Tunnel Sovereign

Communication authority for contested environments.

Tunnel Sovereign gives an organization control of its infrastructure, enrollment, mission relationships and device authority. Message keys stay on authorized endpoints.

System signature: four security domains and the boundary between them

01AUTHORITY
HOLDS
Signing key. Decides who may reach whom, in which direction, until when.
CANNOT
Cannot derive a payload key. Holds no agreement or decapsulation surface.
02ENDPOINTS
HOLDS
Agreement and decapsulation keys. Derive the payload key locally.
CANNOT
Cannot issue authority to themselves or to anyone else.
03RELAY
HOLDS
Ciphertext, a routing alias, a size and a time.
CANNOT
Cannot read content. Never receives the authorization graph.
04OPAQUE CUSTODY
HOLDS
The property the three above produce together.
CANNOT
No single party can both permit a conversation and read it.

Authorization is a signature. Content confidentiality comes from a key agreement. They are different key roles, on different curves, with different lifetimes, and holding the first can never produce the second.

Complete mission communications

One platform for the complete mission communication lifecycle.

Tunnel Sovereign brings communication, identity, authority, operational continuity and sovereign infrastructure into one governed system.

COMMUNICATE

  • Messaging
  • Files
  • Private voice notes
  • Voice and video
  • Mission rooms

GOVERN

  • Enrollment
  • Devices
  • Mission authority
  • Compartments
  • Policy and revocation

OPERATE

  • Connected
  • Intermittent
  • Disconnected
  • Store-carry-forward
  • Transport integration

DEPLOY

  • Managed
  • Sovereign
  • Private cloud
  • On-premises
  • Air-gapped

All four domains are governed as one platform, under one authority model.

The operational problem

Encryption is settled. Authority is the open question.

A secure messenger encrypts well. It leaves unanswered who operates the infrastructure, who decides which devices exist, who may reach whom, and what holds when a device is captured. Those decisions sit with the vendor by default.

Control

Four decisions that belong to the organization.

Each is a separate boundary, with its own enforcement and its own consequence if it sits somewhere else.

The operational authority model: for each of four control domains, who controls it, the consequence of it being held elsewhere, and what enforces it.

Infrastructure

Controlled by
You, or Tunnel under a managed agreement
If held elsewhere
Traffic transits infrastructure you do not govern
Enforced by
Deployment artifact separation at build time

Enrollment

Controlled by
Your enrollment authority
If held elsewhere
A device you never admitted can exist in the deployment
Enforced by
Device-bound credentials

Mission authority

Controlled by
You, per mission and per direction
If held elsewhere
A relationship you never authorized can form
Enforced by
Signed, directional, expiring authority

Message keys

Controlled by
Authorized endpoints only
If held elsewhere
Someone other than the endpoints can read content
Enforced by
Key derivation on the endpoint

EPOCH

Policy epoch

Advances when the rules governing a mission change. Authority issued under an earlier policy no longer applies.

EPOCH

Delivery epoch

Rotates the addressing under which material is carried. Aliases from a previous epoch stop resolving.

EPOCH

Identity epoch

Advances when a device's standing changes, including replacement and withdrawal.

The three advance independently and are always labeled separately, so an operator can tell which one moved.

The unified Tunnel platformTunnel Sovereign is one platform. Tunnel Mobile provides the native endpoint experience on Android and iOS. Tunnel Command governs organization administration, mission authority and device lifecycle. Tunnel Relay provides encrypted custody and delivery. All three are configured by a single deployment model, either Managed or Sovereign. The Tactical Profile runs operationally under Sovereign Deployment, where the customer holds the enrollment authority it depends on; a Managed deployment can host a controlled evaluation of the profile.TUNNEL PLATFORMTunnel MobileAndroid · iOSTunnel CommandNative desktopTunnel RelayCustody and deliveryOperators and endpointsAuthority and governanceTransport-independent carriageManagedTunnel-operatedSovereignCustomer-operatedTactical ProfileSovereign operation Managed evaluationDEPLOYMENT MODEL
One platform, three components, one deployment decision. The Tactical Profile is an operating profile of the same platform, not a separate product.

Under compromise

What holds when something is taken.

A security claim is only useful if it survives a bad day.

Control over who may communicate stays separate from the ability to read what they communicate.

If the relay is seized

Stored traffic is ciphertext and the infrastructure holds no payload decryption key. It never receives the authorization graph, so it cannot reconstruct who could reach whom.

If a device is captured

Its credentials are specific to it and are withdrawn without disturbing the operator’s other devices. Authority is bound to the device it was issued to, so a copy fails elsewhere.

If the network is hostile

Content and mission context stay inside the sealed section. Source address, timing and size remain observable at the network layer.

An adversary holding an unlocked device with content on screen has defeated the cryptography, and a disconnected device cannot apply a revocation it has not received.

The operational model

One encrypted unit, carried under scoped authority.

Communication is protected as a Secure Mission Bundle: an encrypted package carrying its own authorization, policy and expiration. It crosses a network or a physical carry without changing form.

The operational model in four stages. Stages one and two are issued by Tunnel Command in the authority domain. Stages three and four take place in the custody domain, where the payload key exists only on the endpoints. No stage gives Command or Relay the ability to decrypt.

01

Mission authority

An organization creates a mission and admits the devices that may take part.

Tunnel CommandAUTHORITY DOMAIN

02

Directional authorization

One signed authorization permits one direction, for one capability, until an expiry. A reply needs its own.

Tunnel CommandAUTHORITY DOMAIN

SECURITY DOMAIN BOUNDARYBelow this line the payload key exists. It exists only on the endpoints.

03

Endpoint key agreement

The two endpoints derive the payload key themselves, combining an X25519 agreement with an ML-KEM-768 decapsulation.

Tunnel MobileCUSTODY DOMAIN

04

Opaque relay custody

Sealed material is held, scheduled, forwarded and expired. The relay carries what it cannot open.

Tunnel RelayCUSTODY DOMAIN

Tunnel Command issues authority and holds no key that can decrypt mission content. Tunnel Relay holds ciphertext and holds no key either. The two capabilities are separated by construction, not by policy.

Compartmentation

Authority to communicate creates no permanent relationship.

An operator holds a separate mission-scoped identity in each mission. Authorization is directional, bound to the device it was issued to, and expires on its own.

Compartmented relationshipsOne operator holds a separate mission-scoped identity in each mission. In Mission A the operator is authorized to reach one counterpart, and that counterpart is separately authorized to reply. In Mission B the same operator is authorized to reach a different counterpart in one direction only. Neither authorization creates a permanent contact, and neither carries into the other mission. Each device holds only the authorizations naming itself, so no endpoint learns the shape of the mission.One operatorone devicetwo identitiesMISSION APseudonym A-1this operatorPseudonym A-2counterpartauthorizedauthorizedMISSION BPseudonym B-1same operatorPseudonym B-4different counterpartauthorizedno reply authority issuedmissions do not connect
Being authorized to communicate inside a mission does not expose a permanent identity, create a permanent contact, or authorize communication outside that mission.

Network conditions

Built for links that are intermittent, contested or absent.

The Tactical Profile is how the platform operates when connectivity cannot be assumed. It is a profile of the same product, not a second application.

Connected

Bundles are handed to relay custody as they are composed.

Intermittent

Bundles are held on the device until a permitted transport appears. Interrupted transfers resume.

Absent

Work continues without a network. A bundle collected after its validity window closes is refused rather than delivered late.

Queued ciphertext survives device restart. Delivery resumes when the operating environment permits Tunnel to execute after secure unlock.

Evidence

Every claim here has a boundary attached.

Each capability is published with the limit that qualifies it, so an evaluator can check it rather than discover it.

Executive briefing

A technical review, conducted under your constraints.

The briefing covers the trust model, the deployment boundary and the evidence behind each claim, with an engineer present.