Distribution that never runs ahead of authority.
Tunnel Sovereign is the secure mission distribution layer of Verity Command. It delivers an authorized instruction to the endpoints the authorization names — and to no others — across organizational and coalition boundaries, including degraded and disconnected networks.
- OBSERVE
- UNDERSTAND
- SIMULATE
- RECOMMEND
- AUTHORIZE OR REFUSE
- DISTRIBUTE
- ENFORCE
- EXECUTE
- EVIDENCE
Its role
An authorization that cannot be delivered faithfully is not an authorization. In most architectures, messaging is a separate system with its own permissions, and a message can reach people the decision never named. Tunnel Sovereign removes that gap: there is no separation between distribution and authority.
The Authority Kernel authorizes. Tunnel Sovereign delivers. Authorized endpoints read.
What it does
- Secure mission distributionAuthorized instructions, advisories and releases delivered end to end.
- Governed communicationMessaging between cells and enclaves under the same policy as action.
- Mission-scoped deliveryDelivery bounded by the mission, label and validity window of the envelope.
- Authorized endpoint selectionRecipients come from the authorization, not from an address list.
- Coalition and organizational boundariesRelease to partners through recorded release decisions, caveats intact.
- Degraded and disconnected environmentsStore-and-forward within validity; nothing delivered on withdrawn authority.
- Synchronization with the Authority KernelRevocations, epochs and policy travel ahead of queued work.
- Evidence of deliveryDelivery records without content, committed to the Evidence Ledger.
How delivery works
- Verify the envelopeThe Distribution Endpoint acts only on a verified authority envelope bound to a content digest. Without one there is nothing to send.
- Resolve recipientsRecipients are the endpoints the envelope names, filtered again by label and release decision.
- Encrypt end to endContent is encrypted to recipient endpoints. The relay carries ciphertext and metadata and cannot read content.
- Deliver within validityAn offline recipient receives on reconnection only if the authorization is still valid then.
- Record deliveryDelivery and acceptance are evidenced without storing the content in the record.
Stated boundaries
The platform cannot encrypt to recipients without acting as an endpoint, so one accountable endpoint exists: the Distribution Endpoint. It holds plaintext only transiently, runs in a restricted workload profile, and has no access to the Reality Graph, to Kernel internals or to evidence beyond its own records. A compromise of it would expose the packages it is distributing at that time; minimal retention, isolation, separate enrollment, quorum for bulk distribution and volume anomaly detection limit that exposure.
Connection metadata, timing and volume remain observable to network infrastructure. Separating key material per mission does not defeat traffic analysis, and Tunnel Sovereign does not claim anonymity or unlinkable mission activity. See the Public Threat Model.