PROGRAM / BLACK SWAN NETCONTROLLED INTRODUCTION

Dedicated secure communications

Secure communications
without a provider in the middle.

Dedicated secure endpoints for direct, mutually authenticated communications between authorized devices.

Mission communications. Reduced trust surface.

Closed fleet. Direct sessions. Hardware-bound identity. No Black Swan-operated message server.

PROGRAM STATUS / ACTIVE DEVELOPMENTNo operational deployment, general availability, certification, government approval, or authorization is claimed.

What is Black Swan Net?

A dedicated appliance—not an app installed into everyday mobile life.

Black Swan Net is a secure communications program developing hardened, full-Linux endpoints for authorized peers who coordinate direct session windows.

When both endpoints are available, they establish a mutually authenticated encrypted session. If the recipient is unavailable, Black Swan Net does not accept, store, queue, or deliver the message.

Intentional attack-surface reduction

Nothing waiting in the cloud.
Nothing for us to decrypt.

The operational communications session excludes a Black Swan message server, vendor queue, cloud message store, phone-number identity, vendor directory, push service, relay and vendor key custody.

NOBLACK SWAN MESSAGE SERVER
NOVENDOR MESSAGE QUEUE
NOCLOUD MESSAGE STORAGE
NOPHONE-NUMBER IDENTITY
NOVENDOR DIRECTORY IN THE SESSION
IF THE PEER IS UNAVAILABLE

An encrypted local draft or pending object may remain on the sender under policy. It is not transmitted or deposited with Black Swan infrastructure. Availability and delivery are not guaranteed.

One controlled core. Distinct assurance directions.

Select the boundary the mission requires.

Customer variation should be implemented through controlled policy rather than source-code forks wherever feasible. Each product remains subject to the exact status shown.

PRODUCT / 01ACTIVE DEVELOPMENT

Black Swan Direct

The deployable baseline under development.

Stock Pixel 10a hardware with a hardened full-Linux system, closed-fleet identity, direct endpoint sessions, controlled software, no ordinary browser, app store, consumer accounts or cloud backup.

  • Wi-Fi treated as untrusted transport
  • Signed, controlled releases
  • Locked verified boot direction
  • Provisioning, revocation and depot lifecycle
Review Direct
PRODUCT / 02ENGINEERING PROPOSAL

Black Swan Sovereign

The highest-assurance hardware direction.

A modified full-Linux endpoint separates a trusted GREEN client domain from a hostile RED access-network domain through a narrow cryptographic security boundary.

  • RED assumed compromised
  • No ordinary RED-to-GREEN bridge, NAT or routing
  • External USB data eliminated in the field direction
  • Depot-only controlled recovery
Review Sovereign
PRODUCT / 03ARCHITECTURE DIRECTION

Black Swan Gateway

A private cable across a hostile network.

An authenticated trusted workstation connects on GREEN. The intended network path exists only through an authorized Black Swan session to an approved peer—not as ordinary Internet access.

  • Trusted client admission required
  • Narrow attested ciphertext-frame boundary
  • Hostile RED transport cannot establish trust
  • Availability may still be denied
Review Gateway
SERVICE / 04LIFECYCLE OFFERING

Black Swan Assurance

The product is maintained trust.

Controlled releases, vulnerability response, fleet-state renewal, incident support, secure logistics, replacement, depot handling, evidence maintenance and customer-specific operating support.

  • Configuration and release control
  • Security advisories and remediation records
  • Replacement pools and priority response options
  • Independent assurance evidence
Review Assurance
COMMERCIAL BOUNDARY

Pricing is provided by controlled quotation after configuration, logistics, evidence and service scope are defined. Planning ranges are not public offers.

03 / ASSUME THE NETWORK IS HOSTILE

Availability may fail.
Trust does not fail open.

The access network does not establish identity or confidentiality. Peer trust comes from authorized endpoint identity, verified state, current policy and a fresh authenticated session.

Denial of service, jamming, blocking, correlation and outer-network metadata remain possible.

HOTEL WI-FI?HOSTILE.
AIRPORT WI-FI?HOSTILE.
COMPROMISED ROUTER?HOSTILE.
ISP?UNTRUSTED TRANSPORT.
INTERNET?UNTRUSTED TRANSPORT.

Connected does not mean trusted

Only explicitly authorized identities form a session.

Radio association, network reachability or possession of an IP address grants no useful Black Swan service.

CONNECTEDTRUSTED
AUTHORIZED + VERIFIED=TRUSTED FOR THIS SESSION
UNKNOWN DEVICE
NO VALID FLEET IDENTITY
NO SECURE SESSION

Replace the endpoint. Preserve the fleet.

Devices are replaceable.
Trust is not.

Operational continuity should not depend on proving whether a suspect device was actually compromised.

01DEVICE REPORTED LOST, CAPTURED OR TAMPERED
02IDENTITY PERMANENTLY REVOKED
03REPLACEMENT PROVISIONED
04CUSTOMER CONTINUES OPERATIONS
RETURNED HARDWARE

Controlled depot process

Custody verification, inspection, cryptographic sanitization, approved firmware reinstallation, boot-chain verification, diagnostics and recertification may permit a completely new identity.

OLD IDENTITY

Never restored

Opening or defined hostile-custody events permanently revoke the former identity. The old device does not rejoin the fleet under that identity.

HIGH-ASSURANCE POLICY

Quarantine or destruction

Some custody and threat categories require conservative quarantine or mandatory destruction instead of reconstitution.

06 / BLACK SWAN ASSURANCE

Security has a lifecycle.

A dedicated handset without maintained releases, evidence, incident procedures, replacement and configuration control becomes a decaying claim.

Assurance scope is defined per customer and configuration. Secure logistics, replacement coverage, priority response and high-touch support are priced separately from hardware.

  1. 01Controlled signed releases
  2. 02Vulnerability and security-advisory response
  3. 03Fleet, key and policy renewal
  4. 04Incident response and revocation support
  5. 05Secure depot reconstitution or destruction
  6. 06Evidence maintenance and security-review support

Commercial buying paths

Different customers require different decisions.

Every path begins with a sanitized mission description and an explicit current-status boundary.

Summary evidence in public. Detailed evidence under control.

Evidence is part of the product.

Qualified customers and evaluators should be able to review the exact architecture boundary, release, configuration, operating procedures and known residual risk.

  • RMF
  • ATO
  • NIST 800-171
  • NIST 800-53
  • FIPS 140-3
  • NIAP / CC
  • CSfC
  • CNSA
  • STIG / SRG
  • SBOM
  • SSDF

Applicability depends on the customer, contract, information type, system boundary and exact deployed configuration. Listing a framework is not a claim of certification or authorization.

  1. 01
    System boundary and threat model

    Trust assumptions, data flows, dependencies, controls and non-goals.

  2. 02
    SBOM and build provenance

    Controlled components, releases, signing and supply-chain evidence.

  3. 03
    Protocol and penetration evidence

    Specifications, test vectors, findings, remediation and independent retest.

  4. 04
    Custody and incident CONOPS

    Provisioning, loss, revocation, replacement, depot and records procedures.

  5. 05
    Continuous assurance record

    Configuration control, advisories, changes and reassessment triggers.

A different question

How much of the communications ecosystem can be removed?

Black Swan Net is not positioned as a replacement claim against any named consumer secure-messaging product. It starts from a dedicated-appliance operating assumption.

CategoryGeneral-purpose secure messagingDedicated Black Swan appliance direction
EndpointGeneral-purpose personal or enterprise deviceDedicated controlled device
IdentityMay involve accounts, phone numbers or platform servicesAuthorized endpoint-bound identity
Message infrastructureMay use provider-operated delivery servicesNo Black Swan message server, queue or cloud message store in the session
Application environmentBroad app and content ecosystemNo ordinary browser, app store, email or third-party application environment
Capture responseAccount and device recovery model variesRevoke identity, replace endpoint, handle hardware separately
LifecyclePlatform and service lifecycleControlled releases, evidence, custody, depot and Assurance

Current threat signal

The infrastructure carrying the session
is part of the threat model.

Evidence-led analysis of endpoint, network, supply-chain, telecom and secure-communications risks, with source facts separated from commentary.

Gene Avakyan, founder and project lead of Black Swan Net
PROJECT LEAD / 01MIAMI, USA

Founder & project lead

Gene Avakyan

Aerospace engineer · Technology strategist · Enterprise systems architect

Gene Avakyan has spent three decades building enterprise systems that handle billions in transactions, including procurement and contract platforms supporting more than $13 billion in contracts for the City of Los Angeles and the Federal Aviation Administration.

His work spans enterprise systems, law-enforcement technology, aerospace and defense engineering. That background informs Black Swan Net’s emphasis on explicit boundaries, controlled configurations, testable claims and evidence that survives review.

UCLA
Aerospace
Pepperdine
MBA
InfraGard
Member
30 years
Systems
Full biography and work

CLAIM BOUNDARY // CURRENT PROGRAM STATUS

Precision before promotion.

Black Swan Net is in active product development. It is not represented as certified, government-approved, authorized for classified information, equivalent to a SCIF, anonymous, unhackable, free of metadata, free of endpoint risk, or able to guarantee availability.

OPERATING RULEComponent validation does not validate the whole product. Product evaluation does not authorize a customer deployment. A customer’s authorized officials control approval for the exact system and mission.

QUALIFIED INQUIRY CHANNELUNCLASSIFIED INITIAL CONTACT

Define the threat. Then define the system.

Choose the path.
Start the review.

Request a private demonstration, scope an enterprise pilot, request a government briefing, or discuss an integration partnership. Do not submit protected information through the public website.