CCPathSovereign AI-First Engine

CCPath Sovereign Engine

Intent-driven Robotic Process Automation and Test Automation built specifically for the Malaysian public sector and sovereign enterprises. Eliminates brittle CSS/XPath scripts with on-premise local AI LLMs, constrained MCP browser execution, and zero third-party cloud data egress.

Explore Frameworks ↓

100%

On-Premise

Zero cloud data egress

0

Data Egress

Air-gapped deployment ready

7 / 7

GPAISA Principles

100% ethics aligned (JDN 2025)

96%

Cost Savings

RM 525K/yr annual agency savings

Statutory Compliance

National Regulatory & Statutory Alignment

CCPath is engineered to eliminate the six structural statutory barriers currently blocking public-sector digital transformation.

MyTCoE100% READY

MyTCoE (JDN / MSTB)

Full compliance with Malaysian Public Sector Software Testing Center of Excellence (MyTCoE) IV&V Handbook & ISO/IEC/IEEE 29119 standards. Bilingual BM/EN scripting & RTM traceability.

STATUTE100% PASS

Akta 88 (OSA 1972)

100% data sovereignty on local GPU hardware. Classified government and ministerial data is processed strictly within the perimeter with zero egress to foreign cloud AI.

STATUTE100% PASS

PDPA 2024 (Act 709)

Guarantees zero unauthorized cross-border data transfers. Enforces synthetic identifiers for test datasets and encrypts screenshots at rest with AES-256.

STATUTE100% PASS

Act 854 (Cyber Security)

National Critical Information Infrastructure (NCII) compliance with eBPF kernel event probes linked directly to database test logs for NACSA auditability.

ETHICS100% READY

GPAISA JDN 2025

Full compliance with all 7 Public Sector AI Ethics Principles published by Jabatan Digital Negara (JDN 27 Feb 2025). Human-in-the-loop shadow debugging on disagreements.

AKSA / PQC100% PQC

AKSA MySeal 2.1 & PQC

Aligned with CyberSecurity Malaysia AKSA MySeal 2.1 and NIST FIPS 203 using ML-KEM-768 hybrid key encapsulation, SHA3-256 digests, and AES-256-GCM authenticated encryption.

RPA Data Extraction

Tri-Modal Structured JSON Data Extraction

Approaches A, B & C Supported
Approach A: AXTree + Local LLM

Semantic DOM subtree pruning for standard HTML tables & lists, immune to CSS locator changes.

Approach B: Network Interception

Passive XHR/fetch JSON payload harvesting for SPAs. 0 GPU compute, sub-50ms latency.

Approach C: Vision OCR Crop

Targeted element crops for HTML5 canvas charts, SVG graphs, and scanned PDF data tables.

JDN Sovereign Governance

27 Feb 2025

Full Alignment with 7 AI Ethics Principles

Garis Panduan Pengadaptasian AI Sektor Awam (GPAISA), Jabatan Digital Negara (gpaisa.jdn.gov.my)

7 / 7 Complete Alignment
Principle 1100% PASS

Data Privacy & Security

100% on-premise local GPU inference with zero data egress. All step screenshots and DOM artifacts encrypted at rest with AES-256.

Principle 2100% PASS

Transparency & Explainability

No black-box AI decisions. Every step evaluation provides structured semantic rationale, confidence scores, and cryptographic SHA-256 provenance.

Principle 3100% PASS

Accountability & Human Control

Human-in-the-loop by design. Inconclusive signal disagreements trigger a 30-minute interactive Shadow Debugging Canvas where an authorized auditor retains final authority.

Principle 4100% PASS

Fairness & Non-Discrimination

Constrained 7-action MCP allowlist with pinned model digests operating at temperature=0 to eliminate non-deterministic bias and hallucination.

Principle 5100% PASS

Inclusivity & Accessibility

Operates natively on the Chromium Accessibility Tree (AXTree), continuously validating WCAG 2.1 and WAI-ARIA standards across public portals.

Principle 6100% PASS

Reliability & Robustness

Dual-Signal consensus (DOM structural assertions + LLM semantic judge) backed by eBPF kernel probes for tamper-proof reliability.

Principle 7100% PASS

Safety & Sustainability

97% AXTree token compression (<1.5s per step on local GPU hardware) combined with GPU-aware admission control to lower power consumption and server load.

Security Architecture

Data Protection Baseline, Layer by Layer

Security DimensionTechnical ImplementationCompliance Target
Zero Data EgressAI inference runs 100% on-premise on local GPU. No network data leaves the sovereign boundary.Akta 88 (OSA 1972)
Air-Gapped SupportDeployable in fully isolated sovereign data centers with no Internet access.Public Sector ICT
Encrypted Local StorageScreenshots & evidence stored in local S3-compatible storage with AES-256 encryption.PDPA 2024 (Act 709)
Identity & Access (RBAC)SSO with OAuth 2.0 / OIDC + PKCE (S256) via Casdoor with granular reviewer/auditor roles.Gov ICT Security
Web App Firewall (WAF)Dual-node cluster with OWASP Core Rule Set to defend against perimeter threats.Act 854 (Cyber Security)
eBPF Kernel Audit TrailKernel connection events linked directly with database test logs for NACSA audits.Act 854 (NACSA)
Post-Quantum Cryptography (PQC)NIST FIPS 203 ML-KEM-768 hybrid key encapsulation with SHA3-256 for zero-trust mTLS transit and vault storage.AKSA MySeal 2.1

Economic Impact

RM 525,000 in Annual Savings per Agency

Annual operating cost comparison: 5 QA engineers, 500 daily tests, vs foreign cloud SaaS.

95.6% Cost Reduction

Annual Operating Cost

RM 549K➔ RM 24K

Eliminates recurring foreign cloud API and seat license fees.

Payback Horizon

2 - 3 Months

Immediate ROI through turnkey single-host deployment.

Test Maintenance Effort

< 2% Overhead

Intent-driven Markdown over AXTree eliminates DOM locator refactoring.

Ready to explore or execute test plans?

Authenticate via CloudConnect Zero Trust or view test suites.

CloudConnect© 2026. Cloud Connect Asia. All Rights Reserved. Protected by Perisai-Q PQC and Zero Trust.

In compliance with Akta 88 (Official Secrets Act), PDPA, and GPAISA JDN 2025 Sovereign Invariants.