Key Capabilities

Single Binary, Single Deployment

One binary serves as both client and control plane. Bare metal, virtual machine, or container. Same binary, same crypto, same Zero Trust enforcement. Operators install one file.

Post-Quantum Cryptography

Every session uses ML-KEM-1024 (FIPS 203) and ML-DSA-87 (FIPS 204) with hybrid key exchange and AES-256-GCM. The mandated algorithms, running in production today.

Direct Peer-to-Peer Tunnels

Endpoints connect directly to authorized peers. No gateways, no middlemen, no traffic concentration point. Encryption happens once at the source and once at the destination.

Separated Control and Data Planes

The control plane authorizes connections, monitors health, pushes policy, and signs certificates. It never sees or routes application traffic, even if compromised.

Built for the Edge

Endpoints authenticate once and continue communicating with authorized peers when the control plane is unreachable. Satellite, cellular, and disconnected environments keep Zero Trust enforcement.

Federal Compliance Built-In

Aligns with NIST SP 800-207, NSM-10, OMB M-22-09, and FIPS 203/204. Operational ahead of the CNSA 2.0 default for new national security systems in 2027.

What Does GABRL Secure?

If it moves between two endpoints, GABRL secures it. Application agnostic, x86 and ARM, no code changes.
Messaging Telephony Data Pipelines Pub-Sub Applications Media & Streaming Documents & Files Airgapped Systems IoT & Embedded

One Tunnel Per Authorized Pair

The five steps above produce the connection below. Each authorized pair of endpoints holds its own post-quantum tunnel, keyed in memory for the life of the session.

CONTROL PLANE authorizes, never carries Endpoint A keys in memory only Endpoint B keys in memory only ML-KEM-1024  /  ML-DSA-87 direct peer-to-peer tunnel · AES-256-GCM FIGURE 1 One tunnel per authorized pair. Keys are discarded at session end. The control plane holds no peer-to-peer keys, so even its compromise exposes policy, never content.

From the Field

Securing the Skies

How GABRL protects air traffic control communications from quantum threats. Safety-critical voice and data links get post-quantum protection without changes to the systems controllers rely on.

Diplomatic Security Reimagined

Zero Trust for embassy communications. Posts operating on infrastructure they do not control keep sovereign, end-to-end encrypted channels home, with nothing for the host network to find.

Beyond Line of Sight

As forces integrate AI-enabled systems and autonomous platforms, GABRL provides the trusted communications foundation those capabilities require, from RF links to remote operations.

Retire the Gateway

Perimeter architectures concentrate every session on hardware that adversaries treat as a high-value target. GABRL replaces the concentration point with a federated mesh of control planes that authorize direct tunnels and never carry them.

The model today Everything funnels through a gateway HQ Unit Service GATEWAY single target One target. One outage. One breach exposes every session that crossed it. With GABRL A distributed mesh of control planes GARRISON REGION FORWARD Operator Vehicle Sensor Data flows only between endpoints, never the control plane. data tunnel control plane mesh authorization

Watch the GABRL Overview

More GABRL on video