for linux

see what your machine is actually leaking.

veil reads your dns, vpn, firewall, and a dozen other signals and scores what it finds — free, every time. fix the basics yourself for free; unlock plus for the rest, plus automation.

linux only · reads your system, changes nothing without asking · no telemetry

illustration of the check groups veil reads — not a live scan of this page's visitor.

statement

anonymity is a right.

surveillance is a crime.

the eu keeps proposing "chat control" — client-side scanning of your private messages before encryption even applies. that's not a metaphor: it's mass surveillance, mandated by law, sold as child safety. veil doesn't fix that fight. it just makes sure your own machine isn't giving away more than it already has to.

01 / what's actually watching

your isp already knows more than you'd guess.

Most DNS resolvers log every domain you look up by default — your router's default, your ISP's default — a plaintext record of everywhere you go, sitting on someone else's server.

ISPs are required or able to retain connection metadata in most jurisdictions: who you talked to and when, even if not what was said. Unencrypted traffic on the same network segment — a café Wi-Fi, a shared office LAN — is visible to anyone else on that segment, not just the operator.

A VPN that only tunnels IPv4 can still leak your real address over IPv6 if it's active and unrouted. And a Wi-Fi card with a stable MAC address quietly tracks your device across every network you join, VPN or not.

this is about mass surveillance and what your isp/network sees — not anonymity, and not a targeted attacker. more on that further down.

02 / trace the exit

the same signal, from orbit.

drag to spin it, scroll or pinch to zoom in — this is the app's own exit-point globe, blown up and made explorable. the marker is illustrative positioning, not live satellite tracking.

drag to rotate · scroll to zoom

03 / how it works

read. understand. fix.

1

read

veil looks at your dns, vpn, firewall, ipv6, mac address, messaging, and disk encryption — read-only, nothing changes.

  • ok Encrypted DNS
  • fail VPN tunnel
  • warn IPv6 leak guard
2

understand

every gap comes with a plain-english reason it matters — not just "fail."

  • why it matters

    No VPN tunnel — your traffic exits directly and your ISP sees every destination.

3

fix

and the exact command for your system — veil detects your init system and package manager, so it's never a generic guess.

  • systemctl enable --now wg-quick@wg0

free gets you all three for the simplest gaps — dns, mac, messaging. plus unlocks the rest of the fixes and automates step three.

04 / what it checks

eight checks, read-only, every time.

Pulled straight from the app's own check groups — nothing here is aspirational.

network

Encrypted DNS

Plaintext DNS to a public resolver lets your ISP log every domain you look up.

VPN tunnel

Without a full-tunnel VPN, your ISP sees every destination you connect to.

Traffic egress

Confirms traffic actually leaves through the tunnel, not the raw ISP link.

IPv6 leak guard

An active, unrouted IPv6 address can leak your real address past a v4-only VPN.

MAC randomization

A stable Wi-Fi MAC lets networks track your device across locations.

firewall / kill-switch

Firewall

A default-deny firewall is the backstop — if the tunnel drops, nothing leaks.

messaging

Encrypted messaging

An end-to-end messenger means the provider sees ciphertext, not your words.

disk encryption

Disk encryption

None of the network hardening matters if the machine is seized unencrypted.

05 / the network, up close

drag it. spin it. zoom in.

the same hub-and-satellite graph the app draws from your real checks — restaged bigger, with real depth and full orbit controls, so it feels like a live instrument instead of a screenshot.

drag to rotate · scroll or pinch to zoom · click a node

06 / free vs plus

every check, every score, always free. plus unlocks the rest.

free audits everything and fixes the basics yourself. plus fixes the rest for you, plus automation.

free

the honest auditor

  • every check, every score, no limits
  • understand every gap in plain language
  • 2–3 of the simplest fixes, done yourself — encrypted DNS, MAC randomization, encrypted messaging
  • no account, no telemetry, no time limit
download free
plus

every other fix, plus automation

  • the harder fixes — vpn tunnel, egress, firewall, ipv6 leak guard, disk encryption
  • one-click apply — the helper runs the fix, no terminal
  • always-on guardian — desktop alert the moment a protection drops
  • auto-heal — re-applies protection when it breaks
  • deep leak + kill-switch stress tests
  • one-click hardening profiles, one-click revert
  • posture history + scheduled scans
  • back up and restore your hardened setup

one payment. no subscription. every future update included.€18

see pricing

07 / what this is not

the limits, stated plainly.

not anonymous

veil hardens what your isp and local network can see — it doesn't hide who you are from every service you talk to.

not unhackable

no software is. veil reduces exposure to mass, passive surveillance — it is not a defense against someone specifically targeting you.

not untraceable

a determined, resourced adversary with legal reach can still find you. veil raises the bar for dragnet collection, not for a targeted investigation.

we'd rather you trust the 90% we're honest about than sell you the 10% we can't deliver.

built by one person, in the open. source & releases on github: BiksY01/veil

08 / get it

free to see what's wrong and fix the basics. pay once for the rest.

linux · AppImage · nothing to install

09 / questions

frequently asked

No. veil collects nothing — no analytics, no crash reports, no usage data, no phone-home. The only outbound calls the app itself makes are its own read-only egress checks (against am.i.mullvad.net / the Cloudflare trace endpoint) to confirm your tunnel is actually carrying traffic. No personal data is sent. Full detail in the privacy policy.

No. veil audits your system and can help you configure a VPN properly — it isn't a VPN service itself and ships no tunnel of its own. It works with tools you already have (WireGuard, Cloudflare WARP, whatever's on your system).

The harder fixes, plus automation. Free already gives you every check, the full score, plain-language reasons for every gap, and 2–3 of the simplest fixes to run yourself (encrypted DNS, MAC randomization, encrypted messaging). Plus unlocks the rest of the fix commands (VPN tunnel, firewall, IPv6 leak guard, disk encryption, and more) plus one-click apply, an always-on guardian, auto-heal, deep leak/kill-switch stress tests, hardening profiles, posture history, and config backup. See free vs plus.

Likely yes, with an honest caveat: veil detects your init system and package manager at runtime and generates fix commands to match, rather than assuming one distro. It's built and tested against the common systemd + apt/dnf/pacman combinations first — less common setups may need to double-check the generated command before running it.

Probably, but veil can't guarantee compliance with every country's laws — no privacy tool can. Anti-surveillance, VPN, and encryption tools are restricted or illegal in some places. Using veil there may break local law, and that's the user's responsibility, stated explicitly in the terms. Check your local law before use.

Crypto only, no card, no account: you send monero to our own wallet, email us proof of payment, and we email back an offline license key by hand. Full flow on the pricing page.