Managed Deployment
Tunnel operates the infrastructure. You govern the organization.
Managed Deployment is for organizations that need the platform's security properties without taking on the operation of the infrastructure that delivers them. Tunnel runs the relay; the organization holds its own administrative authority; content stays sealed end to end.
- Tunnel-operated
- Managed availability
- Native clients
- Defined controls
What you get
Operational responsibility without operational burden.
The organization decides who is enrolled, which devices are trusted and who may communicate. Tunnel keeps the infrastructure running underneath that decision.
Streamlined deployment
Managed availability
Organizational administration
Native client support
Secure communications
Enterprise integration
The boundary
Managed infrastructure is not managed content.
Tunnel operating the relay does not give Tunnel a way into the traffic. The security boundary in a managed deployment is the same boundary as everywhere else.
- Content
- Encrypted on the endpoint before it reaches relay custody. Relay infrastructure is not designed to possess payload decryption keys, and operating the relay does not change that.
- Authority
- Held by the customer's administrators. Tunnel does not issue communication authority inside a customer's organization.
- Administrative record
- Recorded within the managed service and available to the customer for review.
- Deployment and enrollment authority
- Operated as part of the managed service. This authority decides which devices and operators the deployment admits. It derives no payload keys and cannot read message content. An organization that needs this authority inside its own accreditation boundary should deploy sovereign.
- Endpoint keys
- Private agreement keys are generated on the endpoint and stay there. Payload keys are derived only by authorized endpoints, so operating the managed service confers no ability to decrypt.
In context
Where Managed sits
Both models run the same product architecture and a compatible Secure Mission Bundle model, under separately governed deployment artifacts. The difference is who is in the position of trust.
- Managed infrastructure can host a controlled evaluation of the Tactical Profile; the complete operational posture belongs with customer-controlled authority under Sovereign Deployment.
- A managed deployment is not convertible into a sovereign one at runtime.
- Migration between models is a deliberate deployment exercise.
- Organizations frequently start managed and move sovereign as a program matures.
Next step
Scope a managed deployment for your organization.
A private briefing covers onboarding, administration, integration and the operational controls that apply to the managed infrastructure.