Tunnel Sovereign

Sovereign communication infrastructure.

One platform for secure communication across managed, sovereign and mission-sensitive deployments, without giving relay infrastructure access to message content.

Infrastructure ownership

Managed, or entirely customer-operated

Cryptographic control

Customer-held authority in sovereign deployment

Operational continuity

Delivery across intermittent links

Mission authority

Scoped, directional, time-limited

The problem

Encryption is settled. Control is not.

Government, critical infrastructure, defense programs and regulated enterprises need communication systems whose trust boundaries are explicit. Strong encryption is now ordinary. What remains scarce is knowing who operates the infrastructure, who admits a device, and what holds when the network does not.

The platform

One platform. Three components. One authority model.

Native clients where operators work, a native control environment where the organization governs, and infrastructure that carries sealed traffic without the means to read it.

The unified Tunnel platformTunnel Sovereign is one platform. Tunnel Mobile provides the native endpoint experience on Android and iOS. Tunnel Command governs organization administration, mission authority and device lifecycle. Tunnel Relay provides encrypted custody and delivery. All three are configured by a single deployment model, either Managed or Sovereign. The Tactical Profile runs operationally under Sovereign Deployment, where the customer holds the enrollment authority it depends on; a Managed deployment can host a controlled evaluation of the profile.TUNNEL PLATFORMTunnel MobileAndroid · iOSTunnel CommandNative desktopTunnel RelayCustody and deliveryOperators and endpointsAuthority and governanceTransport-independent carriageManagedTunnel-operatedSovereignCustomer-operatedTactical ProfileSovereign operation Managed evaluationDEPLOYMENT MODEL
One platform, three components, one deployment decision. The Tactical Profile is an operating profile of the same platform, not a separate product.

Deployment

Managed where speed matters. Sovereign where control does.

Both models run the same product architecture under separately governed deployment artifacts. What changes is who operates the infrastructure and who holds the authority to decide whom the deployment trusts.

Managed and Sovereign deploymentIn a Managed deployment the relay infrastructure and the deployment and enrollment authority are operated as part of the managed service, while message content stays encrypted end to end and payload keys are derived only by authorized endpoints. In a Sovereign deployment the customer operates the infrastructure and holds the enrollment authority, the audit domain and the update process. Neither model creates an administrator key that can decrypt customer content. Both models run the same product architecture under separately governed deployment artifacts.MANAGED DEPLOYMENTTunnel MobileTunnel CommandTunnel-operated relayand enrollment authoritySOVEREIGN DEPLOYMENTTunnel MobileTunnel CommandCustomer-operated relayand enrollment authorityCUSTOMER CONTROLSOrganization policy · operators · missionsDevice enrollment and revocationRetention within the managed serviceInfrastructure operated by TunnelEnrollment authority operated for youCUSTOMER CONTROLSOrganization policy · operators · missionsDevice enrollment and revocationInfrastructure, hosting and retentionEnrollment authority and HSM integrationSigned update and audit domain
Two separate trust postures, selected at deployment. Neither holds a key that decrypts customer content, and a managed installation cannot become a sovereign one at runtime.

Tactical Profile

A high-assurance profile of the same platform.

The Tactical Profile is how Tunnel Sovereign operates when connectivity is intermittent, contested or absent, and when operational identity must not accumulate into a permanent relationship record. It is a profile of the platform, not a second product and not a separate application.

  • Disconnected and degraded operation
  • Native mobile and desktop only
  • Mission-scoped pseudonymous identity
  • Compartmented communication authority
  • Store-carry-forward delivery
  • Device-bound trust and independent revocation

The operational model

One encrypted unit, carried under scoped authority.

Operational communication is protected as a Secure Mission Bundle: a transport-independent encrypted package carrying its own authorization, policy and expiration. It crosses a network, a partner-supplied link or a physical carry without changing form.

Anatomy of a Secure Mission BundleA Secure Mission Bundle is the transport-independent encrypted unit Tunnel uses to protect and deliver operational communication. A routing envelope visible to the relay carries only a directional delivery alias, custody policy, priority and expiration. A sealed inner section, readable only by authorized recipients, carries sender authentication, mission and compartment context, transport restrictions and the encrypted content itself.ROUTING ENVELOPE · VISIBLE TO RELAYDirectional delivery aliasmission-scoped, non-enumerableCustody policystore, forward, expirePriorityscheduling classCreation and expirationsigned validity windowReplay and duplicate guardsingle-acceptance markersCryptographic suitealgorithm identificationSEALSEALED SECTION · AUTHORIZED RECIPIENTS ONLYEncrypted message contenttext, files, voice notesSender authenticationsignature over the assertionAuthorized-recipient policywho may open itMission and compartmentoperational contextCommunication authoritydirectional, time-limitedTransport restrictionspermitted carriage
The relay reads the outer envelope in order to carry, schedule and expire the bundle. It does not hold the keys required to open the sealed section.

Trust boundaries

Authority to communicate is separate from the ability to read.

This separation is structural rather than promised. Authorization is a signature; content confidentiality comes from a key agreement. They are different key roles, on different curves, with different lifetimes.

Control over who may communicate remains separate from the ability to read what they communicate.

  • Message content is encrypted before relay custody, and relay infrastructure is not designed to possess payload decryption keys.
  • Endpoint private agreement keys stay on authorized endpoints; payload keys are derived only there.
  • Persistent identity and relationship metadata are minimized according to deployment profile.
  • Network-layer metadata such as source address, timing and session continuity may remain observable.
  • Hybrid post-quantum key establishment combines ML-KEM-768 with X25519.
  • Device compromise is contained through device-specific credentials and revocation.

Who deploys it

Built for institutions that carry consequence.

Tunnel Sovereign is deployed by organizations whose communication has to keep working, and keep its boundaries, under scrutiny and under pressure.

Government

Organizations that must state, on their own authority, whom their deployment trusts, and hold the infrastructure that makes the statement.

Defense programs

Programs operating across degraded and disconnected conditions, with compartmented authority and device loss as ordinary events.

Critical infrastructure

Operators whose continuity requirements outlast any single vendor relationship.

Regulated enterprises

Institutions accountable for where data resides and what an administrator can never see.

Controlled evaluation

Evaluate Tunnel Sovereign against your operational environment.

A controlled evaluation runs on your devices, your compartments and your network conditions, with the scope agreed in writing beforehand.