VEIL
Beta · we're testing this in the wild

Cloak the devices you can't install software on.

Veil makes your services go dark to the public internet — no open ports, nothing to scan, brute-force, or exploit — while staying reachable by a verified identity. The CloakBox is that protection as a box you plug in and forget.

Veil CloakBox appliance — matte black with a green light bar and shield mark
What it is

The connector, now hardware.

Today, Veil cloaks your services with a small software connector you install. The CloakBox is that same connector as a plug-and-play box. You drop it onto your network and it dials out — giving your gear a private, identity-gated path. No agents to deploy, no software on the device, no inbound ports to open. Then you close the old public exposure, and what was exposed goes dark.

What it's for

Cloak the gear you can't put software on.

Not every device can run a connector. Industrial controllers, PLCs, IP cameras, printers, NAS boxes, building systems, legacy machines that will outlive three IT teams — you can't install anything on them, and you definitely can't leave them exposed. The CloakBox sits in front of them and pulls them into the dark. The device stays exactly as it is; the attack surface goes to zero.

The un-agentable

Designed for OT/ICS, PLCs, cameras, printers, NAS and legacy gear — anything with an IP that you can't (or shouldn't) install software on.

Break-glass lifeline · optional

Add an independent 4G/LTE path so you're never locked out. If the primary link dies, you still reach the box — and everything behind it — over a separate lane. Break-glass, not back-door: same zero-trust rules, second physical path.

The lineup

One vision. Two versions.

Same white-box software, same account, same dark-by-default posture — the only thing that changes is capacity. Start on Lite; step up to Pro when a site has more users or more throughput. Both show up in your dashboard as a device with its own id and live status.

CloakBox Lite (Raspberry Pi 5) beside CloakBox Pro (Intel N100), with rear I/O detail

CloakBox Lite · Raspberry Pi 5

1× GbE · a few hundred Mbps · hundreds of sessions · optional 4G. Compact and low-power — perfect for smaller sites & edge: admin panels, NAS, OT/legacy gear.

CloakBox Pro · Intel N100

2× 2.5GbE · ~1–2.5 Gbps · thousands of sessions · optional 4G. More power, more users — for busy sites, OT gateways, and high-availability pairs.

How it works

Three steps. Then it's dark.

1

Plug it in

Connect the CloakBox to your network, in front of the gear you want to protect.

2

It dials out

The box opens an outbound connection only. No inbound ports. Nothing to open, forward, or expose.

3

You close the public door

With the box carrying an identity-gated path to your gear, you remove its inbound exposure — the port-forward or open firewall rule. Now it answers only a verified identity, and a scanner finds nothing.

Who it's for

Built for the people who can't afford an open port.

NIS2-obligated SMBs

Shrink your attack surface to nothing — and show it — without ripping out the OT and legacy gear you already run.

MSPs

A repeatable box you ship to every client site: same deployment, same dark posture, less to babysit.

OT & industrial

Protect controllers, sensors and legacy systems that were never meant to face the internet — without touching the devices.

Honest beta

This is early. We want partners, not spectators.

The CloakBox is in active beta. The cloaking core it's built on is already live with real users — but this hardware is new, and we're shaping it hand-in-hand with the first teams to deploy it. We're being straight with you: specs, packaging, and pricing aren't final, and we won't promise a ship date we can't keep. What we offer is a real seat at the table — early units, direct access to the team, and outsized influence over what this becomes.