Chrysalis

A federated registry for services built on pap://.

Self-hosted. No platform in the trust chain. Baur Software is never in the blast radius.

A live, searchable ledger of the registry's own operation — operational metadata only; no principal data leaves the node.
A live, searchable ledger of the registry's own operation — operational metadata only; no principal data leaves the node.

Agents need infrastructure. Most teams build it themselves and fail.

Orchestration is the reason most agent projects never ship. Routing, context passing, failure handling, state management across agents — teams spend months on the plumbing and either ship something brittle or stop.

The compliance problem lands next. Agents running against a codebase or sensitive data with no audit trail, no scoped permissions, no proof of what ran. Security says no. Legal says no. The project stalls.

Chrysalis is the infrastructure layer. Orchestration is built in. Every execution produces a co-signed receipt. Nothing runs without a human-signed mandate.

No platform in the trust chain.

What is zero trust? →

A gateway is not an enforcement engine.

Most teams put a gateway in front of the model provider. A gateway sees the prompt and the response. It cannot see what the agent does on the host machine — the files it reads, the connections it opens, the processes it starts.

Chrysalis enforces at the execution boundary. That is where it matters.

What Chrysalis does

1

The trust chain stays on your infrastructure.

Chrysalis ships as a single binary. It runs on Linux, macOS, Windows, or Docker. There is no SaaS to connect to. If Baur Software disappears tomorrow, the security posture does not change.

Peer registries on a federated network. The node is sovereign — peering is a runtime action, not a configuration dependency.
Peer registries on a federated network. The node is sovereign — peering is a runtime action, not a configuration dependency.
An agent asked to read a .env file gets a licensing check instead — the request never crossed the perimeter.
An agent asked to read a .env file gets a licensing check instead — the request never crossed the perimeter.
2

Code never crosses the wire.

The built-in code-search service semantically indexes repositories and answers questions on-device. Nothing is transmitted. Lossless recall: if it is in the index, it is in the answer.

3

Deterministic-first. Model as last resort.

Coding tasks run in isolated git worktrees. Scaffolding, boilerplate, and predictable modifications complete with zero model calls. When a model is genuinely needed, it is the last step. Most routine work never reaches a provider at all.

4

Private payments. The mint sees nothing.

Chrysalis uses Chaumian blind-signature ecash to authorize and pay for services. The mint signs each token without seeing its serial. When a token is spent, the mint cannot link the redemption to the purchase. Payment happened. Not to whom, when, or for what.

Deterministic agents registered with signed advertisements and per-agent sandboxing, resolving on-machine.
Deterministic agents registered with signed advertisements and per-agent sandboxing, resolving on-machine.

Built to run without us.

Self-hosted infrastructure means ownership is unconditional. No vendor terms that shift. No platform that can be compelled to hand over data. No central authority the registry depends on.

See the cost of ownership →
Baur Software - Zero-Trust for Everywhere | Product Hunt

Get Chrysalis

Follow up within one business day.