Government and public sector
Public-sector agents that answer to your law, not a vendor's.
Citizens' data cannot leave the country, and every automated decision must be explainable after the fact. MAQPNA runs agents on infrastructure you choose, with no outbound calls you did not configure, and keeps a verifiable record of what each agent did and who approved it.
The problem
Why public bodies hesitate to deploy agents
Sovereignty, accountability and procurement rules come before features.
Data must stay in the jurisdiction
Hosted agent platforms run on someone else's control plane, often under another country's law.
Accountability for decisions
An agent touching a case file needs a record of which person it acted for, under which rule, and who signed off.
Disconnected networks
Classified and restricted networks have no internet access, so cloud-dependent tools are out.
Supply-chain assurance
Accreditation needs to know exactly what software runs, who built it and how to verify it.
How MAQPNA solves it
Sovereign by architecture, not by contract
Jurisdiction as policy
A cluster-wide sovereignty policy pins jurisdiction, registries, egress and model locations. Every session is admitted against it.
Zero phone-home
No telemetry, usage reporting, update checks or licence server. The only egress is what you configure.
Air-gapped install
A signed offline bundle with images, chart, manifests and SBOMs installs into a private registry with no internet.
Customer-held keys
Identity and ledger signing keys stay in your file store, PKCS#11 HSM or KMS.
Human oversight
Approval rules, separation of duties and the kill switch put officials in charge of high-impact actions.
Verifiable records
A hash-chained ledger with signed checkpoints. Anyone with the public key can verify that nothing was changed or removed.
Architecture sketch
A case-work agent on a government cloud
Everything runs inside your accredited environment. Agents reach case systems and models only through the gateway, and the ledger ships to in-country write-once storage.
Sandboxes
tier-1 (microVM) or tier-2 (confidential VM)
case-triagedocument-intakefoi-drafting
MAQPNA gateway
identity · policy · DLP · budgets · approval · audit
- Allowed
cases.read_caseread-only-tools - Held for approval
cases.update_statusofficial must approve - Denied
web.fetch external hostdefault-deny egress
Your systems
- MCPcase management
- MCPdocument store
- modelon-prem model route
Evidence and oversight
Records that support oversight and audit
Mapping only. MAQPNA gives you technical controls and evidence; it does not make a system compliant, and we hold no certifications.
- EU AI Act Art. 12 and 14: automatic, tamper-evident logging and human oversight controls for high-risk uses.
- GDPR: DLP redaction and memory erasure with a signed certificate for data MAQPNA holds.
- Supply chain: cosign-signed releases and images, SPDX SBOMs and build provenance you verify yourself.
- Accreditation: an air-gap bundle and an offline install path, documented end to end.
Plan a sovereign agent deployment.
Tell us about your environment and accreditation needs. We will walk through the sovereign profile and the air-gapped install.
curl -fsSL https://maqpna.com/install.sh | shbrew install azmxai/maqpna/maqpnairm https://maqpna.com/install.ps1 | iexNo Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.