The platform

One platform. Three components. One authority model.

Tunnel is not a messenger with an enterprise tier bolted on. It is communication infrastructure whose components were designed against a single question: can an organization control who may communicate, without the infrastructure gaining the ability to read what they say?

  • Tunnel Mobile
  • Tunnel Command
  • Tunnel Relay
  • Secure Mission Bundle

The suite

A complete communication suite under one authority model.

Every mode is sealed on an authorized endpoint before it reaches infrastructure, and each is authorized separately.

MODE

Secure messaging

Direct and mission-scoped exchange between authorized endpoints.

MODE

Secure files

Carried under the same authority and the same sealed form as a message.

MODE

Private voice notes

Recorded and sealed on the endpoint before anything leaves it.

MODE

Secure voice calls

Live voice between authorized endpoints, with relay-assisted transport.

MODE

Secure video calls

Live video under the same authority model as voice.

MODE

Mission rooms

Controlled group communication scoped to a mission, not to a permanent contact list.

Coverage

Native where operators work.

Three components of one platform.

COMPONENT

Tunnel Mobile

Native Android and native iOS

COMPONENT

Tunnel Command

Native Windows and native macOS

COMPONENT

Tunnel Relay

Linux, private cloud, on-premises and isolated infrastructure

The unified Tunnel platformTunnel Sovereign is one platform. Tunnel Mobile provides the native endpoint experience on Android and iOS. Tunnel Command governs organization administration, mission authority and device lifecycle. Tunnel Relay provides encrypted custody and delivery. All three are configured by a single deployment model, either Managed or Sovereign. The Tactical Profile runs operationally under Sovereign Deployment, where the customer holds the enrollment authority it depends on; a Managed deployment can host a controlled evaluation of the profile.TUNNEL PLATFORMTunnel MobileAndroid · iOSTunnel CommandNative desktopTunnel RelayCustody and deliveryOperators and endpointsAuthority and governanceTransport-independent carriageManagedTunnel-operatedSovereignCustomer-operatedTactical ProfileSovereign operation Managed evaluationDEPLOYMENT MODEL
One platform, three components, one deployment decision. The Tactical Profile is an operating profile of the same platform, not a separate product.

How they relate

Authority flows down. Content flows across. The two paths never meet.

Tunnel Command issues signed authority to devices. Tunnel Mobile seals content on the endpoint. Tunnel Relay carries what it cannot open. No administrative component contributes key material to content encryption.

How Mobile, Command and Relay relateTunnel Command issues signed authority to devices: enrollment, mission membership and communication authority. Tunnel Mobile encrypts content on the endpoint and hands sealed bundles to Tunnel Relay. Relay carries and delivers bundles without holding payload decryption keys. Command does not receive message content and holds no payload keys.Tunnel CommandMission and device authoritysigned authoritysigned authorityTunnel MobileSender endpointTunnel MobileRecipient endpointTunnel RelaySealed custodySECURE MISSION BUNDLE · SEALED IN TRANSITPayload keys are derived on the endpoints only. No Command instance or relay contributes key material.
Authority flows down from Command. Content flows across between endpoints. The two paths do not meet: the authority that permits communication does not possess the keys required to decrypt it.

The authority that permits communication does not possess the keys required to decrypt communication.

Secure Mission Bundle

The unit that ties the platform together

Everything the platform carries is a Secure Mission Bundle: a transport-independent encrypted package that carries its own authorization, its own policy and its own expiration.

Anatomy of a Secure Mission BundleA Secure Mission Bundle is the transport-independent encrypted unit Tunnel uses to protect and deliver operational communication. A routing envelope visible to the relay carries only a directional delivery alias, custody policy, priority and expiration. A sealed inner section, readable only by authorized recipients, carries sender authentication, mission and compartment context, transport restrictions and the encrypted content itself.ROUTING ENVELOPE · VISIBLE TO RELAYDirectional delivery aliasmission-scoped, non-enumerableCustody policystore, forward, expirePriorityscheduling classCreation and expirationsigned validity windowReplay and duplicate guardsingle-acceptance markersCryptographic suitealgorithm identificationSEALSEALED SECTION · AUTHORIZED RECIPIENTS ONLYEncrypted message contenttext, files, voice notesSender authenticationsignature over the assertionAuthorized-recipient policywho may open itMission and compartmentoperational contextCommunication authoritydirectional, time-limitedTransport restrictionspermitted carriage
The relay reads the outer envelope in order to carry, schedule and expire the bundle. It does not hold the keys required to open the sealed section.
Transport-independent
The same bundle crosses a network, a partner-supplied link or a physical carry without changing form. Transport is a delivery decision, not a format decision.
Self-describing policy
Custody rules, priority, validity window and permitted transports travel with the bundle, so a relay that has never seen the sender still knows how to treat it.
Authenticated at the source
Sender authentication and the authorized-recipient policy sit inside the sealed section, where the relay cannot read or alter them.
Single acceptance
Replay and duplicate suppression markers ensure a bundle is accepted once, even when it arrives by more than one route.

Deployment

The same platform, delivered two ways

Managed and Sovereign are separate trust domains selected at deployment, not settings changed at runtime.

  • Sovereign capability is selected at build and deployment time, never at runtime.
  • A managed installation is not convertible into a sovereign one by a setting.
  • A sovereign deployment does not fall back to commercial infrastructure.
  • Application identity, signing identity, enrollment authority and audit domain stay separate.

Next step

See the platform against your own environment.

An executive briefing covers the architecture, the deployment model that fits your trust requirements, and what an evaluation in your environment would involve.