TECHNOLOGY & PRIVACY

Behind your
connection.

Our app. Our infrastructure. Our protocol.

Explore the architecture behind Veilora, and the information available to understand your privacy.

Explore Veilora 2.0 →
Conceptual architecture

THREE FOUNDATIONS

Designed to work together.

01

Veilora App

Our own application, with release information published when available.

02

Veilora 2.0

A published reference architecture for control, sessions and traffic handling.

03

Encrypted nodes

Encrypted node infrastructure developed in-house. Deployment details remain to be confirmed.

FOLLOW THE CONNECTION

From a request to a connection.

A simplified reading of the Veilora 2.0 reference model—not a live connection monitor.

  1. Authorize

    Check identity, permissions and configuration.

  2. Establish

    Establish the connection and confirm session parameters.

  3. Transfer

    Handle routing and TCP or UDP traffic in the reference model.

  4. Close

    Release session state and connection resources.

VEILORA 2.0

Inside the connection.

Two responsibilities. One coordinated architecture. Explore the design before going deeper into the 22 reference processing stages.

CONTROL PLANE

Define how a connection begins.

Identity, permissions, configuration and session coordination establish the conditions for a connection.

DATA PLANE

Handle the traffic that follows.

Routing, encapsulation, forwarding and cleanup handle application traffic within the model.

DNS and domain decisions

The resolver path is chosen alongside routing rules. A local destination may use local resolution; a tunneled destination may require resolution through a protected path. The domain-to-address relationship helps later routing decisions.

Define IPv4 and IPv6 handling, cache lifetime, fallback rules and cache invalidation after a network change. DNS privacy cannot be inferred solely from an encrypted data tunnel.

Traffic classification and routing

A routing engine evaluates destinations and rules to choose direct, tunnel or block. Inputs may include domain, address, port, application, transport and user-defined policy.

Direct traffic uses the local network. Tunneled traffic goes to a node. Blocked traffic is rejected. These are design actions, not a claim that ad or malware filtering is already available.

TCP forwarding and closure

A TCP flow needs ordered bidirectional delivery and explicit success, failure and closure states. The node attempts the target connection, reports the result, and then forwards data in both directions.

Normal closure should account for each direction before releasing state. Errors should be returned to the application and confined to the affected logical connection where the architecture allows.

UDP associations and transport choices

Datagrams retain message boundaries and a relationship to their source, destination and timeout state. Possible carriers include native UDP, a reliable tunnel or a QUIC-based design, each with different network and latency tradeoffs.

UDP-over-TCP can introduce head-of-line blocking. Native UDP depends on network reachability. No automatic transport switching or QUIC support is asserted as deployed here.

Logical streams or separate connections

A session may carry several logical streams, or applications may use separate underlying connections. Multiplexing can reduce repeated setup; separate connections can improve failure isolation at the cost of additional handshakes.

A mixed design may separate bulk transfers from small requests. The actual Veilora 2.0 stream architecture remains an implementation detail to be specified.

Frame encapsulation

Conceptual frames associate payload with version, frame type, session, stream, sequence and length information, plus integrity protection. A receiver needs clear size and state limits before processing them.

The frame names below are explanatory labels only. They do not define numeric opcodes, byte order, offsets or interoperable wire encoding.

Reference design. Deployed specifications and release behavior require implementation documentation.

PROTOCOL CHOICES

Choose with context.

Veilora 2.0, WireGuard, OpenVPN and IKEv2/IPsec address connection design in different ways. Network conditions, deployment and platform implementation matter.

Our guide separates VPN protocols from proxy platforms and explains the comparison boundaries. It does not claim a universal performance winner.

Explore the protocol guide →

PRIVACY & TRANSPARENCY

Privacy, with context.

AVAILABLE

Audit summary

Read the reported findings, operator-confirmed service coverage and limitations of the 2026 report. The summary is not a newly issued audit report.

Read the audit summary →
REFERENCE MATERIAL

Technical disclosures

Architecture notes explain the design model. Node locations, measured performance and detailed deployed specifications have not been published here.

Review the reference design →
AVAILABLE

Privacy policy

Read what the website handles, why it is used, your rights, and where release-specific VPN disclosures begin.

Read the privacy policy →

FROM DESIGN TO YOUR NEEDS

Technology with
a personal brief.

Bring your connection environment, app requirements and setup questions into one conversation.

Our services include connection solutions, app customization and one-to-one setup guidance. Scope, supported platforms and delivery arrangements are confirmed per project.

Explore customization services →

VEILORA / AUDIT FINDINGS

Activity logs and service data.

Veilora coverage is confirmed by the operator. This summary refers to VPNTestor’s verification dated 29 July 2026; conclusions apply only within that review’s scope and date.

Activity records

The review found no persistent browsing, DNS, source-IP or individual connection histories in the inspected systems.

Limited service data

Daily traffic totals: approximately two months. Historical account/order records: three-month cleanup cycle. Voluntary diagnostics: up to 14 days.

Interpretation

No activity logs does not mean no data processing. File signatures establish integrity, not independent proof of every underlying claim.

Source: VPNTestor verification report, version 1.0. Brand summary; not a reissued report or formal privacy policy.

QUESTIONS, ANSWERED

A little more clarity.

Visit the help center →
Is this a production specification?

The technical notes describe a reference architecture. Wire formats, deployed transports and platform-specific behavior must be confirmed in release documentation.

Which platforms are available?

Check Downloads for confirmed releases. App Store and Google Play entries are currently not yet available.

What happens when the network changes?

The reference model discusses timeouts, session recovery and cleanup. Actual reconnection and traffic-blocking behavior depends on the released implementation.

Does encryption alone protect DNS?

No. DNS resolution and routing must be considered together. An encrypted data tunnel alone does not establish how every DNS request is handled.

What does the audit summary cover?

It describes reported findings, service coverage confirmed by the operator, and the report’s limits. It is not a substitute for the report or a formal privacy policy.

Are logging and retention details final?

Read the website privacy policy and audit summary for available information. Release-specific app and deployment disclosures will be published with an available product.

Can the app or connection be customized?

Veilora offers app customization, connection solutions and one-to-one setup guidance. Features, platforms and delivery scope are agreed for each project.

Does a VPN guarantee complete security?

No. A VPN is one part of digital safety. It cannot guarantee the security of accounts, wallets or transactions, and does not replace careful device and application security.