Mission environments

Built for organizations that carry consequence.

These are operating problems, not references. Nothing on this page describes a customer, a contract, a deployment or an endorsement. Each entry states a problem an organization recognizes, the capability that addresses it, and the boundary that stays with the customer.

  • Operating problem
  • Capability
  • Trust boundary
  • Deployment posture

Environments

Eight operating contexts.

The platform does not change between them. Authority, infrastructure, transports, policy and retention are configured to the environment.

01

National security and intelligence

OPERATING PROBLEM
Communication relationships are themselves sensitive. A durable contact graph becomes the most revealing artifact in the system, and it outlives every individual message.
CAPABILITY
Mission-scoped pseudonymous identity, directional pairwise authorization and compartmented relationships. Each device learns only its own edges and no endpoint holds the mission topology.
TRUST BOUNDARY
The organization holds the enrollment authority and decides which devices exist. Payload keys are derived only on authorized endpoints.
DEPLOYMENT POSTURE
Sovereign Deployment, Tactical Profile
02

Defense organizations

OPERATING PROBLEM
Operations run across degraded and disconnected conditions, device loss is an ordinary event, and authority has to be withdrawn without disturbing the rest of a mission.
CAPABILITY
Store-carry-forward delivery, transport-independent Secure Mission Bundles, device-bound credentials and independent revocation with three separately labeled epochs.
TRUST BOUNDARY
Infrastructure, enrollment and mission authority sit inside the customer's own domain. Tunnel governs the application layer; radio and satellite properties belong to the qualified transport system.
DEPLOYMENT POSTURE
Sovereign Deployment, Tactical Profile
03

Critical infrastructure

OPERATING PROBLEM
Continuity requirements outlast any single vendor relationship, and coordination has to keep working when the primary network does not.
CAPABILITY
Offline composition, encrypted queueing, priority under constrained links and controlled refusal once a validity window closes.
TRUST BOUNDARY
The customer holds the infrastructure, the audit domain, the retention policy and the update process.
DEPLOYMENT POSTURE
Sovereign Deployment, on-premises or private cloud
04

Sovereign government communications

OPERATING PROBLEM
An organization must be able to state, on its own authority, whom its deployment trusts, and hold the infrastructure that makes the statement.
CAPABILITY
Customer-held enrollment authority, customer-held cryptographic roots, optional hardware security module integration and signed offline updates.
TRUST BOUNDARY
Nothing in the deployment depends on a vendor-operated service to decide who may communicate.
DEPLOYMENT POSTURE
Sovereign Deployment, isolated or air-gapped
05

Executive protection

OPERATING PROBLEM
Small teams coordinate continuously across moving locations and unreliable coverage, and the existence of the relationship is often as sensitive as its content.
CAPABILITY
Mission rooms scoped to an assignment rather than a permanent contact list, capability-scoped authority, and voice and video under the same authority model as messaging.
TRUST BOUNDARY
Authority expires on its own. A closed assignment leaves no standing permission behind.
DEPLOYMENT POSTURE
Managed evaluation, then Sovereign operation
06

Systems integrators and defense primes

OPERATING PROBLEM
Tunnel is one layer of a larger program, and a defined interface matters more than a broad claim about the whole solution.
CAPABILITY
A stated application-layer boundary, a documented bundle format, and administration that a surrounding program can govern without opening message content.
TRUST BOUNDARY
Radios, satellites, hardened handsets, hardware security modules and accredited hosting belong to partners who build them. That line is written down.
DEPLOYMENT POSTURE
Managed evaluation, integration workshop
07

Telecom, radio and SATCOM integration

OPERATING PROBLEM
A transport provider needs an application layer that does not assume a network, and that does not make claims about the transport it rides on.
CAPABILITY
Transport-independent bundles, adapters for private IP, satellite, tactical radio and short-range links, and delivery that resumes where it stopped.
TRUST BOUNDARY
Waveform protection, anti-jamming and low-probability-of-intercept properties remain the responsibility of the qualified transport system.
DEPLOYMENT POSTURE
Managed evaluation, joint integration
08

High-trust private organizations

OPERATING PROBLEM
Institutions accountable for where data resides need to say what an administrator can never see, and be able to show it.
CAPABILITY
Authority separated from decryption by construction, relay custody without payload keys, and stated limits published alongside every property.
TRUST BOUNDARY
The customer chooses the jurisdiction, the infrastructure and the retention. Message content is never available to the operator of the infrastructure.
DEPLOYMENT POSTURE
Managed Deployment or Sovereign Deployment

One platform

One platform, configured to the environment.

The components stay the same in every context above. What changes is who holds the authority and where the infrastructure sits.

CONSTANT

Tunnel MobileNative Android and iOS
Tunnel CommandNative Windows and macOS
Tunnel RelayLinux and sovereign infrastructure

CONFIGURED

AuthorityWho admits devices and issues relationships
InfrastructureManaged, private cloud, on-premises or isolated
TransportsWhich carriage the environment provides
PolicyThe rules the deployment enforces
RetentionWhat is kept, and for how long
Update processConnected, controlled or fully offline

Transport and integration boundary

What Tunnel governs, and what it does not.

The same sealed package crosses each carriage below without changing form.

TRANSPORT

Internet

Encrypted carriage

TRANSPORT

Private IP

Customer-controlled transport

TRANSPORT

SATCOM

Qualified transport integration

TRANSPORT

Tactical radio

Qualified transport integration

TRANSPORT

Local device link

Short-range exchange

TRANSPORT

Physical carry

Store-carry-forward

TRANSPORT

Air-gapped environment

Controlled transfer

Tunnel governs communication above the transport layer. Radio performance, waveform protection, anti-jamming and low-probability-of-intercept properties remain the responsibility of the qualified transport system.

Next step

Discuss your operating environment.

A conversation starts with the environment rather than the product: what your networks actually do, which authority must stay inside your organization, and what has to keep working when the link does not.