Tessera DB
PX-01
Licensing
One binary, every tier.
You run Tessera on your own hardware. Community is free and needs no key; a signed, time-limited licence key unlocks Enterprise for the term you buy, on the same binary. Nothing phones home.
What it costs.
Community
Apache 2.0 core
Free
no licence key
The full five-dimension engine with every core capability. Build, experiment and deploy with no licence key.
Apache 2.0 open-source core
Five dimensions in one engine
Cypher, TQL and SQL
EXPLAIN and query plans
HNSW vector search and BM25 full-text
Hybrid retrieval (RRF fusion)
Hyperedges and BLAKE3 content-addressed storage
Bitemporal time-travel and Git-style branching
ACID transactions
Bulk import and streaming COPY
Materialized views, triggers, stored procedures
Time-series operations
Authentication and RBAC (four roles)
REST/OpenAPI, PostgreSQL wire, JDBC, SDKs
Admin dashboard, CLI/REPL, observability
Community support (GitHub Discussions)
Enterprise
Licence key
$18,000
per node / year
or $10,900 per node for a 6-month key
The full feature set, unlocked by a time-limited licence key on the same binary. It runs on your own hardware — no hosting, and no data leaving your walls.
Everything in Community
Time-limited licence key — 6 or 12 months
Volume discounts for additional nodes
Falls back to Community when it lapses — nothing breaks
60+ graph algorithms (Graph Data Science)
In-database ML — node classification, GNN, link prediction, GAN, online learning
GraphRAG retrieval depth
8-layer AutoGuard AI-security stack
Anomaly scoring and injection detection
Red-team simulation
Tamper-evident, hash-chained audit log
Data lineage and provenance
OIDC and SAML 2.0 single sign-on
Encryption at rest (AES-256-GCM)
Backup, restore and point-in-time recovery
Monitoring and alerts
Premium connectors (PostgreSQL, REST)
Synthetic-data templates
Multi-node building blocks (Raft consensus)
Priority support (24-hour SLA)
Enterprise Plus
Banking and compliance
Custom
to your term and node count
The fraud, AML and compliance pack, with deployment support and a dedicated architect, for banking and mission-critical workloads.
Everything in Enterprise
Fraud-cycle detection and fraud-pattern engine
AML alerts (structuring, velocity, mule typologies)
Sanctions screening against the lists you provide
Regulatory classification (FIBO + BIAN)
Dedicated solutions architect
Custom SLA (4-hour response)
On-premise deployment support
Training and onboarding
Only production nodes are licensed; development and staging instances are free. A full-featured, time-boxed evaluation key is available before you buy, with no credit card. When a key lapses the binary falls back to Community — it keeps running, the data stays where it is, and only the Enterprise features lock.
Talk about a licence ↗
Four ways to run it.
OSS source
The foundational engine, Apache 2.0 on GitHub. Free to read, fork and compile yourself.
Community
A free downloadable binary for a single node: the full core engine and the admin UI.
Enterprise
The same binary with a licence key, unlocking graph data science, ML, AutoGuard, SSO and governance.
Enterprise Plus
Everything in Enterprise, plus the banking pack — BIAN, FIBO, fraud patterns, AML and sanctions screening.
Core engine
Feature | OSS source | Community | Enterprise | Enterprise Plus |
|---|---|---|---|---|
Hyperedge data model | Yes | Yes | Yes | Yes |
TQL parser | Yes | Yes | Yes | Yes |
Cypher parser and executor | Yes | Yes | Yes | Yes |
SQL parser | Yes | Yes | Yes | Yes |
60+ graph algorithms | — | — | Yes | Yes |
HNSW vector search | Yes | Yes | Yes | Yes |
BM25 full-text search | Yes | Yes | Yes | Yes |
B-tree range indexes | Yes | Yes | Yes | Yes |
Content-addressed storage (BLAKE3) | Yes | Yes | Yes | Yes |
Integrated engine, WAL and MVCC | — | Yes | Yes | Yes |
Bitemporal storage and queries | — | Yes | Yes | Yes |
Git-style branching | — | Yes | Yes | Yes |
ACID transactions | — | Yes | Yes | Yes |
CLI REPL and admin UI | — | Yes | Yes | Yes |
AI and security
Feature | OSS source | Community | Enterprise | Enterprise Plus |
|---|---|---|---|---|
8-layer AutoGuard defence | — | — | Yes | Yes |
AutoGuard compliance monitoring | — | — | Yes | Yes |
Injection detection (query firewall) | — | — | Yes | Yes |
Red-team simulation suite | — | — | Yes | Yes |
Anomaly scoring | — | — | Yes | Yes |
In-database ML (GNN, GAN, link prediction) | — | — | Yes | Yes |
GraphRAG retrieval (vector + text + graph fusion) | — | — | Yes | Yes |
Tamper-evident BLAKE3 audit chain | — | — | Yes | Yes |
Monitoring and alerts | — | — | Yes | Yes |
Compliance and governance
Feature | OSS source | Community | Enterprise | Enterprise Plus |
|---|---|---|---|---|
Encryption at rest (AES-256-GCM) | — | — | Yes | Yes |
Data lineage | — | — | Yes | Yes |
Synthetic data generator | — | — | Yes | Yes |
Regulatory classification (FIBO + BIAN) | — | — | — | Yes |
Fraud-pattern engine (structuring, velocity, mule) | — | — | — | Yes |
Sanctions screening (against lists you provide) | — | — | — | Yes |
AML alerts | — | — | — | Yes |
Infrastructure
Feature | OSS source | Community | Enterprise | Enterprise Plus |
|---|---|---|---|---|
Single-node deployment | — | Yes | Yes | Yes |
Multi-node building blocks (Raft consensus) | — | — | Yes | Yes |
API key and RBAC authentication | — | Yes | Yes | Yes |
OIDC and SAML 2.0 SSO | — | — | Yes | Yes |
PostgreSQL and REST connectors | — | — | Yes | Yes |
MySQL, MongoDB, S3 and Kafka connectors (roadmap) | — | — | — | — |
On-premise deployment support | — | — | — | Yes |
Backup, restore and point-in-time recovery | — | — | Yes | Yes |
Production observability and SLO monitoring | — | — | — | Partial |
Support and delivery
Feature | OSS source | Community | Enterprise | Enterprise Plus |
|---|---|---|---|---|
Source code (Apache 2.0, GitHub) | Yes | — | — | — |
Downloadable binary | — | Yes | Yes | Yes |
Community support (GitHub issues) | Yes | Yes | Yes | Yes |
Priority support (24-hour SLA) | — | — | Yes | Yes |
Dedicated solutions architect | — | — | — | Yes |
Custom SLA (4-hour response) | — | — | — | Yes |
Training and onboarding | — | — | — | Yes |
Yes: included at that tier. Partial: under way at that tier but not complete. Roadmap items are not shipped at any tier.
Questions we actually get.
How does licensing work?
You run the single Tessera binary on your own hardware. Community is free, needs no key and does not expire. For Enterprise you buy a term of 6 or 12 months and receive a signed, time-limited key; enter it and the Enterprise features unlock for that period. The binary starts in seconds, backing up one data folder preserves the whole database, and nothing phones home.
What happens when my licence key expires?
It fails closed. The binary falls back to Community: it keeps running, your data stays where it is, and only the Enterprise features lock until you enter a new key. A missing, expired, malformed or wrongly signed key never unlocks anything, never breaks the database and never loses data.
Can I buy 6 or 12 months?
Both. A 12-month Enterprise key is $18,000 per node; a 6-month key is $10,900 per node. Buy the term that fits the project and renew when you like. Enterprise Plus is priced to your term and node count — talk to us.
What counts as a node, and are there volume discounts?
Each running instance of the Tessera server is one node. Only production nodes are licensed; development and staging instances are free. Volume discounts apply if you run several — ask for a quote.
Is there a trial before I buy?
Yes. We issue a full-featured, time-boxed evaluation key, so you can run the whole Enterprise feature set on your own hardware before committing — no credit card and no hosting to set up.
What tiers are available?
Three, all from one binary. Community (free) has the five-dimension engine, all three query languages, hybrid retrieval, ACID transactions, branching, bitemporal time-travel, bulk import, the admin dashboard, SDKs and observability. Enterprise adds the 60+ graph algorithms, in-database ML, AutoGuard, lineage, OIDC and SAML single sign-on, encryption at rest, backup with point-in-time recovery, and monitoring. Enterprise Plus adds the fraud, AML, sanctions-screening and regulatory-classification pack.
Can Tessera run on-premise or air-gapped?
That is the only way it runs; there is no cloud service to depend on. Tessera is a single self-contained binary — no JVM, no separate install — that starts in seconds and runs entirely on your hardware with no call-home, so regulated data stays where it has to. Enterprise Plus adds deployment support for those environments.
What is Tessera DB?
A multi-model database built for AI workloads. It stores your data once and lets you query it five ways — by connections (graph), by meaning (vector), by keywords (full-text), by tables (SQL) and over time (time-series) — and can fuse them in one query. It adds in-database machine learning, bitemporal time-travel, Git-style branching, data lineage and a tamper-evident audit trail, and ships as one binary that runs on your own hardware.
What does “five dimensions” mean?
Relational, graph, vector, full-text and time-series: five ways of indexing and querying the same copy of your data. Instead of moving data between a graph database, a vector store, a search engine, a SQL store and a time-series database, Tessera indexes it all five ways at once, and a single query can combine whichever dimensions the question needs.
What can Tessera replace?
For an AI or fraud application: a separate graph database, vector database, search engine, SQL store and time-series database, and the ETL that keeps them in sync. It also adds in-database ML, data lineage and a tamper-evident audit log, which those products do not provide.
Is Tessera open source?
The foundational engine is open source under Apache 2.0, which permits commercial use, modification and distribution with no copyleft obligations, and there is a free Community binary. Enterprise and Enterprise Plus features are unlocked by a signed licence key on the same binary; there is no separate build per tier.
What query languages does Tessera support?
Three, over one dataset: Cypher for graph pattern matching; TQL, Tessera's native language, built around its hyperedge model; and SQL for tables, joins, aggregation and the BI tools you already use. Mix them freely — Cypher for a traversal, SQL for a report, TQL for a temporal question. Cypher support covers the common, widely used subset, so check any advanced or unusual Cypher features before migrating.
How does Tessera compare to Neo4j?
Neo4j is a mature, graph-only database with the biggest ecosystem and proven large-scale clustering. Tessera is younger and multi-model — graph, vector, full-text, SQL and in-database ML in one binary — aimed at AI retrieval and at fraud and compliance work. Neo4j is clearly ahead on clustering, high availability and replication, on ecosystem, on maturity and tooling, and on very large graphs. Tessera is ahead on consolidating several systems into one, on in-database ML including graph neural networks, and on native bitemporal history, branching and lineage. Many teams use both.
What is AutoGuard?
An eight-layer AI-security stack (Enterprise) that runs inside the database, so protection travels with the data rather than living in a bolt-on gateway: injection detection that can block in real time, behavioural anomaly scoring against each account's own normal, canary records that reveal probing, adaptive defences that tighten as suspicious activity rises, behavioural biometrics, automatic security-posture escalation, meta-detection of attempts to probe the detectors, and an ensemble layer that acts on the combined signal. Every action is written to the tamper-evident audit log.
How is this better than a vector-only RAG stack?
Vector-only RAG matches by similarity alone, with no relationships, no exact-term precision and no record of which facts an answer used. Tessera fuses graph relationships, semantic similarity and keyword retrieval in one query, and every retrieved fact can be traced to its source through lineage, so the system can show its working.
How does Tessera help with audit and compliance?
The hash-chained audit log makes any change to a past entry detectable on verification; bitemporal time-travel reconstructs both reality and what the database knew at any past moment; lineage traces every fact to its origin; and role-based access control is enforced on every request before the handler runs. Enterprise Plus adds AML typology alerts, sanctions screening against the lists you provide, and regulatory classification against FIBO and BIAN.
Does Tessera screen against sanctions lists?
It provides the screening engine (Enterprise Plus) — name normalisation, alias checks and fuzzy matching, returning matches with confidence scores and a blocking signal — and you load the lists you are required to screen against. There is no built-in list fetcher and no bundled government data.
Is my data encrypted at rest?
It can be (Enterprise): optional, layer-by-layer AES-256-GCM, which gives both confidentiality and tamper detection, across the audit log and storage layers under one key. The reader detects encrypted and plaintext data, so it can be switched on without a migration, and a stolen disk or leaked backup yields only ciphertext.
What is a hyperedge?
A relationship that connects any number of entities, each in a named role, rather than just two. ‘Bank paid Vendor via Account’ — or five accounts in one transaction — is one hyperedge, not an invented middle node, so real-world facts are modelled as they are.
What is content addressing?
Every fact is identified by a BLAKE3 hash of its own content. Identical data always gets the same identity, so deduplication, integrity checks and lineage follow, and there are no auto-increment IDs to manage.
What is bitemporal data?
Every fact carries two times. Valid time is when it was true in the real world; transaction time is when the database learned it. Together they answer both ‘what was true on 1 March?’ and ‘what did the database believe at that moment?’ — the basis of audit, forensics and reconstructing any past state.
Does Tessera support machine learning?
Yes, in-database and in the Enterprise tier, trained where the data already lives with no export pipeline: node classification (a linear baseline and a message-passing graph neural network), link prediction, GAN synthetic data, online learning, standard evaluation metrics and a versioned model catalogue that survives restarts. Predictions are backed by lineage and the audit chain. Accuracy depends on your data; meaningful results need real, sufficiently large datasets.
Does Tessera support ACID transactions?
Yes. Group writes so they all succeed or all fail, with isolation up to serializable. Conflicting transactions are detected and rejected, so the data stays consistent.
How does branching work?
Fork the whole dataset the way Git forks code, change it in isolation, and query either branch without changes leaking across — for what-if analysis, an isolated investigation, a staged bulk change or a pipeline test, all without touching production data.
Can I use my existing Postgres and BI tools?
Yes. Tessera speaks the PostgreSQL wire protocol, so psql, Postgres drivers and tools such as Tableau, Metabase, DBeaver and Grafana connect and run SQL against it as if it were Postgres. There is also a pure-Java JDBC driver and official Python, Rust and TypeScript SDKs.
Does Tessera scale across many nodes for high availability?
It is strongest on a single well-provisioned node, and ships building blocks for multi-node operation, including a Raft consensus module for leader election and log replication. For proven, large-scale clustered HA and failover today, a mature system such as Neo4j is further ahead — and we would rather say so.
