Tunnel Relay
Infrastructure that carries what it cannot open.
Tunnel Relay holds and delivers sealed bundles. It is deliberately incurious: it reads the routing envelope it needs in order to carry, schedule and expire traffic, and it is not designed to possess the keys required to open what it carries.
- Managed or customer-operated
- Store-carry-forward
- Sealed custody
- Resumable delivery
Functions
What the relay does
Delivery infrastructure for environments where the network is not a given and the sender and recipient are rarely online together.
Encrypted bundle custody
Store-carry-forward
Priority scheduling
Expiration enforcement
Replay protection
Duplicate suppression
Intermittent-link operation
Resumable delivery
Minimal persistent metadata
Custody
What the relay sees, and what it does not.
The honest way to describe a relay is to say precisely which fields it reads. Tunnel splits the bundle so that this question has a short, checkable answer.
- Read by the relay
- A directional delivery alias, custody policy, priority, creation and expiration, replay markers and the cryptographic suite identifier. These are what carriage, scheduling and expiration require.
- Sealed from the relay
- Message content, files and voice notes, sender authentication, the authorized-recipient policy, mission and compartment context, and the communication authority itself.
- Not held at all
- Payload decryption keys. Relay infrastructure is not designed to possess them, and no administrative component contributes key material to content encryption.
- Observable regardless
- Network-layer metadata such as source address, timing, size and session continuity remains observable to whoever operates or watches the network. Tunnel Sovereign does not claim otherwise.
Message content is encrypted before relay custody. Relay infrastructure is not designed to possess payload decryption keys.
Delivery
Designed for links that are not there yet.
Delivery does not require sender and recipient to be connected at the same time, and does not require either of them to be connected when the bundle is composed.
Operation
Managed, or entirely yours.
Organizations either subscribe to Tunnel-operated relay infrastructure or run relay infrastructure themselves. The bundle format, the custody rules and the security boundary are identical in both cases.
- In a managed deployment, Tunnel operates the relay under defined operational controls, and content remains sealed end to end.
- In a sovereign deployment, the customer operates the relay inside its own infrastructure and its own jurisdiction.
- Relay administration covers custody behavior, priority classes, retention and expiration, and is exercised from Tunnel Command.
- Neither model gives the relay operator a route to payload decryption keys.
Next step
Review the custody model against your own requirements.
A private briefing covers exactly what the relay persists in your deployment profile, for how long, and under whose control.