Deployment
The same platform. Two answers to the question of control.
Every organization deploying Tunnel makes one decision first: who operates the infrastructure, and who holds the deployment and enrollment authority. That decision produces a Managed or a Sovereign deployment. It does not produce a different product.
- Managed
- Sovereign
- Tactical Profile
- Separate trust domains
Choosing
Which model fits
Most organizations know the answer before the conversation starts. The briefing is usually about what the answer implies.
Managed Deployment
Sovereign Deployment
Comparison
What changes between them
The clients, the bundle format, the authority model and the security boundary are the same. What changes is who is in the position of trust.
| Dimension | Managed | Sovereign |
|---|---|---|
| Infrastructure operation | Tunnel-operated or approved managed | Customer-operated |
| Cryptographic root | Held within the managed service | Held by the customer |
| Hosting location | Managed environment | On-premises, private cloud, approved sovereign hosting or air-gapped |
| HSM integration | Managed | Customer-managed |
| Audit domain | Managed service records, available to the customer | Entirely within the customer domain |
| Retention and logging | Defined operational controls | Customer-controlled |
| Software updates | Managed release process | Customer-controlled, signed, offline-capable |
| Enrollment authority | Customer, within the managed service | Customer, on customer infrastructure |
| Vendor decryption capability | None. Content is sealed end to end | None, and no universal Tunnel master key |
| Tactical Profile | Controlled evaluation | Complete operational posture |
Trust separation
A shared product is not a shared trust domain.
Managed and Sovereign share design. They do not share trust, and the platform is built so that this cannot quietly stop being true.
- Sovereign capability is selected at build and deployment time, never at runtime.
- A user cannot convert a managed installation into a sovereign one.
- A sovereign deployment does not fall back to commercial infrastructure.
- A sovereign deployment accepts no commercial credential, endpoint or account.
- Application identity, signing identity and provisioning authority stay separate.
- Cryptographic root, database, audit domain and operational data stay separate.
Anything that can be switched on at runtime can be switched on by someone else. Build-time separation makes the question unanswerable at runtime, which is the only way it stays answered.
Tactical Profile
A high-assurance profile, at home in sovereign deployment.
The Tactical Profile governs how the platform behaves in disconnected, degraded and mission-sensitive environments. The complete operational posture belongs with customer-controlled authority under Sovereign Deployment. A managed environment can host a controlled evaluation of the profile, which is a different thing from operating it.
Next step
Decide the model with the trade-offs in front of you.
A private briefing covers what each model means for your jurisdiction, your accreditation path, your operations team and your risk owner.