Their own documentation puts the consequence plainly: “Inherently, customers must trust Tailscale’s control plane to make the right decisions about who and what can join any given tailnet.” Tailnet Lock shrinks that trust by making a node you own sign new additions, and their open source page lists the coordination server as closed source.
In QS-WAN the control tower is software you run, on premise, in a private cloud or air gapped, so enrolment, key exchange, certificate issuance and policy signing all happen inside your boundary. The key exchange is hybrid post quantum, X25519 plus ML-KEM-768, with ML-DSA-87 authentication and AES-256-GCM. Crypto agility is operational: eight key exchange options, eight certificate authorities and three ciphers, switchable fleet wide or per gateway, with the certificates re-signed for you.
It hands you a bill, too. Patching, backups and availability are yours now, and Tailscale does all of that for you.