MAQPNA's security model starts from one assumption: the model will sometimes be wrong or manipulated, so safety must not depend on the model. An agent is treated as untrusted code acting with delegated authority. Every action it takes crosses the gateway, which checks identity, policy, data and budget, can ask a human, records proof and can be stopped.
flowchart TB
subgraph L1["1. Isolation"]
I1["Sandbox per session · trust tier RuntimeClass<br/>non-root · read-only root · no SA token"]
end
subgraph L2["2. Network"]
I2["Per-session default-deny NetworkPolicy<br/>egress only to DNS and the gateway"]
end
subgraph L3["3. Identity"]
I3["Short-lived signed session token · scopes<br/>on-behalf-of user · optional SVID binding"]
end
subgraph L4["4. Gateway decisions"]
I4["Kill switch · DLP · guards · tool pins · policy<br/>taint · budgets · approvals · residency dialer"]
end
subgraph L5["5. Evidence"]
I5["Hash-chained ledger · signed checkpoints<br/>SIEM and WORM · evidence bundles"]
end
L1 --> L2 --> L3 --> L4 --> L5
Fail-safe defaults: no applicable policy is a deny; an unreadable revocation list denies every call; an unknown DLP profile fails closed; a Cedar or Rego error denies; an unverified peer agent card fails closed; with auditFailurePolicy: closed, a call is refused when its intent record cannot be written. Two components fail open by default and say so: injection guards (failOpen, configurable per guard) and shared rate-limit counters (they fall back to local limiters when the database is unreachable).
Taint tracking gates sinks after untrusted input; injection guards on tool output; least privilege enforced whatever the model decides
Mitigates: contains the effect, the model can still be fooled
ASI02
Tool misuse and exploitation
Policy per tool and argument (typed conditions, Cedar, Rego), default deny, rate limits, budgets, approvals; policy test, replay, eval before rollout
Enforced
ASI03
Identity and privilege abuse
Short-lived signed identity per session, on-behalf-of user, per-call scope checks, narrowing-only token derivation, token vault for user credentials, optional SVID mTLS
Enforced
ASI04
Agentic supply-chain vulnerabilities
Tool pinning (drift hidden and denied), registry allow-lists, signed and digest-pinned images, cosign-verified releases and air-gap bundles
Enforced for tools and images; mitigates for third-party models
ASI05
Unexpected code execution
Every session in a sandbox (gVisor, microVM or confidential VM), hardened pod, default-deny network, egress only through the gateway
Contained
ASI06
Memory and context poisoning
Governed memory stores scoped per agent and user, DLP on writes, retention, erasure with a signed certificate; ephemeral sessions and forks
Mitigates
ASI07
Insecure inter-agent communication
Governed A2A: signed agent cards, A2APeer allow-lists, nested delegation chain with depth limits, policy and audit on both hops
Enforced inside an installation; cross-organisation clearing Planned
ASI08
Cascading failures
Sandbox and network blast-radius limits, budgets with hard stops, rate limits, TTLs and idle suspend, fail-closed defaults, model fallback with circuit breakers
Mitigates
ASI09
Human-agent trust exploitation
Approvals with four-eyes quorum, no self-approval, redacted argument previews, CIBA confirmation by the user
Enforced
ASI10
Rogue agents
Kill switch across the installation within seconds, session timeline, posture checks, alerts, tamper-evident ledger
Stop and prove are enforced; behavioural anomaly scoring is not built in
maqpna doctor checks an installation's security posture (CRDs, a RuntimeClass for every tier, default-deny NetworkPolicies, sovereignty mode, attestation verifier and response signing, identity key mode, replicas versus state backend, and the gateway's own weak settings) with a 0 to 100 score, and exits 3 when a check fails. See maqpna doctor.