Weft Start free trial

Security

Security, stated plainly

What protects your traffic, who holds which keys, and where your configuration is stored.

Your traffic

Encrypted between sites, never through us

Traffic between sites and from roaming clients is encrypted with WireGuard (Curve25519, ChaCha20-Poly1305). It flows directly between your own sites; Weft's control plane never carries it.

Keys

Private keys never leave the device

Every site and every client generates its own WireGuard key. Weft only ever receives the public half, so there is no central store of private keys to steal.

Joining

One-time invitations

A site or client joins by redeeming an invitation that works once. A site then proves who it is to the control plane with a certificate issued at enrolment.

Management

No remote shell

Weft does not log in to your machines. Sites open an outbound encrypted connection to the control plane and accept a fixed set of structured instructions, not commands.

Policy

Deny unless permitted

Traffic between groups is refused unless a contract permits it, and a device in no group is refused too. Every site checks that the policy in its kernel is still the policy it installed.

Console

Every request needs an identity

Sign-in uses OpenID Connect single sign-on. Every API route requires a signed-in identity unless it is on a short, reviewed list — sign-in itself, and a device's own calls with its own token — and automated tests fail if a route is added without one.

Tenancy

Each customer is scoped

Every console request is confined to one tenant's data, and tests fail the build if a handler reaches past that scope.

Data

Held in London

Configuration, health and public keys are stored in AWS's London region (eu-west-2), encrypted at rest, with point-in-time recovery and deletion protection enabled.

Software

Checked before it runs

The site installer verifies the agent's checksum before installing it, and upgrades roll back automatically if the new version does not come up. The macOS app is signed and notarised by Apple.

Reporting a vulnerability

Email support@weftnetworks.com with the details. Please do not test against other customers’ networks.