PUBLIC ARCHITECTURE BRIEF / v0.4.0

Direct secure communications with fewer parties in the trust path.

Black Swan Net is a product program for dedicated, full-Linux endpoints that communicate only during synchronized, mutually authenticated sessions between authorized devices.

ACTIVE DEVELOPMENTDIRECT ONLYFULL-LINUX DIRECTIONREVISED 08 AUG 2026

01 / SELECTED OPERATIONAL BASELINE

No Black Swan message server participates in the session.

Both authorized endpoints must be available. They mutually authenticate, verify required state and establish an encrypted session. If the peer is absent, no message is transmitted or deposited with Black Swan infrastructure.

BOUNDARY / 01

No vendor queue

No operational Black Swan message mailbox, store-and-forward service, push service or cloud message store accepts content.

BOUNDARY / 02

No provider identity

Phone numbers, SIMs, email addresses, vendor accounts and network association do not become the cryptographic identity.

BOUNDARY / 03

Direct session procedure

Parties coordinate availability using operational procedure or another approved out-of-band mechanism.

BOUNDARY / 04

Honest failure

An unavailable peer means no transmission. Blocking, jamming and denial of service remain possible.

METADATA BOUNDARY

Direct-only operation reduces selected provider-held data but does not make the system anonymous or eliminate timing, IP, RF, location, access-network, endpoint or session metadata.

02 / BLACK SWAN DIRECT

The stock-device track proves the controlled core.

Status: active development. Direct uses unmodified Pixel 10a hardware as the initial reference track with a minimal, immutable full-Linux userspace and controlled boot, release and application boundary. Android and GrapheneOS are historical exploration and hardware-discovery references, not the selected production userspace.

ENDPOINT

Dedicated use

No ordinary browser, email, app store, consumer backup, ordinary messaging accounts or third-party app environment.

IDENTITY

Endpoint-bound

Authorized device identity, approved state, policy, membership and freshness are checked before session authority is released.

TRANSPORT

Hostile by assumption

Wi-Fi carries encrypted traffic but does not establish identity or confidentiality. Cellular is disabled in the selected high-assurance baseline.

LIFECYCLE

Controlled

Signed releases, rollback protection direction, provisioning, revocation, custody, replacement and depot procedures.

03 / BLACK SWAN SOVEREIGN

The RED side is assumed hostile.

Status: engineering proposal selected for development—not a validated production design. Sovereign modifies the endpoint to separate the trusted client-facing GREEN domain from the hostile access-network-facing RED domain.

At the current public architectural level, the GREEN side is the Pixel’s internal WLAN for authenticated trusted clients. The RED side is a separate Murata Type 2EL WLAN controlled behind an STM32MP135F isolation gateway. Production direction eliminates exposed external USB data and permits only a narrow authenticated ciphertext-frame interface.

  • No ordinary RED-to-GREEN bridge, NAT or general IP routing.
  • Radio association alone provides no useful GREEN service.
  • Unknown GREEN clients are rejected by cryptographic admission policy.
  • Compromised RED components may deny availability or expose outer-network metadata; they must not cross into plaintext, endpoint identity keys or the Linux security domain.
PUBLIC DETAIL LIMIT

This summary explains the governing boundary without publishing fabrication details, packet formats, keys, recovery procedures or attack-enabling implementation information.

04 / BLACK SWAN GATEWAY

A private cable across a hostile network.

Status: product and architecture direction pending implementation and test. Gateway uses the Sovereign boundary to connect an authenticated trusted workstation on GREEN to an authorized peer session.

TRUSTED LAPTOP
GREEN WLAN
BLACK SWAN SOVEREIGN
CRYPTOGRAPHIC SECURITY BOUNDARY
RED WLAN / UNTRUSTED INTERNET
AUTHORIZED PEER PATH

The trusted computer does not receive ordinary Internet access through Black Swan. The intended path exists only through an authenticated Black Swan session to an authorized peer. The architecture does not guarantee availability.

Read the secure-gateway mission page

05 / CLOSED-FLEET TRUST

Connected is not trusted.

Black Swan endpoints communicate only with explicitly authorized identities. A device must prove the required identity and state for the current session; network reachability alone grants no session.

Observed stateTrust resultOperational meaning
Network association onlyNot trustedNo useful Black Swan service is granted.
Unknown or revoked identityRejectedNo secure session is established.
Authorized identity with stale or unacceptable stateRestrictedRequired authority is withheld until policy is satisfied.
Authorized, verified and freshTrusted for this sessionOnly the bounded session authority defined by policy is released.

06 / CAPTURE AND CONTINUITY

Replace the endpoint. Preserve the fleet.

If an endpoint is lost, captured, opened or otherwise becomes suspect, the operating assumption is to revoke and replace before waiting for forensic certainty.

  1. Report the custody event and remove the endpoint from operations.
  2. Permanently revoke the affected identity and advance applicable fleet state.
  3. Provision a replacement under controlled policy and custody.
  4. Handle returned hardware through quarantine, depot analysis, full reconstitution or destruction.

The old identity is never restored. Hardware may receive an entirely new identity only if the applicable assurance policy permits reconstitution and the device passes the required evidence gates. High-assurance policies may require destruction after defined custody events.

07 / BLACK SWAN ASSURANCE

The product is maintained trust.

Assurance is the lifecycle offering around the endpoint: controlled signed releases, vulnerability response, fleet recertification, key and policy renewal, incident support, replacement service, secure depot handling, configuration control, security advisories, evidence maintenance and customer-specific spare pools.

Secure logistics, replacement coverage, priority response and high-touch review support are scoped and priced separately. Public planning ranges are not offers.

08 / EXPLICIT NON-GOALS

A narrower system is not a risk-free system.

  • No claim of zero metadata, anonymity or invisibility.
  • No guaranteed delivery, availability, resistance to jamming or freedom from traffic analysis.
  • No claim that an unlocked or compromised endpoint remains safe.
  • No claim of certification, government approval, CUI authorization, classified/NSS authorization or SCIF equivalence.
  • No claim that patent status proves the architecture, limits the security design, or resolves freedom to operate or trademark clearance.

UNCLASSIFIED INITIAL CONTACT

Define the threat before defining the configuration.

Request a controlled briefing, private demonstration, enterprise pilot discussion, government evaluation conversation or integrator engagement.

Select engagement path