Developer documentation

Changelog

Last reviewed 31 August 2026

QuickstartCLI referencePython SDKTypeScript SDKMCPIntegrationsPoliciesActionProofEvidenceCAIN TraceConformanceTroubleshootingDeveloper portalMarketplaceFree tierBenchmarksArchitectureCAIN IdentityCAIN ControlCAIN BudgetCAIN GovernanceCAIN MemorySelf-Hosted MCPGateCAIN PrivateCAIN TrajectoryCAIN Agent SecurityCAIN Drift7-Moat ArchitectureChangelog

CAIN Trust Fabric Changelog

All notable changes, architectural milestones, cryptographic primitives, and enterprise releases for the CAIN Trust Fabric are documented here.

⚡ View Live Interactive Telemetry & Changelog Feed


[42.10.0] — 2026-09-20 (CAIN-42 Epoch 10 — Agentic Trust Fabric: audited, attacked, publicly verifiable)

Status: PASS WITH LIMITATIONS. Not production. Not a Byzantine cluster result. Epoch 10 is a set of in-process Python modules (identity, invocation-bound authority, trust graph and path finder, negotiation, trajectory budgets, recovery, supply chain). The evidence below was produced by running those modules; it is published so that any reader, human or AI, can check it without trusting us.

Verify it yourself in about 30 seconds

Run on any machine with Python 3 and the cryptography package. The same command works on all three sites because they are three profiles of one gateway process:

curl -s https://cainstudio.online/api/v1/epoch10/verify-sites.py | python3 -

It fetches the evidence from cainstudio.online, mcpgate.online and clawx.click, checks every artifact has the same SHA-256 on all three, downloads the bundle and two verifiers, runs them, then asks each site's running process to execute a fresh scenario and runs the clean-room verifier on the result. Every URL is listed in /api/v1/epoch10/manifest.json; the live self-test is at /api/v1/epoch10/selftest/run.

What was found and fixed (real defects, each with a regression test)

Evidence

What this does NOT show


[42.1.0] — 2026-09-19 (CAIN-42 Epoch 6 — Autonomous World-State Integrity & Proof-Carrying Agency)

The Autonomous World-State Integrity & Proof-Carrying Architecture

CAIN-42 Epoch 6 evolves CAIN from a cognitively integrity-protected autonomous system into a self-verifying, world-state-aware, proof-carrying autonomous trust fabric. Built on the core governing doctrine:

$$\text{COMPROMISED COGNITION} \ne \text{COMPROMISED AUTHORITY} \ne \text{COMPROMISED WORLD STATE}$$

$$\text{INTENT MUST NOT BECOME EFFECT WITHOUT CONTINUOUS PROOF}$$


[34.0.0] — 2026-09-17 (CAIN 34.0 — Production-Grade Byzantine CAIN Cluster Release)

Live-Deployed Byzantine Fault Tolerant Cluster Runtime

CAIN 34.0 transitions the Byzantine consensus substrate from an isolated engine module into a fully integrated, live-deployed, production-grade 4-node cluster with zero stubs, zero mocks, and zero unhandled failure modes.

[3.0.0] — 2026-09-17 (CAIN Maximum Evolution — Phase 1, 2, 3: The $1B Enterprise Commercial & Developer Engine)

The 32-Feature Monopoly & Dual-Channel Execution Governance

CAIN establishes the first production execution-channel runtime for autonomous AI systems, overcoming the industry-wide Dual-Channel Control Problem. Governs actions over MCP, shell, database, cloud APIs, and financial rails through the canonical 7-Moat Trust Control System.

Phase 1: Rock-Solid Foundation & Subdomain Resilience

Phase 2: The 10-Minute Adoption Loop (Developer Virality)

Phase 3: The Enterprise Commercial Wedge ($50k–$250k/yr)

12 Monetization Channels Scaling to $1.13B+ Valuation


[2.4.1] — 2026-09-16 (CAIN 23.0 — Immutable Distributed Immune Consensus)

Delegation-chain revocation cascade closed (VULN-001)

Immune transition ledger is now tamper-evident

Multi-process Byzantine consensus — real evidence, honestly scoped

The existing BFT consensus primitive (real Ed25519 signing, real quorum math) previously ran all "nodes" as objects inside a single process, which proves the algorithm but not that independent processes can reach agreement over a real network with independently-verified signatures. This release adds that evidence:

Full raw evidence and reproduction steps: CAIN_23_MULTIPROCESS_BFT_EVIDENCE/. Full claim-by-claim audit: CAIN_23_FINAL_FORENSIC_REPORT.md.


[2.4.2] — 2026-09-16 (CAIN 23.0 follow-up — real multi-independent-host Byzantine consensus)

The [2.4.1] entry above proved Byzantine consensus across genuinely separate OS processes on one shared Docker host, and explicitly stated multi-independent-cloud-host evidence wasn't yet included. Same day, that gap was closed for real:

Raw evidence: CAIN_23_MULTIPROCESS_BFT_EVIDENCE/real_multihost_*.json.


[2.4.0] — 2026-09-16 (Past 96-Hour Maximum Platform Evolution)

Unified 4-Node Byzantine Fault Tolerant (BFT) CAIN Cluster Architecture

The entire CAIN platform has unified across all 4 cluster nodes into a single, identical CAIN Trust Runtime Kernel, providing mathematically proven Byzantine Fault Tolerance (f=1, N=4, Quorum Q=3):


[2.3.0] — 2026-09-15

CAIN 17/18: Distributed Autonomy Constitution & JIT Capability Boundary


[2.2.0] — 2026-09-14

CAIN 14.0: The Agentic Trust Intelligence Engine


[2.0.0] — 2026-09-13 (48-Hour Major Platform Release)

Trajectory Trust & The 16-Stage Dynamic Enforcement Loop

CAIN has officially promoted Trajectory Trust from an internal invariant to a first-class, cryptographically verifiable, continuously enforced runtime primitive.

WHO → AUTHORITY → INTENT → SECURITY CONTEXT → POLICY → RISK → TRUST → TRAJECTORY → BLAST RADIUS → PREDICTION → DECISION → MCPGATE ENFORCEMENT → SYSTEM EXECUTION → EFFECT → EVIDENCE → ATTESTATION


Mechanical Formal Verification via TLA+


BFT Multi-Validator Consensus & Confidential Computing Attestation


Universal SDK Release (cain-trust 2.0.0 on PyPI)


EU AI Act Statutory Pre-Conformity Portal


Actuarial Cyber Insurance Consortium Protocol


Vertical Rego Policy & Threat Intelligence Marketplace


Autonomous Swarm Fleet Quarantine & Emergency Circuit-Breaker


Enterprise SIEM & SOC Connectors


[1.2.0] — 2026-09-10

Strategic Identity & Validated Trust Runtime Baseline