Deployment

The same platform. Two answers to the question of control.

Every organization deploying Tunnel makes one decision first: who operates the infrastructure, and who holds the deployment and enrollment authority. That decision produces a Managed or a Sovereign deployment. It does not produce a different product.

  • Managed
  • Sovereign
  • Tactical Profile
  • Separate trust domains
Managed and Sovereign deploymentIn a Managed deployment the relay infrastructure and the deployment and enrollment authority are operated as part of the managed service, while message content stays encrypted end to end and payload keys are derived only by authorized endpoints. In a Sovereign deployment the customer operates the infrastructure and holds the enrollment authority, the audit domain and the update process. Neither model creates an administrator key that can decrypt customer content. Both models run the same product architecture under separately governed deployment artifacts.MANAGED DEPLOYMENTTunnel MobileTunnel CommandTunnel-operated relayand enrollment authoritySOVEREIGN DEPLOYMENTTunnel MobileTunnel CommandCustomer-operated relayand enrollment authorityCUSTOMER CONTROLSOrganization policy · operators · missionsDevice enrollment and revocationRetention within the managed serviceInfrastructure operated by TunnelEnrollment authority operated for youCUSTOMER CONTROLSOrganization policy · operators · missionsDevice enrollment and revocationInfrastructure, hosting and retentionEnrollment authority and HSM integrationSigned update and audit domain
Two separate trust postures, selected at deployment. Neither holds a key that decrypts customer content, and a managed installation cannot become a sovereign one at runtime.

Comparison

What changes between them

The clients, the bundle format, the authority model and the security boundary are the same. What changes is who is in the position of trust.

Comparison of Managed and Sovereign deployment across ten dimensions of control
DimensionManagedSovereign
Infrastructure operationTunnel-operated or approved managedCustomer-operated
Cryptographic rootHeld within the managed serviceHeld by the customer
Hosting locationManaged environmentOn-premises, private cloud, approved sovereign hosting or air-gapped
HSM integrationManagedCustomer-managed
Audit domainManaged service records, available to the customerEntirely within the customer domain
Retention and loggingDefined operational controlsCustomer-controlled
Software updatesManaged release processCustomer-controlled, signed, offline-capable
Enrollment authorityCustomer, within the managed serviceCustomer, on customer infrastructure
Vendor decryption capabilityNone. Content is sealed end to endNone, and no universal Tunnel master key
Tactical ProfileControlled evaluationComplete operational posture

Trust separation

A shared product is not a shared trust domain.

Managed and Sovereign share design. They do not share trust, and the platform is built so that this cannot quietly stop being true.

  • Sovereign capability is selected at build and deployment time, never at runtime.
  • A user cannot convert a managed installation into a sovereign one.
  • A sovereign deployment does not fall back to commercial infrastructure.
  • A sovereign deployment accepts no commercial credential, endpoint or account.
  • Application identity, signing identity and provisioning authority stay separate.
  • Cryptographic root, database, audit domain and operational data stay separate.

Anything that can be switched on at runtime can be switched on by someone else. Build-time separation makes the question unanswerable at runtime, which is the only way it stays answered.

Tactical Profile

A high-assurance profile, at home in sovereign deployment.

The Tactical Profile governs how the platform behaves in disconnected, degraded and mission-sensitive environments. The complete operational posture belongs with customer-controlled authority under Sovereign Deployment. A managed environment can host a controlled evaluation of the profile, which is a different thing from operating it.

Next step

Decide the model with the trade-offs in front of you.

A private briefing covers what each model means for your jurisdiction, your accreditation path, your operations team and your risk owner.