maqpna evidence
Build and verify compliance evidence packs; export the third-party register
Synopsis#
maqpna evidence register [--gateway URL] [--format table|json|csv] [--since RFC3339] [--until RFC3339] [-n NS] [--agent A] [--include-unused] [--out FILE]
maqpna evidence frameworks [ID] [-o json]
the control mappings (EU AI Act, DORA, ISO/IEC 42001): version, review status, coverage; ID lists its controls
maqpna evidence generate --framework eu-ai-act|dora|iso42001 --system NS/AGENT|namespace:NS|tenant:NAME
(--period 2027-Q1|2027-01|2027 | --from DATE --to DATE) [--ledger FILE | --gateway URL]
--key KEYURI [--jwks URL|FILE] [--checkpoints FILE] [--license FILE] [--no-cluster] [--out DIR|FILE.zip]
signed evidence pack: manifest.json, report.html/.md, CSV workpapers (needs the evidence-packs licence)
maqpna evidence verify DIR|PACK.zip [--pubkey PEM | --jwks URL|FILE] [-o json]
signature and file hashes, offline, no licence needed (exit 3 on tamper)Description#
generate builds a signed, auditor-ready evidence pack for one framework, one system and one period from the audit ledger and the configuration in force (paid: the evidence-packs licence feature or the Sovereign edition). verify checks a pack offline and needs no licence. frameworks lists the control mappings. A pack supports, and does not certify, compliance (docs/evidence-packs.md).
The register lists every external MCP server, model endpoint and A2A peer with first and last use, call counts, residency and cost (DORA Art. 28(3) register of information).
Subcommands#
maqpna evidence registerExport the register of third-party providers (DORA Art. 28)
maqpna evidence frameworksList the compliance frameworks and their control mappings
maqpna evidence generateGenerate a signed evidence pack for one framework, system and period
maqpna evidence verifyVerify an evidence pack's signature and every file hash, offline
Examples#
maqpna evidence frameworks
maqpna evidence generate --framework eu-ai-act --system team-a/coder --period 2027-Q1 --gateway "$GW" --key checkpoint.key --out pack.zip
maqpna evidence verify pack.zip --jwks "$GW/v1/audit/jwks"
maqpna evidence register
maqpna evidence register --format csv --since 2026-01-01T00:00:00Z --out register.csvWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |