Understand how Wavefront secures your data and supports fine-tuning security for your cluster.

Wavefront by VMware protects your data and includes facilities for you to customize authentication and authorization.

This page gives a summary. For a detailed discussion of many aspects of security, download and review the Cloud Security Alliance Consensus Assessments Initiative Questionnaire for Wavefront by VMware.

Certifications

Wavefront has successfully completed all requirements for the following certifications:

  • ISO 27001/27017/27018
  • SOC 2 Type 1
  • GDPR Type 1 attestation
  • CSA STAR Level 1

Data Protection

Wavefront currently uses AWS to run the Wavefront service and to store customer data. The service is served from a single AWS region spread across multiple availability zones for failover. Using AWS also means that we can take advantage of other AWS security features such as encryption at rest and system backups that use asymmetric encryption.

Wavefront customer environments are isolated from each other. Data is stored on encrypted data volumes.

The AWS data centers incorporate physical protection against environmental risks. To access the AWS ISO27001 report, see https://aws.amazon.com/compliance. For more information:

Wavefront development, QA, and production use separate equipment and environments and are managed by separate teams. Customers retain control and ownership of their content. We do not replicate customer content unless the customer asks for it explicitly.

High Availability

Wavefront is architected to be highly available. In the event of a hardware failure, we automatically migrate to, or restart workloads on, another host machine in the cluster and automatically restart the failed host. If the host machine fails to restart, or the performance of the restarted host is degraded, the service is capable of replacing the failed host in a cluster with an entirely new host within minutes.

Disaster Recovery

Wavefront supports the option of DR across regions for customers. Contact your Wavefront representative for details.

Networking

Applications send data to the Wavefront service using either the Wavefront proxy or direct ingestion. We protect all data traffic with TLS (Transport Layer Security) and HTTPS. If you send data directly to the Wavefront service, we recommend TLS 1.2 connections.

The Wavefront proxy uses HTTPS, and we offer options to secure it further:

Authentication

All Wavefront users must be authenticated to log in. Wavefront customers can use the authentication provided by Wavefront or use one of our supported authentication integration. We support several authentication solutions including AzureAD, Google ID, and Okta.

Large customers can request multi-tenant SSO. Users in different teams inside the company can authenticate to different tenants and cannot access the other tenant’s data.

Authorization

Wavefront supports multi-level access management:

  • Global permissions determine which groups or users can manage which objects or perform certain tasks. For example, you could assign Dashboards, Alerts, Proxy, Metrics, and Embed Chart permission to a Developers group and only Dashboard permission to a Novice group.
  • Access control applies to individual objects (dashboards or alerts). Privileged groups or users can revoke grant access to individual groups or users. To support this feature, Wavefront includes a Super Admin user.

Wavefront supports a high security mode where only the object creator and Super Admin user can view and modify new dashboards.

If you use the REST API, you must pass in an API token and must also have the necessary permissions to perform the task, for example, Dashboard permissions to modify dashboards.

If you use direct ingestion you are required to pass in an API token and most also have the Direct Data Ingestion permission.

Audit Trail

You can view changes that were made to dashboards, alerts, etc. by using versions of charts and dashboards.

Integrations

Cloud integrations support monitoring data from different cloud providers using Wavefront. The process is like this:

  1. You open the integration.
  2. You give Wavefront global read-only access or limited access.

VMware Security Development Lifecycle

VMware has an industry-leading Security Development Lifecycle process and a VMware Cloud Services Security organization that focuses on ensuring that VMware cloud services implement industry standard operational and security controls.