Veilo for Teams

One leaked key.
Ten developers.
Zero visibility.

Your developers may be careful. You have no way to know. Veilo catches credentials, PII, and security issues before any git push — on every machine, without any data leaving it. Team seats give you the keys to distribute and revoke.

config/production.env
AWS_SECRET_ACCESS_KEY = "" ■ BLOCKED
veilo intercepted an AWS secret before commit — key never reached the remote.

Individual tools don't give you a team view.

A developer installing a personal secret scanner is better than nothing. But each person's setup is different, and yours is unknown to you. One missed install, one ignored warning, one personal laptop — and the leak comes from your codebase.

Without Veilo team seats

  • No way to know which devs have protection enabled
  • No enforcement — tools are opt-in per machine
  • One contractor, one new hire, one missed install
  • Breach discovered in git history, not at commit time
  • No ability to revoke a compromised key post-rotation

With Veilo team seats

  • You distribute the keys — coverage is explicit
  • Each seat activates the same protection, same ruleset
  • Commit hook blocks pushes at the source, not in CI
  • Revoke a seat immediately if a device is lost or off-boarded
  • Zero data sent anywhere — air-gap friendly

Buy once. Distribute keys. Done.

Team licenses are intentionally simple in Phase 1. Each seat is an independent license key — no central server required for the detection itself.

1

Purchase N seats on Gumroad

Set the quantity to your team size. You'll receive N independent license keys in a single email, clearly numbered and ready to forward.

2

Forward one key to each developer

Each key is self-contained. Developers open VS Code, run Ctrl+Shift+P → Veilo: Enter License Key, and paste their key. Activation is instant and offline.

3

Every commit is protected from that moment

Veilo's pre-commit hook runs on every git commit. Secrets, PII, and security patterns are caught before they reach the remote — on the developer's machine, not in CI.

4

Off-board a developer? Email us to revoke.

In Phase 1, revocation is handled manually — email zein.saleh1994@gmail.com with the seat to revoke and it's disabled within one business day.

Self-service revocation dashboard coming soon

Simple tiers. No per-seat SaaS contracts.

Free

$0

Forever free, no card required


  • Secret & credential detection
  • Inline underlines in VS Code
  • PII detection
  • Security pattern detection
  • Auto-fix suggestions
  • Commit blocking
  • Team seat management
Install free

Team

$500 / 25 seats

$20/seat — one-time payment


  • Everything in Pro, per seat
  • N keys delivered in a single email
  • Revocation on request (same-day)
  • Self-service seat dashboard (coming soon)
  • Priority support via email
  • VSIX delivery for air-gapped installs
Buy team seats

The scanner never calls home. Here's exactly what does.

A security tool that phones home is its own attack surface. We've designed Veilo so the detection engine has no network access, by construction.

Detection runs 100% locally

Every scan is a regex engine running in the VS Code extension process. No LLM, no cloud API, no outbound call. File contents never leave the machine — not even to our servers.

Zero telemetry

We don't collect usage metrics, error reports, or any analytics. The extension has no telemetry instrumentation. You can verify this by inspecting the VSIX — it's a zip file.

License check is the only outbound call

Activation sends a signed key to veilo-ext.fly.dev for validation — nothing else. The payload contains a key hash, not your file contents or editor state. Checked once at activation, then verified locally from cache.

Air-gap & VSIX installable

Teams in restricted environments can install Veilo directly from the VSIX bundle without hitting the VS Code Marketplace. Email us and we'll send the file alongside your license keys.

Ready to put a lock on every commit?

Buy seats and your team is protected the same day. For larger rollouts, custom seat counts, or MSP deployments, reach out directly.