If you run agents or scripts, you have already leaked a key into a prompt, a log, or a repo. Veil is the fix that stays on your machine. Unlock once. Point Veil at the names the child needs. The child gets environment variables. Veil never prints the value. There is no get. There is no network. There is no company holding your vault. Not a password manager. Not a cloud. Not HASP. One job: the work can use the secret. The chat cannot. Free. GPL-3. You hold the passphrase.
Hey Product Hunt — maker here. I build as VesperRun.
I was tired of the same stupid leak. You give an agent a key so it can call GitHub or OpenAI. Ten minutes later the key is in the chat, the log, or a file the agent just wrote. The model did the work. The transcript kept the password.
Veil is the tool I wanted on my own disk:
• You save a name, not a message in a thread
• You unlock a session
• veil run starts one process with only the env it needs
• You lock. Memory is wiped
The agent can finish the job. It does not get a copy to quote back to you.
It does not call a model. It does not phone home. It is not a platform. The child can still read os.environ — we do not pretend otherwise. We pretend nothing. We keep the key out of the one place that keeps getting it: the chat.