MAQPNADocs

Security model and threat model#

MAQPNA's security model starts from one assumption: the model will sometimes be wrong or manipulated, so safety must not depend on the model. An agent is treated as untrusted code acting with delegated authority. Every action it takes crosses the gateway, which checks identity, policy, data and budget, can ask a human, records proof and can be stopped.

Assets, actors and trust#

Asset Threat Main control
Your data reachable through tools and models Exfiltration by a manipulated agent Default-deny egress, gateway-only exits, DLP, taint rules
Your systems reachable through tools Destructive or unauthorised actions Per-tool policy, default deny, approvals, budgets, kill switch
Credentials (API keys, OAuth tokens, signing keys) Theft from the sandbox or logs Credentials only in the gateway or vault, short-lived scoped session tokens, customer-held signing keys
The host and cluster Sandbox escape by LLM-generated code Trust tiers (gVisor, microVM, confidential VM), hardened pod spec, no service-account token
Evidence of what happened Tampering, deletion Hash-chained ledger, signed checkpoints, WORM storage
Agent memory in tier-2 sandboxes Reading by the infrastructure operator Confidential VMs, attestation-gated token release
Actor Trust
You (platform, security and compliance teams) Root of trust: you hold keys, write policies, approve
Approvers and the users agents act for Trusted for their own decisions only: no self-approval, separation of duties
Agent code, models, tools, MCP servers, other agents Untrusted
The infrastructure operator Trusted for availability, not for tier-2 confidentiality
MAQPNA the vendor Not trusted at runtime: no phone-home, no key escrow

Defence in depth#

flowchart TB
    subgraph L1["1. Isolation"]
      I1["Sandbox per session · trust tier RuntimeClass<br/>non-root · read-only root · no SA token"]
    end
    subgraph L2["2. Network"]
      I2["Per-session default-deny NetworkPolicy<br/>egress only to DNS and the gateway"]
    end
    subgraph L3["3. Identity"]
      I3["Short-lived signed session token · scopes<br/>on-behalf-of user · optional SVID binding"]
    end
    subgraph L4["4. Gateway decisions"]
      I4["Kill switch · DLP · guards · tool pins · policy<br/>taint · budgets · approvals · residency dialer"]
    end
    subgraph L5["5. Evidence"]
      I5["Hash-chained ledger · signed checkpoints<br/>SIEM and WORM · evidence bundles"]
    end
    L1 --> L2 --> L3 --> L4 --> L5

Fail-safe defaults: no applicable policy is a deny; an unreadable revocation list denies every call; an unknown DLP profile fails closed; a Cedar or Rego error denies; an unverified peer agent card fails closed; with auditFailurePolicy: closed, a call is refused when its intent record cannot be written. Two components fail open by default and say so: injection guards (failOpen, configurable per guard) and shared rate-limit counters (they fall back to local limiters when the database is unreachable).

OWASP Top 10 for Agentic Applications (2026)#

# Risk MAQPNA control Coverage
ASI01 Agent goal hijack (prompt injection, poisoned content) Taint tracking gates sinks after untrusted input; injection guards on tool output; least privilege enforced whatever the model decides Mitigates: contains the effect, the model can still be fooled
ASI02 Tool misuse and exploitation Policy per tool and argument (typed conditions, Cedar, Rego), default deny, rate limits, budgets, approvals; policy test, replay, eval before rollout Enforced
ASI03 Identity and privilege abuse Short-lived signed identity per session, on-behalf-of user, per-call scope checks, narrowing-only token derivation, token vault for user credentials, optional SVID mTLS Enforced
ASI04 Agentic supply-chain vulnerabilities Tool pinning (drift hidden and denied), registry allow-lists, signed and digest-pinned images, cosign-verified releases and air-gap bundles Enforced for tools and images; mitigates for third-party models
ASI05 Unexpected code execution Every session in a sandbox (gVisor, microVM or confidential VM), hardened pod, default-deny network, egress only through the gateway Contained
ASI06 Memory and context poisoning Governed memory stores scoped per agent and user, DLP on writes, retention, erasure with a signed certificate; ephemeral sessions and forks Mitigates
ASI07 Insecure inter-agent communication Governed A2A: signed agent cards, A2APeer allow-lists, nested delegation chain with depth limits, policy and audit on both hops Enforced inside an installation; cross-organisation clearing Planned
ASI08 Cascading failures Sandbox and network blast-radius limits, budgets with hard stops, rate limits, TTLs and idle suspend, fail-closed defaults, model fallback with circuit breakers Mitigates
ASI09 Human-agent trust exploitation Approvals with four-eyes quorum, no self-approval, redacted argument previews, CIBA confirmation by the user Enforced
ASI10 Rogue agents Kill switch across the installation within seconds, session timeline, posture checks, alerts, tamper-evident ledger Stop and prove are enforced; behavioural anomaly scoring is not built in

What MAQPNA does not solve#

Problem Why What helps
Hallucinations and wrong answers A model-quality problem; MAQPNA limits the damage of a wrong action Model evaluation, grounding, human review of outputs
Prompt injection inside the model No runtime can stop a model being persuaded Model-side defences; MAQPNA contains the effect
Bias and fairness Depends on the model, data and use case Fairness testing; the ledger supports the audit
Behavioural anomaly detection Not built in SIEM or UEBA on the ledger stream
Side channels against TEEs, physical attacks, compromised chip-vendor keys Out of the confidential-computing threat model Vendor and facility controls
GPU memory in confidential tiers GPU confidential computing is not integrated; tier-2 protects CPU memory only Planned

What you see#

maqpna doctor checks an installation's security posture (CRDs, a RuntimeClass for every tier, default-deny NetworkPolicies, sovereignty mode, attestation verifier and response signing, identity key mode, replicas versus state backend, and the gateway's own weak settings) with a 0 to 100 score, and exits 3 when a check fails. See maqpna doctor.