Veiled OriginVeiledOrigin
Security · Data Handling

Nothing leaves your host. Not by policy — by architecture.

Veiled Origin's tools are local-first by design. Your PI tag and SCADA data stays on the host you run them on. There is no cloud to send it to, no telemetry channel, and no account to create — that isn't a setting you have to trust us to honor, it's how the software is built.

0Data leaves your host
0Telemetry channels
0Accounts to create
YESAirgap compatible
Local by design, not by configuration

What the software does — and never does.

Every claim below is about how the shipping products behave on your machine. These are properties of the build, not promises we ask you to take on faith.

Architecture

Local-only, on the host

All tag capture, storage, and export runs in your browser (chrome.storage.local) and your local Excel installation. Your SCADA and PI tag data stays on the host by default — nothing is sent to a remote server.

Telemetry

Zero telemetry

No analytics libraries. No crash reporting. No feature-usage counters. No phone-home on install, launch, or exit. We have no way to see that you use the product — by design.

Accounts

No account, no cloud storage

The browser extension installs anonymously. The Excel add-in activates with a license file (email or USB delivery) — no online activation, no server round-trip. There is nowhere for your data to be stored off-host.

Airgap

Airgap compatible

Works fully offline once installed. License delivery via email attachment or physical media. Custom redistributable builds are available for fully-isolated networks.

Dependencies

No third-party runtime calls

The product code does not load any third-party scripts at runtime. The marketing website loads fonts — but only while you're on veiledorigin.com. The shipping products don't touch the internet.

Internal · the proof

Origin Admin Console

Our internal PI administration console — diagnostics, provisioning, and audit — was rebuilt ground-up to be secure by design. It's the discipline behind everything else on this page.

The architecture ↓
Origin Admin Console · Internal

Command execution is designed to be command-injection-free by construction — not by sanitizing inputs after the fact.

Argv-only execution

Commands are dispatched as discrete argument vectors, never assembled into a shell string — there is no shell for an injected fragment to reach.

Allow-list validation

Only known, enumerated operations are accepted. Anything outside the allow-list is refused before it can run, rather than filtered after.

Loopback-only

The console binds to the local host only. It exposes no remote listener and no network surface for an outside caller to reach.

Audit log

Every provisioning and administration action is recorded, so what ran — and who ran it — is reconstructable after the fact.

Confirmation gates

Destructive operations require an explicit confirmation step. Nothing consequential happens on a single, unguarded action.

On-host by default

Like the rest of the suite, the console runs where you run it — no telemetry, no off-host storage, and the same local-first posture throughout.

Data handling

What runs where.

Component by component, here is exactly what each part of the product reads, where it writes, and how it updates.

Storage · chrome.storage.local · Network · none

Browser extension — Origin Companion for PI Vision

Chrome and Edge extension. Reads tag data from the PI Vision pages you actively browse and stores captured tags locally in the browser (chrome.storage.local). Extension permissions are justified on the privacy page.

Captured data persists in local browser storage until you clear it (an explicit "Clear" action), switch profiles, uninstall, or clear browser data. We have no way to retain it even if we wanted to.

Input · PIBytez-Sync.json · I/O · local filesystem

Excel add-in — Origin Companion for Excel + Origin Migrate

VSTO add-in for Microsoft Excel (Windows). Reads tag data from PIBytez-Sync.json (the Companion's sync file) in your Downloads folder and generates PI DataLink formulas and (for Origin Migrate) PI Builder-ready workbooks. All input and output is local filesystem.

Signed before distribution · cert on request

Code signing

The Excel add-in and its VSTO manifest are code-signed before distribution. Signing certificate details are provided on request.

Extension · policy-controlled · Add-in · manual

Updates

Browser extension updates come through the Edge Add-ons Store auto-update channel and can be disabled by policy. The Excel add-in updates via manual installer download — you control the timing.

Procurement & infosec

Built for regulated industrial environments — where data governance is regulatory, not optional.

PO & invoicing

Single-source purchase orders and quarterly invoicing accepted.

Site licenses

Unlimited seats within a facility under one site license.

Offline license delivery

License files delivered via email or USB — no online activation.

Airgap builds

Custom redistributable builds for fully-airgapped networks.

Source-code escrow

Available for high-value contracts (quote required).

Security review docs

Security review documentation provided on request — [email protected].

Enterprise

Need a security review?

We'll send the documentation your infosec and procurement teams need — architecture posture, data handling, and signing details.