Public beta privacy
Private from public Git.
Honest about every other boundary.
This page describes Veil v0.3.0. It is a product boundary, not a promise of forensic secrecy or hardened containment.
Local work
Local Veil workflows keep captured changes in encrypted local state and do not require a hosted account. Managed workspaces contain plaintext while you or an authorized coding harness works. Your operating-system account, host administrator, editor, local tools, repository scripts, and authorized model provider may see that plaintext.
Optional hosted dashboard
When you connect an organization, Veil may receive allowlisted operational metadata such as opaque identifiers, surface, operation type, outcome, duration, device status, quota usage, and timestamps. Dashboard metrics do not include source code, prompts, plaintext objectives, repository paths or names, diffs, model output, Codex credentials, GitHub credentials, cookies, or tokens.
Encrypted Connector dispatch
Private objectives and dispatch context are encrypted to a paired device public key and bound to the tenant, device, job, idempotency key, and expiry. Hosted infrastructure stores the authenticated ciphertext and bounded delivery metadata. The paired foreground Connector shows request context and requires local terminal approval before decryption and execution. Closing or revoking the Connector prevents new local work from starting.
Retention and deletion
Organization event retention defaults to 30 days and may be shortened to 1–30 days. If the 50-organization beta cap is reached, waitlist consent and verified email are retained for no more than 90 days. Organization deletion immediately suspends sessions, devices, and jobs, schedules permanent hosted-data purge after seven days, and does not claim forensic erasure from backups, local devices, provider systems, memory, swap, or storage media.
Publication
Hosted dispatch never authorizes publication. Veil does not create a public Git branch or pull request until the current local result satisfies its publication policy and you explicitly confirm the exact patch or draft PR using local GitHub credentials. Results without a configured recipe remain labeled unchecked.
Current isolation limits
The public beta does not claim protection from the local OS account, proven host-wide read isolation on macOS or Linux, production containment for hostile repositories, end-to-end secrecy from an authorized model provider, operator-blind execution, or forensic erasure. Use only repositories and verification commands you trust.
Contact
Privacy and best-effort beta support: useveil.dev@gmail.com.