About

Communication infrastructure for institutions.

Tunnel Sovereign exists because the hard question in secure communication is no longer whether a message is encrypted. It is who operates the system carrying it, who holds the authority to decide what that system trusts, and what remains true when the network does not.

  • Sovereign deployment
  • Mission continuity
  • Explicit trust boundaries

Mission

Give the institution the authority, and keep it there.

Strong end-to-end encryption is now widely available, and that is a genuine achievement. It also moved the interesting question elsewhere. For organizations that carry consequence, the pressing problem is ownership: of the infrastructure, of the authority that decides who is trusted, and of the record of who authorized what.

  • Infrastructure ownership. A platform someone else operates is a dependency someone else controls.
  • Cryptographic trust. An organization that does not hold its own authority cannot state, on its own authority, whom it trusts.
  • Operational identity. Permanent identity turns every conversation into a durable relationship record.
  • Deployment boundaries. A managed service and a sovereign installation are different trust postures, and must not be able to become each other.

Security philosophy

Make the boundary structural, then say where it is.

A security property that depends on good behavior is a policy. A security property that depends on which key can perform which operation is architecture. Tunnel Sovereign is built on the second kind, and states where each boundary sits.

Separation by key role
Authorization to communicate is a signature. Content confidentiality comes from a key agreement. These are different key roles, on different curves, with different lifetimes. Holding the authority to admit a participant therefore cannot produce the ability to read what they say.
Endpoint-derived content keys
Private agreement keys are generated on the endpoint and stay there. Payload keys are derived only by authorized endpoints. No administrative component contributes an input to that derivation.
Scoped rather than ambient authority
Authority is issued per mission, per direction, for a capability, for a period. It expires on its own, so permission is not something an organization has to remember to remove.
Boundaries stated, not implied
Network-layer metadata remains observable. A device an adversary controls while content is displayed is a device that has already lost. These limits are published alongside the properties, because an evaluator will find them either way.

Control over who may communicate remains separate from the ability to read what they communicate.

Operational sovereignty

Sovereignty is a list of specific things, not an adjective.

In a sovereign deployment each item below moves from the platform operator's domain into the customer's. That transfer is what the word is being used to mean here.

01

The infrastructure

The relay and supporting services run inside the customer's own environment, under the customer's operations team and jurisdiction.
02

The authority

The deployment and enrollment authority is generated and held by the customer, optionally in customer-managed hardware security modules.
03

The lifecycle

Software and policy arrive as signed artifacts through a customer-controlled process, including where the deployment has no route to a public network.

Mission continuity

Designed for the conditions, not for the demonstration.

Most communication software assumes the network. Tunnel Sovereign assumes it will be intermittent, contested or absent, and treats that as ordinary operation rather than failure.

  • Communication is composed as a self-describing encrypted package, so it does not depend on both parties being present.
  • Custody, priority and expiration travel with the package, so infrastructure that has never seen the sender still knows how to treat it.
  • A package past its validity window is refused rather than delivered late. That is a deliberate trade, and it is published as one.
  • Device loss is an ordinary event: credentials are per device, and withdrawing one does not disturb an operator's standing on the others.

Long-term responsibility

Deployments outlast the conversation that started them.

An institution adopting communication infrastructure is making a decision it will live with for years. That shapes how the platform is built and how it is described.

01

Continuity of operation

Sovereign deployment is designed so that operation does not depend on a commercial relationship remaining in place, or on anyone else's infrastructure remaining available.
02

Evidence over assertion

Every stated property is one an evaluator can examine. Where a property depends on the platform beneath it, the site says which platform and which key.
03

Accountability inside the customer

In a sovereign deployment the administrative record lives in the customer's own audit domain. The organization does not have to ask anyone what its own administrators did.

Contact

Briefings and deployment: enterprise@tunnelmessenger.com
Partnership and integration: enterprise@tunnelmessenger.com
Security reports: security@tunnelmessenger.com

Next step

The conversation is the entry point.

Tunnel Sovereign is deployed after a discussion about your environment, your trust model and your operational constraints. That conversation is held privately, with the people responsible for the decision.