Weft Start free trial

Use case · Remote access

Replace the remote-access VPN

Laptops join the same fabric as your offices, so remote staff reach every site through one connection that stays up when a hub does not.

The problem

A traditional remote-access VPN terminates at one head-end. Staff reach that office and are hairpinned to everywhere else; when the head-end fails, everyone is disconnected at once. Configuration files carrying private keys get emailed around.

How Weft does it

  • Apps for macOS and Windows, and a Linux client. On Windows the helper runs as a system service, so the tunnel recovers even with nobody signed in.
  • Private keys never leave the device. Each client generates its own key and joins by redeeming a one-time invitation. Only the public key is sent.
  • Split or full tunnel, per client. Send only company traffic through Weft, or everything.
  • Hub failover is automatic. The apps check the tunnel every ten seconds. If the hub stays unreachable they fetch a fresh profile and move to the new one, keeping their key.
  • Policy applies to people as well as places. Clients belong to groups, and segmentation decides what each group may reach.
  • Posture is reported. The Mac and Windows apps report device posture to the console.