Tunnel Relay
Infrastructure that carries what it cannot open.
Tunnel Relay holds and delivers sealed bundles. It is deliberately incurious: it reads the routing envelope it needs in order to carry, schedule and expire traffic, and it is not designed to possess the keys required to open what it carries.
- Managed or customer-operated
- Store-carry-forward
- Sealed custody
- Resumable delivery
Custody
Linux and sovereign infrastructure, carrying what it cannot open.
The relay holds ciphertext, a routing alias, a size and a time. It holds no payload decryption key and never receives the authorization graph.
CARRIES
Opaque message custody
Sealed material held exactly as it arrived.
CARRIES
File carriage
Files carried in the same sealed form as messages.
CARRIES
Relay-assisted voice and video
Live call transport carried without access to the media keys.
CARRIES
Store-carry-forward
Accepted when a sender has a link, held while nobody does, forwarded when the recipient appears.
CARRIES
Priority
A constrained link carries what matters first.
CARRIES
Expiration
Material collected after its validity window closes is refused rather than carried late.
CARRIES
Replay protection
Single-acceptance markers stop a captured bundle being re-presented.
CARRIES
Transport adapters
Private IP, satellite, tactical radio and short-range links.
Tunnel governs communication above the transport layer. Radio performance, waveform protection, anti-jamming and low-probability-of-intercept properties remain the responsibility of the qualified transport system.
Functions
What the relay does
Delivery infrastructure for environments where the network is not a given and the sender and recipient are rarely online together.
01
Encrypted bundle custody
Sealed bundles are held exactly as they arrived. The relay stores ciphertext and the routing envelope, not content.
02
Store-carry-forward
Accepted when the sender has a link, held while nobody does, forwarded when the recipient appears.
03
Priority scheduling
Bundles carry a scheduling class, so a constrained link carries what matters first rather than what arrived first.
04
Expiration enforcement
A bundle collected after its validity window has closed is refused rather than carried late.
05
Replay protection
Single-acceptance markers stop a captured bundle being re-presented as new traffic.
06
Duplicate suppression
A bundle arriving by more than one route is carried once.
07
Intermittent-link operation
Links appearing and disappearing is normal operation, not failure.
08
Resumable transfer
A transfer interrupted mid-carriage resumes rather than restarting.
09
Minimal persistent metadata
What the relay persists is bounded by deployment profile and kept to what custody requires.
Delivery state
What a sender is told, and what the system will not claim.
Every state below says what is actually known. The two states a reader will expect are absent, and their absence is deliberate.
ON DEVICE
Sealed
Composed and encrypted on the device. Not yet handed to any transport.
ON DEVICE
Waiting for a link
Held on the device because no permitted transport is available. It goes on its own when one appears.
IN TRANSIT
Held by relay
Handed to the relay and accepted into custody. This is not the same as reaching anyone.
IN TRANSIT
Collected
The recipient's device fetched it from the relay. Still not evidence that a person saw it.
IN TRANSIT
Accepted by recipient
The recipient's device verified and accepted it. This is the strongest statement the system can make.
IN TRANSIT
Expired uncollected
The validity window closed before anyone collected it. It no longer exists at the relay.
ON DEVICE
Relay refused
The relay declined custody. The material is still on the sending device.
ON DEVICE
Not sent
Refused locally, before any key was derived. Nothing left the device.
There is no state for delivered and none for read. A relay holding ciphertext has not delivered anything to a person, and reporting that a recipient displayed something would create a signal about that person which this system declines to produce.
Custody
What the relay sees, and what it does not.
The honest way to describe a relay is to say precisely which fields it reads. Tunnel splits the bundle so that this question has a short, checkable answer.
- Read by the relay
- A directional delivery alias, custody policy, priority, creation and expiration, replay markers and the cryptographic suite identifier. These are what carriage, scheduling and expiration require.
- Sealed from the relay
- Message content, files and voice notes, sender authentication, the authorized-recipient policy, mission and compartment context, and the communication authority itself.
- Not held at all
- Payload decryption keys. Relay infrastructure is not designed to possess them, and no administrative component contributes key material to content encryption.
- Observable regardless
- Network-layer metadata such as source address, timing, size and session continuity remains observable to whoever operates or watches the network. Tunnel Sovereign does not claim otherwise.
Message content is encrypted before relay custody. Relay infrastructure is not designed to possess payload decryption keys.
Delivery
Designed for links that are not there yet.
Delivery does not require sender and recipient to be connected at the same time, and does not require either of them to be connected when the bundle is composed.
Operation
Managed, or entirely yours.
Organizations either subscribe to Tunnel-operated relay infrastructure or run relay infrastructure themselves. The bundle format, the custody rules and the security boundary are identical in both cases.
- In a managed deployment, Tunnel operates the relay under defined operational controls, and content remains sealed end to end.
- In a sovereign deployment, the customer operates the relay inside its own infrastructure and its own jurisdiction.
- Relay administration covers custody behavior, priority classes, retention and expiration, and is exercised from Tunnel Command.
- Neither model gives the relay operator a route to payload decryption keys.
Next step
Review the custody model against your own requirements.
An executive briefing covers exactly what the relay persists in your deployment profile, for how long, and under whose control.