Everything a TAK deployment needs, and none of it yours to run

The certificate that expires mid-operation, the config file that has to agree with itself at both ends, the host nobody patched. All of it still has to happen. None of it has to be yours.

Automated certificates

Certificate authority, enrolment and rotation handled for you. Devices connect with a data package instead of a support ticket.

Federation

Connect networks between organizations, or out to external TAK systems, with the controls to decide exactly what crosses the boundary.

Streaming video

Publish and consume video feeds alongside the common operating picture, so what a camera sees reaches the people who need it.

Learn more

Users and organizations

Roles, invitations and per-organization isolation. Add an operator in seconds and remove their access just as fast.

Data packages and missions

Share imagery, overlays and mission data across the team, with change history and subscriptions handled by the server.

Works with what you own

ATAK on Android, iTAK on iOS and WinTAK on Windows all connect to the same network. No client modifications.

The certificate nobody remembered until it stopped everything

Every TAK deployment runs on mutual TLS, which means every deployment needs a certificate authority. Standing one up is a day’s work for someone who has done it before and a week for someone who has not. Keeping it alive is the part nobody budgets for: certificates expire on a schedule that has no relationship to whether you are in the middle of something.

ArgusTAK runs the authority. Enrolment, issue and rotation all happen server-side, and what an operator receives is a data package they import once. The whole category of problem — expired certificates, mismatched trust chains, a .p12 emailed to the wrong person — stops being yours.

Federation you configure in a console, not in XML

Federation is how two organizations share a picture without becoming one organization. It is also, in a hand-built deployment, a configuration file on both ends that has to agree with itself, plus a certificate exchange, plus a firewall conversation.

Here it is a screen, and it is three things sharing one set of controls. Another network in your own organization takes effect immediately, with no code to exchange, because both ends already have the same owner. A network belonging to a different organization is joined by passing them a short federation code — they paste it, pick their direction, and there is no config file and no certificate to exchange. A TAK Server outside ArgusTAK is the third, and it is the one that still involves certificates: you register the peer with its client certificate, a hostname and a port. Fewer moving parts than editing a config file at both ends, but not a code.

Across organizations, each side then owns its own end: your switches govern only what you send and what you accept, theirs govern theirs, and either of you can stop without asking permission or filing a change. Between two networks you both own it behaves as you would expect instead — change one end and the other follows, because there is nobody on the far side to negotiate with. Accepting an invitation does open the receiving side to inbound traffic and data packages — that is what accepting means — and you change it from there like any other setting. That is the part a hand-built federation cannot really give you, because there both ends live in one file that has to agree with itself.

What federation does not do is add capacity. Every network in an organization draws on the same pool, so joining two of them together lets people see each other without collapsing two teams into one network that neither administers — it does not give you more room than you had.

Who can do what, in an organization

Roles are collections of permissions, and each permission in a role is granted, denied or left unset. The denial is the part worth knowing: it wins. If any role a person holds denies a permission, they do not have it, no matter what another role grants. That is what lets you hand someone a broad role and subtract from it, rather than assembling every person’s access from scratch.

Not everything on a network needs to be a person. A device account exists for the things that cannot hold a login or should not have one — TAK Tracker on a shipping container, or on a search dog — and it appears on the map like anything else without ever being able to sign in to the console.

And where a set of devices should share one credential rather than carry their own, a network certificate does that: one certificate, many devices on that network. You set the maximum number allowed to connect at the same time, and it is that ceiling that is reserved against your plan — set when you issue the certificate, not counted as devices come and go.

How to connect your first device

Start to finish, for a team that has never run TAK before, this is minutes rather than days. Nothing below requires a server, a Linux administrator or a purchase order.

  1. Create an ArgusTAK account. The free tier needs no card.
  2. Create a network. This is the thing your devices will connect to.
  3. Install the client on the device — ATAK from the Play Store or tak.gov, iTAK from the App Store, WinTAK from tak.gov. All three are free.
  4. Generate an enrolment data package in the console and send it to the operator.
  5. Import the package on the device. It carries the certificate, the hostname and the channel configuration, so there is nothing to type in.
  6. Confirm the device appears on the map, then repeat for everyone else.

Video, missions and the rest of the picture

Positions are the easy half. What usually decides whether a team keeps using TAK is whether the rest of what they know travels with them: the overlay somebody built the night before, the imagery for an area with no signal, the camera feed from the one vantage point nobody can occupy.

Missions carry imagery, overlays and mission data across the team, with change history and subscriptions handled by the server rather than by whoever remembered to re-send the file. Video feeds publish and consume alongside the map, so a camera or an aircraft reaches the people already looking at it. Both are on Team and above.

Common questions

Which TAK clients does ArgusTAK support?

ATAK on Android, iTAK on iOS and WinTAK on Windows, all unmodified and all on the same network at the same time. The clients come from tak.gov; there is nothing ArgusTAK-specific to install on a device.

How do certificates get onto a device?

Inside the enrolment data package. The console generates it, the operator imports it, and the client trusts the server from that point on. Nobody handles a .p12 by hand or reads a fingerprint down a phone line.

What happens when a certificate is about to expire?

Rotation is handled server-side rather than becoming a support ticket. The failure mode this is designed around is the one every self-hosted deployment eventually hits: a certificate that expired on a Friday night with an operation running.

Can two organizations share a picture without merging?

Yes, that is what federation is for. You connect two networks and control exactly what crosses the boundary, so a mutual-aid partner sees what you meant to share and nothing else.

Does video work on the same network as the map?

Yes. Feeds are published and consumed alongside the common operating picture, so what a camera or an aircraft sees reaches the people already looking at the map.

The server was the only thing in the way

Five devices, free, with no card and no clock. Put your team on one map for a weekend and find out properly.