Per-app tunnel isolation + anti-detect identity engine.
Veil routes any application through any tunnel chain (WireGuard, OpenVPN, SOCKS5, HTTP proxy, Tor) inside its own network namespace, then layers fingerprint impersonation on top: TCP / TLS / HTTP-2 / browser identity all consistent with a chosen persona.
Local-first. No telemetry. Source-available (free edition: PolyForm Noncommercial).
| Layer | What it does |
|---|---|
| Network namespace per profile | Each profile is a fully isolated network stack. Apps in profile A literally cannot see profile B's traffic. |
| Chain composability | Stack hops freely: VPN → Tor → SOCKS5, Tor with bridges, multi-hop WireGuard, etc. |
| Kill switch (verified) | iptables rules drop everything outside the tunnel. Veil reads back the rules at launch and refuses to start if they didn't install correctly. Fail-closed verified, not assumed. |
| TCP fingerprint spoofing (Pro) | NFQUEUE rewrites SYN options + window scale + TTL + MSS to match a chosen OS persona. Defeats p0f-style passive OS detection. |
| TLS impersonation (Pro) | uTLS-pinned ClientHello matches Chrome / Firefox / Safari byte-for-byte. JA3/JA4 signatures align with the persona's claimed browser. |
| HTTP/2 mediator (Pro) | SETTINGS frame, WINDOW_UPDATE pacing, HPACK header order all rewritten to match the target browser. |
| Persona system (Pro) | UA, locale, timezone, screen, hardware concurrency, GPU strings, Client Hints, all consistent across every layer. |
| Persona forge (Pro) | Generate a deterministic, realistic, unique identity per profile (veil persona forge work-twitter). Same name → same persona forever. Different profiles → different real-looking people. |
| Locked endpoint (Pro) | Profile refuses to launch if exit IP / city / ASN drifts from claimed persona. Auto-captures on first run. |
| Schedule guard (Pro) | Refuses to launch outside the persona's plausible hours (HH:MM-HH:MM in persona TZ). |
| Behavioral jitter (Pro) | uinput keyboard + mouse jitter defeats keystroke-dynamics + mouse-curvature fingerprinting. |
| Audit log + crash reports | JSON-lines security events at ~/.config/veil/audit.log. Critical failures snapshot full state to ~/.config/veil/crashes/. |
| Free | Pro | |
|---|---|---|
| Per-app netns isolation | ✓ | ✓ |
| All chain backends (WG/OVPN/Tor/SOCKS5/HTTP) | ✓ | ✓ |
| Kill switch | ✓ | ✓ |
| GUI + CLI + bulk import (Mullvad/Proton/IVPN configs) | ✓ | ✓ |
| Tor (basic) | ✓ | ✓ |
| Anti-detect stack (TCP/TLS/HTTP-2 spoofing) | ✗ | ✓ |
| Persona system + forge | ✗ | ✓ |
| Locked endpoint + schedule guard + drift detection | ✗ | ✓ |
| Behavioral jitter + CPU throttle | ✗ | ✓ |
| Tor advanced (NEWNYM, ExitCountry, bridges/obfs4) | ✗ | ✓ |
| TLS-MITM proxy + CA management | ✗ | ✓ |
| Email support | ✗ | ✓ |
The Free tier is vopono-equivalent + a GUI. Use it if you just want per-app VPN/Tor with kill switch.
The Pro tier is the anti-detect stack on top: layered fingerprint impersonation across the whole transport+browser surface.
sudo apt install -y wireguard openvpn tor curl iptables
make build
sudo cp bin/veil bin/veil-gui /usr/local/bin/
sudo veil setup # one-time: ip_forward, sudoers entry
veil-gui # GUI; or: veil --helpSame flow, different package manager. See docs/CROSS_PLATFORM.md for full requirements.
Partial support today. macOS uses pf instead of iptables; Windows uses Wintun. Some pro features (TCP-options rewrite, time namespace) are Linux-only, see docs/CROSS_PLATFORM.md for the feature matrix.
veil profile import-mullvad ~/Downloads/mullvad-wg/ # → one profile per server
veil run mullvad-de-fra-wg-001 -- firefoxOr via GUI: Profiles → New → Network chain → Add hop → WireGuard → save → Launch.
# Forge a unique persona for this profile (Pro)
veil persona forge work-twitter
# → "Windows Chrome 134, Intel UHD, 1920×1080, 4 cores, US/Pacific, ..."
# Create a profile that pins this persona, locks the endpoint, blocks
# launches outside business hours
cat > ~/.config/veil/profiles/work-twitter.yaml <<EOF
name: work-twitter
chain:
- kind: wireguard
config_path: /home/me/wg/mullvad-de-fra.conf
forge_persona: true
locked_endpoint: true
schedule_window: "08:00-22:00"
behavioral_jitter: true
mouse_jitter: true
app:
preset: brave
EOF
veil run work-twitter
veil profile drift work-twitter # confirm exit matches persona claims
veil profile probe work-twitter # DNS/IPv6/listening-socket leak testsmake build # CLI + GUI
make test # all tests
make vet
make verify-reproducible # build twice, byte-compareProject layout:
cmd/veil/, CLI entry pointcmd/veil-gui/, Wails GUIinternal/engine/, namespace + chain lifecycleinternal/backends/, wireguard, openvpn, tor, socks5, http, tlsmitminternal/persona/, persona model + forge + bundled defaultsinternal/launcher/, app launch + persona applicationinternal/audit/, security event log + crash reportsinternal/validate/, input validationinternal/osutil/, atomic file writes
veil is provided "as is", with no warranty of any kind, and is a privacy
tool — not a guarantee. The authors accept no liability for any damages —
including, without limitation, an IP or DNS leak, a kill switch that fails to
contain traffic, deanonymization, or data loss — arising from use of veil.
Verify your own setup (veil doctor, veil selftest <profile>), understand the
threat model (docs/SPEC.md), and use at your own risk. See LICENSE for the
full terms.
Found a bug? Please report it — veil bug-report, or open an issue at
https://github.com/mstampfli/veil/issues. Bug reports genuinely help.
Veil free edition: PolyForm Noncommercial 1.0.0 (source-available — use, modify, and contribute for noncommercial purposes; commercial use requires a separate license). See LICENSE. Third-party notices: THIRD_PARTY_NOTICES.
Privacy of the Pro license. The free edition makes zero network calls. Pro validates its license fully offline; its only network actions are manual updates (veil update) and a single activation ping on veil license install. That ping carries your license token and a one-way hash of your machine-id (no usage data, not reversible, not your hardware) so the seller can see if a license is being shared widely. It is logging only: there is no device cap, nothing is ever blocked, and Pro works offline/airgapped/firewalled regardless. Use it on your own machines; veil license deactivate removes one from the record.
Veil is not affiliated with, endorsed by, or related to Mozilla, Brave Software, The Tor Project, Mullvad, or Google. "Tor", "Brave", "Firefox", "Chrome", and other names referenced are trademarks of their respective owners.