{"schema_version":"1.0","timestamp":"2026-09-20T20:01:34.741933+00:00","limitations":[{"id":"deployment_topology","category":"DEPLOYMENT","status":"LIMITED","description":"Public proof does not expose internal deployment topology, geo-distribution, or redundancy architecture","public_visibility":"limited"},{"id":"availability","category":"AVAILABILITY","status":"LIMITED","description":"Public proof does not provide real-time availability status; use /health for current state","public_visibility":"limited"},{"id":"unsupported_protocols","category":"CAPABILITY","status":"LIMITED","description":"Not all AI agent frameworks and protocols are supported; check /api/v1/proof/capabilities for deployed list","public_visibility":"full"},{"id":"incomplete_components","category":"CAPABILITY","status":"LIMITED","description":"Some planned capabilities are not yet deployed; see capabilities with status != OPERATIONAL","public_visibility":"full"},{"id":"public_proof_scope","category":"SCOPE","status":"LIMITED","description":"Public proof covers only synthetic/public interactions; customer evidence is never exposed","public_visibility":"full"},{"id":"cryptographic_limitations","category":"SECURITY","status":"LIMITED","description":"Evidence signing not yet implemented; integrity verified via SHA-256 hash only","public_visibility":"full"},{"id":"testing_limitations","category":"TESTING","status":"LIMITED","description":"Replay protection and dependency failure handling not independently verified","public_visibility":"full"},{"id":"performance","category":"BENCHMARK","status":"LIMITED","description":"Benchmarks based on synthetic workload; individual results may vary in production","public_visibility":"full"},{"id":"source_visibility","category":"PROVENANCE","status":"LIMITED","description":"Source code is proprietary; public provenance is limited to version and release identifiers","public_visibility":"partial"},{"id":"independent_audit","category":"SECURITY","status":"LIMITED","description":"Security controls have not undergone independent third-party audit","public_visibility":"full"}],"scope_does":["Demonstrate deployed CAIN capabilities","Verify synthetic decision and enforcement","Confirm evidence generation","Validate integrity mechanism","Show conformance test results","Expose benchmark metrics"],"scope_does_not":["Guarantee freedom from vulnerabilities","Confirm all internal components are observable","Provide real-time security monitoring","Replace independent security audit","Expose customer data or private evidence","Verify third-party dependencies"],"caveat":"Public proof demonstrates selected properties of the deployed system. It does not constitute a guarantee that CAIN is free of vulnerabilities or that every internal component is publicly observable."}