Skip to content

VEIL specification / overview · v0.1.0

VEIL, written
down in full.

The protocol behind private lanes on Verify Route: attestation, transport, blind credits, receipts and measured policy, as an open draft anyone can review or implement.
The VEIL specification is an open draft published so anyone can review or implement it. Nothing described here is deployed by the router yet unless a section says otherwise.
Status
Draft
Version
0.1.0
Updated
2026-09-30
License
Apache-2.0 (specification text)

Documents

The specification is split into five numbered documents and a changelog. Each can be read on its own.

Lanes

LanePathPayment
standardTLS to the router, then to a bonded providerKey, USDG balance or per-call
attestedSealed to an enclave with a fresh quoteKey, USDG balance, per-call or blind credit
blindOblivious relay, then sealed to an enclaveBlind credits only

Guarantees (design targets)

  1. Every attested answer traces to a published image and weight digest.
  2. No party outside the enclave reads prompts on attested lanes.
  3. Blind-lane payments do not link to a wallet.
  4. Missing or stale evidence refuses a call instead of downgrading it.
  5. Receipts verify offline with published keys and on-chain anchors.

Parties

PartyLearnsDoes not learn
ClientEverything about its own call—
RelayClient addressContent, model
RouterModel, lane, size, costSealed content; address on the blind lane
EnclaveContent, in memoryWho paid, with blind credits

Honest limits

  • Hardware trust roots and firmware flaws bound every guarantee.
  • Traffic analysis can link requests at low volume.
  • Attestation shows what code runs, not that it is correct.

Status

Draft 0.1.0. Not deployed. Machine-readable status is at /veil/status.json; the design overview is on the VEIL page.

License

The specification text is offered under the Apache License 2.0 so that anyone may implement it.