Executive overview
Sovereign mission communications, governed from enrollment to delivery.
A short account of what Tunnel Sovereign is, what it protects, where it runs and how an organization evaluates it. The security architecture and the full capability register carry the detail.
- Problem
- Platform
- Security model
- Deployment
- Evaluation
01 · The operational problem
Encryption is settled. Authority is the open question.
A secure messenger encrypts well. It leaves unanswered who operates the infrastructure, who decides which devices exist, who may reach whom, and what holds when a device is captured. Those decisions sit with the vendor by default, and for an organization whose communication carries consequence that default is the problem.
02 · The Tunnel Sovereign solution
Communication infrastructure an organization holds itself.
Tunnel Sovereign moves infrastructure, enrollment, mission authority and key custody to the organization. It is one platform rather than a messenger with an administrative console bolted alongside it.
INFRASTRUCTURE
Operated by the customer, or by Tunnel under a managed agreement.
ENROLLMENT
The customer decides which operators and devices exist at all.
MISSION AUTHORITY
The customer decides who may reach whom, in which direction, for which capability, until when.
MESSAGE KEYS
Derived on authorized endpoints and held only there.
03 · One platform, three components
The same authority model, everywhere it runs.
Tunnel Mobile enables the operator surface. Tunnel Command governs authority. Tunnel Relay carries sealed traffic. The Tactical Profile is how the same platform operates when connectivity cannot be assumed, not a second product.
TUNNEL SOVEREIGN
One platform. One authority model. One bundle format.
Tunnel Mobile
Android · iOS
Operator surface. Content sealed on the endpoint, keys held there.
Tunnel Command
Windows · macOS
Governs authority. Holds no key that can decrypt mission content.
Tunnel Relay
Linux · sovereign infrastructure
Carries sealed traffic. No payload key, no authorization graph.
PROFILE
Tactical Profile
Operating profile of the same platform
DEPLOYMENT
Sovereign Deployment
Customer operates it and holds the authority
DEPLOYMENT
Managed Deployment
Tunnel-operated, defined operational controls
04 · Complete communications capability
Messaging, files, voice, video and mission rooms.
Every mode is sealed on an authorized endpoint before it reaches infrastructure, and each is authorized separately: permission to message is not permission to call.
MESSAGING
Direct and mission-scoped exchange between authorized endpoints.
FILES
Carried under the same authority and the same sealed form as a message.
VOICE NOTES
Recorded and sealed on the endpoint before anything leaves it.
VOICE AND VIDEO
Live calls between authorized endpoints, with relay-assisted transport.
MISSION ROOMS
Controlled group communication scoped to a mission, not to a permanent contact list.
DELIVERY STATE
An operator sees Not sent, Collected and Accepted by recipient. There is no delivered state and no read state.
05 · Authority separated from decryption
The invariant the whole platform is built to hold.
Authorization is expressed as a signature. Content confidentiality comes from a key agreement. These are different key roles, on different curves, with different lifetimes.
The authority that permits communication does not possess the keys required to decrypt communication.
ENDPOINTS
Generate and retain private key material, and derive the payload key locally. Key establishment is hybrid, combining ML-KEM-768 with X25519.
COMMAND
Holds a signing key. It governs what is authorized, never what was said, and holds no key that can decrypt mission content.
RELAY
Holds ciphertext, a routing alias, a size and a time. It cannot read content and never receives the authorization graph.
06 · Compartmented relationship control
Authority creates no permanent relationship.
An operator holds a separate mission-scoped identity in each mission. Authorization is directional, bound to the device it was issued to, and expires on its own. Being cleared to reach a counterpart inside one mission reveals nothing outside it, and each device learns only its own edges.
POLICY EPOCH
Advances when the rules governing a mission change.
DELIVERY EPOCH
Rotates the addressing under which material is carried.
IDENTITY EPOCH
Advances when a device's standing changes.
07 · Degraded and disconnected operation
The network is a variable, not a given.
Communication is protected as a transport-independent encrypted package carrying its own authorization, policy and expiration. It is composed offline, held sealed, and handed on when a permitted transport appears. Material collected after its validity window closes is refused rather than carried late.
Queued ciphertext survives device restart. Delivery resumes when the operating environment permits Tunnel to execute after secure unlock.
08 · Managed and Sovereign Deployment
Two trust postures, separated at build time.
Sovereign Deployment places control with the customer. Managed Deployment is Tunnel-operated infrastructure with defined operational controls, and is the usual route to a controlled evaluation.
SOVEREIGN OPERATION
Customer-operated infrastructure, customer-held enrollment authority and cryptographic roots, on-premises, private cloud, isolated or air-gapped, with optional hardware security module integration.
MANAGED EVALUATION
Tunnel-operated infrastructure with managed availability. Message content stays sealed end to end.
Product configurations, integrations and operational capabilities are delivered according to customer requirements, deployment environment, validation scope and applicable authorization.
09 · Mission environments
Where communication authority carries consequence.
National security and intelligence organizations, defense organizations, critical infrastructure, sovereign government communications, executive protection, systems integrators and defense primes, telecom, radio and SATCOM integrators, and high-trust private organizations.
10 · Controlled evaluation
Assessed on your devices, under an agreed scope.
An evaluation runs on your own devices, compartments and network conditions, with the scope, environment and acceptance criteria agreed in writing beforehand. Nothing on this site describes a certification, a customer or a deployment.
11 · Executive briefing
A technical review, conducted under your constraints.
The briefing covers the trust model, the deployment boundary and the evidence behind each claim, with an engineer present.