Tunnel Relay

Infrastructure that carries what it cannot open.

Tunnel Relay holds and delivers sealed bundles. It is deliberately incurious: it reads the routing envelope it needs in order to carry, schedule and expire traffic, and it is not designed to possess the keys required to open what it carries.

  • Managed or customer-operated
  • Store-carry-forward
  • Sealed custody
  • Resumable delivery

Custody

Linux and sovereign infrastructure, carrying what it cannot open.

The relay holds ciphertext, a routing alias, a size and a time. It holds no payload decryption key and never receives the authorization graph.

CARRIES

Opaque message custody

Sealed material held exactly as it arrived.

CARRIES

File carriage

Files carried in the same sealed form as messages.

CARRIES

Relay-assisted voice and video

Live call transport carried without access to the media keys.

CARRIES

Store-carry-forward

Accepted when a sender has a link, held while nobody does, forwarded when the recipient appears.

CARRIES

Priority

A constrained link carries what matters first.

CARRIES

Expiration

Material collected after its validity window closes is refused rather than carried late.

CARRIES

Replay protection

Single-acceptance markers stop a captured bundle being re-presented.

CARRIES

Transport adapters

Private IP, satellite, tactical radio and short-range links.

Tunnel governs communication above the transport layer. Radio performance, waveform protection, anti-jamming and low-probability-of-intercept properties remain the responsibility of the qualified transport system.

Functions

What the relay does

Delivery infrastructure for environments where the network is not a given and the sender and recipient are rarely online together.

01

Encrypted bundle custody

Sealed bundles are held exactly as they arrived. The relay stores ciphertext and the routing envelope, not content.

02

Store-carry-forward

Accepted when the sender has a link, held while nobody does, forwarded when the recipient appears.

03

Priority scheduling

Bundles carry a scheduling class, so a constrained link carries what matters first rather than what arrived first.

04

Expiration enforcement

A bundle collected after its validity window has closed is refused rather than carried late.

05

Replay protection

Single-acceptance markers stop a captured bundle being re-presented as new traffic.

06

Duplicate suppression

A bundle arriving by more than one route is carried once.

07

Intermittent-link operation

Links appearing and disappearing is normal operation, not failure.

08

Resumable transfer

A transfer interrupted mid-carriage resumes rather than restarting.

09

Minimal persistent metadata

What the relay persists is bounded by deployment profile and kept to what custody requires.

Delivery state

What a sender is told, and what the system will not claim.

Every state below says what is actually known. The two states a reader will expect are absent, and their absence is deliberate.

ON DEVICE

Sealed

Composed and encrypted on the device. Not yet handed to any transport.

ON DEVICE

Waiting for a link

Held on the device because no permitted transport is available. It goes on its own when one appears.

IN TRANSIT

Held by relay

Handed to the relay and accepted into custody. This is not the same as reaching anyone.

IN TRANSIT

Collected

The recipient's device fetched it from the relay. Still not evidence that a person saw it.

IN TRANSIT

Accepted by recipient

The recipient's device verified and accepted it. This is the strongest statement the system can make.

IN TRANSIT

Expired uncollected

The validity window closed before anyone collected it. It no longer exists at the relay.

ON DEVICE

Relay refused

The relay declined custody. The material is still on the sending device.

ON DEVICE

Not sent

Refused locally, before any key was derived. Nothing left the device.

There is no state for delivered and none for read. A relay holding ciphertext has not delivered anything to a person, and reporting that a recipient displayed something would create a signal about that person which this system declines to produce.

Custody

What the relay sees, and what it does not.

The honest way to describe a relay is to say precisely which fields it reads. Tunnel splits the bundle so that this question has a short, checkable answer.

Anatomy of a Secure Mission BundleA Secure Mission Bundle is the transport-independent encrypted unit Tunnel uses to protect and deliver operational communication. A routing envelope visible to the relay carries only a directional delivery alias, custody policy, priority and expiration. A sealed inner section, readable only by authorized recipients, carries sender authentication, mission and compartment context, transport restrictions and the encrypted content itself.ROUTING ENVELOPE · VISIBLE TO RELAYDirectional delivery aliasmission-scoped, non-enumerableCustody policystore, forward, expirePriorityscheduling classCreation and expirationsigned validity windowReplay and duplicate guardsingle-acceptance markersCryptographic suitealgorithm identificationSEALSEALED SECTION · AUTHORIZED RECIPIENTS ONLYEncrypted message contenttext, files, voice notesSender authenticationsignature over the assertionAuthorized-recipient policywho may open itMission and compartmentoperational contextCommunication authoritydirectional, time-limitedTransport restrictionspermitted carriage
The relay reads the outer envelope in order to carry, schedule and expire the bundle. It does not hold the keys required to open the sealed section.
Read by the relay
A directional delivery alias, custody policy, priority, creation and expiration, replay markers and the cryptographic suite identifier. These are what carriage, scheduling and expiration require.
Sealed from the relay
Message content, files and voice notes, sender authentication, the authorized-recipient policy, mission and compartment context, and the communication authority itself.
Not held at all
Payload decryption keys. Relay infrastructure is not designed to possess them, and no administrative component contributes key material to content encryption.
Observable regardless
Network-layer metadata such as source address, timing, size and session continuity remains observable to whoever operates or watches the network. Tunnel Sovereign does not claim otherwise.

Message content is encrypted before relay custody. Relay infrastructure is not designed to possess payload decryption keys.

Delivery

Designed for links that are not there yet.

Delivery does not require sender and recipient to be connected at the same time, and does not require either of them to be connected when the bundle is composed.

Delivery across an intermittent linkA sender composes and seals a bundle while disconnected. The bundle waits on the device. When any permitted transport becomes available it is handed to the relay, which holds it in encrypted custody. The recipient collects it on the next contact window. If the validity window closes first, the bundle expires rather than being delivered late.1Composed offlinesealed on device2Held on deviceawaiting any transport3Relay custodyencrypted, opaque4Collectednext contact windowDASHED: LINK AVAILABLE ONLY INTERMITTENTLYContent is encrypted before it reaches relay custody and stays sealed for the whole journey.A bundle collected after its validity window has closed is refused rather than opened.
Delivery is resumable and does not require sender and recipient to be connected at the same time. Carriage windows and radio-layer performance depend on the transport and its integration partner.

Operation

Managed, or entirely yours.

Organizations either subscribe to Tunnel-operated relay infrastructure or run relay infrastructure themselves. The bundle format, the custody rules and the security boundary are identical in both cases.

  • In a managed deployment, Tunnel operates the relay under defined operational controls, and content remains sealed end to end.
  • In a sovereign deployment, the customer operates the relay inside its own infrastructure and its own jurisdiction.
  • Relay administration covers custody behavior, priority classes, retention and expiration, and is exercised from Tunnel Command.
  • Neither model gives the relay operator a route to payload decryption keys.

Next step

Review the custody model against your own requirements.

An executive briefing covers exactly what the relay persists in your deployment profile, for how long, and under whose control.