Capabilities

The complete mission communication lifecycle, governed as one system.

Tunnel Sovereign combines communication, identity, authority, degraded-network operation and sovereign infrastructure in one platform. Tunnel Mobile carries the operator surface, Tunnel Command governs authority, and Tunnel Relay carries sealed traffic it cannot open.

  • Communication
  • Authority
  • Continuity
  • Governance
  • Sovereign infrastructure

01 · Communication

A complete communication suite, sealed on the endpoint.

Every mode below is protected the same way: content is sealed on an authorized endpoint before it reaches any infrastructure, and the payload key is derived only on the endpoints.

MODE

Secure messaging

Direct and mission-scoped exchange between authorized endpoints.

MODE

Secure files

File exchange carried under the same authority and the same sealed form as a message.

MODE

Private voice notes

Recorded on the endpoint and sealed before it leaves the device.

MODE

Secure voice calls

Live voice between authorized endpoints, with relay-assisted transport.

MODE

Secure video calls

Live video under the same authority model as voice.

MODE

Mission rooms

Controlled group communication scoped to a mission rather than to a permanent contact list.

MODE

Capability-scoped communication

Authority is issued for a capability. Permission to message is not permission to call.

Delivery state

What a sender is told, and what the system will not claim.

An operator sees what is actually known about a message. Two states a reader will expect are deliberately absent.

STATE

Not sent

Refused on the device before any key was derived. Nothing left the endpoint.

STATE

Collected

The recipient's device fetched it. This is not evidence that a person saw it.

STATE

Accepted by recipient

The recipient's device verified and accepted it. This is the strongest statement the system makes.

There is no state for delivered and none for read. Infrastructure holding ciphertext has not handed anything to a person, and reporting that a recipient displayed something would create a behavioral signal about that person which this system declines to produce. No read receipt exists anywhere in the platform.

02 · Identity and authority

Who exists, who may reach whom, and for how long.

Authority is issued by the organization, scoped to a mission, pointed in one direction, limited to a capability, and given an expiry.

CONTROL

Customer-controlled enrollment

The deployment trusts the devices its own enrollment authority admits, and nothing else.

CONTROL

Device-bound credentials

Credentials are specific to one device. A capability copied elsewhere does not function there.

CONTROL

Endpoint-generated private keys

Private key material is generated on the endpoint and stays there.

CONTROL

Mission-scoped identity

An operator holds a separate pseudonym in each mission. It exists only inside that mission.

CONTROL

Directional pairwise authorization

One authorization permits one direction between two parties. A reply needs its own.

CONTROL

Compartmented relationships

Each device learns only its own edges. No endpoint holds the mission topology.

CONTROL

Capability-scoped authority

Authority names what may be done, not merely who may be reached.

CONTROL

Time-limited authority

Every authorization carries a signed validity window and expires on its own.

CONTROL

Revocation

A device is withdrawn independently of the operator's other devices.

CONTROL

Multi-device security

Each device is trusted separately, enrolled separately and withdrawn separately.

Epochs

Three clocks, never collapsed into one.

Each answers a different question, and each advances on its own. Collapsing them into a single version number would hide which one moved.

EPOCH

Policy epoch

Advances when the rules governing a mission change. Authority issued under an earlier policy no longer applies.

EPOCH

Delivery epoch

Rotates the addressing under which material is carried. Addresses from a previous epoch stop resolving.

EPOCH

Identity epoch

Advances when a device's standing changes, including replacement and withdrawal.

03 · Operational continuity

Designed for links that are intermittent, contested or absent.

Communication is protected as a Secure Mission Bundle: a transport-independent encrypted package carrying its own authorization, policy and expiration. It crosses a network or a physical carry without changing form.

CONDITION

Connected

Ordinary operation. Material is handed to custody as it is composed.

CONDITION

Intermittent

Held on the device until a permitted transport appears. Interrupted transfers resume.

CONDITION

Disconnected

Work continues with no network at all. Nothing waits on connectivity to be composed.

CONDITION

Offline composition

Messages, files and voice notes are created and sealed with no link present.

CONDITION

Encrypted queueing

Queued material is held sealed. It is never staged in the clear.

CONDITION

Store-carry-forward

Material is carried and handed on when a permitted route appears.

CONDITION

Local exchange

Short-range device-to-device transfer where no network exists.

CONDITION

Physical carry

Controlled transfer by hand across an isolated boundary.

CONDITION

Priority

A constrained link carries what matters first rather than what arrived first.

CONDITION

Controlled refusal

Material collected after its validity window closes is refused rather than carried late.

Queued ciphertext survives device restart. Delivery resumes when the operating environment permits Tunnel to execute after secure unlock.

04 · Governance

Command governs what is authorized, not what was said.

Administration is a separate surface with separate roles. It issues and withdraws authority, and it holds no key that can decrypt mission content.

FUNCTION

Mission administration

Missions are created, governed and closed as first-class objects.

FUNCTION

Device administration

Devices are enrolled, certified, replaced and withdrawn.

FUNCTION

Directional relationships

Each authorized path is issued explicitly, in one direction, and listed as such.

FUNCTION

Capability administration

Messaging, files, voice and video are authorized separately.

FUNCTION

Preview before issuance

An operator sees exactly what an authorization will permit before it is signed.

FUNCTION

Policy

Policy is set by the customer and distributed under signature.

FUNCTION

Revocation

Withdrawal takes effect when the device receives newer signed state, or at expiry, whichever is first.

FUNCTION

Audit

Administrative actions are recorded. The record carries no message content.

FUNCTION

Role separation

Administration and audit are held by different people, enforced rather than advised.

FUNCTION

Signed distribution

Software and policy reach devices under signature.

The authority that permits communication does not possess the keys required to decrypt communication.

05 · Sovereign infrastructure

Infrastructure and authority under customer control.

Managed and Sovereign are trust postures, separated at build and deployment time rather than by runtime configuration.

OPTION

Managed Deployment

Tunnel-operated infrastructure with defined operational controls. Message content stays sealed end to end.

OPTION

Sovereign Deployment

The customer operates the infrastructure and holds the enrollment authority.

OPTION

Private cloud

Installation inside customer-governed cloud infrastructure.

OPTION

On-premises

Installation inside customer-operated facilities.

OPTION

Isolated and air-gapped

Installation with no route to a public network, updated through controlled transfer.

OPTION

Customer-held enrollment authority

The organization decides which devices exist in its deployment.

OPTION

Customer-held cryptographic roots

Root material is held by the customer under the customer's own procedure.

OPTION

HSM integration

Authority custody sits behind a provider boundary a hardware security module can implement.

OPTION

Customer-controlled audit and retention

The audit domain, its retention and its access belong to the customer.

OPTION

Signed offline updates

Updates are verified under signature and can be applied without a network path.

06 · Platform coverage

Three components, native where operators work.

One platform. The components share an authority model and a bundle format.

COMPONENT

Tunnel Mobile

Native Android and native iOS.

COMPONENT

Tunnel Command

Native Windows and native macOS.

COMPONENT

Tunnel Relay

Linux, private cloud, on-premises and isolated infrastructure.

Transport

Carried over whatever the environment provides.

The same sealed package crosses each of these without changing form.

TRANSPORT

Internet

Encrypted carriage

TRANSPORT

Private IP

Customer-controlled transport

TRANSPORT

SATCOM

Qualified transport integration

TRANSPORT

Tactical radio

Qualified transport integration

TRANSPORT

Local device link

Short-range exchange

TRANSPORT

Physical carry

Store-carry-forward

TRANSPORT

Air-gapped environment

Controlled transfer

Tunnel governs communication above the transport layer. Radio performance, waveform protection, anti-jamming and low-probability-of-intercept properties remain the responsibility of the qualified transport system.

07 · Security boundary

Where each capability stops.

Each property is published with the limit that qualifies it, so an evaluator can check the limit rather than discover it.

LIMIT

Endpoint compromise

Device compromise is contained through device-specific credentials and revocation. An adversary holding an unlocked device with content on screen has defeated the cryptography.

LIMIT

Revocation timing

Withdrawal takes effect when the device receives newer signed state, or at expiry. A disconnected device cannot apply state it has not received.

LIMIT

Network observability

Source address, timing, size and session continuity remain observable at the network layer. No claim of anonymity is made anywhere.

LIMIT

Key protection

Protection class is stated per platform, per algorithm and per security level. There is no blanket hardware-backed claim.

LIMIT

Post-quantum scope

Key establishment is hybrid, combining ML-KEM-768 with X25519. Signature authentication remains classical.

LIMIT

Transport properties

Radio, satellite and waveform behavior belong to the qualified transport system, not to Tunnel.

Product configurations, integrations and operational capabilities are delivered according to customer requirements, deployment environment, validation scope and applicable authorization.

08 · Next step

Review the platform against your own environment.

An executive briefing covers the trust model, the deployment boundary and the evidence behind each capability, with an engineer present.