Security and privacy

Your infrastructure data never leaves your network.

VIA is designed to run entirely within your infrastructure. This page describes what stays local, what's read-only, and how the software is validated.

Diagram: from vCenter to the VIA appliance to the local report, no data leaves your network.
Principle

Your infrastructure stays yours. VIA runs entirely inside your network: nothing is uploaded, transmitted, or stored externally, and MB Tools receives no data from your environment. The report is a file on your machine. An anonymized version is produced by default: it automatically removes hostnames, IPs, and identifiers.

100% local

No external network calls.

Fully offline

No internet connection required during collection, analysis, or report generation. Air-gap environment compatible.

Read-only

Minimal service account. VIA changes no configuration, in vCenter or in your VMs. Read-only collection, schedulable during production hours.

Anonymized version

Every assessment also produces an anonymized report: VM names and client identifiers removed. Designed to be shared or presented to third parties.

Zero phone-home

The license is validated locally, offline, using a signed key: no license server to reach, no online activation.

Your data flows

Nothing leaves your network without an action from you.

Yours to keep and share

You decide whether to share, or not

Analysis report
Full version, produced on the appliance. For your team, stays with you.
Anonymized copyby default
Identifiers removed (opt-out: uncheck Anonymize before the scan). Designed for your vendors and integrators.

To MB Tools, only if you choose

Explicit action, always anonymized

Support bundle
To diagnose a specific case. Anonymized by default; real identifiers only after a separate choice.
Contribution bundle
To improve the product. Anonymized, uploaded via the Feedback page. No impact on your use of VIA.

Nothing is sent to MB Tools without an explicit action from you. For a bundle, we recommend reviewing its contents before sharing it.

Trust summary

VIA's security model, in plain terms.

VIA is a self-hosted appliance. What stays with you, what is read-only, what can leave and only on your action. Point by point.

Deployment
Self-hosted OVA appliance, imported into your own vSphere.
Network boundary
Everything runs inside your network. No outbound calls, no data transmitted externally.
Analysis levels
L1 via the vCenter API, read-only. L2 and L3 are optional and require guest access (VMware Tools, WinRM, or SSH).
Privileges
Minimal read-only vCenter service account, with no write privileges. VIA changes no configuration in your environment.
Credentials
Entered into the appliance and used locally. They stay on your network.
Retention
Deliverables are files on your machine. MB Tools retains no data from your environment.
Updates and integrity
Release notices and OVA integrity information are published in the participant portal.
Vulnerabilities
Confidential reporting to security@mbtools.ca.
Documentation available in the participant portal
Security & complianceGetting startedWebUI referenceReading the reportDeliverablesAnonymizationDiagnostic bundlesAPI referenceThird-party noticesTroubleshootingFAQ

Accessible after sign-in, for beta participants.

What we collect, outside your environment

Only what's needed for purchase and support.

When you purchase a license, we collect information via our payment processor (name, email, billing). If you contact us for support, we collect the content of your message. No technical data from your environment is collected automatically. If you choose to share a bundle from the appliance, it is always at your initiative: the Support bundle (anonymized by default, with an option to include real identifiers when the anonymized version is not enough to diagnose) and the Contribution bundle (always anonymized, uploaded via the Feedback page). Full details in our privacy policy.

More questions about what stays local, what can leave, or the access required?

See the FAQ