Hostveil / Docs

Hostveil documentation

Hostveil finds the security mistakes on your self-hosted Linux server, explains them in plain language, and fixes them safely — with a preview, a backup, and one-command rollback. One binary, no config file, no cloud account.

Self-hosting is booming, and a single misconfiguration on a home server — Jellyfin, Nextcloud, a game server, a self-hosted AI agent like OpenClaw or Hermes Agent — can turn into a serious breach. Hostveil is a guided hardening tool for exactly those hosts. Point it at a Linux server: it scans the highest-impact areas, merges everything into one 0–100 score, explains each finding without jargon, and walks you through fixing it — showing the exact change, backing up the original first, and letting you undo any fix with one command.

The safety model

Nothing is changed blindly. Every fix is previewed before it runs, the original file is backed up to a checkpoint, and hostveil rollback restores it byte-for-byte. Every interface drives the same engine, so a fix applied anywhere is reversible everywhere.

Where the criteria are

Every judgement Hostveil makes is written down somewhere you can check it.

Auto-fix, Review and Manual: the three tests a fix has to pass, and the four steps that settle which kind you are shown.
High, Medium and Low: the three definitions, and what each domain is worth.
The score: the arithmetic in full, a worked example from a real scan, and what a given score is called.
The names in --json and SARIF: every value a machine reads.

New here? Start with these

Reference