MAQPNA

About

Safety must not depend on the model.

AI agents now read email, change code, move money and operate infrastructure. Models will sometimes be wrong, and sometimes be manipulated by what they read. We build the runtime that makes that survivable: every action checked, approved when it matters, recorded, and stoppable.

Mission

Let organisations say yes to agents in production.

Most agent projects never reach production. The blocker is rarely the model. It is the questions a platform or security lead must answer before signing off: where does it run, what can it touch, who approves the risky parts, how do we stop it, and how do we prove what it did?

MAQPNA answers those questions in the infrastructure itself, on the customer's own clusters and in their own jurisdiction, with no vendor control plane. We build on upstream open source (Kubernetes, agent-sandbox, gVisor, Kata Containers, Confidential Containers) and open protocols (MCP, A2A, SPIFFE, OIDC, OpenTelemetry) rather than replacing them.

The name

Multi-Agent Quarantine & Policy-Native Architecture

Multi-agent quarantine

Every session of every agent runs in its own sandbox, with its own identity and default-deny networking. Agents are untrusted until a rule says otherwise.

Policy-native

Policy is not a bolt-on filter. Every tool, model and agent-to-agent call crosses one gateway that decides, records and only then forwards.

Architecture

Sovereignty and safety come from how the system is built, not from a contract: your clusters, your keys, your records.

Say it "mak-pna". Written MAQPNA, always in capitals.

Principles

How we build.

Honest scope

We say what is not built, not certified or not proven. MAQPNA helps you document compliance; it does not make you compliant.

Your infrastructure

No phone-home, no licence server, no hosted dependency. A licence never blocks agent traffic.

Upstream first

We build on open projects and standards, so your agents and tools stay portable.

Verifiable

Signed releases, SBOMs and a ledger anyone with the public key can check.

Let agents act. Keep control.

Try MAQPNA on your laptop, or tell us what you are building.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.