Tunnel Sovereign
Communication authority for contested environments.
Tunnel Sovereign gives an organization control of its infrastructure, enrollment, mission relationships and device authority. Message keys stay on authorized endpoints.
System signature: four security domains and the boundary between them
- HOLDS
- Signing key. Decides who may reach whom, in which direction, until when.
- CANNOT
- Cannot derive a payload key. Holds no agreement or decapsulation surface.
- HOLDS
- Agreement and decapsulation keys. Derive the payload key locally.
- CANNOT
- Cannot issue authority to themselves or to anyone else.
- HOLDS
- Ciphertext, a routing alias, a size and a time.
- CANNOT
- Cannot read content. Never receives the authorization graph.
- HOLDS
- The property the three above produce together.
- CANNOT
- No single party can both permit a conversation and read it.
Authorization is a signature. Content confidentiality comes from a key agreement. They are different key roles, on different curves, with different lifetimes, and holding the first can never produce the second.
Complete mission communications
One platform for the complete mission communication lifecycle.
Tunnel Sovereign brings communication, identity, authority, operational continuity and sovereign infrastructure into one governed system.
COMMUNICATE
- Messaging
- Files
- Private voice notes
- Voice and video
- Mission rooms
GOVERN
- Enrollment
- Devices
- Mission authority
- Compartments
- Policy and revocation
OPERATE
- Connected
- Intermittent
- Disconnected
- Store-carry-forward
- Transport integration
DEPLOY
- Managed
- Sovereign
- Private cloud
- On-premises
- Air-gapped
All four domains are governed as one platform, under one authority model.
The operational problem
Encryption is settled. Authority is the open question.
A secure messenger encrypts well. It leaves unanswered who operates the infrastructure, who decides which devices exist, who may reach whom, and what holds when a device is captured. Those decisions sit with the vendor by default.
Control
Four decisions that belong to the organization.
Each is a separate boundary, with its own enforcement and its own consequence if it sits somewhere else.
Infrastructure
- Controlled by
- You, or Tunnel under a managed agreement
- If held elsewhere
- Traffic transits infrastructure you do not govern
- Enforced by
- Deployment artifact separation at build time
Enrollment
- Controlled by
- Your enrollment authority
- If held elsewhere
- A device you never admitted can exist in the deployment
- Enforced by
- Device-bound credentials
Mission authority
- Controlled by
- You, per mission and per direction
- If held elsewhere
- A relationship you never authorized can form
- Enforced by
- Signed, directional, expiring authority
Message keys
- Controlled by
- Authorized endpoints only
- If held elsewhere
- Someone other than the endpoints can read content
- Enforced by
- Key derivation on the endpoint
EPOCH
Policy epoch
Advances when the rules governing a mission change. Authority issued under an earlier policy no longer applies.
EPOCH
Delivery epoch
Rotates the addressing under which material is carried. Aliases from a previous epoch stop resolving.
EPOCH
Identity epoch
Advances when a device's standing changes, including replacement and withdrawal.
The three advance independently and are always labeled separately, so an operator can tell which one moved.
Under compromise
What holds when something is taken.
A security claim is only useful if it survives a bad day.
Control over who may communicate stays separate from the ability to read what they communicate.
If the relay is seized
If a device is captured
If the network is hostile
An adversary holding an unlocked device with content on screen has defeated the cryptography, and a disconnected device cannot apply a revocation it has not received.
The operational model
One encrypted unit, carried under scoped authority.
Communication is protected as a Secure Mission Bundle: an encrypted package carrying its own authorization, policy and expiration. It crosses a network or a physical carry without changing form.
01
Mission authority
An organization creates a mission and admits the devices that may take part.
Tunnel CommandAUTHORITY DOMAIN
02
Directional authorization
One signed authorization permits one direction, for one capability, until an expiry. A reply needs its own.
Tunnel CommandAUTHORITY DOMAIN
03
Endpoint key agreement
The two endpoints derive the payload key themselves, combining an X25519 agreement with an ML-KEM-768 decapsulation.
Tunnel MobileCUSTODY DOMAIN
04
Opaque relay custody
Sealed material is held, scheduled, forwarded and expired. The relay carries what it cannot open.
Tunnel RelayCUSTODY DOMAIN
Tunnel Command issues authority and holds no key that can decrypt mission content. Tunnel Relay holds ciphertext and holds no key either. The two capabilities are separated by construction, not by policy.
Compartmentation
Authority to communicate creates no permanent relationship.
An operator holds a separate mission-scoped identity in each mission. Authorization is directional, bound to the device it was issued to, and expires on its own.
Network conditions
Built for links that are intermittent, contested or absent.
The Tactical Profile is how the platform operates when connectivity cannot be assumed. It is a profile of the same product, not a second application.
Connected
Intermittent
Absent
Queued ciphertext survives device restart. Delivery resumes when the operating environment permits Tunnel to execute after secure unlock.
Evidence
Every claim here has a boundary attached.
Each capability is published with the limit that qualifies it, so an evaluator can check it rather than discover it.
Executive briefing
A technical review, conducted under your constraints.
The briefing covers the trust model, the deployment boundary and the evidence behind each claim, with an engineer present.