MAQPNA

Trust centre

Verify everything you run.

MAQPNA is a security boundary for untrusted agent code, so you should not have to take our word for anything. Every release is signed, every image carries an SBOM, and nothing calls home.

Release signing

Keyless signatures, bound to the workflow that built them.

Releases are signed in GitHub Actions with Sigstore cosign keyless signing. The certificate binds each signature to the workflow identity that built and signed it. There is no long-lived signing key to steal.

Binaries

CLI and server binaries for Linux, macOS and Windows, signed by the release-of-record workflow, with a .sigstore.json bundle next to each file and a signed checksums.txt.

Container images

11 multi-arch images (linux/amd64, linux/arm64), distroless, running as UID 65532, cosign-signed with SPDX SBOM attestations.

Helm chart and air-gap bundles

The chart is published as a signed OCI artifact. Air-gap bundles include a SHA256SUMS file, signed with cosign when built with a signing key.

Verify a download

Check the checksum and the signature.

The install scripts always check the SHA-256 and verify the cosign signature when cosign is installed (--cosign requires it). To check by hand, use cosign 2.x or later.

maqpna verify checks signatures, SBOM attestations and checksums of MAQPNA releases from the CLI. Per-file commands for every platform are on the download page.

verify a binary
V=v0.1.0
R=https://github.com/AzmxAI/maqpna-releases/releases/download/$V
curl -fsSLO $R/maqpna_linux_amd64 -fsSLO $R/maqpna_linux_amd64.sigstore.json -fsSLO $R/checksums.txt
grep ' maqpna_linux_amd64$' checksums.txt | sha256sum --check
cosign verify-blob maqpna_linux_amd64 --bundle maqpna_linux_amd64.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/AzmxAI/azmx-ai/\.github/workflows/maqpna-signed-release\.yml@refs/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

SBOMs and provenance

Know exactly what is inside.

Every archive ships with an SPDX 2.3 SBOM next to it, and every image carries its SBOM as a signed attestation.

  • SLSA build provenance attestations on archives and packages, checked with gh attestation verify.
  • Image SBOMs as cosign attestations: cosign verify-attestation --type spdxjson.
  • Static binaries (CGO_ENABLED=0) built from the tagged source.
  • Pin images by digest in production; the download page lists every digest.

No phone-home

MAQPNA makes no outbound calls by default.

No telemetry, usage analytics, update checks or licence validation. An unexpected outbound network call is treated as a vulnerability.

  • The only egress is what you configure, constrained by allowedEgressHosts and allowedEgressCIDRs.
  • Licences are verified offline. An expired licence never blocks agent traffic.
  • This website sets no cookies, runs no trackers and loads nothing from third parties.

Secure defaults

Safe until you say otherwise.

Default deny

No matching rule, or no policy, means the call is denied. Sandboxes start with default-deny egress.

Fail closed

If the revocation list is unavailable, calls are denied. In the sovereign profile, so are calls when the audit ledger is unavailable.

Hardened sandboxes

Non-root, read-only root filesystem and no Kubernetes service-account token in the agent's pod.

Dev-only is labelled

The generated identity key and the sample attestation verifier are for development and say so; the attestation service will not start without verifier keys.

Security testing

Checked on every change.

The CI pipeline runs on every pull request and on main.

  • govulncheck and staticcheck on the Go code.
  • All 11 images built with an SBOM and scanned with Trivy.
  • Nightly fuzzing of the gateway's message parser, token verification, the DLP scanner, policy conditions and canonical JSON.
  • End-to-end tests on a real kube-apiserver and on kind with gVisor and NetworkPolicy enforcement.

Vulnerability disclosure

Report a vulnerability privately.

Do not open a public issue. Email [email protected] with the affected component and version, your configuration (trust tier, runtime, Kubernetes version), reproduction steps and the impact you observed.

  • We aim to acknowledge reports within 3 business days.
  • We agree a disclosure timeline with you: 90 days by default, sooner once a fix is released.
  • We credit reporters who want to be credited.
  • Until 1.0, only the latest minor release receives security fixes.

In scope

  • Sandbox escapes or isolation bypasses caused by MAQPNA configuration
  • Identity token forgery, replay, audience or scope confusion
  • Attestation bypasses: identities or secrets released without valid evidence
  • Gateway policy bypasses: calls that evade policy, approvals or rate limits
  • Audit-ledger tampering that verification does not detect
  • Any unexpected outbound network call
  • Privilege escalation through operator RBAC, chart defaults or images

Out of scope

Vulnerabilities in upstream projects (gVisor, Kata Containers, Firecracker, Confidential Containers, agent-sandbox, Kubernetes) go to those projects; tell us too if our defaults make them worse. Findings that need cluster-admin, and the documented development-only modes, are out of scope.

Verify it yourself.

Install the CLI with checksum and signature verification, or read the release before you run it.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.