Defence and national security
Agents for disconnected networks, fail-closed by design.
On a classified network an agent must never reach anything it was not allowed to, and you must prove what it ran on. MAQPNA installs offline from a signed bundle, isolates each session in a sandbox or confidential VM, and denies calls when a control is unavailable.
The problem
What stops agents on defence networks
Assurance requirements rule out most agent tooling before evaluation starts.
No internet, ever
Tools that download models, plugins or updates at runtime cannot be accredited for a disconnected network.
Untrusted hosts
Workloads on shared or partner infrastructure must be protected from the host operator.
Model-written code
Agents execute code nobody reviewed. A container shares the host kernel, so one exploit reaches the node.
Proof of provenance
You must show exactly which signed software ran and that nothing was altered.
How MAQPNA solves it
Isolation, attestation and evidence
Signed air-gap bundle
Images, chart, upstream manifests, SBOMs and SHA256SUMS in one tarball, verified and mirrored into your registry offline.
Attestation-gated identity
tier-2 sessions run in confidential VMs (AMD SEV-SNP or Intel TDX) and get an identity only after attestation passes.
Sandbox per session
gVisor, Kata Containers with Firecracker microVMs, or confidential VMs, with default-deny networking per session.
Fail-closed defaults
If the revocation list or the audit ledger is unavailable, calls are denied in the sovereign profile.
Kill switch
Stop an agent, session, user or token across the installation within about a second.
Verifiable releases
Every binary and image is signed with Sigstore cosign;
maqpna verifychecks signatures, SBOM attestations and checksums.
Architecture sketch
An analysis agent on an accredited enclave
The enclave has no route to the internet. Identities and secrets reach only sandboxes that prove they are genuine confidential VMs.
Sandboxes
tier-2 (confidential VM, attestation required)
intel-summarylogistics-plannercode-assist
MAQPNA gateway
identity · policy · DLP · budgets · approval · audit
- Allowed
docs.search_reportsread-only-tools - Held for approval
plans.publish_ordertwo approvers - Denied
any call, ledger unavailablefail closed
Your systems
- MCPreport archive
- MCPlogistics system
- modelenclave model route
Evidence and oversight
Assurance you can demonstrate
Mapping only. MAQPNA gives you technical controls and evidence; it does not make a system compliant, and we hold no certifications.
- Supply chain: signed binaries and images, SPDX SBOMs and provenance; verify offline before import.
- Isolation evidence: the trust tier, runtime and attestation result of each session are recorded with its decisions.
- Human oversight: four-eyes approval and separation of duties on high-impact tools.
- Honest scope: confidential computing protects data in use within the limits of the hardware vendor's trust model.
Talk to us about an offline evaluation.
We can walk your team through the air-gap bundle, the sovereign profile and attestation with your hardware.
curl -fsSL https://maqpna.com/install.sh | shbrew install azmxai/maqpna/maqpnairm https://maqpna.com/install.ps1 | iexNo Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.