The multi-cloud networking field side by side — what each platform leads on, and where Telaron does something different. Several of these are companions to Telaron rather than alternatives to it, and the pages below say so.
| capability | Telaron | Aviatrix | Cisco MCF | Zscaler ZTGW | Cisco MCD | Cilium Mesh | Tailscale | AWS Interconnect |
|---|---|---|---|---|---|---|---|---|
| Encryption & throughput | WireGuard ChaCha20; throughput not yet published | IPSec ESP, ~1.25 Gbps/core | IPsec/ESP; throughput not published | GENEVE, 10 Gbps per gateway | IPSec (NGFW), per-core ceiling | WireGuard / IPSec, eBPF | WireGuard, peer-to-peer | MACsec L2, managed |
| Spoke compute | None in workload VPCs; edge tier in customer-owned central VPCs | Gateway VM per spoke | None — Cisco runs the vPoPs; Meraki MX is the stated entry | None — a gateway endpoint per VPC | Gateway VMs per cloud | DaemonSet on every K8s node | Agent on every device | N/A — managed service |
| Control plane | SaaS (app.dev.telaron.io) | Self-hosted Controller + CoPilot | Cloud Control SaaS, intent-based | SaaS (Zscaler); data plane in their account | Cisco Security Cloud Control | Self-hosted Cilium Operator | SaaS (Tailscale Inc.) or Headscale | AWS Console / API |
| Dynamic routing | iBGP/eBGP via FRR — you own the overlaycoming | Proprietary orchestration | Intent-based; Cisco owns the routing overlay | None — inspection only, not transit | Static / limited BGP | Limited BGP + eBPF L3/L4 | None — endpoint mesh | Automated BGP, limited control |
| Kubernetes required | No | No | No | No | No | Yes — mandatory | No | No |
| Open source | Gateway data plane (Apache 2.0), Terraform provider (MPL 2.0) | No | No | No | No | Yes (Apache 2.0) | Client BSD, Headscale community | API spec (Apache 2.0) |
| Data sovereignty | Config metadata only | Controller processes routing metadata | Routing overlay operated by Cisco | Traffic transits Zscaler’s tenancy | SaaS controller in Cisco cloud | Self-hosted only | Coordination server SaaS | Traffic on CSP backbones |
| Pricing model | Per-gateway tiered; Community free | $100k–$500k+/yr typical | Consumption-based; pricing not published | Per-GB metered, plus per-gateway | Gateway-hours subscription | ~$300k/yr (Isovalent); OSS free | $6–$18/user/month | Flat hourly by bandwidth |
ordered by closeness to Telaron · comparison reflects publicly documented capabilities at time of writing · scroll horizontally for the full matrix
The mature incumbent — deep feature surface, enterprise operating model.
See the comparisonCisco-operated NaaS — managed simplicity, Cisco-controlled routing.
See the comparisonInspection as a service — on a fabric you still build and run.
See the comparisonNGFW-centric multi-cloud security gateways.
See the comparisonPowerful eBPF networking — if you live in Kubernetes.
See the comparisonEffortless WireGuard mesh — for devices and users.
See the comparisonA managed underlay circuit — that Telaron runs on top of.
See the comparisonOne secure fabric across every cloud — identity-aware policy, encrypted end to end, and no agents in your workloads. Start on the free Community tier; no sales call to get going.