Oracle Veil

Security

Oracle Veil does not distribute executable files, request passwords, process payments, or ask for cryptocurrency wallet information.

The production site uses encrypted HTTPS connections, a restrictive content policy, same-origin request checks, input allowlists, request-size limits, and no third-party advertising scripts. The Gemini credential stays in the server environment and is never included in browser code.

Questions and generated interpretations are intentionally excluded from persistent browser storage and service-worker caching. The site still depends on its hosting and AI providers, so no internet service can promise absolute security or availability.

Report a vulnerability

Please submit a private report through GitHub Security Advisories. Include the affected URL, the behavior you observed, and a minimal reproduction. Do not include real passwords, API keys, payment information, or other people’s personal data.

The machine-readable disclosure policy is available at /.well-known/security.txt.