Tunnel Relay

Infrastructure that carries what it cannot open.

Tunnel Relay holds and delivers sealed bundles. It is deliberately incurious: it reads the routing envelope it needs in order to carry, schedule and expire traffic, and it is not designed to possess the keys required to open what it carries.

  • Managed or customer-operated
  • Store-carry-forward
  • Sealed custody
  • Resumable delivery

Functions

What the relay does

Delivery infrastructure for environments where the network is not a given and the sender and recipient are rarely online together.

01

Encrypted bundle custody

Sealed bundles are held in custody exactly as they arrived. The relay stores ciphertext and the routing envelope, not content.
02

Store-carry-forward

A bundle is accepted when the sender has a link, held while nobody does, and forwarded when the recipient appears.
03

Priority scheduling

Bundles carry a scheduling class, so a constrained link carries what matters first rather than what arrived first.
04

Expiration enforcement

A bundle collected after its validity window has closed is refused rather than delivered late.
05

Replay protection

Single-acceptance markers stop a captured bundle from being re-presented as new traffic.
06

Duplicate suppression

A bundle that arrives by more than one route is delivered once.
07

Intermittent-link operation

The relay expects links to appear and disappear, and treats that as normal operation rather than failure.
08

Resumable delivery

A transfer interrupted mid-carriage resumes rather than restarting.
09

Minimal persistent metadata

What the relay persists is bounded by deployment profile and kept to what custody and delivery require.

Custody

What the relay sees, and what it does not.

The honest way to describe a relay is to say precisely which fields it reads. Tunnel splits the bundle so that this question has a short, checkable answer.

Anatomy of a Secure Mission BundleA Secure Mission Bundle is the transport-independent encrypted unit Tunnel uses to protect and deliver operational communication. A routing envelope visible to the relay carries only a directional delivery alias, custody policy, priority and expiration. A sealed inner section, readable only by authorized recipients, carries sender authentication, mission and compartment context, transport restrictions and the encrypted content itself.ROUTING ENVELOPE · VISIBLE TO RELAYDirectional delivery aliasmission-scoped, non-enumerableCustody policystore, forward, expirePriorityscheduling classCreation and expirationsigned validity windowReplay and duplicate guardsingle-acceptance markersCryptographic suitealgorithm identificationSEALSEALED SECTION · AUTHORIZED RECIPIENTS ONLYEncrypted message contenttext, files, voice notesSender authenticationsignature over the assertionAuthorized-recipient policywho may open itMission and compartmentoperational contextCommunication authoritydirectional, time-limitedTransport restrictionspermitted carriage
The relay reads the outer envelope in order to carry, schedule and expire the bundle. It does not hold the keys required to open the sealed section.
Read by the relay
A directional delivery alias, custody policy, priority, creation and expiration, replay markers and the cryptographic suite identifier. These are what carriage, scheduling and expiration require.
Sealed from the relay
Message content, files and voice notes, sender authentication, the authorized-recipient policy, mission and compartment context, and the communication authority itself.
Not held at all
Payload decryption keys. Relay infrastructure is not designed to possess them, and no administrative component contributes key material to content encryption.
Observable regardless
Network-layer metadata such as source address, timing, size and session continuity remains observable to whoever operates or watches the network. Tunnel Sovereign does not claim otherwise.

Message content is encrypted before relay custody. Relay infrastructure is not designed to possess payload decryption keys.

Delivery

Designed for links that are not there yet.

Delivery does not require sender and recipient to be connected at the same time, and does not require either of them to be connected when the bundle is composed.

Delivery across an intermittent linkA sender composes and seals a bundle while disconnected. The bundle waits on the device. When any permitted transport becomes available it is handed to the relay, which holds it in encrypted custody. The recipient collects it on the next contact window. If the validity window closes first, the bundle expires rather than being delivered late.1Composed offlinesealed on device2Held on deviceawaiting any transport3Relay custodyencrypted, opaque4Collectednext contact windowDASHED: LINK AVAILABLE ONLY INTERMITTENTLYContent is encrypted before it reaches relay custody and stays sealed for the whole journey.A bundle collected after its validity window has closed is refused rather than opened.
Delivery is resumable and does not require sender and recipient to be connected at the same time. Carriage windows and radio-layer performance depend on the transport and its integration partner.

Operation

Managed, or entirely yours.

Organizations either subscribe to Tunnel-operated relay infrastructure or run relay infrastructure themselves. The bundle format, the custody rules and the security boundary are identical in both cases.

  • In a managed deployment, Tunnel operates the relay under defined operational controls, and content remains sealed end to end.
  • In a sovereign deployment, the customer operates the relay inside its own infrastructure and its own jurisdiction.
  • Relay administration covers custody behavior, priority classes, retention and expiration, and is exercised from Tunnel Command.
  • Neither model gives the relay operator a route to payload decryption keys.

Next step

Review the custody model against your own requirements.

A private briefing covers exactly what the relay persists in your deployment profile, for how long, and under whose control.