VEIL specification / overview · v0.1.0
VEIL, written
down in full.
The protocol behind private lanes on Verify Route: attestation, transport, blind credits, receipts and measured policy, as an open draft anyone can review or implement.
The VEIL specification is an open draft published so anyone can review or implement it. Nothing described here is deployed by the router yet unless a section says otherwise.
- Status
- Draft
- Version
- 0.1.0
- Updated
- 2026-09-30
- License
- Apache-2.0 (specification text)
Documents
The specification is split into five numbered documents and a changelog. Each can be read on its own.
Lanes
| Lane | Path | Payment |
|---|---|---|
| standard | TLS to the router, then to a bonded provider | Key, USDG balance or per-call |
| attested | Sealed to an enclave with a fresh quote | Key, USDG balance, per-call or blind credit |
| blind | Oblivious relay, then sealed to an enclave | Blind credits only |
Guarantees (design targets)
- Every attested answer traces to a published image and weight digest.
- No party outside the enclave reads prompts on attested lanes.
- Blind-lane payments do not link to a wallet.
- Missing or stale evidence refuses a call instead of downgrading it.
- Receipts verify offline with published keys and on-chain anchors.
Parties
| Party | Learns | Does not learn |
|---|---|---|
| Client | Everything about its own call | — |
| Relay | Client address | Content, model |
| Router | Model, lane, size, cost | Sealed content; address on the blind lane |
| Enclave | Content, in memory | Who paid, with blind credits |
Honest limits
- Hardware trust roots and firmware flaws bound every guarantee.
- Traffic analysis can link requests at low volume.
- Attestation shows what code runs, not that it is correct.
Status
Draft 0.1.0. Not deployed. Machine-readable status is at /veil/status.json; the design overview is on the VEIL page.
License
The specification text is offered under the Apache License 2.0 so that anyone may implement it.