Thirteen ideas explain most of Nexus Atlas.
Each idea is a single picture and a plain-language explanation — written for the decision-maker, not the network engineer. Every one links to the engineering site, where your advisors can go deeper — most of them into an interactive demonstration of the same idea. And every one is labelled: what is demonstrated, what ships, what is opt-in.
One connection from many links.
The foundation. Dissimilar links — satellite, cellular, radio, Wi-Fi, mesh, wired — become one encrypted connection, and applications see one ordinary network. They never learn which link carried the bytes, so nothing has to be integrated, modified or made "Atlas-aware". Six dissimilar link types have been bonded on one field node — a demonstrated point, not a ceiling: there is no fixed link limit, and a node bonds as many links as the deployment and its resources require.
The interactive bonding demo — nexusatlas.ioFour links keep the picture simple — any IP-capable transport joins the same bond: 802.11s mesh, Wi-Fi HaLow, Bluetooth and serial telemetry radios via small adapters, from a few kbps to multi-gigabit.
Failover you never notice.
There is no moment where a link "fails over". Every path is measured continuously — delay, jitter, loss — and traffic shifts away from trouble in proportion to measured quality, on a cadence typically configured between 0.1 and 0.75 seconds. By the time a link actually dies, the traffic has usually already left. A response cadence, not a universal recovery guarantee — and never a binary up/down switch.
The gradual-degradation demo — nexusatlas.ioShares are illustrative; the real split follows the measured delay, jitter and loss of each link, re-weighted on the configured cadence.
Redundancy that escalates.
Eight scheduling strategies ship; three are adaptive. As loss or latency worsens, the traffic that matters is duplicated across one, then two, then three simultaneous paths — and scaled back the moment conditions clear. The arithmetic is why it works: three independent links each losing 2% of packets yield 0.0008% effective loss with copies on all three. In the scripted demonstration, three links forced to 30% loss delivered roughly 2.7% effective loss end-to-end.
The strategies in detail — nexusatlas.ioThe interference-adaptive mode is the live demonstration mode — the escalation shown here is the behaviour exhibited under controlled link degradation.
The fleet routes around loss.
When two nodes cannot reach each other directly, traffic crosses the other members of your own fleet — re-encrypted at every hop, up to 8 hops by default. Every node holds the same picture of the topology; lose a relay and every survivor recomputes independently, with no controller anywhere. Relay nodes are trusted, authenticated members of your fleet — stated plainly, because your security review will ask.
The distributed control-plane demo — nexusatlas.ioThe route re-forms the moment the loss is detected — ≈ 1.25 s at default probe settings. Re-encrypted per hop; every relay is an authenticated member of your own fleet.
One stream, many watchers.
When several stations watch the same live feed across the mesh, the scarce hops carry it once — not once per viewer. The network computes where the watchers' paths diverge from the topology it already floods, and duplicates the stream only there; the cost of the trunk does not grow with the audience. Measured on an eight-node rig: five minutes of Full-HD-rate video to three stations, with the scarce first hop carrying exactly one copy per packet.
How the tree is computed — nexusatlas.ioThree stations watching one feed: the scarce hops carry it once — copies are made only where the stations’ paths part. Delivery stays video-shaped: losses repaired by forward error correction, never by retransmission storms.
Video can never starve the command link.
Reliability and priority are a property of the message, not the connection. Six service classes — Control, Voice, Position, Telemetry, Video, Bulk — each get their own delivery contract, and strict priority comes with reserved floors: with classes enabled, a 4 Mbps video stream cannot crowd out a 2 kbps command channel — measured, with the drop counters to show it. Classification uses standard packet marks and flow heuristics: zero application changes.
Priority under pressure, measured — nexusatlas.ioOff by default; with classes off the data path is byte-identical. Deadline delivery and erasure recovery are contracts of the same system — too-late video frames are dropped, never retransmitted.
Nothing is lost in the blackout.
Bulk data addressed to an unreachable peer is held — surviving reboots — and drained automatically the instant a path returns: the home network, or a passing relay vehicle, vessel or aerial node. Sender and receiver never need to be connected at the same moment. Delivery that waits, instead of failing — demonstrated as the "data mule" scenario.
Survive the blackout — nexusatlas.ioThe queue is a delivery contract of the Bulk traffic class — real-time classes are never held back behind it.
Unreachable, then upgraded.
A node behind carrier-grade NAT — no inbound ports, no fixed address — becomes reachable outbound-only in under a second through a relay, and the relay path is an ordinary link in the bond with its own measurements. Path candidates are then exchanged over that already-working relay, and crossing probes open a direct path through both NATs. The upgrade is a scheduler decision: the relay stays in the bond as a warm standby, so a failed attempt costs nothing. Managed relay and exit locations in the EU and North America run today; private, on-premises relay estates serve closed networks.
The traversal deep-dive — nexusatlas.ioRelay and gateway lists are signed with an offline key and verified by every client — a directory outage never becomes a tunnel outage.
Addresses change. Sessions don’t.
A link whose public address changes mid-mission — a cellular modem crossing carriers, a moving vehicle — keeps its tunnel without a reconnect. Sessions are bound to cryptographic identity, not to addresses, and only cryptographically verified traffic can move an endpoint. The same indifference to link identity is what lets SIM and eSIM profiles cycle underneath a mission without dropping it.
How sessions bind to identity — nexusatlas.ioAddresses illustrative. Roaming is a property of every link in the bond — each link roams independently while the others keep carrying.
Predict, don’t react.
For platforms that move, the killer is geometry. Nodes share position and velocity inside the routing flood; the scheduler projects each node along its track and hands traffic to the longer-reaching link before the short one stretches past its declared range — while both still work. Signal-trend and range prediction ship today, opt-in; terrain awareness is in development. Prediction is advisory: it biases decisions, never kills a link, and never falsifies a measurement.
The position & velocity demo — nexusatlas.ioEach radio is scored against its own declared reach — a 300 m Wi-Fi leg and a multi-kilometre radio leg get different risk from the same distance.
Encrypted everywhere, with the boundaries stated.
Always on — there is no unencrypted production mode. Noise IK handshake; X25519, ChaCha20-Poly1305, BLAKE2s: the cryptographic family of WireGuard and Signal. And the word “encrypted” is not allowed to hide who can read what: direct peer traffic is end-to-end; mesh relays re-encrypt per hop and are trusted, authenticated members of your own fleet; hosted Traversal relays forward envelopes they cannot open. Three different boundaries, stated as three different facts — because your security review will ask.
Hop honesty — the three boundaries — nexusatlas.ioThe suite is the default, not a lock-in — the primitives can be exchanged without changing the protocol, the engineering basis of the FIPS and post-quantum tracks.
Names, with no name server to lose.
Your people should type isr02.narva, not read an address off a laminated card. Every node already announces who it is and where it can be reached, so every node answers name lookups itself, out of its own copy of the fleet — there is no name server anywhere in the mesh to stand up, defend or lose. Names keep resolving with the uplink dead, and when a network splits in two, each half keeps resolving its own half. Existing corporate names can be pointed down the tunnel without touching your DNS estate, and a mesh-only mode fits an EMCON posture: no query ever leaves on an uplink.
How names resolve without a server — nexusatlas.ioAnswers come out of the routing database itself, so they track the topology — 30-second lifetimes, never stale by design. Names resolve only inside the tunnel, and the tunnel itself never waits on a lookup.
No controller. No cloud. Fully offline.
Every node is autonomous and carries everything it needs: its full configuration, its own view of the topology, its own decisions. There is no orchestrator to stand up, no cloud that must be reachable, no licence server to call — licensing is an offline signed file. The data plane needs no internet at any point in its life, air-gapped networks are a first-class operating condition, and a partitioned network keeps operating on both sides of the split.
Operations without a controller — nexusatlas.ioThe only hosted pieces are optional — Traversal relays and the fleet console — and losing them costs visibility, never connectivity.
Thirteen ideas. Seventy-five capabilities.
These pages showed the shape of the platform. The full catalogue goes through everything it does, in the same plain language — seventy-five capabilities across ten groups, each with an engineering deep link where your advisors can go deeper.
Browse the full catalogue — /product/capabilities