Tactical Profile
For environments where the network is a variable, not a given.
The Tactical Profile is an operational and security profile of the Tunnel platform. It governs how Tunnel Mobile, Tunnel Command and Tunnel Relay behave when connectivity is intermittent, contested or absent, and when operational identity must not become a permanent relationship record. It is a profile of the platform, not a separate product and not a second mobile application.
- Disconnected operation
- Mission-scoped identity
- Native only
- Customer-controlled trust
One platform
The same components, operating under different assumptions.
Nothing in the Tactical Profile is a parallel system. The clients, the authority model and the bundle format are the platform's own, placed under a profile that assumes the environment is hostile to the assumptions ordinary software makes.
Tunnel Mobile
Tunnel Command
Tunnel Relay
Secure Mission Bundles
Communication as a package, not a session.
A session assumes both parties are present. A package does not. Under the Tactical Profile every communication is a Secure Mission Bundle that carries its own authorization, policy and expiration, and can be delivered whenever a permitted transport appears.
Store-carry-forward
Offline operation as the normal case.
Bundles are composed offline, held on the device, handed to relay custody when a link appears, and collected on the next contact window. An interrupted transfer resumes; a bundle past its validity window is refused rather than delivered late.
Mission-scoped identity
Operational identity that does not accumulate.
An operator holds a mission-scoped pseudonym in each operational context. Authority to communicate is directional, capability-scoped and time-limited, and it does not carry into another mission or become a permanent contact.
- Mission-scoped pseudonyms
- The identity an operator presents in a mission is scoped to that mission. Two missions on one device do not present the same operational identity.
- Mission compartments
- Compartments bound who may communicate within a mission. They are an authorization structure issued by the customer's authority, not a renamed group chat.
- Directional communication authority
- Authority is issued per edge and per direction. Authority to reach a counterpart does not create authority for that counterpart to reply; a reply requires separately issued authority.
- Expiring authorization
- Authority carries a signed validity window and ends on its own, so permission is not something the organization must remember to remove.
- Contact-graph minimization
- Each device learns its own edges rather than the mission topology, so a captured device does not disclose the shape of the mission.
Authorization to communicate with someone in one operational context does not automatically create an independent or permanent relationship with that person.
Provisioning and device trust
Bringing a device into a mission, and taking it out again.
Enrollment happens under the customer's authority. Trust is bound to the device. A device that is lost is a device that can be withdrawn without disturbing anything else.
QR-controlled provisioning
Device-bound trust where supported
Independent device revocation
Customer-controlled trust
Boundaries
Native only. Deliberately.
The Tactical Profile runs on native clients because a browser cannot hold the properties the profile depends on. This is not a gap to be filled later. It is the boundary.
- Native Android
- Native iOS
- Native desktop Tunnel Command
- No browser Tactical client
- No browser Tactical administration
- No browser credential storage
- No cookie-based Tactical authentication
- No browser fallback
Transport and partners
Tunnel is the application layer.
The Tactical Profile is designed to carry bundles over approved transports and customer-operated relay infrastructure. The links themselves come from partners.
Radio-layer performance and protection depend on qualified communications hardware and integration partners. Tunnel makes no waveform-layer claim.
- Approved transport integration is scoped per deployment and per partner.
- Relay infrastructure under the Tactical Profile is customer-operated.
- Hardened-device integration is a partner boundary with a defined interface.
- Tunnel holds no government authorization and represents no approval for classified information.
Notice
Product configurations, integrations and operational capabilities are delivered according to customer requirements, deployment environment, validation scope and applicable authorization. No approval for classified information is represented.
Controlled evaluation
Prove the profile under your own operating conditions.
Organizations assess this profile against their own operational conditions: their links, their compartments, their device handling and their loss scenarios. Tunnel runs controlled evaluations built around those questions.