PROGRAM FAQ / v0.4.0

Direct answers. Explicit boundaries.

Current product, architecture, commercial, lifecycle and government-evaluation answers for the public record.

ACTIVE DEVELOPMENTDIRECT ONLYREVISED 08 AUG 2026

01 / PRODUCT

What is being built?

What is Black Swan Net?

Black Swan Net is a secure communications program developing dedicated full-Linux endpoint appliances for direct, mutually authenticated sessions between explicitly authorized devices. It is not an app added to a general-purpose phone.

What are Black Swan Direct, Sovereign, Gateway and Assurance?

Direct is the stock Pixel 10a reference track and deployable baseline under development. Sovereign is the modified RED/GREEN dual-WLAN high-assurance hardware direction. Gateway extends Sovereign to an authenticated trusted workstation without ordinary Internet access. Assurance is the maintained release, evidence, incident, replacement, logistics and depot lifecycle.

Is the production endpoint Android or GrapheneOS?

No. The selected production direction is a minimal, immutable and independently controlled full-Linux userspace on the Pixel-derived boot chain. Android and GrapheneOS are obsolete as the production baseline; they may remain only as temporary hardware-discovery or comparison environments.

Is the product generally available?

No. Black Swan Net is in active product development. The public record does not claim general availability, an operational customer deployment, a completed Sovereign/Gateway implementation, or independent proof of the final product.

02 / ARCHITECTURE

How do direct sessions work?

Does Black Swan Net store messages for an offline recipient?

No. The selected operational baseline is synchronized and direct only. If the recipient is unavailable, an encrypted local draft or pending object may remain on the sender under policy, but nothing is transmitted or deposited with Black Swan infrastructure.

Does the session use a Black Swan server, directory, relay or push service?

No operational Black Swan message server, queue, cloud message store, identity service, directory, relay, push service or vendor key-custody system participates in the selected session baseline. Parties coordinate availability through operating procedure or another approved out-of-band mechanism.

Is Black Swan Net completely serverless?

That absolute claim is not made. Public web hosting, customer systems, software distribution, time, provisioning, evidence or administrative processes may use infrastructure outside the direct content path. The scoped claim is that the operational communications session excludes the listed Black Swan message and identity services.

Does Black Swan Net eliminate metadata or provide anonymity?

No. Access networks, endpoints and observers may still learn or infer IP, timing, volume, RF, location, session or relationship information. Direct-only operation removes selected provider dependencies; it does not create zero metadata or anonymity.

What does “the RED side is assumed hostile” mean?

In the Sovereign engineering direction, the external access network and separate RED radio are treated as compromisable. Compromise may deny service or expose outer-network metadata, but the design objective is to prevent that compromise from reaching plaintext, identity private keys, fleet secrets or the full-Linux security domain. This objective still requires implementation and independent testing.

Does connecting to GREEN make a client trusted?

No. Radio association and network reachability never establish trust. A GREEN client must satisfy cryptographic identity and policy admission. Unknown or revoked clients receive no useful session service.

03 / LIFECYCLE

What happens when trust changes?

What happens if a device is lost, captured, opened or tampered with?

The device is removed from operations, its identity is permanently revoked, applicable fleet state advances, and a replacement can be provisioned. Returned hardware enters controlled quarantine, depot analysis, complete reconstitution or destruction according to customer policy.

Can a returned device rejoin with its old identity?

No. The compromised or suspect identity is never restored. Hardware may receive an entirely new identity only if the assurance policy permits reconstitution and the device passes the required inspection, sanitization, firmware, boot, diagnostic and recertification gates.

What is Black Swan Assurance?

A recurring lifecycle offering that can include controlled signed releases, vulnerability response, fleet and policy renewal, incident response, replacement service, secure depot handling, configuration control, security advisories, evidence maintenance, spare pools and priority response options.

04 / COMMERCIAL

How does an organization engage?

What buying paths are available?

The four public paths are a private demonstration, an enterprise pilot, a government briefing and an integration-partner discussion. Government paths may lead to a paid design study, controlled technical evaluation, unclassified/CUI pilot or sponsor-defined high-assurance program.

Does the site publish prices?

Not in this release. Available device and annual-Assurance ranges remain planning hypotheses, not approved public offers. Pricing depends on exact hardware, policy, evidence, secure logistics, support, replacement and deployment scope.

What information can be submitted through the public inquiry page?

Only an unclassified, non-sensitive mission category, sector, approximate fleet size and desired timing. Do not submit classified, CUI, export-controlled, privileged, case-specific, security-sensitive, credential, vulnerability, source-identity, evidence or operational information.

05 / GOVERNMENT

What is the current assurance boundary?

Is Black Swan Net certified, government-approved or authorized for classified information?

No. It is not currently represented as certified, government-approved, authorized for CUI or classified information, or equivalent to a SCIF.

What is the difference between component validation, product evaluation and authorization?

Component validation applies to a defined component and scope. Product evaluation applies to a specified product version and configuration. System assessment examines the assembled system and operating boundary. Customer authorization—such as an ATO—is a decision by the responsible customer authority for the exact mission and deployment. These are not interchangeable.

Why does the site mention RMF, NIST, FIPS, NIAP, CSfC, CNSA, STIG, SBOM and SSDF?

They may inform evidence planning for a specific customer or configuration. Their mention does not claim validation, certification, compliance, inclusion on a government list, or authorization. Applicability must be established for the exact system.

06 / BRAND AND IP

What does the name and patent status establish?

Has the Black Swan Net name received formal trademark clearance?

No clearance conclusion is stated. A reported prior Ohio emergency-network use is only a diligence lead. Formal USPTO, common-law, domain, category and confusion analysis by trademark counsel remains an open workstream.

Does patent-pending status prove the product or limit the architecture?

No. Patent status does not prove security, product performance, claim scope, freedom to operate or trademark rights. Security engineering takes precedence over preserving an earlier provisional-filing architecture.

PUBLIC INFORMATION BOUNDARY

This FAQ is a public summary. It does not replace an exact architecture, threat model, security plan, contract requirement, assessment, legal review or authorization decision.

UNCLASSIFIED INITIAL CONTACT

Turn a question into a testable requirement.

Choose a private, enterprise, government or integration-partner path.

Select engagement path