Security
Security, stated plainly
What protects your traffic, who holds which keys, and where your configuration is stored.
Your traffic
Encrypted between sites, never through us
Traffic between sites and from roaming clients is encrypted with WireGuard (Curve25519, ChaCha20-Poly1305). It flows directly between your own sites; Weft's control plane never carries it.
Keys
Private keys never leave the device
Every site and every client generates its own WireGuard key. Weft only ever receives the public half, so there is no central store of private keys to steal.
Joining
One-time invitations
A site or client joins by redeeming an invitation that works once. A site then proves who it is to the control plane with a certificate issued at enrolment.
Management
No remote shell
Weft does not log in to your machines. Sites open an outbound encrypted connection to the control plane and accept a fixed set of structured instructions, not commands.
Policy
Deny unless permitted
Traffic between groups is refused unless a contract permits it, and a device in no group is refused too. Every site checks that the policy in its kernel is still the policy it installed.
Console
Every request needs an identity
Sign-in uses OpenID Connect single sign-on. Every API route requires a signed-in identity unless it is on a short, reviewed list — sign-in itself, and a device's own calls with its own token — and automated tests fail if a route is added without one.
Tenancy
Each customer is scoped
Every console request is confined to one tenant's data, and tests fail the build if a handler reaches past that scope.
Data
Held in London
Configuration, health and public keys are stored in AWS's London region (eu-west-2), encrypted at rest, with point-in-time recovery and deletion protection enabled.
Software
Checked before it runs
The site installer verifies the agent's checksum before installing it, and upgrades roll back automatically if the new version does not come up. The macOS app is signed and notarised by Apple.
Reporting a vulnerability
Email support@weftnetworks.com with the details. Please do not test against other customers’ networks.