Veil makes your services go dark to the public internet — no open ports, nothing to scan, brute-force, or exploit — while staying reachable by a verified identity. The CloakBox is that protection as a box you plug in and forget.

Today, Veil cloaks your services with a small software connector you install. The CloakBox is that same connector as a plug-and-play box. You drop it onto your network and it dials out — giving your gear a private, identity-gated path. No agents to deploy, no software on the device, no inbound ports to open. Then you close the old public exposure, and what was exposed goes dark.
Not every device can run a connector. Industrial controllers, PLCs, IP cameras, printers, NAS boxes, building systems, legacy machines that will outlive three IT teams — you can't install anything on them, and you definitely can't leave them exposed. The CloakBox sits in front of them and pulls them into the dark. The device stays exactly as it is; the attack surface goes to zero.
Designed for OT/ICS, PLCs, cameras, printers, NAS and legacy gear — anything with an IP that you can't (or shouldn't) install software on.
Add an independent 4G/LTE path so you're never locked out. If the primary link dies, you still reach the box — and everything behind it — over a separate lane. Break-glass, not back-door: same zero-trust rules, second physical path.
Same white-box software, same account, same dark-by-default posture — the only thing that changes is capacity. Start on Lite; step up to Pro when a site has more users or more throughput. Both show up in your dashboard as a device with its own id and live status.
1× GbE · a few hundred Mbps · hundreds of sessions · optional 4G. Compact and low-power — perfect for smaller sites & edge: admin panels, NAS, OT/legacy gear.
2× 2.5GbE · ~1–2.5 Gbps · thousands of sessions · optional 4G. More power, more users — for busy sites, OT gateways, and high-availability pairs.
Connect the CloakBox to your network, in front of the gear you want to protect.
The box opens an outbound connection only. No inbound ports. Nothing to open, forward, or expose.
With the box carrying an identity-gated path to your gear, you remove its inbound exposure — the port-forward or open firewall rule. Now it answers only a verified identity, and a scanner finds nothing.
Shrink your attack surface to nothing — and show it — without ripping out the OT and legacy gear you already run.
A repeatable box you ship to every client site: same deployment, same dark posture, less to babysit.
Protect controllers, sensors and legacy systems that were never meant to face the internet — without touching the devices.
The CloakBox is in active beta. The cloaking core it's built on is already live with real users — but this hardware is new, and we're shaping it hand-in-hand with the first teams to deploy it. We're being straight with you: specs, packaging, and pricing aren't final, and we won't promise a ship date we can't keep. What we offer is a real seat at the table — early units, direct access to the team, and outsized influence over what this becomes.