MAQPNA

Banks and financial services

Agents for payments and KYC, with four eyes on every transfer.

A wrong transfer is irreversible and your regulator will ask who approved it. MAQPNA runs banking agents in isolated sandboxes on your infrastructure, holds high-impact calls for two approvers and records every decision in a ledger anyone can verify.

The problem

Why banking agents stall before production

The model is not the blocker. Control, evidence and accountability are.

  1. Irreversible actions

    An agent that can initiate a payment or close an account can do it wrongly, or be talked into it by a crafted email or document.

  2. Four-eyes rules

    Internal controls need two people on high-value actions, and an agent is not one of them.

  3. DORA and ICT third-party risk

    Every MCP server and model endpoint an agent uses is an ICT third party you must register, monitor and evidence.

  4. Customer data in prompts

    Account numbers, IBANs and personal data must not leak into tool arguments, model prompts or logs.

How MAQPNA solves it

Controls the agent cannot bypass

  • Four-eyes approval

    A rule holds a transfer above your threshold for two different approvers. Approvers cannot approve calls made on their own behalf.

  • User approval on their own device

    The customer or employee the agent acts for confirms the action on their own device (CIBA).

  • Per-argument policy

    Typed conditions on amounts, currencies and counterparties. Default deny for anything you have not allowed.

  • Data loss prevention (DLP)

    The gateway finds and blocks or redacts IBANs, card numbers, keys and personal data in arguments, results and prompts.

  • Third-party register

    Export the DORA Art. 28 register of MCP servers and model routes your agents used, built from the ledger.

  • Kill switch

    Revoke an agent, session or user across the installation within about a second, with the reason recorded.

Architecture sketch

A payments-operations agent, governed end to end

The agent runs in a confidential VM in your data centre. It reaches core banking only through the gateway, which checks every call against your policy before it leaves.

Your data centre · jurisdiction EU-DE · your keys (HSM)

Sandboxes

tier-2 (confidential VM, attested)

  • payments-ops
  • kyc-review
  • reconciliation

MAQPNA gateway

identity · policy · DLP · budgets · approval · audit

  • Allowedcore.get_accountread-only-tools
  • Held for approvalcore.create_transferfour-eyes above €10,000
  • Deniedcrm.export_customersdefault deny

Your systems

  • MCPcore banking
  • MCPKYC provider
  • modelin-country model route
Hash-chained audit ledger → write-once storage (WORM) · DORA third-party register export
Illustrative. Agent, tool and rule names are examples; you write your own policies.

Evidence and oversight

Evidence for your supervisors

Mapping only. MAQPNA gives you technical controls and evidence; it does not make a system compliant, and we hold no certifications.

  • DORA: ledger evidence of ICT operations, backups and recovery drills (maqpna dr drill), key rotation and the Art. 28 third-party register.
  • EU AI Act Art. 12: automatic, tamper-evident record-keeping of every agent decision, with signed checkpoints.
  • EU AI Act Art. 14: human oversight through approvals, the kill switch and the session timeline.
  • GDPR: DLP redaction, encrypted argument capture (off by default) and memory erasure with a signed certificate.

Put your first banking agent under control.

Tell us which workflow you want to automate. We will walk through the policy, the approval flow and the evidence it produces.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.