No vendor queue
No operational Black Swan message mailbox, store-and-forward service, push service or cloud message store accepts content.
PUBLIC ARCHITECTURE BRIEF / v0.4.0
Black Swan Net is a product program for dedicated, full-Linux endpoints that communicate only during synchronized, mutually authenticated sessions between authorized devices.
01 / SELECTED OPERATIONAL BASELINE
Both authorized endpoints must be available. They mutually authenticate, verify required state and establish an encrypted session. If the peer is absent, no message is transmitted or deposited with Black Swan infrastructure.
No operational Black Swan message mailbox, store-and-forward service, push service or cloud message store accepts content.
Phone numbers, SIMs, email addresses, vendor accounts and network association do not become the cryptographic identity.
Parties coordinate availability using operational procedure or another approved out-of-band mechanism.
An unavailable peer means no transmission. Blocking, jamming and denial of service remain possible.
Direct-only operation reduces selected provider-held data but does not make the system anonymous or eliminate timing, IP, RF, location, access-network, endpoint or session metadata.
02 / BLACK SWAN DIRECT
Status: active development. Direct uses unmodified Pixel 10a hardware as the initial reference track with a minimal, immutable full-Linux userspace and controlled boot, release and application boundary. Android and GrapheneOS are historical exploration and hardware-discovery references, not the selected production userspace.
No ordinary browser, email, app store, consumer backup, ordinary messaging accounts or third-party app environment.
Authorized device identity, approved state, policy, membership and freshness are checked before session authority is released.
Wi-Fi carries encrypted traffic but does not establish identity or confidentiality. Cellular is disabled in the selected high-assurance baseline.
Signed releases, rollback protection direction, provisioning, revocation, custody, replacement and depot procedures.
03 / BLACK SWAN SOVEREIGN
Status: engineering proposal selected for development—not a validated production design. Sovereign modifies the endpoint to separate the trusted client-facing GREEN domain from the hostile access-network-facing RED domain.
At the current public architectural level, the GREEN side is the Pixel’s internal WLAN for authenticated trusted clients. The RED side is a separate Murata Type 2EL WLAN controlled behind an STM32MP135F isolation gateway. Production direction eliminates exposed external USB data and permits only a narrow authenticated ciphertext-frame interface.
This summary explains the governing boundary without publishing fabrication details, packet formats, keys, recovery procedures or attack-enabling implementation information.
04 / BLACK SWAN GATEWAY
Status: product and architecture direction pending implementation and test. Gateway uses the Sovereign boundary to connect an authenticated trusted workstation on GREEN to an authorized peer session.
The trusted computer does not receive ordinary Internet access through Black Swan. The intended path exists only through an authenticated Black Swan session to an authorized peer. The architecture does not guarantee availability.
Read the secure-gateway mission page05 / CLOSED-FLEET TRUST
Black Swan endpoints communicate only with explicitly authorized identities. A device must prove the required identity and state for the current session; network reachability alone grants no session.
| Observed state | Trust result | Operational meaning |
|---|---|---|
| Network association only | Not trusted | No useful Black Swan service is granted. |
| Unknown or revoked identity | Rejected | No secure session is established. |
| Authorized identity with stale or unacceptable state | Restricted | Required authority is withheld until policy is satisfied. |
| Authorized, verified and fresh | Trusted for this session | Only the bounded session authority defined by policy is released. |
06 / CAPTURE AND CONTINUITY
If an endpoint is lost, captured, opened or otherwise becomes suspect, the operating assumption is to revoke and replace before waiting for forensic certainty.
The old identity is never restored. Hardware may receive an entirely new identity only if the applicable assurance policy permits reconstitution and the device passes the required evidence gates. High-assurance policies may require destruction after defined custody events.
07 / BLACK SWAN ASSURANCE
Assurance is the lifecycle offering around the endpoint: controlled signed releases, vulnerability response, fleet recertification, key and policy renewal, incident support, replacement service, secure depot handling, configuration control, security advisories, evidence maintenance and customer-specific spare pools.
Secure logistics, replacement coverage, priority response and high-touch review support are scoped and priced separately. Public planning ranges are not offers.
08 / EXPLICIT NON-GOALS
UNCLASSIFIED INITIAL CONTACT
Request a controlled briefing, private demonstration, enterprise pilot discussion, government evaluation conversation or integrator engagement.
Select engagement path