MAQPNA

Data centres, neoclouds and telco clouds

Turn GPUs into governed agent cloud.

Your customers want to run agents next to the GPUs they already rent from you, but they need isolation, governance and evidence first. MAQPNA gives you a multi-tenant agent runtime to sell, with per-tenant keys, ledgers and usage, on hardware you operate.

The problem

Why capacity alone does not sell agent hosting

Raw sandboxes are a commodity. Governed, sovereign agent capacity is not.

  1. No governed agent product

    Customers can rent GPUs and VMs from you, but nothing that makes their agents safe to run.

  2. Tenant isolation

    Hosting many customers' agents needs hard isolation of sandboxes, keys, servers and records.

  3. Billing per customer

    You need metered usage per tenant (sandbox time, governed calls, model tokens) to charge for it.

  4. Sovereignty as a selling point

    Customers choose a regional provider for sovereignty, and want proof, not a promise.

How MAQPNA solves it

A multi-tenant agent platform you operate

  • Tenants

    Each tenant has its own namespaces, trust domain, signing key, ledger, write-once storage prefix and quotas.

  • Usage metering

    Hourly usage per tenant: sandbox seconds, governed calls, model tokens and approvals, exportable in FOCUS.

  • Signed usage reports

    maqpna usage report writes an Ed25519-signed report that usage verify checks offline.

  • Three trust tiers

    Offer gVisor, microVM and confidential-VM tiers as products, priced by isolation level.

  • Sovereign profile

    Jurisdiction, registries and egress as policy, attestation and customer-held keys, for regulated tenants.

  • Day-2 operations

    preflight, upgrade check, backup, dr drill, keys rotate, alerts and runbooks.

Architecture sketch

Governed agent hosting for many tenants

Each tenant's agents run in their own namespaces and sandboxes. One gateway enforces each tenant's policy, and usage is metered per tenant for your billing.

Your data centre · your GPUs · tenants isolated by namespace, key and ledger

Sandboxes

tier-0, tier-1 or tier-2, chosen per tenant

  • tenant-a/support-agent
  • tenant-b/coder
  • tenant-c/research

MAQPNA gateway

identity · policy · DLP · budgets · approval · audit

  • Allowedtenant-a: crm.get_tickettenant policy
  • Held for approvaltenant-b: git.merge_prdestructive-needs-human
  • Deniedtenant-c: tenant-a servertenant isolation

Your systems

  • modelGPU model routes
  • MCPtenant tool servers
  • usageper-tenant metering
One ledger and signing key per tenant · signed usage reports for billing
Illustrative. Agent, tool and rule names are examples; you write your own policies.

Evidence and oversight

What your customers can show their auditors

Mapping only. MAQPNA gives you technical controls and evidence; it does not make a system compliant, and we hold no certifications.

  • Per-tenant evidence: each tenant's ledger is signed with its own key and can be verified by the tenant.
  • Sovereignty: jurisdiction, registry and egress rules every session is admitted against.
  • EU AI Act and DORA: record-keeping, oversight controls and a third-party register for your customers' own compliance work.
  • Roadmap, not built yet: a white-label console and tenant self-service; ask us about timing.

Turn GPUs into governed agent cloud.

The Operator edition is for service providers that host agents for their own customers. Tell us about your platform.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.