The platform
One platform. Three components. One authority model.
Tunnel is not a messenger with an enterprise tier bolted on. It is communication infrastructure whose components were designed against a single question: can an organization control who may communicate, without the infrastructure gaining the ability to read what they say?
- Tunnel Mobile
- Tunnel Command
- Tunnel Relay
- Secure Mission Bundle
The suite
A complete communication suite under one authority model.
Every mode is sealed on an authorized endpoint before it reaches infrastructure, and each is authorized separately.
MODE
Secure messaging
Direct and mission-scoped exchange between authorized endpoints.
MODE
Secure files
Carried under the same authority and the same sealed form as a message.
MODE
Private voice notes
Recorded and sealed on the endpoint before anything leaves it.
MODE
Secure voice calls
Live voice between authorized endpoints, with relay-assisted transport.
MODE
Secure video calls
Live video under the same authority model as voice.
MODE
Mission rooms
Controlled group communication scoped to a mission, not to a permanent contact list.
Coverage
Native where operators work.
Three components of one platform.
COMPONENT
Tunnel Mobile
Native Android and native iOS
COMPONENT
Tunnel Command
Native Windows and native macOS
COMPONENT
Tunnel Relay
Linux, private cloud, on-premises and isolated infrastructure
Components
What each component is responsible for
The separation between them is the architecture. Each component holds exactly the authority its role requires, and no more.
Tunnel Mobile
Tunnel Command
Tunnel Relay
How they relate
Authority flows down. Content flows across. The two paths never meet.
Tunnel Command issues signed authority to devices. Tunnel Mobile seals content on the endpoint. Tunnel Relay carries what it cannot open. No administrative component contributes key material to content encryption.
The authority that permits communication does not possess the keys required to decrypt communication.
Secure Mission Bundle
The unit that ties the platform together
Everything the platform carries is a Secure Mission Bundle: a transport-independent encrypted package that carries its own authorization, its own policy and its own expiration.
- Transport-independent
- The same bundle crosses a network, a partner-supplied link or a physical carry without changing form. Transport is a delivery decision, not a format decision.
- Self-describing policy
- Custody rules, priority, validity window and permitted transports travel with the bundle, so a relay that has never seen the sender still knows how to treat it.
- Authenticated at the source
- Sender authentication and the authorized-recipient policy sit inside the sealed section, where the relay cannot read or alter them.
- Single acceptance
- Replay and duplicate suppression markers ensure a bundle is accepted once, even when it arrives by more than one route.
Deployment
The same platform, delivered two ways
Managed and Sovereign are separate trust domains selected at deployment, not settings changed at runtime.
Managed Deployment
Sovereign Deployment
- Sovereign capability is selected at build and deployment time, never at runtime.
- A managed installation is not convertible into a sovereign one by a setting.
- A sovereign deployment does not fall back to commercial infrastructure.
- Application identity, signing identity, enrollment authority and audit domain stay separate.
Next step
See the platform against your own environment.
An executive briefing covers the architecture, the deployment model that fits your trust requirements, and what an evaluation in your environment would involve.