Managed Deployment

Tunnel operates the infrastructure. You govern the organization.

Managed Deployment is for organizations that need the platform's security properties without taking on the operation of the infrastructure that delivers them. Tunnel runs the relay; the organization holds its own administrative authority; content stays sealed end to end.

  • Tunnel-operated
  • Managed availability
  • Native clients
  • Defined controls

What you get

Operational responsibility without operational burden.

The organization decides who is enrolled, which devices are trusted and who may communicate. Tunnel keeps the infrastructure running underneath that decision.

01

Streamlined deployment

A deployment path measured in a defined onboarding program rather than an infrastructure project.
02

Managed availability

Tunnel operates, monitors and maintains the relay infrastructure under defined operational controls.
03

Organizational administration

The customer's administrators hold enrollment, mission and authority functions in Tunnel Command.
04

Native client support

Tunnel Mobile on Android and iOS, and native Tunnel Command, supported across the organization.
05

Secure communications

Messaging, files and voice notes carried as Secure Mission Bundles under the same authority model as every other deployment.
06

Enterprise integration

Integration with the organization's identity, directory and operational processes, scoped during deployment.

The boundary

Managed infrastructure is not managed content.

Tunnel operating the relay does not give Tunnel a way into the traffic. The security boundary in a managed deployment is the same boundary as everywhere else.

Content
Encrypted on the endpoint before it reaches relay custody. Relay infrastructure is not designed to possess payload decryption keys, and operating the relay does not change that.
Authority
Held by the customer's administrators. Tunnel does not issue communication authority inside a customer's organization.
Administrative record
Recorded within the managed service and available to the customer for review.
Deployment and enrollment authority
Operated as part of the managed service. This authority decides which devices and operators the deployment admits. It derives no payload keys and cannot read message content. An organization that needs this authority inside its own accreditation boundary should deploy sovereign.
Endpoint keys
Private agreement keys are generated on the endpoint and stay there. Payload keys are derived only by authorized endpoints, so operating the managed service confers no ability to decrypt.

In context

Where Managed sits

Both models run the same product architecture and a compatible Secure Mission Bundle model, under separately governed deployment artifacts. The difference is who is in the position of trust.

Managed and Sovereign deploymentIn a Managed deployment the relay infrastructure and the deployment and enrollment authority are operated as part of the managed service, while message content stays encrypted end to end and payload keys are derived only by authorized endpoints. In a Sovereign deployment the customer operates the infrastructure and holds the enrollment authority, the audit domain and the update process. Neither model creates an administrator key that can decrypt customer content. Both models run the same product architecture under separately governed deployment artifacts.MANAGED DEPLOYMENTTunnel MobileTunnel CommandTunnel-operated relayand enrollment authoritySOVEREIGN DEPLOYMENTTunnel MobileTunnel CommandCustomer-operated relayand enrollment authorityCUSTOMER CONTROLSOrganization policy · operators · missionsDevice enrollment and revocationRetention within the managed serviceInfrastructure operated by TunnelEnrollment authority operated for youCUSTOMER CONTROLSOrganization policy · operators · missionsDevice enrollment and revocationInfrastructure, hosting and retentionEnrollment authority and HSM integrationSigned update and audit domain
Two separate trust postures, selected at deployment. Neither holds a key that decrypts customer content, and a managed installation cannot become a sovereign one at runtime.
  • Managed infrastructure can host a controlled evaluation of the Tactical Profile; the complete operational posture belongs with customer-controlled authority under Sovereign Deployment.
  • A managed deployment is not convertible into a sovereign one at runtime.
  • Migration between models is a deliberate deployment exercise.
  • Organizations frequently start managed and move sovereign as a program matures.

Next step

Scope a managed deployment for your organization.

A private briefing covers onboarding, administration, integration and the operational controls that apply to the managed infrastructure.