Energy, utilities and critical infrastructure
Agents for critical infrastructure, safe when things go wrong.
In operational technology a wrong action has physical consequences. MAQPNA keeps agents in isolated sandboxes on your own sites, requires an engineer for safety-relevant calls and fails closed when a control is unavailable.
The problem
Why operators keep agents away from operations
Safety, regulation and segmentation come first.
Physical consequences
Switching, setpoints and work orders affect equipment and people.
Segmented networks
OT networks are segmented or disconnected; cloud-hosted agents cannot reach them, and should not.
NIS2 obligations
Operators of essential services must show access control, logging and incident handling.
Failure modes
When a dependency fails, the safe default is to stop, not to carry on.
How MAQPNA solves it
Safety-first defaults
Fail-closed defaults
If the revocation list or ledger is unavailable, calls are denied in the sovereign profile.
Engineer approval
Safety-relevant tools need an approver, or two, with separation of duties.
Isolated sandboxes
Each session is isolated, with default-deny egress and tools reachable only through the gateway.
On-site and air-gapped
Install from a signed offline bundle on your own sites, with no phone-home.
Kill switch
Stop an agent, session or user across the installation within about a second.
Incident evidence
A tamper-evident ledger and session timeline for incident reviews and regulators.
Architecture sketch
A maintenance-planning agent on an operator's site
The agent reads asset data and drafts work orders. Anything that touches operations is held for an engineer, and nothing leaves the site.
Sandboxes
tier-1 (microVM)
asset-maintenanceoutage-summaryprocurement-assist
MAQPNA gateway
identity · policy · DLP · budgets · approval · audit
- Allowed
historian.read_seriesread-only-tools - Held for approval
wms.create_work_orderengineer approval - Denied
scada.write_setpointdefault deny
Your systems
- MCPhistorian (read-only)
- MCPwork-management system
- modelon-site model route
Evidence and oversight
Evidence for operators of essential services
Mapping only. MAQPNA gives you technical controls and evidence; it does not make a system compliant, and we hold no certifications.
- NIS2: access control, logging, incident handling and supply-chain evidence for agent actions.
- EU AI Act Art. 12 and 14: record-keeping and human oversight controls.
- Supply chain: signed releases, SBOMs and an offline install path.
- Honest scope: MAQPNA governs what agents may call; it is not a safety-instrumented system.
Talk to us about a safe first use case.
We will help you pick a read-mostly workflow and the approval rules around it.
curl -fsSL https://maqpna.com/install.sh | shbrew install azmxai/maqpna/maqpnairm https://maqpna.com/install.ps1 | iexNo Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.