MAQPNA

AI companies and agent builders

Ship agents your customers' security team will approve.

Your agent works in the demo. Then the enterprise security review asks where it runs, what it can touch, who approves risky actions and where the logs are. MAQPNA answers those questions in your customer's own cloud, without rewriting your agent.

The problem

Why enterprise deals stall in security review

Buyers want your agent, on their terms.

  1. It must run in their cloud

    Regulated buyers will not send data to your SaaS. They want the agent in their VPC or data centre.

  2. Least privilege per call

    Security teams ask which tools your agent can call, with which arguments, and who can stop it.

  3. Prompt injection

    An agent that reads emails, tickets or web pages can be steered by what it reads.

  4. Evidence on demand

    Auditors want a record of every action, not screenshots or mutable application logs.

How MAQPNA solves it

Governance as a runtime, not a rewrite

  • SDKs and adapters

    Python, TypeScript and Go SDKs with adapters for LangGraph, LangChain, the OpenAI Agents SDK, the Claude Agent SDK and CrewAI.

  • Same code, laptop to cluster

    maqpna dev up runs the gateway locally; the same agent runs in a sandbox in your customer's Kubernetes.

  • Taint tracking

    Content from untrusted sources marks the session, and later sensitive tools then need approval or are denied.

  • Token vault

    Users' OAuth tokens stay in the vault, outside the agent. The gateway injects credentials, so the agent never sees upstream keys.

  • Policy your customer controls

    Per tool and per argument, with policy test, replay and eval before rollout.

  • Evidence bundles

    Export verifiable audit records per session or period for your customer's auditors.

Architecture sketch

Your agent, in your customer's cloud

Your agent image runs in a sandbox in the customer's cluster. Their gateway, their policy, their keys. You ship the agent; they keep control.

Customer VPC or data centre · their policy · their keys

Sandboxes

tier-0 (gVisor) or tier-1 (microVM)

  • your-agent (Python SDK)
  • your-agent-worker
  • browser profile

MAQPNA gateway

identity · policy · DLP · budgets · approval · audit

  • Allowedgithub.get_issueread-only-tools
  • Held for approvalgithub.merge_pr after web readtainted session needs approval
  • Deniedvault.read_secretno-secret-exfiltration

Your systems

  • MCPcustomer's tools
  • modelcustomer's model route
  • A2Aother governed agents
Customer-owned ledger · OpenTelemetry traces linked to records
Illustrative. Agent, tool and rule names are examples; you write your own policies.

Evidence and oversight

Answers for the security questionnaire

Mapping only. MAQPNA gives you technical controls and evidence; it does not make a system compliant, and we hold no certifications.

  • OWASP Top 10 for Agentic Applications: a control mapping for each of ASI01–ASI10, with honest coverage.
  • EU AI Act Art. 12 and 14: record-keeping and human oversight your customers configure.
  • No vendor dependency: no phone-home, standard protocols (MCP, A2A, OIDC, OpenTelemetry) and any model.
  • Supply chain: signed releases and SBOMs your customers can verify.

Make your agent enterprise-ready.

Install the CLI and run your agent under a local gateway today, or tell us about the deal you are trying to close.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.