MAQPNADocs

maqpna evidence

Build and verify compliance evidence packs; export the third-party register

Observe-o json | yaml

Synopsis#

maqpna evidence register [--gateway URL] [--format table|json|csv] [--since RFC3339] [--until RFC3339] [-n NS] [--agent A] [--include-unused] [--out FILE]
maqpna evidence frameworks [ID] [-o json]
                     the control mappings (EU AI Act, DORA, ISO/IEC 42001): version, review status, coverage; ID lists its controls
maqpna evidence generate --framework eu-ai-act|dora|iso42001 --system NS/AGENT|namespace:NS|tenant:NAME
                     (--period 2027-Q1|2027-01|2027 | --from DATE --to DATE) [--ledger FILE | --gateway URL]
                     --key KEYURI [--jwks URL|FILE] [--checkpoints FILE] [--license FILE] [--no-cluster] [--out DIR|FILE.zip]
                     signed evidence pack: manifest.json, report.html/.md, CSV workpapers (needs the evidence-packs licence)
maqpna evidence verify DIR|PACK.zip [--pubkey PEM | --jwks URL|FILE] [-o json]
                     signature and file hashes, offline, no licence needed (exit 3 on tamper)

Description#

generate builds a signed, auditor-ready evidence pack for one framework, one system and one period from the audit ledger and the configuration in force (paid: the evidence-packs licence feature or the Sovereign edition). verify checks a pack offline and needs no licence. frameworks lists the control mappings. A pack supports, and does not certify, compliance (docs/evidence-packs.md).

The register lists every external MCP server, model endpoint and A2A peer with first and last use, call counts, residency and cost (DORA Art. 28(3) register of information).

Subcommands#

Examples#

maqpna evidence frameworks
maqpna evidence generate --framework eu-ai-act --system team-a/coder --period 2027-Q1 --gateway "$GW" --key checkpoint.key --out pack.zip
maqpna evidence verify pack.zip --jwks "$GW/v1/audit/jwks"
maqpna evidence register
maqpna evidence register --format csv --since 2026-01-01T00:00:00Z --out register.csv

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna evidence.cast