MAQPNADocs

What "sovereign" means#

"Sovereign" in MAQPNA has a precise meaning: you can run AI agents in your own jurisdiction, on your own infrastructure, with your own keys, and the people who operate that infrastructure cannot read what a confidential agent holds in memory. Sovereignty is part of the core product, not an add-on: the same controls run in every edition, and the Sovereign edition adds the hardware-backed parts.

Who is trusted#

Party Trusted? Why
You, the customer (platform team, CISO, data protection officer) Yes. You are the root of trust. You hold every key, write the sovereignty policy, approve the reference measurements and run the verifier and the write-once storage (WORM).
The infrastructure operator (cloud, sovereign cloud, colocation) For availability only It controls hypervisors, host kernels, firmware and nodes, and could be compelled by a foreign authority. For tier-2 sessions it is not trusted with confidentiality.
MAQPNA the vendor No, not at runtime No runtime dependency, no telemetry, no key escrow, no vendor-run verifier. Releases are checked with signatures and SBOMs.
The Kubernetes cluster admin For scheduling and policy integrity A cluster admin can delete a sandbox, but cannot get a tier-2 session token released into a non-attested environment.
Agent code, models, tools and MCP servers No Contained by trust tiers, the gateway, policy and egress control.

Out of scope: side channels against trusted execution environments, physical attacks beyond the chip vendor's guarantees, compromise of the chip vendor's root keys, and denial of service by the infrastructure operator.

The three layers#

flowchart TB
    subgraph J["Jurisdictional: data and compute stay in-country"]
      J1["TrustTier jurisdiction + node affinity"]
      J2["SovereigntyPolicy allow-lists:<br/>registries, egress hosts and CIDRs, jurisdictions"]
      J3["Residency-checking dialer in the gateway"]
    end
    subgraph O["Operational: no vendor dependency"]
      O1["Air-gap bundle, private registry mirror"]
      O2["Zero phone-home, licence verified offline"]
      O3["Customer-held signing keys (pkg/keys)"]
      O4["In-country WORM audit storage"]
    end
    subgraph T["Technical: the operator cannot read agent memory"]
      T1["tier-2 confidential VM (AMD SEV-SNP or Intel TDX)"]
      T2["Remote attestation against your reference values"]
      T3["Token sealed to a key that exists only in the VM"]
    end
    J --> O --> T

Jurisdictional#

  • A SovereigntyPolicy named default (cluster-scoped) declares allowedJurisdictions, allowedRegistries, allowedEgressHosts, allowedEgressCIDRs, requireAttestationFor, keyCustody, auditRetentionDays and enforcement (enforce or audit).
  • Jurisdiction codes are hierarchical: EU allows EU-DE and EU-FR; EU-DE allows EU-DE-BY but not EU-FR.
  • Each TrustTier declares a jurisdiction and allowedNodeLabels; the operator turns the labels into required node affinity, so sessions only schedule on in-jurisdiction nodes.
  • The operator rejects an agent whose image registry, model endpoint, tool URL or tier jurisdiction is outside the policy (SovereigntyViolation). In audit mode it only reports.
  • The gateway connects to every upstream through a residency-checking dialer: it resolves the host once, refuses unless every address is allowed, dials the checked address (no DNS rebinding) and blocks cloud-metadata and link-local ranges.

Operational#

  • Zero phone-home. No telemetry, update checks or licence calls. The licence is a signed file verified offline.
  • Customer-held keys. The identity broker signs with your Ed25519 key (a PEM file, typically from a Secret you create). Audit checkpoint, A2A card and data-at-rest keys are referenced by URI; file:// works today, while pkcs11: (HSM) and kms:// URIs are parsed but need a signing backend that is Planned. See key management.
  • Air-gapped install. maqpna airgap bundle builds an offline bundle of images, chart and checksums; maqpna airgap verify checks it.
  • In-country evidence. Ledger segments ship to your S3-compatible WORM store with Object Lock in COMPLIANCE mode. auditRetentionDays below 183 sets RetentionBelowAIAct=True on the policy.

Technical#

  • tier-2 sandboxes run in confidential VMs (Kata Containers with AMD SEV-SNP or Intel TDX).
  • The session token is never stored in a Kubernetes Secret for these sessions. The attestation service releases it only after the VM proves, with a hardware-signed report, that it runs a measurement you approved with debug disabled. The token is sealed to an ephemeral key bound into that report. See attestation-gated secrets.

Where each control is enforced#

Point What is checked
Operator reconcile Agent image, model endpoint, tool URLs and tier jurisdiction against the default sovereignty policy
Gateway upstream transport Residency dialer on every MCP, model, A2A, SIEM, WORM, IdP and notifier connection
Attestation service Tiers listed in requireAttestationFor must set attestationRequired; tokens released only to attested VMs
WORM and SIEM sinks Endpoints must pass the residency check; a refusal sends nothing and does not advance the cursor
DLP Secrets and personal data in arguments, results, prompts and completions are redacted or denied in-process, with no external classifier
Telemetry OpenTelemetry export is off by default; when on, the collector must pass the residency check

What you see#

maqpna sovereignty check evaluates Agent manifests against a sovereignty policy offline, with the same code the operator runs (pkg/sovereignty). It prints one line per agent and one line per violation, and exits 3 when an agent would not be admitted. The line formats come from cmd/maqpna/sovereignty.go; the values below are illustrative:

COMPLIANT      Agent team-a/coder (agent.yaml)
NON-COMPLIANT  Agent team-a/scraper (scraper.yaml): 2 violation(s)
  - [registry-not-allowed] spec.image: image "docker.io/library/python:3.13" (registry docker.io) is not from an allowed registry [registry.acme.eu]
  - [jurisdiction-not-allowed] tier.jurisdiction: jurisdiction "US" is not within [EU]

The violation codes are invalid-image, registry-not-allowed, digest-required, invalid-url, egress-not-allowed, insecure-transport, jurisdiction-not-allowed, jurisdiction-unspecified and attestation-required. In audit mode the first word is AUDIT and the agent is admitted. See maqpna sovereignty check and maqpna validate.