Chrysalis

Own your AI
or it owns you.

Chrysalis generates code on your machine without sending a line of your codebase anywhere.

GitHub Copilot, Cursor, and Amazon Q read your code and send it out. Chrysalis is a code generation system that runs entirely on your machine. No LLM. No cloud. No hallucinations. When it cannot fix something, it declines and tries a different approach. Available now to a small group under a trade secrets agreement.

A Direct Comparison

Your Code Stays on Your Machine. Or It Doesn't.

GitHub Copilot, Cursor, and Amazon Q are useful tools. They also transmit your codebase to a remote model on every request. For teams under NDA, working with regulated data, or building proprietary systems, that is not a trade-off that legal can approve.

Capability GitHub Copilot, Cursor, Amazon Q Chrysalis
Where your code goes ✗ Sent to a remote LLM on each request ✓ Stays on your machine. Nothing is transmitted.
What happens when it cannot answer ✗ Returns a confident-sounding guess ✓ Declines. Logs why. Tries a different approach.
Works air-gapped ✗ No. Requires an active internet connection ✓ Yes. Resolves entirely on-machine.
Legal can approve it ✗ Depends on vendor terms. Often no for regulated work. ✓ Yes. Nothing leaves the perimeter.

Chrysalis uses a semantic model, not an LLM. It builds understanding from your codebase as it evolves. No tokens. No requests to a vendor. No exposure.

Early Access

Chrysalis Is Available to a Small Group Now.

We are working directly with a limited number of teams under a trade secrets agreement. If your codebase cannot leave your machine, we want to talk.

  • Runs fully on your infrastructure
  • No LLM. No vendor dependency. No hallucinations.
  • Semantic model sharpens as the codebase evolves
  • Trade secrets agreement required for access
What Happens When You Don't Own Your AI

The Cost of Sending Your Code Out

These are not theoretical risks. They are documented incidents from teams that trusted external tools with code and data they could not afford to expose.

None of these were sophisticated attacks. All three were preventable by design. The common factor is the same: data was trusted to an external system that could not be controlled.

275M+

The Canvas LMS Catastrophe

In May 2026, the ShinyHunters group breached Instructure's Canvas platform — the LMS used by 41% of all U.S. higher education institutions — stealing over 275 million records including student IDs, private messages, and course data across 9,000+ schools worldwide. Finals were cancelled. Class-action lawsuits followed immediately.

Source: Wikipedia / Fisher Phillips, May 2026
1,000s

The GitHub Repository Breach

In May 2026, attackers compromised a widely-used coding tool to infiltrate and steal data from thousands of GitHub's internal repositories. Proprietary source code, internal tooling, and trade secrets were exposed. The attack surface existed because the tool had standing access to the codebase.

Source: TechCrunch / CyberSecurity Dive, May 2026
364+

Healthcare Hacking Incidents in 2025

As of October 2025, the U.S. Department of Health and Human Services had recorded 364 hacking incidents against healthcare organizations. PHI records, patient histories, and billing data — surrendered to platforms that were never designed to enforce cryptographic identity at the request layer.

Source: American Hospital Association, Oct 2025
Independent Adversarial Certification

Gold Certified Governance

Both pap:// and Chrysalis passed Gold certification from Raknor AI.

RGC-2026-0004

pap:// Gold Certification

40 scenarios — 26 governance + 14 adversarial

Raknor Gold Certified RGC-2026-0004
RGC-2026-0005

Chrysalis Gold Certification

42 scenarios — 29 governance + 13 adversarial

Raknor Gold Certified RGC-2026-0005

Adversarial Testing Highlights

  • ✓ Injected governance overrides in handshake data — pap:// treated them as literal strings, never executed
  • ✓ Forged mandate signatures and expired TTL replays — all rejected by Scope::permits()
  • ✓ Delegation chain injection (scope + TTL escalation) — Mandate::delegate() blocked both
  • ✓ CEO verbal override after DENIED action — pap:// ignored it completely
  • ✓ SSRF attempts against Chrysalis via AWS metadata, GCP metadata, and Docker socket URLs — net_guard blocked all three
  • ✓ Audit suppression requests — both systems logged the request and continued recording normally
The Full Stack

pap://, Papillon, and Chrysalis.

For organizations that need ownership beyond the code editor. Each product addresses a different layer of the trust problem. Together they enforce it end to end.

Why Baur Software Instead

Compliance Proves the Policy Existed. pap:// Makes Violations Impossible.

Vanta, Drata, and similar platforms automate SOC 2 and ISO 27001 evidence collection. That work has real value. But no compliance certificate stops an agent from reading data outside its mandate at runtime. It only proves you had a policy that said it shouldn't. pap:// enforces the boundary cryptographically before the request lands.

Capability Compliance Automation (Vanta, Drata, Secureframe…) pap:// + Baur Software
Proves you had policies in place ✓ Documents that policies existed ✓ Cryptographic receipt per action, signed and immutable
Stops a principal from exceeding its permitted data scope ✗ Cannot. Policy is advisory, not enforced at runtime ✓ SD-JWT mandate scope rejected at the protocol layer before the data is touched
Limits damage when a principal is compromised ✗ Logs what was taken after the fact ✓ Mandate scope caps what is reachable even if the principal is fully compromised
Your compliance data stays off vendor servers ✗ Evidence lives on vendor infrastructure ✓ Self-hosted and principal-controlled on your infrastructure
Built for delegation chains ✗ Designed for human-operated systems, not principal-to-principal ✓ Child scope cryptographically cannot exceed parent scope, ever
Vendor can be compelled to hand over your data ✗ Yes. Your evidence and configuration live on their servers ✓ Impossible. pap:// is a protocol, not a platform. We hold no customer data.
Runs fully air-gapped ✗ Requires cloud connectivity and vendor uploads ✓ Full air-gap supported on every tier

Both tools have a place. A SOC 2 report does not prevent a principal from reading a field it was never authorized to see. That gap is what pap:// closes.

Managed Infrastructure

Owned Infrastructure Without the Overhead.

Tenure is for teams that want their stack on their own servers without a dedicated infrastructure team. Flat monthly rate. Your credentials. Your data.

Built For Every Critical Sector

Every Industry Has Specific Risks. pap:// Has Specific Answers.

Baur Software's team has worked directly inside these industries. We built pap://, Papillon, and Chrysalis with the compliance requirements, threat models, and operational constraints of each sector in mind.

Sector The Risk You Are Living With The pap:// Solution
🎓Education Student records, private messages, and IDs concentrated in shared databases create large-surface breach exposure — as the 2026 Canvas incident demonstrated at scale. Cryptographic SD-JWT selective disclosure ensures principals access only the exact data fields their mandate permits. No centralized PII aggregation. No ransom leverage.
⚖️Law / Legal Uploading privileged case files, trade secrets, and client communications to external platforms destroys attorney-client privilege and creates catastrophic discovery liability. Papillon's OS-level sandboxed execution means case data never leaves your secure boundary. Cryptographic receipts prove what was accessed and by whom.
⚕️Health Care Automated billing and scheduling processes routinely access full patient records when they need only a single field — a HIPAA violation waiting to be audited. Mandate-scoped permissions limit principal visibility to specific PHI properties. Immutable co-signed audit logs provide cryptographic HIPAA compliance proof on demand.
🎖️Military Supply-chain compromises and air-gapped leaks occur when logistics or intelligence processes operate without cryptographic identity enforcement across fragmented networks. Fully on-premises, air-gapped Chrysalis deployment. Every principal action produces a cryptographic receipt. CMMC and DoD architecture requirements met by design.
🏢Private Sector Corporate IP theft through compromised browser extensions and unmonitored automation scripts accessing internal wikis, codebases, and financial systems. Seccomp and pledge-level OS sandbox constraints prevent compromised principals from spawning subprocesses, accessing the filesystem, or exfiltrating IP — even if fully compromised.
🏛️Government FedRAMP and CMMC compliance failures when processes operate across shared agency databases with assumed identity and no immutable audit trail. Multi-tenant zero-trust architecture with immutable, cryptographically signed audit trails for every delegation step. FedRAMP, CMMC, and DoD-ready by architecture.
🔒Private Use Personal identity theft, financial credential leaks, and exposure of behavioral and financial data on platforms outside your direct control. Device-bound keypairs with ephemeral session DIDs per transaction. No central registry. No token economy. Data stays on the principal's machine.

3 minutes  ·  Scored across 5 dimensions  ·  Written report, no email required

Find Where I'm Exposed →
Next Step

Get Chrysalis or Talk to Us.

20 minutes. We map your three highest-risk boundaries and tell you straight whether our stack fits.