What "sovereign" means#
"Sovereign" in MAQPNA has a precise meaning: you can run AI agents in your own jurisdiction, on your own infrastructure, with your own keys, and the people who operate that infrastructure cannot read what a confidential agent holds in memory. Sovereignty is part of the core product, not an add-on: the same controls run in every edition, and the Sovereign edition adds the hardware-backed parts.
Who is trusted#
| Party | Trusted? | Why |
|---|---|---|
| You, the customer (platform team, CISO, data protection officer) | Yes. You are the root of trust. | You hold every key, write the sovereignty policy, approve the reference measurements and run the verifier and the write-once storage (WORM). |
| The infrastructure operator (cloud, sovereign cloud, colocation) | For availability only | It controls hypervisors, host kernels, firmware and nodes, and could be compelled by a foreign authority. For tier-2 sessions it is not trusted with confidentiality. |
| MAQPNA the vendor | No, not at runtime | No runtime dependency, no telemetry, no key escrow, no vendor-run verifier. Releases are checked with signatures and SBOMs. |
| The Kubernetes cluster admin | For scheduling and policy integrity | A cluster admin can delete a sandbox, but cannot get a tier-2 session token released into a non-attested environment. |
| Agent code, models, tools and MCP servers | No | Contained by trust tiers, the gateway, policy and egress control. |
Out of scope: side channels against trusted execution environments, physical attacks beyond the chip vendor's guarantees, compromise of the chip vendor's root keys, and denial of service by the infrastructure operator.
The three layers#
flowchart TB
subgraph J["Jurisdictional: data and compute stay in-country"]
J1["TrustTier jurisdiction + node affinity"]
J2["SovereigntyPolicy allow-lists:<br/>registries, egress hosts and CIDRs, jurisdictions"]
J3["Residency-checking dialer in the gateway"]
end
subgraph O["Operational: no vendor dependency"]
O1["Air-gap bundle, private registry mirror"]
O2["Zero phone-home, licence verified offline"]
O3["Customer-held signing keys (pkg/keys)"]
O4["In-country WORM audit storage"]
end
subgraph T["Technical: the operator cannot read agent memory"]
T1["tier-2 confidential VM (AMD SEV-SNP or Intel TDX)"]
T2["Remote attestation against your reference values"]
T3["Token sealed to a key that exists only in the VM"]
end
J --> O --> T
Jurisdictional#
- A
SovereigntyPolicynameddefault(cluster-scoped) declaresallowedJurisdictions,allowedRegistries,allowedEgressHosts,allowedEgressCIDRs,requireAttestationFor,keyCustody,auditRetentionDaysandenforcement(enforceoraudit). - Jurisdiction codes are hierarchical:
EUallowsEU-DEandEU-FR;EU-DEallowsEU-DE-BYbut notEU-FR. - Each
TrustTierdeclares ajurisdictionandallowedNodeLabels; the operator turns the labels into required node affinity, so sessions only schedule on in-jurisdiction nodes. - The operator rejects an agent whose image registry, model endpoint, tool URL or tier jurisdiction is outside the policy (
SovereigntyViolation). Inauditmode it only reports. - The gateway connects to every upstream through a residency-checking dialer: it resolves the host once, refuses unless every address is allowed, dials the checked address (no DNS rebinding) and blocks cloud-metadata and link-local ranges.
Operational#
- Zero phone-home. No telemetry, update checks or licence calls. The licence is a signed file verified offline.
- Customer-held keys. The identity broker signs with your Ed25519 key (a PEM file, typically from a Secret you create). Audit checkpoint, A2A card and data-at-rest keys are referenced by URI;
file://works today, whilepkcs11:(HSM) andkms://URIs are parsed but need a signing backend that is Planned. See key management. - Air-gapped install.
maqpna airgap bundlebuilds an offline bundle of images, chart and checksums;maqpna airgap verifychecks it. - In-country evidence. Ledger segments ship to your S3-compatible WORM store with Object Lock in
COMPLIANCEmode.auditRetentionDaysbelow 183 setsRetentionBelowAIAct=Trueon the policy.
Technical#
- tier-2 sandboxes run in confidential VMs (Kata Containers with AMD SEV-SNP or Intel TDX).
- The session token is never stored in a Kubernetes Secret for these sessions. The attestation service releases it only after the VM proves, with a hardware-signed report, that it runs a measurement you approved with debug disabled. The token is sealed to an ephemeral key bound into that report. See attestation-gated secrets.
Where each control is enforced#
| Point | What is checked |
|---|---|
| Operator reconcile | Agent image, model endpoint, tool URLs and tier jurisdiction against the default sovereignty policy |
| Gateway upstream transport | Residency dialer on every MCP, model, A2A, SIEM, WORM, IdP and notifier connection |
| Attestation service | Tiers listed in requireAttestationFor must set attestationRequired; tokens released only to attested VMs |
| WORM and SIEM sinks | Endpoints must pass the residency check; a refusal sends nothing and does not advance the cursor |
| DLP | Secrets and personal data in arguments, results, prompts and completions are redacted or denied in-process, with no external classifier |
| Telemetry | OpenTelemetry export is off by default; when on, the collector must pass the residency check |
What you see#
maqpna sovereignty check evaluates Agent manifests against a sovereignty policy offline, with the same code the operator runs (pkg/sovereignty). It prints one line per agent and one line per violation, and exits 3 when an agent would not be admitted. The line formats come from cmd/maqpna/sovereignty.go; the values below are illustrative:
COMPLIANT Agent team-a/coder (agent.yaml)
NON-COMPLIANT Agent team-a/scraper (scraper.yaml): 2 violation(s)
- [registry-not-allowed] spec.image: image "docker.io/library/python:3.13" (registry docker.io) is not from an allowed registry [registry.acme.eu]
- [jurisdiction-not-allowed] tier.jurisdiction: jurisdiction "US" is not within [EU]
The violation codes are invalid-image, registry-not-allowed, digest-required, invalid-url, egress-not-allowed, insecure-transport, jurisdiction-not-allowed, jurisdiction-unspecified and attestation-required. In audit mode the first word is AUDIT and the agent is admitted. See maqpna sovereignty check and maqpna validate.