FAQ
Frequently asked questions
What hardware does a site need?
Any machine that runs Ubuntu 24.04 LTS on x86-64 or ARM64 — a small PC, a server, or a cloud instance — with one or two internet connections. You bring the hardware; there is no appliance to buy or ship.
Does my traffic pass through Weft's servers?
No. Traffic goes directly between your own sites over WireGuard, or through a hub that is also one of your sites. The Weft control plane handles configuration and health, and is never in the path of your packets.
What happens if the Weft control plane is unreachable?
Your network keeps forwarding. Every site holds a complete copy of its configuration and keeps applying it. You cannot make changes until the control plane is back, and nothing that is already working stops.
Which devices can connect as roaming clients?
macOS, Windows and Linux. Each device generates its own WireGuard key and joins with a one-time invitation, so its private key never leaves it. You choose per client whether it sends only company traffic through Weft or everything.
Will it work with the routers and firewalls we already have?
Yes. A site can exchange routes with your existing equipment over OSPF or eBGP, hand off a routed network on a dedicated port, or stretch a layer-2 segment. Internet traffic can leave through your own perimeter firewall rather than from each branch.
How is Weft priced?
Per site and per roaming client, monthly, with every feature on one plan. See pricing.
How does the free trial work?
Thirty days, up to three sites and ten roaming clients, every feature, and no card. If you need longer, ask and we will extend it once.
What happens when a trial ends or a payment fails?
Your network does not go down. After a 14-day grace period the console becomes read-only — no changes or new devices — while every site keeps forwarding on its last configuration. We will never switch off a running network to collect a bill.
Where is our data held?
The control plane and its data run in AWS's London region (eu-west-2). It holds your network's configuration, health measurements and device public keys. It never sees your traffic or any private key.
Can we sign in with our own identity provider?
Console sign-in uses single sign-on through OpenID Connect. Connecting your own identity provider is not self-service yet — talk to us.
Something not answered here? Email hello@weftnetworks.com. Found a problem, or want a feature? support@weftnetworks.com.