for linux
see what your machine is actually leaking.
veil reads your dns, vpn, firewall, and a dozen other signals, scores what it finds, and hands you the exact fix commands for your system — free.
linux only · reads your system, changes nothing without asking · no telemetry
01 / what's actually watching
your isp already knows more than you'd guess.
Most DNS resolvers log every domain you look up by default — your router's default, your ISP's default — a plaintext record of everywhere you go, sitting on someone else's server.
ISPs are required or able to retain connection metadata in most jurisdictions: who you talked to and when, even if not what was said. Unencrypted traffic on the same network segment — a café Wi-Fi, a shared office LAN — is visible to anyone else on that segment, not just the operator.
A VPN that only tunnels IPv4 can still leak your real address over IPv6 if it's active and unrouted. And a Wi-Fi card with a stable MAC address quietly tracks your device across every network you join, VPN or not.
webgl isn't available here, so this is a plain list instead of the illustration.
this is about mass surveillance and what your isp/network sees — not anonymity, and not a targeted attacker. more on that further down.
02 / trace the exit
the same signal, from orbit.
drag to spin it, scroll or pinch to zoom in — this is the app's own exit-point globe, blown up and made explorable. the marker is illustrative positioning, not live satellite tracking.
drag to rotate · scroll to zoom
webgl isn't available here — an interactive globe would normally sit in this frame.
03 / how it works
read. understand. fix.
read
veil looks at your dns, vpn, firewall, ipv6, mac address, messaging, and disk encryption — read-only, nothing changes.
-
ok Encrypted DNS
-
fail VPN tunnel
-
warn IPv6 leak guard
understand
every gap comes with a plain-english reason it matters — not just "fail."
fix
and the exact command for your system — veil detects your init system and package manager, so it's never a generic guess.
- systemctl enable --now wg-quick@wg0
free gets you all three, every time. plus automates step three.
04 / what it checks
eight checks, read-only, every time.
Pulled straight from the app's own check groups — nothing here is aspirational.
network
Plaintext DNS to a public resolver lets your ISP log every domain you look up.
Without a full-tunnel VPN, your ISP sees every destination you connect to.
Confirms traffic actually leaves through the tunnel, not the raw ISP link.
An active, unrouted IPv6 address can leak your real address past a v4-only VPN.
A stable Wi-Fi MAC lets networks track your device across locations.
firewall / kill-switch
A default-deny firewall is the backstop — if the tunnel drops, nothing leaks.
messaging
An end-to-end messenger means the provider sees ciphertext, not your words.
disk encryption
None of the network hardening matters if the machine is seized unencrypted.
05 / the network, up close
drag it. spin it. zoom in.
the same hub-and-satellite graph the app draws from your real checks — restaged bigger, with real depth and full orbit controls, so it feels like a live instrument instead of a screenshot.
drag to rotate · scroll or pinch to zoom · click a node
webgl isn't available here, so this is a plain list of the same check groups.
06 / free vs plus
every finding, every reason, every fix command — free, always.
plus buys automation, not answers.
the honest auditor
- see every check
- understand every gap in plain language
- get the exact fix command for your system
- run it yourself
automation, for people who'd rather not
- one-click apply — the helper runs the fix, no terminal
- always-on guardian — desktop alert the moment a protection drops
- auto-heal — re-applies protection when it breaks
- deep leak + kill-switch stress tests
- one-click hardening profiles, one-click revert
- posture history + scheduled scans
- back up and restore your hardened setup
- lifetime updates — one payment, every future version
one payment. no subscription. every future update included. — €18
see pricing07 / what this is not
the limits, stated plainly.
not anonymous
veil hardens what your isp and local network can see — it doesn't hide who you are from every service you talk to.
not unhackable
no software is. veil reduces exposure to mass, passive surveillance — it is not a defense against someone specifically targeting you.
not untraceable
a determined, resourced adversary with legal reach can still find you. veil raises the bar for dragnet collection, not for a targeted investigation.
we'd rather you trust the 90% we're honest about than sell you the 10% we can't deliver.
built by one person, in the open. [[NEEDS REAL CONTENT — repo link / star badge / dev-log, do not invent]]
08 / get it
free to see what's wrong. pay once, if you want it fixed for you.
linux · [[package formats once decided — e.g. AppImage / .deb / .rpm]]
09 / questions
frequently asked
No. veil collects nothing — no analytics, no crash reports, no usage data, no phone-home. The only outbound calls the app itself makes are its own read-only egress checks (against am.i.mullvad.net / the Cloudflare trace endpoint) to confirm your tunnel is actually carrying traffic. No personal data is sent. Full detail in the privacy policy.
No. veil audits your system and can help you configure a VPN properly — it isn't a VPN service itself and ships no tunnel of its own. It works with tools you already have (WireGuard, Cloudflare WARP, whatever's on your system).
Automation and monitoring — one-click apply, an always-on guardian, auto-heal, deep leak/kill-switch stress tests, hardening profiles, posture history, and config backup. Every finding, every reason, and every manual fix command stays free forever. See free vs plus.
Likely yes, with an honest caveat: veil detects your init system and package manager at runtime and generates fix commands to match, rather than assuming one distro. It's built and tested against the common systemd + apt/dnf/pacman combinations first — less common setups may need to double-check the generated command before running it.
Probably, but veil can't guarantee compliance with every country's laws — no privacy tool can. Anti-surveillance, VPN, and encryption tools are restricted or illegal in some places. Using veil there may break local law, and that's the user's responsibility, stated explicitly in the terms. Check your local law before use.
Checkout and card data are handled by a merchant of record (Lemon Squeezy or Paddle) — veil itself never sees your payment details. You get a license key by email and paste it into the app; it's validated once and then works fully offline.