# Buoyant Enterprise for Linkerd vs Tetrate Service Bridge

| Attribute | Buoyant Enterprise for Linkerd | Tetrate Service Bridge |
|---|---|---|
| **Vioscale score** | 38.8 (42% (low)) | 54.7 (33% (low)) |
| deployment.options | `{"cloud":true,"hybrid":true,"on_prem":true,"self_hosted":true}` | `{"cloud":true,"hybrid":true,"on_prem":true,"self_hosted":true}` |
| description.long | An enterprise service mesh that automatically manages and secures communication between containerized workloads in Kubernetes clusters through zero-configuration mutual TLS, traffic optimization, and observability—without code changes or complex setup. | An enterprise AI gateway platform based on Envoy that manages language model access, cost control, and AI agent governance. Provides unified LLM catalog, automatic model fallback, token brokering, AI guardrails, and MCP gateway capabilities. |
| features.capabilities | `{"proxy":"linkerd2","fips_mode":true,"data_plane":"sidecar","vm_support":true,"multicluster":true,"cncf_maturity":"graduated","automatic_mtls":true,"fault_injection":true,"traffic_splitting":true,"commercial_support":true,"gateway_api_support":true,"built_in_observability":true}` | `{"proxy":"envoy","fips_mode":true,"vm_support":true,"multicluster":true,"automatic_mtls":true,"commercial_support":true,"gateway_api_support":true,"built_in_observability":true}` |
| integrations.count | 3 | 12 |
| integrations.list | `[{"name":"Datadog"},{"name":"Microsoft Teams"},{"name":"PagerDuty"},{"name":"Prometheus"},{"name":"OpenTelemetry"}]` | `[{"name":"AWS"},{"name":"AWS CloudMap"},{"name":"AWS AppMesh"},{"name":"Amazon EKS Distro"},{"name":"Amazon ECS Anywhere"},{"name":"Amazon EKS Anywhere"},{"name":"Istio"},{"name":"Envoy"},{"name":"Kubernetes Gateway API"},{"name":"NGINX"},{"name":"LDAP"},{"name":"SSO"}]` |
| market.availability | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | - |
| platform.support | `{"cli":true,"web":true}` | `{"linux":true}` |
| pricing | `{"type":"quote","plans":[{"free":true,"name":"Open source","features":["Zero-config encryption and authentication of all meshed traffic","Cryptographic workload identities, not IP addresses","Secure-by-default Rust data plane","Zero-trust granular authorization policies","Latency-based load balancing","Timeouts and retries","Circuit breaking","gRPC load balancing","Blue-green / canary deploys","L7-aware request routing","Transparent multi-cluster communication","Federated services","Uniform L7 metrics including success rates and latency distributions","Easy export to any Prometheus-compatible metrics store","Distributed tracing (OpenTelemetry)","Egress metrics","Gateway API support","Mutual TLS (mTLS) with TLS 1.3","IPv6","Buoyant Linkerd Public Forums"],"contactSales":false},{"free":false,"name":"Premium","features":["Stable release artifacts","Automated installs and upgrades","SLAs on CVE remediation","Mutual TLS and basic service mesh featureset","Multi-cluster communication","L7 network security policies","Automatic cross-cluster failover","Support for Linux VM workloads","Security policy generation from live traffic","VM application management and automation","On cluster single pane of glass dashboard","Software Bills-of-Materials (SBOMs) for all components","Private support ticketing","Architecture review and best practice guidance"],"description":"For companies standardizing on security, high availability, and multi-cluster communication.","contactSales":true},{"free":false,"name":"Strategic","features":["Everything in Premium, plus:","Hotpatch releases and SBOMs","High Availability Zone-aware Load Balancing (HAZL)","FIPS 140-3 and 140-2 validated cryptography (optional)","Enterprise support with 24x7 SLAs","30-day white glove onboarding"],"description":"For enterprises with special security, compliance, and additional operational requirements.","contactSales":true}],"addOns":[{"name":"Buoyant Cloud Management"},{"name":"Continuous health checking"},{"name":"Datadog/Teams/PagerDuty alerts and metrics integration"},{"name":"High Availability Zone-aware Load Balancing (HAZL)"}],"summary":"Free tier for companies under 50 employees; Premium and Strategic tiers available by quote","currency":"USD","freeTier":true,"sourceUrl":"https://www.buoyant.io/blog/pod-based-pricing-for-buoyant-enterprise-for-linkerd","retrievedAt":"2026-08-16T21:36:01.639Z"}` | `{"type":"quote","plans":[{"free":false,"name":"Agent Router Service","contactSales":true},{"free":false,"name":"Agent Router Enterprise","contactSales":true}],"summary":"Contact sales for pricing","freeTier":false,"sourceUrl":"https://tetrate.io/tetrate-service-bridge/","retrievedAt":"2026-08-03T13:02:27.685Z"}` |
| pricing.free_tier | yes | no |
| pricing.model | quote | commercial |
| pricing.price_level | low | unknown |
| pricing.transparent | no | no |
| security.fedramp | yes | yes |
| security.gdpr | yes | yes |
| security.hipaa | yes | yes |
| security.iso27001 | - | yes |
| security.soc2 | - | yes |

## Capabilities (Service Mesh)

| Capability | Buoyant Enterprise for Linkerd | Tetrate Service Bridge |
|---|:--:|:--:|
| **Architecture** |  |  |
| Data plane | Sidecar | - |
| Proxy | linkerd2-proxy | Envoy |
| **Security** |  |  |
| Automatic mutual TLS | ✓ | ✓ |
| SPIFFE / SPIRE identity | - | - |
| **Traffic** |  |  |
| Traffic splitting / canary | ✓ | - |
| Fault injection / resilience | ✓ | - |
| **Scale** |  |  |
| Multi-cluster federation | ✓ | ✓ |
| **Portability** |  |  |
| VM support (beyond Kubernetes) | ✓ | ✓ |
| **Observability** |  |  |
| Built-in observability | ✓ | ✓ |
| **Standards** |  |  |
| Gateway API / GAMMA support | ✓ | ✓ |
| **Extensibility** |  |  |
| WASM extensibility | - | - |
| **Compliance** |  |  |
| FIPS mode | ✓ | ✓ |
| **Ecosystem** |  |  |
| CNCF maturity | Graduated | - |
| **Ops** |  |  |
| Commercial support / enterprise edition | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T16:50:16.579Z. "-" = undocumented, not absent.*
