MAQPNA

Defence and national security

Agents for disconnected networks, fail-closed by design.

On a classified network an agent must never reach anything it was not allowed to, and you must prove what it ran on. MAQPNA installs offline from a signed bundle, isolates each session in a sandbox or confidential VM, and denies calls when a control is unavailable.

The problem

What stops agents on defence networks

Assurance requirements rule out most agent tooling before evaluation starts.

  1. No internet, ever

    Tools that download models, plugins or updates at runtime cannot be accredited for a disconnected network.

  2. Untrusted hosts

    Workloads on shared or partner infrastructure must be protected from the host operator.

  3. Model-written code

    Agents execute code nobody reviewed. A container shares the host kernel, so one exploit reaches the node.

  4. Proof of provenance

    You must show exactly which signed software ran and that nothing was altered.

How MAQPNA solves it

Isolation, attestation and evidence

  • Signed air-gap bundle

    Images, chart, upstream manifests, SBOMs and SHA256SUMS in one tarball, verified and mirrored into your registry offline.

  • Attestation-gated identity

    tier-2 sessions run in confidential VMs (AMD SEV-SNP or Intel TDX) and get an identity only after attestation passes.

  • Sandbox per session

    gVisor, Kata Containers with Firecracker microVMs, or confidential VMs, with default-deny networking per session.

  • Fail-closed defaults

    If the revocation list or the audit ledger is unavailable, calls are denied in the sovereign profile.

  • Kill switch

    Stop an agent, session, user or token across the installation within about a second.

  • Verifiable releases

    Every binary and image is signed with Sigstore cosign; maqpna verify checks signatures, SBOM attestations and checksums.

Architecture sketch

An analysis agent on an accredited enclave

The enclave has no route to the internet. Identities and secrets reach only sandboxes that prove they are genuine confidential VMs.

Accredited enclave · disconnected · keys in your HSM

Sandboxes

tier-2 (confidential VM, attestation required)

  • intel-summary
  • logistics-planner
  • code-assist

MAQPNA gateway

identity · policy · DLP · budgets · approval · audit

  • Alloweddocs.search_reportsread-only-tools
  • Held for approvalplans.publish_ordertwo approvers
  • Deniedany call, ledger unavailablefail closed

Your systems

  • MCPreport archive
  • MCPlogistics system
  • modelenclave model route
Hash-chained audit ledger with signed checkpoints, kept inside the enclave
Illustrative. Agent, tool and rule names are examples; you write your own policies.

Evidence and oversight

Assurance you can demonstrate

Mapping only. MAQPNA gives you technical controls and evidence; it does not make a system compliant, and we hold no certifications.

  • Supply chain: signed binaries and images, SPDX SBOMs and provenance; verify offline before import.
  • Isolation evidence: the trust tier, runtime and attestation result of each session are recorded with its decisions.
  • Human oversight: four-eyes approval and separation of duties on high-impact tools.
  • Honest scope: confidential computing protects data in use within the limits of the hardware vendor's trust model.

Talk to us about an offline evaluation.

We can walk your team through the air-gap bundle, the sovereign profile and attestation with your hardware.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.