Capabilities

Everything the platform does, in plain language.

Everything the platform does, in plain language — seventy-five capabilities across ten groups, each with an engineering deep link where your advisors can go deeper. What this page claims, the engineering site can demonstrate.

75 capabilities · 10 groupsDeep links to nexusatlas.io
1

Multi-link bonding

Each link is an independent, isolated path with its own queue and watchdog — a wedged link never blocks the rest. Six dissimilar link types have been bonded on one field node.

2

Heterogeneous bearers

Any IP-capable transport joins the bond: satellite, cellular, microwave, Wi-Fi, 802.11s mesh, Bluetooth, serial telemetry radios via PPP, wired — each with a declared capacity — from a few kbps to multi-gigabit links — that the scheduler respects.

3

Transparent to applications

Applications see a normal Linux network interface. Command links, video, SCADA and voice run unmodified — no SDK, no integration project.

4

Smart fragmentation

Large packets are fragmented and reassembled across MTU boundaries, so a full-size frame still crosses a narrow serial-radio link. Out-of-order arrival is handled; applications never know.

5

Endpoint roaming

A link whose public address changes mid-mission — a cellular modem crossing carriers, a moving vehicle — keeps its tunnel without a reconnect. Only cryptographically verified traffic can move an endpoint.

6

IPv6 underlay

Links and peer endpoints may be IPv6; radios on IPv6-only carrier networks bond without translation layers. The inner tunnel is IPv4 today — a stated boundary, not a footnote.

7

USB resilience

A re-enumerated modem or radio — an unplugged USB hub, a power blip — is detected and rebound automatically. No daemon restart, no operator action.

8

Continuous link measurement

Every link is probed on its own clock — four times a second by default. Delay is smoothed by moving average; jitter and loss are windowed; a link is never assumed alive before its first completed round trip.

9

Per-link probe clocks

A 4G path checked four times a second can be bonded beside a geostationary satellite path checked once a second — without the slow link reading as phantom loss.

10

Data-path loss measurement

Sequence numbers ride the real traffic, so loss is measured on the packets that matter — not only on sparse control probes that can miss burst interference.

11

Radio telemetry

Companion adapters feed live signal strength, noise, SNR, buffer depth and error counters from the radio itself into the same decision loop — the radio’s own early warnings, not just end-to-end symptoms.

12

Eight scheduling strategies

Best delivery time, weighted distribution, strict priority order, broadcast, hop-count — and three adaptive modes that escalate redundancy from one to two to three simultaneous paths as loss or latency worsens, then scale back when conditions clear. The interference-adaptive mode is the live demonstration mode.

13

Redundancy arithmetic

Three independent links each losing 2% of packets yield 0.0008% effective loss in broadcast mode. In the scripted demonstration, three links forced to 30% loss delivered roughly 2.7% effective loss end-to-end.

14

Gradual, non-binary failover

Load shifts in proportion to measured quality, on a cadence typically configured between 0.1 and 0.75 seconds. A response cadence, not a universal recovery guarantee — and by the time a link actually dies, the traffic has usually already left.

15

Bonding tax, measured

The daemon measures its own added latency continuously and publishes it: p50 0.18 ms, p95 0.42 ms added in the reference measurement. A reproducible number, not a slogan.

16

Near real-time, end to end

The whole control loop runs at sub-second cadence: every link measured four times a second, traffic reweighted on a cadence typically configured between 0.1 and 0.75 seconds as quality changes, mesh routes recomputed the moment a change is detected (≈1.25 s at default probe settings for a lost node) — while the bonding pipeline itself adds about 0.18 ms (p50, self-measured). Decisions are made per packet, on current evidence — never on last minute’s averages. A response cadence, not a universal recovery guarantee.

17

Metered-link budgets

A satellite or cellular link can be given a monthly allowance. Once it is spent the scheduler stops preferring that link while anything else is usable — but still uses it when it is the last path left, because running out of budget is not the same as running out of connectivity.

18

Signal-trend prediction

The trend of a fading radio is projected ahead; traffic leaves a link before it crosses its usable floor — while it still carries — instead of waiting for probes to start missing.

19

Position & velocity

Nodes share GNSS position and velocity inside the routing flood. The scheduler projects each node along its track and raises the cost of links about to stretch out of range — handing traffic to a closer path before the geometry breaks, not after packets start missing.

20

Per-link range envelopes

Each radio is scored against its own declared reach: a 300 m Wi-Fi leg and a multi-kilometre telemetry-radio leg to the same node get different risk from the same distance — so traffic walks onto the longer-legged radio first.

21

Terrain awareness engineering ↗

Position, velocity and signal all miss one case: two nodes stay in range while a ridge slides into the path between them. Elevation-model line-of-sight and Fresnel-zone analysis flag a link entering terrain shadow before the radio confirms the fade. The analysis engine is built, tested, and drives the 3D mission simulator today; wiring into live routing is in progress.

22

One risk model

Range, signal and — when wired — terrain fold into a single per-link risk that drives both packet scheduling and multi-hop routing. Whichever threat arrives first, the route bends around it on one shared cost model. Range and signal are live today; terrain joins the same model.

23

Prediction is advisory

Prediction biases decisions; it never kills a link and never falsifies measurements. Dashboards always show what was measured, not what was predicted.

24

Self-healing mesh

Nodes flood a shared topology view — costs, liveness, prefixes, positions. When a node joins, moves or is lost, the topology refloods and every node recomputes independently — within whatever detection costs, ≈1.25 s at default probe settings. No controller anywhere.

25

Multi-hop relay

Traffic routes through other nodes — not just across the links on one node — up to 8 hops by default (configurable), re-encrypted at every hop. Relay nodes are trusted, authenticated members of your fleet — stated plainly, because your security review will ask.

26

Disjoint-path delivery

Two or more disjoint routes per destination; critical traffic rides all of them with receive-side deduplication. The demonstration shows zero-loss relay failover at twice the backbone cost.

27

One stream, many watchers

When several stations watch the same drone feed across the mesh, the scarce hops carry it once — not once per viewer. The network computes where the watchers’ paths diverge from the topology it already floods and duplicates the video only there; a feed nobody subscribes to costs nothing at all, and the tree re-forms as the fleet moves — no controller, no multicast infrastructure to stand up. Measured on an eight-node verification rig — an ISR aircraft, two layers of drone relays, three subscribed ground stations: five minutes of video at full-HD rate — 6 megabits per second, 187,500 packets — crossed the mesh with at least 187,454 of the 187,500 packets arriving at every station. The scarce first hop carried exactly 187,500 copies — one per packet — where sending each station its own copy would have tripled that, and the copies tripled only at the junction where the stations’ paths separate. However many stations watch, the scarce hops carry the stream once — the cost of the trunk does not grow with the audience. Opt-in; delivery stays video-shaped — losses repaired by forward error correction, never by retransmission storms. How the tree is computed — nexusatlas.io

28

Operator-pinned paths

For rehearsed operations, routes can be pinned statically — fully deterministic behavior when predictability matters more than adaptation.

29

Gossip configuration

Push a configuration change at any node — it reaches every node over the encrypted tunnels themselves. A new node joins with a bootstrap peer and a shared secret, not a hand-edit on every box.

30

Live positions

Three position sources — static configuration, a live GPS feed, or operator entry on the dashboard. Park a relay vehicle, type its coordinates, and every peer’s map updates.

31

Roles across the fleet

Each node can declare what it is — ground station, UAV, UGV, USV, dismount, relay — and a fleet-wide policy change can target roles, so one push tightens the drones without touching the ground stations. The topology views use the same roles to draw the right symbol.

32

Mesh DNS no name server ↗

Type ssh isr02.narva instead of reading an address off a laminated card. Nodes already share who they are and where they are reachable, so every node answers name lookups locally, from its own copy of the fleet — there is no name server anywhere in the mesh to lose. Names keep resolving when reachback is gone, and when a network partitions, each half keeps resolving its own half. Split-horizon overrides keep existing corporate hostnames working over the tunnel, and a mesh-only mode fits EMCON postures: no query ever leaves on an uplink. Opt-in, and honest about its boundary: names resolve only inside the tunnel — and the tunnel itself never depends on a name lookup.

33

Control traffic that fits the bearer

Membership updates are paged, and a page fits a single UDP datagram by construction — losing one costs a page, never the roster. Measured to fit a 250 kbit tactical bearer.

34

Six service classes contracts ↗

Control > Voice > Position > Telemetry > Video > Bulk — each with its own reliability mode, priority and latency budget. Classification by standard packet marks and flow heuristics: zero application changes.

35

Priority lanes measured ↗

Strict priority with reserved floors: video can never starve the command link. With classes enabled, a 4 Mbps video stream cannot crowd out a 2 kbps command channel — measured, with the drop counters to show it.

36

Deadline delivery bends, not breaks ↗

Every frame carries a latency budget derived from the live path set; too-late frames are dropped, not retransmitted. Stale video never chokes fresh video. Video bends — it doesn’t break.

37

Store-carry-forward survive the blackout ↗

Bulk data addressed to an unreachable peer is held — surviving reboots — and drained automatically the instant a path returns. Data arrives even though sender and receiver were never simultaneously connected.

38

Per-class bonding per-class links ↗

Duplicate command traffic across the best links, aggregate video across all of them, keep position on the single best — and adapt the mix as conditions change. Per class, not per tunnel.

39

Erasure recovery (FEC) one-trip repair ↗

Forward error correction across the bond: systematic Reed–Solomon parity striped across the bonded links — any K of K+M shards reconstruct the block. Even a whole link going dark is repaired in one trip — no retransmission, no return channel.

40

Zero app changes

Everything stays plain UDP on the wire; wire format is compatible with nodes that have classes off; switching QoS off leaves the data path byte-identical.

41

Modern authenticated encryption

Noise IK handshake; X25519 key agreement, ChaCha20-Poly1305 authenticated encryption, BLAKE2s — the cryptographic family of WireGuard and Signal. Always on; there is no unencrypted production mode.

The suite is the default, not a lock-in. The security subsystem is built so the primitives behind the handshake can be exchanged without changing the protocol — the engineering basis of the FIPS and post-quantum tracks — and Atlas composes freely with the encryption you already trust: end-to-end tools inside the tunnel, or an outer layer such as IPsec or MACsec around it.

42

Zero-loss key rotation

New keys are negotiated make-before-break every 2 minutes or 1 GiB, with the previous session kept warm for in-flight packets — measured at zero packet loss across rotations.

43

Replay protection

A 2048-entry sliding window per session rejects replayed traffic — the same mechanism deduplicates broadcast-mode copies.

44

Pluggable peer authorisation

A static allowlist, a hot-reloaded keyfile, or an external command hook wired to your identity systems. Grant and revoke nodes without restarting anything; every failure mode fails closed.

45

Hop honesty

Direct peer traffic is end-to-end encrypted. Mesh relays re-encrypt per hop and are trusted nodes of your own fleet. Hosted Traversal relays forward envelopes they cannot open. Three different boundaries, stated as three different facts.

46

NAT awareness

Every link classifies the NAT in front of it from its own data socket — the mapping that is measured is the mapping traffic actually uses — and re-checks periodically.

47

Relay links

A node behind carrier-grade NAT becomes reachable outbound-only in under a second through a relay — and the relay path is an ordinary link in the bond: its own probes, its own quality, the same scheduler.

48

Automatic direct upgrade

Path candidates are exchanged over the already-working relay; crossing probes open a direct path through both NATs. The upgrade is a scheduler decision — the relay stays in the bond as a warm standby, so a failed attempt costs nothing. Proven end-to-end behind two simulated carrier-grade NATs.

49

Deterministic relay election

Both ends independently compute the same relay choice from measured latency — no negotiation protocol to fail — and re-elect make-before-break when a relay degrades. Hardware-verified on the standing fleet.

50

Hosted or private relays

Managed relay and exit locations in the EU and North America run today. Private, on-premises relay estates serve closed networks; hybrid estates mix both. Relays are published only after outside-in verification.

51

Signed directory

Relay and gateway lists are signed with an offline key and verified by every client — a compromised directory server cannot forge membership, and a directory outage never becomes a tunnel outage.

52

No controller, no cloud, no licence server

Every node is autonomous and carries everything it needs: its full configuration, its own view of the topology, its own decisions. There is no orchestrator to stand up, no cloud that must be reachable, no licence server to call — licensing itself is an offline signed file. Autonomy is the architecture, not a fallback.

53

Works fully offline

Yes — completely, and by design rather than as a degraded mode. The data plane needs no internet at any point in its life: not to install, not to start, not to keep routing, not to stay licensed. Air-gapped networks, disconnected sites and denied environments are first-class operating conditions, and a partitioned network keeps operating on both sides of the split. The only components that touch the outside world are the optional hosted services — Traversal relays and the fleet console — and losing them costs visibility, never connectivity.

54

Web dashboard on every node

Links with live delay, jitter, loss, capacity and queue depth; live topology; the scheduler’s actual decisions, explorable after the fact; traffic-policy editing; a position editor. A browser, not an SSH session.

55

Plain-text configuration

One human-readable file that lives in your version control and ships through your existing automation. Traffic policy reloads live; the daemon validates configuration at load time and warns about field-known mistakes.

56

Configuration wizard & mesh-wide rollout

A guided wizard builds a node’s configuration and rolls changes out across the fleet over the Atlas mesh itself — there is no central controller to do it for you — while tracking the rollout as it spreads: which nodes have received the change, which have applied it, and how far the propagation has reached. The wizard also runs offline, serving the same interface on an air-gapped machine.

57

CLI & structured logs

Status, statistics and a live terminal monitor for headless estates; structured logs with configurable verbosity to journald, syslog or any aggregator.

58

REST API

The same telemetry the daemon uses internally — links, topology, scheduler decisions, traffic policy, positions — exposed for your NOC and C2 integrations.

59

Hosted console

Enrolment by one-time code with cryptographic proof-of-possession, nodes on a live map, per-link telemetry, offline alerts with recovery notices, organisations and roles, an audit trail, hardware-key second factor.

60

Configuration validation that knows the field

The misconfigurations that bite in the field — two links sharing one port, a single-address NAT-test server list, mismatched address families, inert knobs — are caught at load time with a plain-language warning.

61

Feeds your existing monitoring

The daemon speaks Prometheus/OpenMetrics on its own endpoint, so link quality, session state, traffic classes and the bonding overhead land in the monitoring system you already run. No exporter process and no second agent to keep alive on a remote node.

62

Feeds your existing SIEM

Operationally meaningful events — a link going down, a session tearing down — are exported as RFC 5424 syslog or ArcSight CEF to a collector of your choosing. A collector outage drops and counts events rather than slowing the node down.

63

A health check that means something

One endpoint answers whether the daemon is alive, whether its data path is actually being serviced, and whether anything is reachable — separately. A daemon whose data path has stalled reports unhealthy even though the process is still running — the case ordinary process checks miss. An idle-but-serviced tunnel stays healthy by design: a node whose peer is legitimately offline is a healthy node with nothing to talk to.

64

One-file escalation

A single command, or one button in the dashboard, packages configuration, statistics, health, the event journal, scheduler decisions and any crash reports into one archive for support. The configuration is filtered by an allowlist, so keys and credentials never leave the node — including keys a newer version might add.

65

Crashes that explain themselves

If the daemon ever dies, the failure is captured inside the dying process, stripped of keys and secrets as it is written, and stored on the node under a hard size limit. Sending it anywhere is a separate decision, off by default: a report can go attributed, anonymously, or be forwarded by a neighbouring node for a radio-only device with no route to the internet at all. Identical failures group together automatically, so a fleet-wide bug reads as one problem rather than fifty — and optional memory dumps are encrypted with your key or not written.

66

Fleet comparison from any node

There is no controller, so any node can pull every other member’s configuration over the tunnels and show where they differ. Policy that has drifted is flagged; node-local differences that are supposed to differ stay quiet. Each node redacts its own secrets before sending.

67

Cross-node consistency checks

Thirty-nine checks answer the question a single node cannot ask alone: not “do these configurations differ?” but “are they wrong about each other?” — a peer listed on one side only, a key that resolves to no node. Each finding names the nodes, the exact settings, and what will go wrong.

68

Fleet health in one request

One question — “is my fleet healthy?” — answered for every member, from whichever node you happen to have open.

69

Credentials for automation

Where a hardware security key protects human sign-in, scripts and monitoring use operator-issued API tokens instead. Any mesh member can also mint a read-only token that expires within minutes, for reading a locked-down node without holding a password.

70

One binary, one file

A Linux daemon for x86-64 and ARM, from datacenter servers to a board weighing around 15 grams — and the same engine as an Android VPN app on aarch64 devices. Hardened service profiles and deployment automation included.

71

Adapters — hardware that talks back

Small companion processes own a specific radio, split its byte stream into a transparent data channel and an out-of-band telemetry channel, and feed both to the daemon. Serial telemetry radios, Wi-Fi, Ethernet and Bluetooth adapters exist today; any hardware family can have one.

72

Cross-layer intent — telling a segment what “good” means

Adapters carry telemetry upward; the same boundary can carry intent downward. Atlas is the glue between vendors, so it holds the whole topology — every link, peer and hop — while a vendor-locked segment such as an IP mesh radio sees only its own cell. Downward intent hands that segment an objective rather than a setting — carry the control class here, hold latency under this, favour range over rate — and lets the segment’s own intelligence decide how, so an isolated part can be tuned for what the whole network is trying to achieve. Objectives, never knobs; advisory by construction. Research direction: the upward half ships today, the downward half is a design.

73

Android

The same Rust engine on a phone: Wi-Fi and cellular bonded into one tunnel, verified live against the hosted gateways from a real device. Evaluation builds; not yet in an app store.

74

Adaptive video chain

An optional governor watches link health and steps the camera encoder’s bitrate to what the surviving links can carry — the stream degrades before the link does, and recovers with hysteresis instead of flapping.

75

The map ships with the node

Nodes carry their own vector basemaps and serve them to their dashboard, so the topology map draws over real terrain with no internet and no tile service. World coverage comes from public-domain data; area-of-operations detail is built offline from OpenStreetMap.

Request a briefing

Bring the network that is limiting your platform.

We will map the links, vendors, shared failure domains and integration boundary—and define what a useful demonstration or pilot should prove.