Tessera

You can't defend what you can't see.

Tessera shows you every application installed across your fleet, classified by AI, with policy-driven removal of what shouldn't be there.

Demo video coming soon

How it works

Three jobs, one agent.

01 / DISCOVER
See every application on every endpoint

A lightweight agent enumerates installed software from every available source — registry, package managers, AppX, install paths. Inventory is deduplicated, normalized, and continuously updated.

02 / CLASSIFY
Categorize the long tail automatically

Every application is classified across 16 categories — Security, Productivity, Driver, Risk, and more — by an LLM that understands naming patterns no static rule set can keep up with. New apps get categorized within minutes of first appearing on a fleet.

03 / ENFORCE
Remove what doesn't belong

Define allow lists, block lists, and category-based rules. Tessera removes flagged software using the right uninstall path for each platform — silently, with full audit trail. Approval workflows available for higher-stakes actions.

Why Tessera

Built for the gap between inventory and control.

Pricing

Tiers that scale with you.

Community
Free

Self-hosted. Up to 5 endpoints.

  • Self-hosted via Docker
  • Bring your own LLM
  • 30-day audit retention
  • Community support
Starter EARLY ACCESS
$6 / endpoint / month

For small IT and security teams. Up to 100 endpoints.

  • Hosted by us
  • Managed LLM included (1,000 classifications/month)
  • 6-month audit retention
  • Email support
Enterprise
Custom

1,000+ endpoints. Compliance-driven deployments.

  • Single-tenant deployment, BYO-LLM, or in-VPC
  • Custom retention, MSA, DPA, BAA
  • Dedicated support
  • SLA with credits

Ready to see what's actually installed?

We're working with a small group of teams to refine Tessera. Tell us about your environment and we'll be in touch within a few days.

Request access