Tunnel Sovereign

Sovereign communications. From command authority to the tactical edge.

Tunnel Sovereign unifies secure messaging, files, voice, video and mission coordination across mobile, desktop and customer-controlled infrastructure. Command governs who may communicate. Authorized endpoints alone hold the keys required to read.

RUNS ONAndroid · iOS · Windows · macOS · Linux and sovereign infrastructure

  1. 01

    COMMAND AUTHORIZES

    Who may reach whom, in which direction, until when.

  2. 02

    ENDPOINTS HOLD KEYS

    Payload keys are derived on authorized devices and stay there.

  3. 03

    RELAY HOLDS CIPHERTEXT

    Sealed material in custody, with no key that opens it.

  4. 04

    CUSTOMER HOLDS INFRASTRUCTURE

    Managed, sovereign, on-premises or isolated.

System signature: four security domains and the boundary between them

01AUTHORITY
HOLDS
Signing key. Decides who may reach whom, in which direction, until when.
CANNOT
Cannot derive a payload key. Holds no agreement or decapsulation surface.
02ENDPOINTS
HOLDS
Agreement and decapsulation keys. Derive the payload key locally.
CANNOT
Cannot issue authority to themselves or to anyone else.
03RELAY
HOLDS
Ciphertext, a routing alias, a size and a time.
CANNOT
Cannot read content. Never receives the authorization graph.
04OPAQUE CUSTODY
HOLDS
The property the three above produce together.
CANNOT
No single party can both permit a conversation and read it.

Authorization is a signature. Content confidentiality comes from a key agreement. They are different key roles, on different curves, with different lifetimes, and holding the first can never produce the second.

Complete mission communications

One platform for the complete mission communication lifecycle.

Tunnel Sovereign brings communication, identity, authority, operational continuity and sovereign infrastructure into one governed system.

Tunnel Mobile

Native Android and native iOS

  • Secure messaging and file exchange
  • Private voice notes
  • Voice and video communication
  • Mission rooms for group coordination
  • Connected, intermittent and offline operation

OPERATOR IDENTITYNo phone number or personal email is required for operator identity. Device-bound credentials and mission-scoped pseudonyms establish the operational identity instead.

HOLDS KEYSPayload keys are derived on the device and held there. This is the only surface that can read message content.

Tunnel Command

Native Windows and native macOS

  • Device enrollment and certification
  • Mission creation, governance and closure
  • Directional, time-limited relationship authority
  • Revocation and expiry
  • Administrative audit, with no message content in the record

NO PAYLOAD KEYSGoverns who may communicate. Holds a signing key, not a payload key, and cannot derive one or decrypt content.

Tunnel Relay

Linux, private cloud, on-premises and isolated infrastructure

  • Accepts and forwards sealed communication bundles
  • Store-carry-forward across degraded links
  • Priority handling under constrained transport
  • Replay protection and validity-window enforcement
  • Transport adapters for IP, satellite and radio links

NO PAYLOAD KEYSCarries ciphertext, a routing alias, a size and a time. Receives no payload decryption key and no authorization graph.

The operational problem

Encryption is settled. Authority is the open question.

A secure messenger encrypts well. It leaves unanswered who operates the infrastructure, who decides which devices exist, who may reach whom, and what holds when a device is captured. Those decisions sit with the vendor by default.

Control

Four decisions that belong to the organization.

Each is a separate boundary, with its own enforcement and its own consequence if it sits somewhere else.

The operational authority model: for each of four control domains, who controls it, the consequence of it being held elsewhere, and what enforces it.

Infrastructure

Controlled by
You, or Tunnel under a managed agreement
If held elsewhere
Traffic transits infrastructure you do not govern
Enforced by
Deployment artifact separation at build time

Enrollment

Controlled by
Your enrollment authority
If held elsewhere
A device you never admitted can exist in the deployment
Enforced by
Device-bound credentials

Mission authority

Controlled by
You, per mission and per direction
If held elsewhere
A relationship you never authorized can form
Enforced by
Signed, directional, expiring authority

Message keys

Controlled by
Authorized endpoints only
If held elsewhere
Someone other than the endpoints can read content
Enforced by
Key derivation on the endpoint

EPOCH

Policy epoch

Advances when the rules governing a mission change. Authority issued under an earlier policy no longer applies.

EPOCH

Delivery epoch

Rotates the addressing under which material is carried. Aliases from a previous epoch stop resolving.

EPOCH

Identity epoch

Advances when a device's standing changes, including replacement and withdrawal.

The three advance independently and are always labeled separately, so an operator can tell which one moved.

Under compromise

What holds when something is taken.

A security claim is only useful if it survives a bad day.

If the relay is seized

Stored traffic is ciphertext and the infrastructure holds no payload decryption key. It never receives the authorization graph, so it cannot reconstruct who could reach whom.

If a device is captured

Its credentials are specific to it and are withdrawn without disturbing the operator’s other devices. Authority is bound to the device it was issued to, so a copy fails elsewhere.

If the network is hostile

Content and mission context stay inside the sealed section. Source address, timing and size remain observable at the network layer.

An adversary holding an unlocked device with content on screen has defeated the cryptography, and a disconnected device cannot apply a revocation it has not received.

The operational model

One encrypted unit, carried under scoped authority.

Communication is protected as a Secure Mission Bundle: an encrypted package carrying its own authorization, policy and expiration. It crosses a network or a physical carry without changing form.

The operational model in four stages. Stages one and two are issued by Tunnel Command in the authority domain. Stages three and four take place in the custody domain, where the payload key exists only on the endpoints. No stage gives Command or Relay the ability to decrypt.

01

Mission authority

An organization creates a mission and admits the devices that may take part.

Tunnel CommandAUTHORITY DOMAIN

02

Directional authorization

One signed authorization permits one direction, for one capability, until an expiry. A reply needs its own.

Tunnel CommandAUTHORITY DOMAIN

SECURITY DOMAIN BOUNDARYBelow this line the payload key exists. It exists only on the endpoints.

03

Endpoint key agreement

The two endpoints derive the payload key themselves, combining an X25519 agreement with an ML-KEM-768 decapsulation.

Tunnel MobileCUSTODY DOMAIN

04

Opaque relay custody

Sealed material is held, scheduled, forwarded and expired. The relay carries what it cannot open.

Tunnel RelayCUSTODY DOMAIN

Tunnel Command issues authority and holds no key that can decrypt mission content. Tunnel Relay holds ciphertext and holds no key either. The two capabilities are separated by construction, not by policy.

Compartmentation

Authority to communicate creates no permanent relationship.

An operator holds a separate mission-scoped identity in each mission. Authorization is directional, bound to the device it was issued to, and expires on its own.

Compartmented relationshipsOne operator holds a separate mission-scoped identity in each mission. In Mission A the operator is authorized to reach one counterpart, and that counterpart is separately authorized to reply. In Mission B the same operator is authorized to reach a different counterpart in one direction only. Neither authorization creates a permanent contact, and neither carries into the other mission. Each device holds only the authorizations naming itself, so no endpoint learns the shape of the mission.One operatorone devicetwo identitiesMISSION APseudonym A-1this operatorPseudonym A-2counterpartauthorizedauthorizedMISSION BPseudonym B-1same operatorPseudonym B-4different counterpartauthorizedno reply authority issuedmissions do not connect
Being authorized to communicate inside a mission does not expose a permanent identity, create a permanent contact, or authorize communication outside that mission.

Network conditions

Built for links that are intermittent, contested or absent.

The Tactical Profile is how the platform operates when connectivity cannot be assumed. It is a profile of the same product, not a second application.

Queued ciphertext survives device restart. Delivery resumes when the operating environment permits Tunnel to execute after secure unlock.

Evidence

Every claim here has a boundary attached.

Each capability is published with the limit that qualifies it, so an evaluator can check it rather than discover it.

Executive briefing

A technical review, conducted under your constraints.

The briefing covers the trust model, the deployment boundary and the evidence behind each claim, with an engineer present.