bodies are kept, or "enable zero data retention so bodies are never written to disk" (Privacy and data retention). Tailscale's configuration page says the default retention is one year. The page adds that this holds unless a gateway is configured otherwise, and that a longer value an admin sets does not extend retention.

#One number from the talk: a spend dashboard

One slide shows a count. An Aperture usage screen, filtered to the last 30 days, shows 14 active users, 11,808,327,928 total tokens and an estimated cost of $13,247.20. The slide does not say whose gateway it is. It measures spend, not lock-in, and the cost is an estimate: the slide labels it "estimated", and the docs above say Aperture estimates the dollar cost of each request. It does show what a gateway can count.

#What the Terms and docs say that the talk does not cover

The talk was given on July 2, 2026. Tailscale's Aperture Terms took effect on August 25, 2026.

Switching models works when the formats match. In the talk: "Again, doesn't matter if you're trying to switch models or providers, you can do that." Tailscale's supported providers and clients page says "The client, provider, and selected model must support the same API format." The overview page says "Changing the model name does not make incompatible APIs work together." In plain terms, a swap works when the tool and the new model speak the same request format.

Leaving may take more than one setting. To send Claude Code through Aperture, the setup page says to set ANTHROPIC_BASE_URL to your Aperture URL. Our reading, which we did not test, is that for the model call, leaving means pointing the tool back at the provider, and each person would then need their own provider key, because by default the keys sit in the gateway. By the same reading, connector logins, budget balances and the recorded history live in the gateway. For connectors with per-user sign-in, the docs say the tokens "are managed by Aperture, not the user's local tools", and "Aperture persists quota bucket balances." Tailscale's docs describe exporting usage data to S3 ("Export captured usage data to S3-compatible storage for long-term retention and archiving."), but no page we read describes a full leaving procedure.

The Terms say Tailscale hosts what the gateway records. The Aperture Terms say Aperture can "log, host, access, and modify content", specifically "model or inference endpoint session histories and API requests and responses". They add: "By default, Customer AI Content includes headers and message bodies of prompts and model outputs, and Customer AI Content is hosted by Tailscale." They say you "direct Tailscale to send your Customer AI Content to the relevant Third Party Service provider", and that "Customer AI Content constitutes your Confidential Information under the Agreement." The zero-retention page calls the product "your managed Aperture service". Our reading is that Tailscale runs the gateway. No page we read says that in so many words. The same page describes a zero-retention mode in which "Aperture never writes prompt and response content to disk", while token counts, estimated cost, model and identity are still recorded.

Support and audits are not promised by default. The Terms say "Unless expressly agreed in writing, Tailscale is not responsible for any technical or customer support for Aperture, and our SLA (if and as applicable to you) does not apply to Aperture." They also say "Aperture is not yet included within the scope of third-party security assessments, audit reports, or compliance certifications applicable to Tailscale's generally available services." And unless Tailscale agrees in writing, the Terms bar uses that involve "payment card data or bank account numbers" or "protected health information regulated by HIPAA".

Who it is written for, and what it costs. Tailscale's general availability post, dated August 26, 2026, says Aperture has grown into a gateway "with countless visibility and control features for enterprises", and that with this announcement Tailscale wants an "it just works" experience for "individuals and homelab enthusiasts". The post does not say whether Aperture is meant for a business your size, so ask the vendor in writing. On cost, the Terms say "Fees for Aperture, usage limits, and usage based components are described in the applicable Order Form, pricing page, rate card, or other Documentation." The get started page says "To use your own API keys with Aperture on a plan other than the personal Tailscale plan, contact sales." We looked for a published business price on Tailscale's pricing page, the get started page, the token purchase page, the general availability post and the Terms, and found none. The token page says "Each user starts with $1 in tokens" and sets purchase limits ($10 minimum, $25 maximum), not a plan price.

#What an outside survey adds, and who published it

Zapier sells workflow software that its own page calls "AI model-neutral". The same page says "Zapier is specifically designed to help companies reduce reliance on a single AI vendor." Read the numbers with that stake in mind.

The page gives two sample sizes. Its introduction says "We polled 500 U.S. enterprise executives about AI vendor lock-in". Its methodology note says the survey was "conducted via Centiment between Jan. 30 and Feb. 6, 2026" and "Results are based on 542 U.S. C-level executives and decision-makers at organizations that currently pay for one or more AI-related vendors." It adds "The targeted margin of error is approximately ±4% at a 95% confidence level." The report is dated April 1, 2026.

Two of its figures can be read as one story, but they answer different questions.

  • The first is a what-if. "When we asked enterprise leaders what would happen if their primary AI vendor's services ended tomorrow, only 6% said they could stop using it without interruption."
  • The second is a confidence figure about switching vendors: "nearly 9 in 10 (89%) saying they could do it within four weeks". The page does not print the exact question wording.

Then comes what happened to people who tried. "Two-thirds (66%) have already attempted to migrate between AI platforms. Among those, only 42% report a smooth transition. The remaining 58% say the process either failed outright or required significantly more effort than expected." So the 58% is a share of the 66% who had tried, not of everyone surveyed. The top concerns tied: "Nearly half cite data migration challenges (46%) and overdependence on a single vendor (46%) as primary risks."

These are self-reported answers from enterprise leaders, published by a vendor with a stake. The survey is about dependence on AI vendors in general. It does not test gateways, and the page does not break results out by company size, so we cannot say how a small business would answer.

#What to do this month

These are our suggestions, not findings from the sources. None of them needs a gateway.

  1. Know your spend, tool by tool. Owner: whoever approves software spending. First step this week: list every AI subscription and API account, and write down last month's charge for each from its billing page. The talk's slide shows a gateway counting spend, but a list of bills gets you the first answer.
  2. Keep your work in formats that outlive any one model. Owner: whoever runs your AI tools day to day. First step: pick the three pieces of work that live only inside an AI tool today (saved prompts, custom assistants, chat histories you rely on) and copy each into a plain document you control. In the Zapier survey, data migration tied for the most-cited concern at 46%, and 58% of those who had tried a switch said it failed outright or took significantly more effort than expected.
  3. If you are pitched a gateway, ask in writing before any trial. Owner: whoever signs the contract. These six questions are ours. Five follow topics Tailscale's Terms cover (hosting, confidentiality, support, audits, barred data); the one about leaving does not, and any vendor should be able to answer all six.
    • Where are our prompts and the AI's answers stored, and for how long?
    • Who at the vendor can read them, and does the contract call them our confidential information?
    • What happens to our history, connector logins and budgets if we leave?
    • What support and uptime promise do we get in writing?
    • Has an outside auditor covered this product?
    • Which kinds of data does the contract bar us from sending?

#What we did not check

We did not run Aperture or any gateway, so everything about what it does is the documentation's claim. We did not check whose gateway the dashboard slide shows. We read auto-generated captions, which can mishear, so every quotation from the talk was matched against the caption text, and slide text against frames we viewed. We did not crawl Tailscale's whole documentation site, so "no page we read" means the pages listed under Sources. We did not check Anthropic's or OpenAI's own terms, and we did not look at any other gateway. We also opened Tailscale's docs home, its blog post on a flexible AI stack and its client setup page; none changes these statements.

One independent write-up we read, from Signal Over Noise on August 28, 2026, says: "Tailscale has announced the controls. It has not published evidence of how they hold up under sustained enterprise use, hostile prompts, or a complicated incident response. Test it yourself before you rely on it." Its author also says "I have not run Aperture".

Related field notes: Same task, twice: how to test whether giving your AI assistant more context saves you money shows one way to measure AI spend on your own work.

Start with the bills. You cannot keep options open on spend you cannot see.

#Sources