The platform
One platform. Three components. One authority model.
Tunnel is not a messenger with an enterprise tier bolted on. It is communication infrastructure whose components were designed against a single question: can an organization control who may communicate, without the infrastructure gaining the ability to read what they say?
- Tunnel Mobile
- Tunnel Command
- Tunnel Relay
- Secure Mission Bundle
Components
What each component is responsible for
The separation between them is the architecture. Each component holds exactly the authority its role requires, and no more.
Tunnel Mobile
Tunnel Command
Tunnel Relay
How they relate
Authority flows down. Content flows across. The two paths never meet.
Tunnel Command issues signed authority to devices. Tunnel Mobile seals content on the endpoint. Tunnel Relay carries what it cannot open. No administrative component contributes key material to content encryption.
The authority that permits communication does not possess the keys required to decrypt communication.
Secure Mission Bundle
The unit that ties the platform together
Everything the platform carries is a Secure Mission Bundle: a transport-independent encrypted package that carries its own authorization, its own policy and its own expiration.
- Transport-independent
- The same bundle crosses a network, a partner-supplied link or a physical carry without changing form. Transport is a delivery decision, not a format decision.
- Self-describing policy
- Custody rules, priority, validity window and permitted transports travel with the bundle, so a relay that has never seen the sender still knows how to treat it.
- Authenticated at the source
- Sender authentication and the authorized-recipient policy sit inside the sealed section, where the relay cannot read or alter them.
- Single acceptance
- Replay and duplicate suppression markers ensure a bundle is accepted once, even when it arrives by more than one route.
Deployment
The same platform, delivered two ways
Managed and Sovereign are separate trust domains selected at deployment, not settings changed at runtime.
Managed Deployment
Sovereign Deployment
- Sovereign capability is selected at build and deployment time, never at runtime.
- A managed installation is not convertible into a sovereign one by a setting.
- A sovereign deployment does not fall back to commercial infrastructure.
- Application identity, signing identity, enrollment authority and audit domain stay separate.
Next step
See the platform against your own environment.
A private briefing covers the architecture, the deployment model that fits your trust requirements, and what an evaluation in your environment would involve.