Capabilities
The complete mission communication lifecycle, governed as one system.
Tunnel Sovereign combines communication, identity, authority, degraded-network operation and sovereign infrastructure in one platform. Tunnel Mobile carries the operator surface, Tunnel Command governs authority, and Tunnel Relay carries sealed traffic it cannot open.
- Communication
- Authority
- Continuity
- Governance
- Sovereign infrastructure
01 · Communication
A complete communication suite, sealed on the endpoint.
Every mode below is protected the same way: content is sealed on an authorized endpoint before it reaches any infrastructure, and the payload key is derived only on the endpoints.
MODE
Secure messaging
Direct and mission-scoped exchange between authorized endpoints.
MODE
Secure files
File exchange carried under the same authority and the same sealed form as a message.
MODE
Private voice notes
Recorded on the endpoint and sealed before it leaves the device.
MODE
Secure voice calls
Live voice between authorized endpoints, with relay-assisted transport.
MODE
Secure video calls
Live video under the same authority model as voice.
MODE
Mission rooms
Controlled group communication scoped to a mission rather than to a permanent contact list.
MODE
Capability-scoped communication
Authority is issued for a capability. Permission to message is not permission to call.
Delivery state
What a sender is told, and what the system will not claim.
An operator sees what is actually known about a message. Two states a reader will expect are deliberately absent.
STATE
Not sent
Refused on the device before any key was derived. Nothing left the endpoint.
STATE
Collected
The recipient's device fetched it. This is not evidence that a person saw it.
STATE
Accepted by recipient
The recipient's device verified and accepted it. This is the strongest statement the system makes.
There is no state for delivered and none for read. Infrastructure holding ciphertext has not handed anything to a person, and reporting that a recipient displayed something would create a behavioral signal about that person which this system declines to produce. No read receipt exists anywhere in the platform.
03 · Operational continuity
Designed for links that are intermittent, contested or absent.
Communication is protected as a Secure Mission Bundle: a transport-independent encrypted package carrying its own authorization, policy and expiration. It crosses a network or a physical carry without changing form.
CONDITION
Connected
Ordinary operation. Material is handed to custody as it is composed.
CONDITION
Intermittent
Held on the device until a permitted transport appears. Interrupted transfers resume.
CONDITION
Disconnected
Work continues with no network at all. Nothing waits on connectivity to be composed.
CONDITION
Offline composition
Messages, files and voice notes are created and sealed with no link present.
CONDITION
Encrypted queueing
Queued material is held sealed. It is never staged in the clear.
CONDITION
Store-carry-forward
Material is carried and handed on when a permitted route appears.
CONDITION
Local exchange
Short-range device-to-device transfer where no network exists.
CONDITION
Physical carry
Controlled transfer by hand across an isolated boundary.
CONDITION
Priority
A constrained link carries what matters first rather than what arrived first.
CONDITION
Controlled refusal
Material collected after its validity window closes is refused rather than carried late.
Queued ciphertext survives device restart. Delivery resumes when the operating environment permits Tunnel to execute after secure unlock.
04 · Governance
Command governs what is authorized, not what was said.
Administration is a separate surface with separate roles. It issues and withdraws authority, and it holds no key that can decrypt mission content.
FUNCTION
Mission administration
Missions are created, governed and closed as first-class objects.
FUNCTION
Device administration
Devices are enrolled, certified, replaced and withdrawn.
FUNCTION
Directional relationships
Each authorized path is issued explicitly, in one direction, and listed as such.
FUNCTION
Capability administration
Messaging, files, voice and video are authorized separately.
FUNCTION
Preview before issuance
An operator sees exactly what an authorization will permit before it is signed.
FUNCTION
Policy
Policy is set by the customer and distributed under signature.
FUNCTION
Revocation
Withdrawal takes effect when the device receives newer signed state, or at expiry, whichever is first.
FUNCTION
Audit
Administrative actions are recorded. The record carries no message content.
FUNCTION
Role separation
Administration and audit are held by different people, enforced rather than advised.
FUNCTION
Signed distribution
Software and policy reach devices under signature.
The authority that permits communication does not possess the keys required to decrypt communication.
05 · Sovereign infrastructure
Infrastructure and authority under customer control.
Managed and Sovereign are trust postures, separated at build and deployment time rather than by runtime configuration.
OPTION
Managed Deployment
Tunnel-operated infrastructure with defined operational controls. Message content stays sealed end to end.
OPTION
Sovereign Deployment
The customer operates the infrastructure and holds the enrollment authority.
OPTION
Private cloud
Installation inside customer-governed cloud infrastructure.
OPTION
On-premises
Installation inside customer-operated facilities.
OPTION
Isolated and air-gapped
Installation with no route to a public network, updated through controlled transfer.
OPTION
Customer-held enrollment authority
The organization decides which devices exist in its deployment.
OPTION
Customer-held cryptographic roots
Root material is held by the customer under the customer's own procedure.
OPTION
HSM integration
Authority custody sits behind a provider boundary a hardware security module can implement.
OPTION
Customer-controlled audit and retention
The audit domain, its retention and its access belong to the customer.
OPTION
Signed offline updates
Updates are verified under signature and can be applied without a network path.
06 · Platform coverage
Three components, native where operators work.
One platform. The components share an authority model and a bundle format.
COMPONENT
Tunnel Mobile
Native Android and native iOS.
COMPONENT
Tunnel Command
Native Windows and native macOS.
COMPONENT
Tunnel Relay
Linux, private cloud, on-premises and isolated infrastructure.
Transport
Carried over whatever the environment provides.
The same sealed package crosses each of these without changing form.
TRANSPORT
Internet
Encrypted carriage
TRANSPORT
Private IP
Customer-controlled transport
TRANSPORT
SATCOM
Qualified transport integration
TRANSPORT
Tactical radio
Qualified transport integration
TRANSPORT
Local device link
Short-range exchange
TRANSPORT
Physical carry
Store-carry-forward
TRANSPORT
Air-gapped environment
Controlled transfer
Tunnel governs communication above the transport layer. Radio performance, waveform protection, anti-jamming and low-probability-of-intercept properties remain the responsibility of the qualified transport system.
07 · Security boundary
Where each capability stops.
Each property is published with the limit that qualifies it, so an evaluator can check the limit rather than discover it.
LIMIT
Endpoint compromise
Device compromise is contained through device-specific credentials and revocation. An adversary holding an unlocked device with content on screen has defeated the cryptography.
LIMIT
Revocation timing
Withdrawal takes effect when the device receives newer signed state, or at expiry. A disconnected device cannot apply state it has not received.
LIMIT
Network observability
Source address, timing, size and session continuity remain observable at the network layer. No claim of anonymity is made anywhere.
LIMIT
Key protection
Protection class is stated per platform, per algorithm and per security level. There is no blanket hardware-backed claim.
LIMIT
Post-quantum scope
Key establishment is hybrid, combining ML-KEM-768 with X25519. Signature authentication remains classical.
LIMIT
Transport properties
Radio, satellite and waveform behavior belong to the qualified transport system, not to Tunnel.
Product configurations, integrations and operational capabilities are delivered according to customer requirements, deployment environment, validation scope and applicable authorization.
08 · Next step
Review the platform against your own environment.
An executive briefing covers the trust model, the deployment boundary and the evidence behind each capability, with an engineer present.