Endpoint identity
Atlas peers authenticate their static keys through the tunnel handshake. A changing carrier address does not change who the node is.
Carrier addresses change and relay IPs can be redirected. Nexus Atlas anchors trust in cryptographic identities while keeping the hosted traversal relay outside the customer payload boundary.
The control plane publishes availability. The signed map authenticates that publication. Each relay then proves the static identity named by the map.
Atlas peers authenticate their static keys through the tunnel handshake. A changing carrier address does not change who the node is.
Every relay uses a pinned static key. Redirecting its IP is insufficient to impersonate the server.
The relay map is Ed25519-signed with an offline key and checked against the public key built into Atlas.
“Encrypted” should not be used as a substitute for a precise data-boundary explanation.
Atlas separates discovery from ongoing data-plane operation and retains a last-known-good trust anchor locally.
A relay is tested from outside before the control plane publishes it.
Canonical relay-map data is signed by a key that is not available to the serving control plane.
Clients store the last valid map and reject older signed maps as rollbacks.
The selected address must still prove possession of the relay identity named in the map.
Apply as a pilot partner if you have a deployment ready to test, or start evaluating Nexus Atlas Traversal as a future customer. Tell us enough to understand the endpoints, carriers, regions, and operational constraints involved.
Run an early deployment with direct engineering contact and help shape priorities through real-world feedback.
Research architecture, security, deployment options, and commercial fit before committing to a pilot.