Domains, DNS, business email, hosting, storage, and applied AI in one console — daily operations with per-organization isolation. Multi-region expansion as new nuclei come online.
Ilustração do console — não são dados ao vivo
Infrastructure, platform, and product teams manage domains, DNS zones, corporate mailboxes, deployments, files, and AI quotas in one corporate environment — centralized identity, policy, and billing.
Each organization has its own tenant, quotas, and billing, with data segregated in the API. Admins and engineers provision resources in the console — without tickets for routine operational tasks.
TLS via Let's Encrypt on managed domains, logical per-organization isolation, bcrypt (cost 12) password hashing, rotated refresh tokens, lockout after failed attempts, and server-side logging of authentication and selected sensitive actions.
Domains, DNS, email, projects, hosting, AI consumption, and billing are administered in the console. Plan changes, limits, and cancellation follow the same flow — operational autonomy, not dependency on a sales queue.
From DNS zones to AI models in production: a coherent stack with governance where scale demands it and flexibility where engineering needs it — built for corporate environments and critical workloads.
Bring any domain, manage A, AAAA, CNAME, MX, TXT, SRV, and CAA records through a visual zone editor or our API. Automatic ownership verification, BIND zonefile export, no provider lock-in.
Mailboxes and aliases on your own domain with strong password hashing, configurable forwarding, multi-destination aliases, and per-mailbox quotas. A real email server — not a forwarding hack.
Upload your application, edit files inline, version your work, and keep everything sandboxed per project. Drag-and-drop UI, live quota usage, and S3-compatible API for programmatic access.
Configurable replicas per resource, load balancing across replicas, and periodic health checks. Multi-zone when two or more zones are active; multi-region on the roadmap.
Domain-tuned assistants integrated into the workspace. Predictable monthly token quota, transparent overage at the line-item level, and usage tracked per organization. Dedicated model deployments available on Enterprise.
Logical per-organization isolation, TLS via Let's Encrypt, rate limiting per API key and per origin, configured CSP and HSTS headers, and server-side logging of selected sensitive events.

Orchestration and automation layer on compute nuclei. Each organization has its own tenant, billing, and segregated data. Production today runs on zone br-sp-1 (São Paulo); other regions on the landing page are planned expansions.
Active nucleus in São Paulo (BR). UK, EU, US, and APAC regions are listed as future expansion — no production traffic runs there until we provision new nuclei.
When two or more zones are active in the same region, replicas can be spread across them. Multi-region requires nuclei on different continents (roadmap).
Login, authentication failures, and selected sensitive actions are recorded with timestamp, user, IP, and detail on the server (auth_eventos table).
Production today in São Paulo (br-sp-1). The United Kingdom, Germany, United States, and India on the map are on-demand regions, not operational clusters yet.
br-sp-1· São PauloActiveuk-west-1· WolverhamptonPlannedeu-north-1· HamburgPlannedus-east-1· New YorkPlannedus-central-1· DallasPlannedap-south-1· MumbaiPlannedStart with what you need today, scale to your largest deployment tomorrow. Volume discounts and committed-use contracts available for Enterprise.
Para builders independentes lançando seus primeiros produtos na Tesserra.
Times iniciando desenvolvimento assistido por IA e deploys automatizados.
Produtos em crescimento com suporte prioritário e quotas maiores.
Organizações que precisam de SSO, SLA e controles avançados.
We work with regulated industries, multinationals, and high-throughput AI products. Talk to our team about dedicated capacity, on-prem connectivity, bespoke compliance reviews, and committed-use pricing.

Tesserra is operated by a remote-first team headquartered in São Paulo, Brazil. Founded in 2022 to deliver an enterprise infrastructure layer — domains, DNS, business email, hosting, storage, and applied AI — in a fully self-managed console with unified identity and billing per organization.
Customer support is delivered directly by the engineering team. When you escalate a ticket, you reach the people who built the system — not a script or an outsourced queue.
Engineering, infrastructure, and product in one loop — the same people who design also operate and support what customers run in production.

Core services, multi-tenant isolation, and APIs for domains, DNS, provisioning, and per-organization billing.

Multi-region nuclei, capacity planning, observability, and the operational posture of production workloads.

Console, onboarding for new organizations, and direct support from the people who built the system — no outsourced queue.
Our office sits in the corporate corridor of Avenida Paulista, in the Bela Vista district. The avenue concentrates a large share of the country's financial, technology, and consulting headquarters, and is well served by metro and major bus lines.
Visits are by appointment only. The engineering team operates remote-first, but the address is open for customer meetings, vendor reviews, and on-site contract signing.


Why work at Tesserra
We are a self-managed cloud platform built by people who run real production. You ship features enterprise customers use the same day — DNS, provisioning, billing, webmail — with technical autonomy and world-class documentation.
Work from where you perform best, with Paulista hub meetups when it matters.
Small teams, fast decisions, and direct contact with people using the product.
FastAPI, Next.js, Docker, Ollama, Stripe — all in production, not on slides.
Budget for certifications, conferences, and protected learning time.
We hire engineers and operators who want depth — production systems, clear ownership, and direct contact with customers. Remote-first, with a corporate hub in São Paulo for in-person collaboration when it matters.
View open rolesTesserra was founded in 2022 so mid-size and large organizations can run domains, DNS, business email, hosting, storage, and AI workloads in a fully self-managed environment — without a fragmented vendor catalog or ad hoc integrations.
Each customer organization has its own tenant and invoice, with logically segregated data in the API. Payment via Stripe in BRL, USD, or EUR, with PDF invoice export.
Every plan includes a monthly token quota. Overage tokens are billed at a small per-thousand rate on the next invoice, with a per-line-item breakdown. Real-time usage is visible in the dashboard at all times, and you can set hard caps to prevent overage entirely.
No. You can sign up first, explore the platform, and add one or more domains whenever you want — within your plan limits, at no extra cost. Bring an existing domain or transfer one to us; we handle DNS, TLS, and email setup automatically.
Yes. You create mailboxes on @yourdomain directly from the dashboard, set quotas, configure forwarding, and manage aliases. Email is included in plan limits — no separate invoice from a third-party email vendor.
Periodic health checks and auto-restart when compute stops. The Health console shows real state (up / down). Detailed SLA and throughput metrics arrive with Prometheus/Insight. Contractual SLAs are negotiated on Enterprise plans.
On request, on Enterprise plans. Talk to our team — we don't publish standard SLAs or pricing for these scenarios.
For security review and DPA, contact our team. Documentable technical controls today: TLS (Let's Encrypt) on managed domains, logical per-organization isolation, bcrypt (cost 12) password hashing, rotated refresh tokens, lockout after failures, CSP/HSTS headers, and server-side logging of authentication and selected sensitive actions. Formal audits (SOC 2, ISO 27001) have not yet been completed.
On Enterprise plans, dedicated GPU capacity can be negotiated. Self-serve plans use a shared pool with a monthly token quota.
Yes. There's no long-term commitment on self-serve plans. Cancel from the customer portal — your access continues through the end of the paid cycle. Enterprise contracts have committed terms negotiated upfront.
Each organization has data segregated by tenant_id in the API, files in a per-project directory, short-lived access tokens with rotated refresh and lockout, and strict security headers in the console. Login and selected sensitive actions are logged on the server.
Production data today lives on the br-sp-1 nucleus (São Paulo). Other regions on the map are planned — contact sales for residency requirements. You are the data controller; Tessera acts as processor (LGPD/GDPR).
Via Stripe in BRL, USD, or EUR (credit card or ACH/SEPA). We issue an invoice and PDF every cycle. Payment methods, plan changes, and cancellation are self-service in the dashboard. Enterprise customers can pay via PO and bank transfer.
Access the console, evaluate the platform at your pace, and scale to enterprise contracts with dedicated regions, custom SLAs, and compliance reviews when operations require it.