
What happened
Tailscale built Aperture by Tailscale, its model router, on Vercel AI Gateway and Vercel Sandbox, and moved from prototype to paying customers in months, says product lead Remy Guercio.
Why it matters
Instead of handing out provider API keys, Aperture grants and revokes model access through the tailnet itself, and AI Gateway returns cost and usage on every request without Tailscale maintaining price tables.
What to watch
The outcome hinges on Aperture's new 'time to first app' goal, where David Carney wants signup, a prompt, an app and sharing in ten minutes or less, and the team says it will have to iterate quickly.
WHO IT HITSThis lands on engineering and platform teams at companies that want to give employees and agents access to many AI models without managing one cloud provider account per model.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
Tailscale already connects a company's laptops, servers, cloud instances and personal devices into one private network called a tailnet. Aperture takes that same idea and applies it to AI, so companies control model access through the network rather than issuing every employee, agent or tool a separate provider API key.
The build-versus-buy decision is the backdrop here. Tailscale is an infrastructure company, so building the routing and execution layers in-house was the obvious first option, but Remy Guercio says the provider layer looked deceptively simple and was not. Tailscale even shopped the routing layer and the sandbox layer, and it had a working implementation on a different sandbox provider before switching to Vercel — so the choice of AI Gateway and Sandbox reads as a deliberate comparison rather than a default.
Agents then raised the stakes, because an agent that can read private data, act on it and reach the public internet is a security problem now called the 'lethal trifecta.' Aperture's answer is a workflow where a sandbox spins up, Aperture connects to AI Gateway, Tailscale validates identity, the agent works, the sandbox shuts down, and no key is ever issued to the agent. The next test appears to be whether Aperture can hit its stated 'time to first app' goal, which is the outcome the team itself says it must iterate toward.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Much of the attention on AI infrastructure buildouts is now tied to sheer compute power, with dominance define…

Barron's reported September 10 that Kepler Computing emerged from stealth with a memory architecture using fer…

Dynatrace acquired Arize AI, adding AI observability, evaluation and agent monitoring to its application obser…
Reuters reported September 10 that inference-chip startup d-Matrix will use Nvidia's NVLink Fusion to connect…

A Daily Dose of Data Science test kept LoRA adapters separate from a shared 7B base model, cutting 100 fine-tu…

A report by Spencer Kitts, Thomas Larsen and Sydney Von Arx says an OpenAI agent swarm very likely ran an atta…
