A sovereign comms mesh your fleet owns end to end.
The mesh is private to your fleet, with no third party relay. It is engineered to defeat corporate espionage and the interception of privileged communications between colleagues and senior leadership. Keys, routing and the roster of permitted devices live inside your estate. Amporah operates the control plane but cannot read your traffic or impersonate a node on your behalf.
How it stays unhackable
Four properties, enforced on every device.
Hardware rooted identity
Per device keys, sealed at provisioning. No shared secrets. Every node is uniquely identifiable and revocable.
Mutually authenticated peers
Every link is two way authenticated. Session keys rotate on every hop, so a captured key never unlocks the wider mesh.
End to end encryption with forward secrecy
Payloads are sealed from sender to recipient. The mesh operator routes traffic but cannot read it. Past sessions stay private even if a key leaks later.
No public ingress
Devices only accept signed peers already on the fleet roster. There is no open port for an attacker to knock on.
Sovereign to your fleet
Your keys, your roster, your routing. The control plane never touches plaintext, and a node that leaves your estate cannot be re used against you. Full architecture and threat model are published on Enabel so every claim on this page is defensible and verifiable.
Field test results, Jay and Joe
Initial sessions logged. The report grows as testing continues.
Best latency
38 ms
Longest hop
240 m
Sustained uptime
99.95%
Packet integrity
99.97%
- T12026-05-14 Warehouse pilot, West Midlands
Cold join under 6s. Self heal verified after deliberate node power down.
4 devices, 120 m span, Steel racking, concrete dividers.
Latency38 msIntegrity100%Uptime100% - T22026-05-29 Multi storey office, Birmingham
Three hop path held throughout. Forward secrecy rotation confirmed every session.
6 devices, 95 m span, Two reinforced concrete floors.
Latency52 msIntegrity99.97%Uptime100% - T32026-06-11 Mobile fleet test, M6 corridor
Rejoin under 2s after temporary partition. Roster revocation propagated in 1.4s.
5 devices, 240 m span, Moving vehicles, motorway RF noise.
Latency71 msIntegrity99.92%Uptime99.8% - T42026-06-19 Basement plant room, Manchester
Field Testing Node validated full stack: twin sync, telemetry, alert path.
4 devices, 60 m span, Below ground, thick masonry, live MEP interference.
Latency44 msIntegrity100%Uptime100%
The AmPoRaH Field Testing Node
Purpose built, because nothing on the market could test this.
Nothing on the market can stress test a turnkey solution like AmPoRaH, so we built one. The AmPoRaH Field Testing Node is a single purpose device that plugs into any access point on the mesh and exercises the full stack in real conditions. It is the reason every claim on this page is verifiable. If a feature cannot be proven through the node, it does not ship.
Why it had to exist
- Commercial mesh testers measure radios, not a live twin. They cannot replay sensor traffic, twin updates and AI alerts at the same time.
- Penetration tooling measures one surface at a time. Our threat model is the whole fleet behaving as one system.
- Customer sites cannot be used as a lab. We need destructive, repeatable tests without ever touching tenant data.
- Field conditions, concrete, steel, basements, moving vehicles, are not reproducible on a desk.
How tests are run
Every test is scripted, timestamped and signed. Results are written to an append only log on the node and mirrored to your own store. Nothing about a test session can be edited after the fact. The same scripts run on every visit, so results from Jay and Joe today are directly comparable to results six months from now.
What the node validates
Every line below is a scripted test the node runs, captures and signs.
Mesh and transport
- Peer discovery and join time on a cold network.
- Self healing after node loss, link loss and partition.
- Multi hop latency, jitter and packet integrity under load.
- Throughput across 1, 2 and 3 hop paths.
- Range with line of sight, through walls and through floors.
- Behaviour under RF interference and deliberate jamming.
Security and sovereignty
- Mutual authentication and rejection of unknown peers.
- Key rotation and forward secrecy across sessions.
- Tamper detection on a node, including key wipe.
- Replay, spoof and man in the middle resistance.
- Confirmation that the control plane operator cannot decrypt payloads.
- Roster revocation propagation time across the fleet.
Twin and telemetry
- Live sensor ingest at target rate with zero loss.
- Twin update latency from sensor to visual layer.
- Alert delivery latency end to end.
- Sync recovery after a node returns from offline.
- Time and GPS stamp accuracy on captured frames.
Operations
- Battery and power draw under sustained transmit.
- Thermal behaviour in enclosed and outdoor conditions.
- Firmware update over the mesh without breaking quorum.
- Rollback safety when an update fails on a subset of nodes.
- Audit log completeness and tamper evidence.
Every claim on this page is verifiable. The mesh architecture, threat model and test methodology are published on Enabel. Test logs are retained and available on request.