This paper introduces Hill-Enigma-SPN (HESPN), a 128-bit byte-oriented substitution–permutation network research construction combining rotor-scheduled GF(2) byte-matrix diffusion, the AES S-box, a round-dependent inter-byte routing permutation, and an Argon2id profile for password-based key derivation. HESPN is not proposed as a deployment-ready alternative to standardized ciphers; its contribution is architectural. The key-setup admissibility filter guarantees branch number B ≥ 4 for every scheduled matrix orientation, trading weaker per-round intra-byte diffusion for 64 scheduled key-dependent (seed, orientation) pairs across 16 rounds. Across five experimental sessions, avalanche, sampled-differential, random-mask-uniformity, algebraic-degree, and selected NIST SP 800-22 screens approach their observable ideals at 16 rounds. A new whole-cipher boomerang-style returned-difference calibration tested eight (α,δ) jobs over eight keys and 20,000 nondegenerate quartets per key at rounds 4–16, with randomized SPN and Feistel null controls. All 64 broad tests remained significant through 10 rounds and 51/64 at 12 rounds; none was significant at 14 or 16 rounds. At 16 rounds no exact or weight-1 returns occurred in 1.28 million trials, and the lowest Benjamini–Hochberg q-value was 0.092. These bounded screens do not establish resistance to optimized boomerang or differential trails; low-weight iterative trails remain an open threat.