Papyrus / Trust Center

Security evidence, published in the open.

Papyrus is a customer-hosted durable agent runtime powered by Mastra. Entra ID is the identity authority. The product surface is a Mastra-native agent runtime with governed plugin lifecycle, offline licensing, sandboxed execution, and zero-inline-secrets architecture.

Abstract reflective green and orange forms

Scope: potential software control contributions only. These materials are not a FedRAMP authorization, ATO, SSP, certification, or independent assessment. Papyrus is not an authorization to operate, a cross-domain solution, or a claim of GCC High, DoD, IL4, IL6, or SIPR accreditation.

Architecture

Six pillars

Papyrus is a licensed daemon for durable, event-driven agent work. Mastra owns sessions; plugins are adapters; Entra is authoritative.

Mastra Runtime

Owns sessions, memory, schedules, workflows, and signal delivery. Storage starts even without a configured model.

Plugin Architecture

Teams, Exchange email, ACP, A2A, and customer systems are plugins. Disabling them does not disable the runtime.

Entra ID Native

No local identity system. Six application roles: Integration.View, Integration.Manage, Security.Manage, Action.Approve, Audit.View, System.Owner.

Zero-Inline-Secrets

Connector config accepts only customer-vault, certificate, or managed-identity references. Inline tokens and keys are rejected.

Sandboxed Execution

Agent code runs only on Linux under Bubblewrap with network denied. Off-host execution is explicitly disabled.

Offline Licensing

Deployment-bound, signed, offline license format. No Beag cloud callback required. License authorities are customer-pinned.

Governed plugin lifecycle

Draft → Tested → Awaiting Approval → Active → Degraded / Disabled

Credential values never enter model context. The card sends credential references directly to the daemon.

Draft

Initial configuration authored by an integration owner

Tested

Configuration validated; health checked against the target system

Awaiting Approval

Submitted for review by an Entra-authorized approver

Active

Approved and operational; actions can be released

Degraded / Disabled

Health issues detected or explicitly disabled by governance

Components

85

Mapped controls

35

OSCAL version

1.2.1

SBOM generated

8/7/2026

Machine-readable controls

The model is explicit about ownership.

The OSCAL component definition separates behavior provided by Papyrus from configuration, infrastructure, and inherited services owned by the customer.

Mapping status

31

Partial

4

Customer-configured

No mapping is represented as fully implemented or assessed. "Partial" records a potential Papyrus contribution; "customer-configured" depends on the deployed boundary.

papyrus

7

shared

24

customer

3

inherited

1

AC family5 mappings+
IA family4 mappings+
AU family6 mappings+
CM family6 mappings+
cm-2

Baseline Configuration

sharedpartial

Papyrus provides profile-driven defaults for commercial, NIPRNet/IL4, and SIPRNet/IL6 modes. Customers document the approved deployment manifest, operating system, container, network, IdP, model endpoint, service binding, and storage configuration.

cm-3

Configuration Change Control

customercustomer-configured

Papyrus configuration is file- and environment-driven and can be version controlled. Approval, testing, deployment, rollback, and emergency-change processes are customer operational responsibilities.

cm-5

Access Restrictions for Change

sharedpartial

Administrative and project permissions restrict application-level changes. Repository, deployment pipeline, host, secret-store, and production configuration access are controlled by the customer.

cm-6

Configuration Settings

sharedpartial

PAPYRUS_PROFILE gates authentication, model endpoint, internet use, agent availability, and cross-domain features. Customers set secure values and validate them against the authorized environment.

cm-7

Least Functionality

sharedpartial

Papyrus can disable agents, external model endpoints, internet-assisted discovery, and cross-domain export by profile. Customers remove unused services, block unnecessary ports, and constrain runtime capabilities.

cm-8

System Component Inventory

sharedpartial

Papyrus publishes a lockfile and can produce SPDX or CycloneDX SBOMs for application dependencies. Customers add operating system, container, hardware, IdP, database, model server, and infrastructure components.

SC family6 mappings+
sc-7

Boundary Protection

sharedpartial

Papyrus supports explicit service binding, profile-based internet restrictions, authenticated project-scoped WebSocket sessions, and no required public discovery or relay infrastructure. Firewalls, proxies, segmentation, CDS boundaries, and enclave routing remain customer controls.

sc-8

Transmission Confidentiality and Integrity

sharedpartial

Browser, API, and realtime WebSocket traffic can use TLS through the authoritative Papyrus service. Customers provision certificates, approved cipher policy, termination architecture, and any required FIPS-validated modules.

sc-12

Cryptographic Key Establishment and Management

sharedpartial

Papyrus uses a deployment identity for session and transfer signing, TLS certificates, SAML certificates, OIDC verification keys, trusted deployment identities, and a pinned license authority key. Customers define key custody, approved generation, backup, rotation, revocation, escrow, and destruction.

sc-13

Cryptographic Protection

sharedpartial

Papyrus relies on platform cryptographic implementations for TLS, WebAuthn, X.509, token signatures, signed licenses, and QUIC. Algorithm availability does not itself establish FIPS validation; customers select validated modules when required.

sc-23

Session Authenticity

papyruspartial

Papyrus binds requests to validated session tokens, protects state-changing browser flows with CSRF challenges, validates WebAuthn challenges, and validates OIDC state and PKCE data.

sc-28

Protection of Information at Rest

customercustomer-configured

Papyrus stores projects, credentials, audit records, and configuration locally. Encryption at rest is inherited from customer-managed full-disk, volume, database, or platform encryption and associated key management.

SI family5 mappings+
RA family1 mappings+
SA family1 mappings+
SR family1 mappings+

Software bill of materials

85 inspectable components.

63 MIT8 ISC5 Apache-2.02 BSD-3-Clause
  1. @@ai-sdk/openai4.0.34Apache-2.0
  2. @@node-saml/node-saml5.1.0MIT
  3. @@simplewebauthn/browser10.0.0MIT
  4. @@simplewebauthn/server10.0.1MIT
  5. @@types/node22.20.1MIT
  6. @@xyflow/react12.11.2MIT
  7. aai7.0.56Apache-2.0 + MIT
  8. bbetter-sqlite313.0.3MIT
  9. ccitty0.1.6MIT
  10. ggsap3.15.0Not declared
  11. rreact18.3.1MIT
  12. rreact-dom18.3.1MIT
  13. wws8.21.2MIT
  14. @@ai-sdk/gateway4.0.44Apache-2.0
  15. @@ai-sdk/provider4.0.6Apache-2.0
  16. @@ai-sdk/provider-utils5.0.23Apache-2.0 + BSD-3-Clause + ISC
  17. @@hexagon/base641.1.28MIT
  18. @@levischuck/tiny-cbor0.2.11MIT
  19. @@peculiar/asn1-android2.8.0MIT
  20. @@peculiar/asn1-ecc2.8.0MIT
  21. @@peculiar/asn1-rsa2.8.0MIT
  22. @@peculiar/asn1-schema2.8.0MIT
  23. @@peculiar/asn1-x5092.8.0MIT
  24. @@simplewebauthn/types10.0.0MIT
  25. @@types/debug4.1.13MIT
  26. @@types/qs6.15.1MIT
  27. @@types/xml-encryption1.2.4MIT
  28. @@types/xml2js0.4.14MIT
  29. @@xmldom/is-dom-node1.0.1MIT
  30. @@xmldom/xmldom0.8.13MIT
  31. @@xyflow/system0.0.79MIT
  32. cclasscat5.0.5MIT
  33. cconsola3.4.2MIT
  34. ccross-fetch4.1.0MIT
  35. ddebug4.4.3MIT
  36. lloose-envify1.4.0MIT
  37. nnode-addon-api8.9.1MIT
  38. sscheduler0.23.2MIT
  39. uundici-types6.21.0MIT
  40. xxml-crypto6.1.2MIT
  41. xxml-encryption3.1.0MIT
  42. xxml2js0.6.2MIT
  43. xxmlbuilder15.1.1MIT
  44. xxpath0.0.34MIT
  45. zzod4.4.3MIT
  46. zzustand4.5.7MIT
  47. @@peculiar/utils2.0.3MIT
  48. @@standard-schema/spec1.1.0MIT
  49. @@types/d3-drag3.0.7MIT
  50. @@types/d3-interpolate3.0.4MIT
  51. @@types/d3-selection3.0.11MIT
  52. @@types/d3-transition3.0.9MIT
  53. @@types/d3-zoom3.0.8MIT
  54. @@types/ms2.1.0MIT
  55. @@vercel/oidc3.2.0Apache-2.0
  56. @@workflow/serde4.1.0Apache-2.0
  57. aasn1js3.0.10BSD-3-Clause
  58. dd3-drag3.0.0ISC
  59. dd3-interpolate3.0.1ISC
  60. dd3-selection3.0.0ISC
  61. dd3-zoom3.0.0ISC
  62. eescape-html1.0.3MIT
  63. eeventsource-parser3.1.0MIT
  64. jjs-tokens4.0.0MIT
  65. jjson-schema0.4.0AFL-2.1 + BSD-3-Clause
  66. mms2.1.3MIT
  67. nnode-fetch2.7.0MIT
  68. ssax1.6.1BlueOak-1.0.0
  69. ttslib2.8.10BSD
  70. uundici7.29.0MIT
  71. uuse-sync-external-store1.6.0MIT
  72. xxmlbuilder11.0.1MIT
  73. xxpath0.0.32MIT
  74. xxpath0.0.33MIT
  75. @@types/d3-color3.1.3MIT
  76. dd3-color3.1.0ISC
  77. dd3-dispatch3.0.1ISC
  78. dd3-transition3.0.1ISC
  79. ppvtsutils1.3.6MIT
  80. ppvutils1.2.0MIT
  81. wwhatwg-url5.0.0MIT
  82. dd3-ease3.0.1BSD-3-Clause
  83. dd3-timer3.0.1ISC
  84. ttr460.0.3MIT
  85. wwebidl-conversions3.0.1BSD-2-Clause

Component names, versions, and declared licenses are read from the published CycloneDX SBOM. Project links are taken from each component's repository metadata, with npm as the fallback. Marks identify their respective projects or maintainers and do not imply endorsement.

Deployment alignment

Aligned with

Alignment describes supported deployment profiles and documented mappings—not government approval or authorization.

DoD IL4

Customer-managed controlled environment profile

DoD IL6

Customer-managed classified environment profile

NIST SP 800-53 Rev. 5

35 documented control mappings

Published artifact

OSCAL component definition

OSCAL 1.2.1 · v0.2.0

FOSSAPublished artifact

FOSSA third-party report

Dependency licenses and notices · PDF

Need deployment evidence?

Map the component into your actual authorization boundary.

Request evidence