MAQPNA

Healthcare and life sciences

Clinical agents that keep patient data at home.

Health data is the most sensitive data you hold, and it must stay in the country. MAQPNA runs agents next to your clinical systems, redacts patient data before it leaves the gateway, routes model calls in-country and records each action.

The problem

Why clinical agents are hard to approve

Privacy, residency and safety reviews come first.

  1. Patient data in prompts

    Names, identifiers and diagnoses can leak into model prompts, tool arguments and logs.

  2. Residency rules

    Health data often may not be processed outside the country, including by a model endpoint.

  3. Safety-relevant actions

    An agent that writes to a record or schedules care needs a clinician in the loop.

  4. Proof for review boards

    Ethics and data-protection reviews ask what the agent accessed and why.

How MAQPNA solves it

Controls for sensitive data

  • DLP and redaction

    Find and redact personal data in arguments, results and prompts before they leave the gateway.

  • In-country model routing

    Model routes with allow-lists per agent, model-for-data-class rules and residency checks.

  • Clinician approval

    Writes to clinical systems are held for a qualified approver, with the context they need.

  • Sandboxed tools

    Each session runs in an isolated sandbox with default-deny egress, so tools reach only what policy allows.

  • Governed memory

    Memory stores scoped per agent and user, with DLP on writes, retention and erasure with a signed certificate.

  • Access records

    Every access is a record with the session, the person the agent acted for, the rule and the decision.

Architecture sketch

A clinical-summary agent inside the hospital network

The agent reads records through the gateway, which redacts identifiers before the model route sees them and holds writes for a clinician.

Hospital network · in-country · your keys

Sandboxes

tier-1 (microVM) or tier-2 (confidential VM)

  • clinical-summary
  • trial-ops
  • coding-assist

MAQPNA gateway

identity · policy · DLP · budgets · approval · audit

  • Allowedehr.read_encounterread-only-tools + DLP redact
  • Held for approvalehr.create_noteclinician approval
  • Deniedmodel route outside countryresidency

Your systems

  • MCPEHR adapter
  • MCPtrial database
  • modelin-country model route
Hash-chained audit ledger of every access → write-once storage (WORM)
Illustrative. Agent, tool and rule names are examples; you write your own policies.

Evidence and oversight

Support for privacy and oversight work

Mapping only. MAQPNA gives you technical controls and evidence; it does not make a system compliant, and we hold no certifications.

  • GDPR: minimisation through DLP redaction, erasure with a signed certificate and argument capture off by default.
  • EU AI Act Art. 12 and 14: record-keeping and human oversight controls.
  • Residency: sovereignty policy rules for model locations, registries and egress.
  • Honest scope: MAQPNA limits what an agent can do; clinical validation of the model's output is yours.

Bring an agent to a clinical workflow.

Tell us which workflow you are evaluating. We will show how the data controls and approvals fit around it.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.