Security
vCenter stays private. Customers stay separate.
This page explains how ExoVM is put together, what it protects, and what stays your responsibility. No certifications on display, no vague promises: just the design.
In short
ExoVM is built so that vCenter never has to be reachable from the internet: a Docker connector inside your network opens outbound connections to the ExoVM cloud and calls vCenter locally. vCenter credentials stay in the connector’s environment, each customer user sees only the VMs assigned to them, and VM actions and access changes are audit-logged. The one inbound requirement is port 443 on the connector host, for console streams served over TLS.
Last updated:
The design in five lines
-
Nothing on the internet needs to reach vCenter.
-
vCenter credentials stay on your host.
-
Customers only see the VMs assigned to them.
-
Console sessions use short-lived, single-use tickets.
-
VM actions and access changes are logged with user, action and time.
Network
No inbound access to vCenter
The ExoVM connector runs inside your network and opens outbound connections to the ExoVM cloud to receive commands. It then calls the vSphere APIs on your internal network. vCenter and ESXi never accept connections from the internet, and browsers never talk to vCenter directly.
- No port forwarding to vCenter or ESXi
- No VPN needed for your team or your customers to use the panel
- The ExoVM cloud never opens connections into your network
Console
The console path, stated plainly
VM console streams are served over TLS from the connector host on port 443, so browsers that open consoles must be able to reach that host on 443. vCenter itself is never exposed. Each session starts with a short-lived, single-use ticket issued by your connector, and the connector relays the stream to the browser.
- The connector host is yours, so your firewall rules decide who can reach port 443
- Tickets are short-lived and work once
- The browser never connects to vCenter or ESXi
Credentials
vCenter credentials stay with the connector
You give the connector its vCenter credentials through its environment on your host. They are used locally to call the vSphere APIs and are never stored in the ExoVM cloud.
Tip: Give the connector’s account only the permissions for the actions you plan to use.
Isolation
Customers see only their own VMs
Admins assign specific VMs to specific users, and a customer user sees only the VMs assigned to them.
- Admins assign specific VMs to specific users
- Customer users see only their assigned VMs
Shared responsibility
What stays in your hands
Because the connector runs on your infrastructure, a few things are yours to manage.
- Keep the connector host patched and its access limited
- Decide who can reach the connector host on port 443
- Scope the connector’s vCenter account to the permissions you need
- Decide which VMs each customer user is assigned
Straight talk
What we don’t claim
-
Not “no ports at all”. vCenter needs no inbound access. The connector host does need port 443 reachable for consoles.
-
Not “every console works everywhere”. Console behaviour depends on your ESXi hosts and guest configuration, so we validate it for your environment during onboarding.
-
Not an offline product. The connector needs outbound internet access to the ExoVM cloud. If a site’s connector is offline, that site’s VMs keep running on your hosts, but the panel can’t control them until it reconnects.
-
No certification badges. If your procurement process needs a security questionnaire answered, ask us and we’ll answer it plainly.
Found something?
Report a security issue
Email contact@exovm.com with “Security” in the subject line. Please include what you found and how to reproduce it.
Security questions
Is vCenter exposed to the internet when I use ExoVM?
No. The connector opens outbound connections to the ExoVM cloud and calls vCenter on your internal network. vCenter and ESXi never accept connections from the internet, and browsers never talk to vCenter directly.
Where are my vCenter credentials stored?
In the connector’s environment on your own host. They are used locally to call the vSphere APIs and are never stored in the ExoVM cloud.
How are customers kept apart?
In ExoVM, each customer user only sees the VMs an admin has assigned to them.
Which inbound port does ExoVM need?
None to vCenter. VM console streams are served over TLS from the connector host on port 443, so browsers that open consoles must be able to reach that host on 443.
Bring your security questions to the demo
We’ll walk your team through the connector, the network paths and the isolation model on your own diagram.