Sovereign AI-First EngineCCPath Sovereign Engine
Intent-driven Robotic Process Automation and Test Automation built specifically for the Malaysian public sector and sovereign enterprises. Eliminates brittle CSS/XPath scripts with on-premise local AI LLMs, constrained MCP browser execution, and zero third-party cloud data egress.
100%
On-Premise
Zero cloud data egress
0
Data Egress
Air-gapped deployment ready
7 / 7
GPAISA Principles
100% ethics aligned (JDN 2025)
96%
Cost Savings
RM 525K/yr annual agency savings
Statutory Compliance
National Regulatory & Statutory Alignment
CCPath is engineered to eliminate the six structural statutory barriers currently blocking public-sector digital transformation.
MyTCoE (JDN / MSTB)
Full compliance with Malaysian Public Sector Software Testing Center of Excellence (MyTCoE) IV&V Handbook & ISO/IEC/IEEE 29119 standards. Bilingual BM/EN scripting & RTM traceability.
Akta 88 (OSA 1972)
100% data sovereignty on local GPU hardware. Classified government and ministerial data is processed strictly within the perimeter with zero egress to foreign cloud AI.
PDPA 2024 (Act 709)
Guarantees zero unauthorized cross-border data transfers. Enforces synthetic identifiers for test datasets and encrypts screenshots at rest with AES-256.
Act 854 (Cyber Security)
National Critical Information Infrastructure (NCII) compliance with eBPF kernel event probes linked directly to database test logs for NACSA auditability.
GPAISA JDN 2025
Full compliance with all 7 Public Sector AI Ethics Principles published by Jabatan Digital Negara (JDN 27 Feb 2025). Human-in-the-loop shadow debugging on disagreements.
AKSA MySeal 2.1 & PQC
Aligned with CyberSecurity Malaysia AKSA MySeal 2.1 and NIST FIPS 203 using ML-KEM-768 hybrid key encapsulation, SHA3-256 digests, and AES-256-GCM authenticated encryption.
Tri-Modal Structured JSON Data Extraction
Semantic DOM subtree pruning for standard HTML tables & lists, immune to CSS locator changes.
Passive XHR/fetch JSON payload harvesting for SPAs. 0 GPU compute, sub-50ms latency.
Targeted element crops for HTML5 canvas charts, SVG graphs, and scanned PDF data tables.
JDN Sovereign Governance
27 Feb 2025Full Alignment with 7 AI Ethics Principles
Garis Panduan Pengadaptasian AI Sektor Awam (GPAISA), Jabatan Digital Negara (gpaisa.jdn.gov.my)
Data Privacy & Security
100% on-premise local GPU inference with zero data egress. All step screenshots and DOM artifacts encrypted at rest with AES-256.
Transparency & Explainability
No black-box AI decisions. Every step evaluation provides structured semantic rationale, confidence scores, and cryptographic SHA-256 provenance.
Accountability & Human Control
Human-in-the-loop by design. Inconclusive signal disagreements trigger a 30-minute interactive Shadow Debugging Canvas where an authorized auditor retains final authority.
Fairness & Non-Discrimination
Constrained 7-action MCP allowlist with pinned model digests operating at temperature=0 to eliminate non-deterministic bias and hallucination.
Inclusivity & Accessibility
Operates natively on the Chromium Accessibility Tree (AXTree), continuously validating WCAG 2.1 and WAI-ARIA standards across public portals.
Reliability & Robustness
Dual-Signal consensus (DOM structural assertions + LLM semantic judge) backed by eBPF kernel probes for tamper-proof reliability.
Safety & Sustainability
97% AXTree token compression (<1.5s per step on local GPU hardware) combined with GPU-aware admission control to lower power consumption and server load.
Security Architecture
Data Protection Baseline, Layer by Layer
| Security Dimension | Technical Implementation | Compliance Target |
|---|---|---|
| Zero Data Egress | AI inference runs 100% on-premise on local GPU. No network data leaves the sovereign boundary. | Akta 88 (OSA 1972) |
| Air-Gapped Support | Deployable in fully isolated sovereign data centers with no Internet access. | Public Sector ICT |
| Encrypted Local Storage | Screenshots & evidence stored in local S3-compatible storage with AES-256 encryption. | PDPA 2024 (Act 709) |
| Identity & Access (RBAC) | SSO with OAuth 2.0 / OIDC + PKCE (S256) via Casdoor with granular reviewer/auditor roles. | Gov ICT Security |
| Web App Firewall (WAF) | Dual-node cluster with OWASP Core Rule Set to defend against perimeter threats. | Act 854 (Cyber Security) |
| eBPF Kernel Audit Trail | Kernel connection events linked directly with database test logs for NACSA audits. | Act 854 (NACSA) |
| Post-Quantum Cryptography (PQC) | NIST FIPS 203 ML-KEM-768 hybrid key encapsulation with SHA3-256 for zero-trust mTLS transit and vault storage. | AKSA MySeal 2.1 |
Economic Impact
RM 525,000 in Annual Savings per Agency
Annual operating cost comparison: 5 QA engineers, 500 daily tests, vs foreign cloud SaaS.
Annual Operating Cost
Eliminates recurring foreign cloud API and seat license fees.
Payback Horizon
2 - 3 Months
Immediate ROI through turnkey single-host deployment.
Test Maintenance Effort
< 2% Overhead
Intent-driven Markdown over AXTree eliminates DOM locator refactoring.
Ready to explore or execute test plans?
Authenticate via CloudConnect Zero Trust or view test suites.