The platform

One platform. Three components. One authority model.

Tunnel is not a messenger with an enterprise tier bolted on. It is communication infrastructure whose components were designed against a single question: can an organization control who may communicate, without the infrastructure gaining the ability to read what they say?

  • Tunnel Mobile
  • Tunnel Command
  • Tunnel Relay
  • Secure Mission Bundle
The unified Tunnel platformTunnel Sovereign is one platform. Tunnel Mobile provides the native endpoint experience on Android and iOS. Tunnel Command governs organization administration, mission authority and device lifecycle. Tunnel Relay provides encrypted custody and delivery. All three are configured by a single deployment model, either Managed or Sovereign. The Tactical Profile runs operationally under Sovereign Deployment, where the customer holds the enrollment authority it depends on; a Managed deployment can host a controlled evaluation of the profile.TUNNEL PLATFORMTunnel MobileAndroid · iOSTunnel CommandNative desktopTunnel RelayCustody and deliveryOperators and endpointsAuthority and governanceTransport-independent carriageManagedTunnel-operatedSovereignCustomer-operatedTactical ProfileSovereign operation Managed evaluationDEPLOYMENT MODEL
One platform, three components, one deployment decision. The Tactical Profile is an operating profile of the same platform, not a separate product.

How they relate

Authority flows down. Content flows across. The two paths never meet.

Tunnel Command issues signed authority to devices. Tunnel Mobile seals content on the endpoint. Tunnel Relay carries what it cannot open. No administrative component contributes key material to content encryption.

How Mobile, Command and Relay relateTunnel Command issues signed authority to devices: enrollment, mission membership and communication authority. Tunnel Mobile encrypts content on the endpoint and hands sealed bundles to Tunnel Relay. Relay carries and delivers bundles without holding payload decryption keys. Command does not receive message content and holds no payload keys.Tunnel CommandMission and device authoritysigned authoritysigned authorityTunnel MobileSender endpointTunnel MobileRecipient endpointTunnel RelaySealed custodySECURE MISSION BUNDLE · SEALED IN TRANSITPayload keys are derived on the endpoints only. No Command instance or relay contributes key material.
Authority flows down from Command. Content flows across between endpoints. The two paths do not meet: the authority that permits communication does not possess the keys required to decrypt it.

The authority that permits communication does not possess the keys required to decrypt communication.

Secure Mission Bundle

The unit that ties the platform together

Everything the platform carries is a Secure Mission Bundle: a transport-independent encrypted package that carries its own authorization, its own policy and its own expiration.

Anatomy of a Secure Mission BundleA Secure Mission Bundle is the transport-independent encrypted unit Tunnel uses to protect and deliver operational communication. A routing envelope visible to the relay carries only a directional delivery alias, custody policy, priority and expiration. A sealed inner section, readable only by authorized recipients, carries sender authentication, mission and compartment context, transport restrictions and the encrypted content itself.ROUTING ENVELOPE · VISIBLE TO RELAYDirectional delivery aliasmission-scoped, non-enumerableCustody policystore, forward, expirePriorityscheduling classCreation and expirationsigned validity windowReplay and duplicate guardsingle-acceptance markersCryptographic suitealgorithm identificationSEALSEALED SECTION · AUTHORIZED RECIPIENTS ONLYEncrypted message contenttext, files, voice notesSender authenticationsignature over the assertionAuthorized-recipient policywho may open itMission and compartmentoperational contextCommunication authoritydirectional, time-limitedTransport restrictionspermitted carriage
The relay reads the outer envelope in order to carry, schedule and expire the bundle. It does not hold the keys required to open the sealed section.
Transport-independent
The same bundle crosses a network, a partner-supplied link or a physical carry without changing form. Transport is a delivery decision, not a format decision.
Self-describing policy
Custody rules, priority, validity window and permitted transports travel with the bundle, so a relay that has never seen the sender still knows how to treat it.
Authenticated at the source
Sender authentication and the authorized-recipient policy sit inside the sealed section, where the relay cannot read or alter them.
Single acceptance
Replay and duplicate suppression markers ensure a bundle is accepted once, even when it arrives by more than one route.

Deployment

The same platform, delivered two ways

Managed and Sovereign are separate trust domains selected at deployment, not settings changed at runtime.

  • Sovereign capability is selected at build and deployment time, never at runtime.
  • A managed installation is not convertible into a sovereign one by a setting.
  • A sovereign deployment does not fall back to commercial infrastructure.
  • Application identity, signing identity, enrollment authority and audit domain stay separate.

Next step

See the platform against your own environment.

A private briefing covers the architecture, the deployment model that fits your trust requirements, and what an evaluation in your environment would involve.