Executive overview

Sovereign mission communications, governed from enrollment to delivery.

A short account of what Tunnel Sovereign is, what it protects, where it runs and how an organization evaluates it. The security architecture and the full capability register carry the detail.

  • Problem
  • Platform
  • Security model
  • Deployment
  • Evaluation

01 · The operational problem

Encryption is settled. Authority is the open question.

A secure messenger encrypts well. It leaves unanswered who operates the infrastructure, who decides which devices exist, who may reach whom, and what holds when a device is captured. Those decisions sit with the vendor by default, and for an organization whose communication carries consequence that default is the problem.

02 · The Tunnel Sovereign solution

Communication infrastructure an organization holds itself.

Tunnel Sovereign moves infrastructure, enrollment, mission authority and key custody to the organization. It is one platform rather than a messenger with an administrative console bolted alongside it.

INFRASTRUCTURE

Operated by the customer, or by Tunnel under a managed agreement.

ENROLLMENT

The customer decides which operators and devices exist at all.

MISSION AUTHORITY

The customer decides who may reach whom, in which direction, for which capability, until when.

MESSAGE KEYS

Derived on authorized endpoints and held only there.

03 · One platform, three components

The same authority model, everywhere it runs.

Tunnel Mobile enables the operator surface. Tunnel Command governs authority. Tunnel Relay carries sealed traffic. The Tactical Profile is how the same platform operates when connectivity cannot be assumed, not a second product.

Tunnel Sovereign is one platform containing Tunnel Mobile on Android and iOS, Tunnel Command on Windows and macOS, and Tunnel Relay on Linux and sovereign infrastructure. The Tactical Profile is an operating profile of the same platform, and Managed and Sovereign are its two deployment postures.

TUNNEL SOVEREIGN

One platform. One authority model. One bundle format.

Tunnel Mobile

Android · iOS

Operator surface. Content sealed on the endpoint, keys held there.

Tunnel Command

Windows · macOS

Governs authority. Holds no key that can decrypt mission content.

Tunnel Relay

Linux · sovereign infrastructure

Carries sealed traffic. No payload key, no authorization graph.

PROFILE

Tactical Profile

Operating profile of the same platform

DEPLOYMENT

Sovereign Deployment

Customer operates it and holds the authority

DEPLOYMENT

Managed Deployment

Tunnel-operated, defined operational controls

04 · Complete communications capability

Messaging, files, voice, video and mission rooms.

Every mode is sealed on an authorized endpoint before it reaches infrastructure, and each is authorized separately: permission to message is not permission to call.

MESSAGING

Direct and mission-scoped exchange between authorized endpoints.

FILES

Carried under the same authority and the same sealed form as a message.

VOICE NOTES

Recorded and sealed on the endpoint before anything leaves it.

VOICE AND VIDEO

Live calls between authorized endpoints, with relay-assisted transport.

MISSION ROOMS

Controlled group communication scoped to a mission, not to a permanent contact list.

DELIVERY STATE

An operator sees Not sent, Collected and Accepted by recipient. There is no delivered state and no read state.

05 · Authority separated from decryption

The invariant the whole platform is built to hold.

Authorization is expressed as a signature. Content confidentiality comes from a key agreement. These are different key roles, on different curves, with different lifetimes.

The authority that permits communication does not possess the keys required to decrypt communication.

ENDPOINTS

Generate and retain private key material, and derive the payload key locally. Key establishment is hybrid, combining ML-KEM-768 with X25519.

COMMAND

Holds a signing key. It governs what is authorized, never what was said, and holds no key that can decrypt mission content.

RELAY

Holds ciphertext, a routing alias, a size and a time. It cannot read content and never receives the authorization graph.

06 · Compartmented relationship control

Authority creates no permanent relationship.

An operator holds a separate mission-scoped identity in each mission. Authorization is directional, bound to the device it was issued to, and expires on its own. Being cleared to reach a counterpart inside one mission reveals nothing outside it, and each device learns only its own edges.

POLICY EPOCH

Advances when the rules governing a mission change.

DELIVERY EPOCH

Rotates the addressing under which material is carried.

IDENTITY EPOCH

Advances when a device's standing changes.

07 · Degraded and disconnected operation

The network is a variable, not a given.

Communication is protected as a transport-independent encrypted package carrying its own authorization, policy and expiration. It is composed offline, held sealed, and handed on when a permitted transport appears. Material collected after its validity window closes is refused rather than carried late.

Queued ciphertext survives device restart. Delivery resumes when the operating environment permits Tunnel to execute after secure unlock.

08 · Managed and Sovereign Deployment

Two trust postures, separated at build time.

Sovereign Deployment places control with the customer. Managed Deployment is Tunnel-operated infrastructure with defined operational controls, and is the usual route to a controlled evaluation.

SOVEREIGN OPERATION

Customer-operated infrastructure, customer-held enrollment authority and cryptographic roots, on-premises, private cloud, isolated or air-gapped, with optional hardware security module integration.

MANAGED EVALUATION

Tunnel-operated infrastructure with managed availability. Message content stays sealed end to end.

Product configurations, integrations and operational capabilities are delivered according to customer requirements, deployment environment, validation scope and applicable authorization.

09 · Mission environments

Where communication authority carries consequence.

National security and intelligence organizations, defense organizations, critical infrastructure, sovereign government communications, executive protection, systems integrators and defense primes, telecom, radio and SATCOM integrators, and high-trust private organizations.

10 · Controlled evaluation

Assessed on your devices, under an agreed scope.

An evaluation runs on your own devices, compartments and network conditions, with the scope, environment and acceptance criteria agreed in writing beforehand. Nothing on this site describes a certification, a customer or a deployment.

11 · Executive briefing

A technical review, conducted under your constraints.

The briefing covers the trust model, the deployment boundary and the evidence behind each claim, with an engineer present.