for linux

see what your machine is actually leaking.

veil reads your dns, vpn, firewall, and a dozen other signals, scores what it finds, and hands you the exact fix commands for your system — free.

linux only · reads your system, changes nothing without asking · no telemetry

01 / what's actually watching

your isp already knows more than you'd guess.

Most DNS resolvers log every domain you look up by default — your router's default, your ISP's default — a plaintext record of everywhere you go, sitting on someone else's server.

ISPs are required or able to retain connection metadata in most jurisdictions: who you talked to and when, even if not what was said. Unencrypted traffic on the same network segment — a café Wi-Fi, a shared office LAN — is visible to anyone else on that segment, not just the operator.

A VPN that only tunnels IPv4 can still leak your real address over IPv6 if it's active and unrouted. And a Wi-Fi card with a stable MAC address quietly tracks your device across every network you join, VPN or not.

this is about mass surveillance and what your isp/network sees — not anonymity, and not a targeted attacker. more on that further down.

02 / trace the exit

the same signal, from orbit.

drag to spin it, scroll or pinch to zoom in — this is the app's own exit-point globe, blown up and made explorable. the marker is illustrative positioning, not live satellite tracking.

drag to rotate · scroll to zoom

03 / how it works

read. understand. fix.

1

read

veil looks at your dns, vpn, firewall, ipv6, mac address, messaging, and disk encryption — read-only, nothing changes.

  • ok Encrypted DNS
  • fail VPN tunnel
  • warn IPv6 leak guard
2

understand

every gap comes with a plain-english reason it matters — not just "fail."

  • why it matters

    No VPN tunnel — your traffic exits directly and your ISP sees every destination.

3

fix

and the exact command for your system — veil detects your init system and package manager, so it's never a generic guess.

  • systemctl enable --now wg-quick@wg0

free gets you all three, every time. plus automates step three.

04 / what it checks

eight checks, read-only, every time.

Pulled straight from the app's own check groups — nothing here is aspirational.

network

Encrypted DNS

Plaintext DNS to a public resolver lets your ISP log every domain you look up.

VPN tunnel

Without a full-tunnel VPN, your ISP sees every destination you connect to.

Traffic egress

Confirms traffic actually leaves through the tunnel, not the raw ISP link.

IPv6 leak guard

An active, unrouted IPv6 address can leak your real address past a v4-only VPN.

MAC randomization

A stable Wi-Fi MAC lets networks track your device across locations.

firewall / kill-switch

Firewall

A default-deny firewall is the backstop — if the tunnel drops, nothing leaks.

messaging

Encrypted messaging

An end-to-end messenger means the provider sees ciphertext, not your words.

disk encryption

Disk encryption

None of the network hardening matters if the machine is seized unencrypted.

05 / the network, up close

drag it. spin it. zoom in.

the same hub-and-satellite graph the app draws from your real checks — restaged bigger, with real depth and full orbit controls, so it feels like a live instrument instead of a screenshot.

drag to rotate · scroll or pinch to zoom · click a node

06 / free vs plus

every finding, every reason, every fix command — free, always.

plus buys automation, not answers.

free

the honest auditor

  • see every check
  • understand every gap in plain language
  • get the exact fix command for your system
  • run it yourself
download free
plus

automation, for people who'd rather not

  • one-click apply — the helper runs the fix, no terminal
  • always-on guardian — desktop alert the moment a protection drops
  • auto-heal — re-applies protection when it breaks
  • deep leak + kill-switch stress tests
  • one-click hardening profiles, one-click revert
  • posture history + scheduled scans
  • back up and restore your hardened setup
  • lifetime updates — one payment, every future version

one payment. no subscription. every future update included.€18

see pricing

07 / what this is not

the limits, stated plainly.

not anonymous

veil hardens what your isp and local network can see — it doesn't hide who you are from every service you talk to.

not unhackable

no software is. veil reduces exposure to mass, passive surveillance — it is not a defense against someone specifically targeting you.

not untraceable

a determined, resourced adversary with legal reach can still find you. veil raises the bar for dragnet collection, not for a targeted investigation.

we'd rather you trust the 90% we're honest about than sell you the 10% we can't deliver.

built by one person, in the open. [[NEEDS REAL CONTENT — repo link / star badge / dev-log, do not invent]]

08 / get it

free to see what's wrong. pay once, if you want it fixed for you.

linux · [[package formats once decided — e.g. AppImage / .deb / .rpm]]

09 / questions

frequently asked

No. veil collects nothing — no analytics, no crash reports, no usage data, no phone-home. The only outbound calls the app itself makes are its own read-only egress checks (against am.i.mullvad.net / the Cloudflare trace endpoint) to confirm your tunnel is actually carrying traffic. No personal data is sent. Full detail in the privacy policy.

No. veil audits your system and can help you configure a VPN properly — it isn't a VPN service itself and ships no tunnel of its own. It works with tools you already have (WireGuard, Cloudflare WARP, whatever's on your system).

Automation and monitoring — one-click apply, an always-on guardian, auto-heal, deep leak/kill-switch stress tests, hardening profiles, posture history, and config backup. Every finding, every reason, and every manual fix command stays free forever. See free vs plus.

Likely yes, with an honest caveat: veil detects your init system and package manager at runtime and generates fix commands to match, rather than assuming one distro. It's built and tested against the common systemd + apt/dnf/pacman combinations first — less common setups may need to double-check the generated command before running it.

Probably, but veil can't guarantee compliance with every country's laws — no privacy tool can. Anti-surveillance, VPN, and encryption tools are restricted or illegal in some places. Using veil there may break local law, and that's the user's responsibility, stated explicitly in the terms. Check your local law before use.

Checkout and card data are handled by a merchant of record (Lemon Squeezy or Paddle) — veil itself never sees your payment details. You get a license key by email and paste it into the app; it's validated once and then works fully offline.