Cloak the devices you can't install software on

Plenty of gear can't run a connector: PLCs and industrial controllers, IP cameras, printers, NAS boxes, building systems, and legacy machines that will outlive three IT teams. You can't install anything on them, and you can't leave them facing the internet either. The answer is to put the connector next to them instead of on them — a box on the same LAN that dials out to the Veil overlay and publishes those devices as dark services. The device is untouched, its internet reachability goes to zero, and only a verified identity can reach it. That's exactly what the CloakBox does, as a plug-and-play appliance.

Frequently asked questions

How do you cloak a device you can't install software on?

You don't install anything on the device. You put a connector on the same network — a small host, or the plug-and-play CloakBox appliance — that can reach the device over the LAN. It dials outbound only, publishes the device as a dark service on the overlay, and you close the device's inbound exposure. The device stays exactly as it is.

Does traffic for everything else go through the box?

No. The box only carries sessions to the services it cloaks — a PLC, a camera, a NAS. Normal internet traffic on the network doesn't touch it; it isn't a router for everything, it's a connector that hosts specific dark services.

What if the box or its link fails — am I locked out?

The connector auto-reconnects (it only dials outbound), and the control plane is always reachable, so most blips self-heal. For the rare hard failure keep an out-of-band path — a cloud/IPMI console, or the CloakBox's optional 4G lifeline — exactly as you would with any remote-access system.

Sources: Veil CloakBox (beta) · CyberLeveling — EU internet exposure research

Back to the Veil blog