Live testing · v0.1.22 — Baryon is in early public preview. Expect bugs, missing UI states, and rough edges. We're shipping fixes constantly. Send feedback from inside the app or to lapizh@icloud.com.
Baryon Systems is a desktop application that
hosts a growing line of independent security products. Today it
ships two: Gluon, the eBPF host-defence stack,
and Tachyon, the runaway-process autopilot. More
products in the same shell are in private beta.
Baryon Systems is the shell. The products inside are independent of each other — different problems, different audiences, separate licenses. Pick the one you need.
Live · free during beta
Baryon Gluon
Kernel-grade defence for B2B / B2B2C APIs
eBPF firewall, hardware-bound identity, hash-chained WORM audit
ledger, private Postgres tied to your tunnel, and a chat panel
where kernel events become messages. Three independent layers,
one console.
For the 3 a.m. pages where one Python script forks 40,000 times
or a customer’s ML job saturates a shared box. Tachyon
throttles the offender by itself, sub-second, so on-call wakes
up to a logged incident instead of a fire.
For CI runners, multi-tenant nodes, gameservers, ML hosts
Zero policy out of the box: “> 50k syscalls/sec for 3s → stop”
Never touches init, sshd, or any pid you allow-list
One installer. Two products today. The shell stays out of the way.
Install Baryon Systems on your Windows desktop. Sign in. Open the Products panel. Each product runs on its own — different installer flow, different Linux footprint, different audit trail.
Using Gluon
Open Products → Gluon in the desktop app.
Pair a Linux host. The desktop SSHes in and runs
install.sh — creates the gluon user,
installs clang + kernel headers, starts
gluon-agent.service.
Write firewall rules in the desktop, hit Apply. eBPF C is
generated, shipped over SSH, clang-compiled on the host,
ip link set xdp attaches it to the NIC.
Watch the audit ledger walk its hash chain. Verify any line
offline.
Using Tachyon
Open Products → Tachyon in the desktop app.
Pair a Linux host. The desktop runs a separate, much smaller
installer that drops only the Tachyon binary and policy file.
No Postgres, no chat, no firewall toolchain.
Edit the policy (or accept the default: > 50k syscalls/sec
for 3 s → stop). Add never-touch globs for processes
you want Tachyon to leave alone.
Walk away. Trips and recoveries are logged to Tachyon’s
own SQLite store, surfaced in the desktop’s Tachyon panel.
Baryon Systems — first run
# On your laptop:
$ BaryonSystems
# Sign-in panel → create account → Products panel opens.# Two tiles are unlocked today: Gluon and Tachyon.# Pick Gluon, pair a host:ssh root@vps.example.com bash install.sh # gluon-agent
GLUON_INSTALL_OK
# Pick Tachyon, pair the same (or a different) host:ssh root@host2 bash tachyon-install.sh # tachyon only
TACHYON_INSTALL_OK
How it differs
Baryon Systems vs. SaaS-shaped infrastructure.
The same problems. Two very different deals. (This table compares Gluon, the host-defence product, against the SaaS stack most teams cobble together.)
Capability
Hosted SaaS stack
Baryon Systems · Gluon
Audit trail you can hash-verify offline
✕ Vendor-controlled
✓ JSONL on your disk
Firewall you can read the source of
✕ Black box
✓ Generated C, compiled on-host
Per-row billing
✕ Yes, always
✓ Your hardware, your bill
Migration cost when you leave
✕ Painful
✓ Plain Postgres, done
Verifiable agent identity
✕ Account-based
✓ HMAC challenge-response
Inbound ports needed
✕ Multiple, vendor-defined
✓ Just SSH
In other words…
You pay them to know more than you.
You always know more than the software.
In numbers
Small, auditable, durable.
Every Baryon Systems product is written so one engineer can read the whole thing in an afternoon. Plain Python, plain SQL, plain Electron.
~1300
Lines of Python in the Gluon agent
~600
Lines of Python in the Tachyon daemon
0
Third-party deps in either agent
XDP
Real in-kernel packet filter (Gluon)
250 ms
Tachyon remediation loop
SSH
Only inbound port either product needs
Public preview · free during 2026
Install Baryon Systems on a $5 VPS this afternoon.
One installer, two products today, more on the way. The desktop comes seeded; you get the Gluon and Tachyon installers; we want your feedback when something breaks.