CAIN-42 evidence library
CAIN-42 signed public claims registry
Evidence bundle: 67 claims, 0 of 0 invariants held.
Last reviewed 2026-10-01
Claims (67)
| Claim | Level |
|---|---|
| C42-PBFT-QC: A 4-node CAIN-42 PBFT cluster produced authentic quorum certificates (>= 3 of 4 pinned Ed25519 members) with an identical decision chain on every node across a primary failover. | DISPOSABLE CLUSTER VERIFIED |
| C42-FAST-PATH: The Evolution 3 fast path commits only with all 4 members' votes and its view-change rule was model-checked (the naive rule was shown unsafe); a real run produced FAST_COMMIT_QCs that verify. | DISPOSABLE CLUSTER VERIFIED |
| C42-FAST-PATH-LATENCY: The fast path did NOT produce a measurable latency improvement on this host (paired A/B, 95% CI includes 0). | IMPLEMENTED |
| C42-DAG-ORDER: DAG data is availability-certified (3 of 4), anchored only through PBFT, and ordered identically on all 4 nodes including a crash-restarted one; the verifier recomputes the order. | DISPOSABLE CLUSTER VERIFIED |
| C42-MCPGATE-ENFORCES: MCPGate lets a tool call run only with a PBFT-committed authorization bound to the exact action, scope, identity, security context, expiry and single use. On the LIVE 4-region cluster cain-mr-02, through the MCPGate HTTP proxy to a separate MCP server process: 5 authorized calls ran (per the server's own execution log) and 12 attacks were blocked, each with a signed denial returned to the caller (replay, action and tool substitution, capability escalation, identity substitution, context drift, forged QC, forged body, post-consensus mutation, another cluster's certificate, no authorization, expiry). | LIVE + DISPOSABLE CLUSTER VERIFIED |
| C42-AGENTS-CANNOT-SELF-AUTHORIZE: Agents propose; only PBFT authorizes. Plan mutation, model update or tool swap after consensus forces reauthorization; undeclared actions, impersonation, replay, forged trajectories, delegation escalation and aggregate-policy (salami) attacks are blocked. | SIMULATED |
| C42-INVARIANTS: 28 executable CAIN-42 invariants (I001-I028: no quorum -> no consensus -> no authorization -> no execution; agents, memory, DAG, delegation, trust and AI predictions cannot create authority; replay, expiry, substitution, tampering rejected) pass on the real code; 22 with full coverage, 6 partial with the gap named. | SIMULATED |
| C42-1000-TRAJECTORIES: 1,000 agent trajectories (9 kinds incl. 380 attacks) all ended as expected; all 620 allowed actions carry complete, re-verified proof chains; a 1,000-step trajectory accepted 0 stale authorizations. | SIMULATED |
| C42-ORDERING-FAIRNESS: DAG within-round order is seeded by committed PBFT history: validator-position bias measured before (chi-square 542) and after (1.75). | SIMULATED |
| C42-LIVE-CLUSTER-EVO2: The live cain-vc cluster runs the Evolution 2 engine (upgraded node by node, state preserved). | NOT ESTABLISHED |
| C42-PRIVACY-FIREWALL: Every published evidence bundle passes the public-evidence privacy firewall (keys, tokens, credentials, private IPs, internal URLs, server paths, source). | IMPLEMENTED |
| C42-INDEPENDENT-FAILURE-DOMAINS: Consensus runs on independent geographic failure domains: cain-mr-02 has 4 replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; every server was taken offline in turn and the cluster kept committing, and with two down it refused to commit. | LIVE VERIFIED |
| C42-MULTI-PROVIDER: Replicas on more than one infrastructure provider. | NOT ESTABLISHED |
| C42-LIVE-MULTI-REGION: Two live multi-region clusters: cain-mr-01 (4 replicas, 3 regions, WireGuard) and cain-mr-02 (4 servers, 4 regions); each publishes a 30-minute signed proof of its live state, and every decision carries signatures from at least 2 regions. | LIVE VERIFIED |
| C42-PARTITION-BYZANTINE: Live network-partition tests (isolated host commits nothing; 2|2 split commits nothing on either side; agreement within ~3 s of heal) one-way (asymmetric) partitions on the 4-server cluster (deaf replica, one-way link, mute replica: commits continued, identical chains after each heal), and Byzantine tests on the production image (forged votes rejected; equivocating primary proven from its own signatures, quarantined and replaced). | LIVE + DISPOSABLE CLUSTER VERIFIED |
| C42-DEGRADED-NETWORK: Safety under a degraded network: with 10% packet loss, 120 +/- 40 ms delay, 5% duplication and reordering on all four replicas' traffic of the live 4-server cluster for 4 minutes, no fork (identical decision chains on all four, 341 certificates each). Liveness degraded sharply: 0.16 commits/s under the impairment versus 1.76/s before (39 of 61 writes committed within the client's 30 s timeout; p95 7173.9 ms), and fully recovered after (2.02/s, p95 644.0 ms). Re-run after engine 948b189 (backoff resets only on progress): 44 of 62 committed, 0.18/s, view changes cut from 14 to at most 6; throughput did not improve beyond noise, so the view-change storm was not the bottleneck. Safety held again. | LIVE VERIFIED |
| C42-DISASTER-RECOVERY: Disaster recovery on the live clusters: two replicas lost their storage at once and were rebuilt only from off-host backups in other regions (0 of 4 writes committed while quorum was lost; 0 decisions lost; identical height and state 10.3 s after restart); a single replica restored from a snapshot in 8.3 s under writes. Hourly backups of both clusters are copied to another region; every day each replica's newest off-host backup is proven to be a quorum-signed prefix of the live history. | LIVE VERIFIED |
| C42-ROLLBACK: Live rollback to the previous engine and forward again, one replica at a time with the primary last; every replica caught up in 10-14 s, cluster HEALTHY 4/4 after each direction. | LIVE VERIFIED |
| C42-REPRODUCIBLE-RELEASE: The 4-server cluster runs an image that rebuilds bit-for-bit from its commit (two independent from-scratch builds produced the deployed image ID); pinned base and packages, SBOM, Ed25519-signed release manifest. | LIVE VERIFIED |
| C42-HOSTED-CONSENSUS: The hosted Fabric orders every recorded decision through the live PBFT cluster; since 2026-09-27 the gateway itself verifies the commit quorum certificate (>= 3 pinned Ed25519 signatures over the digest it computes for that decision) and a replica's unproven 'COMMITTED' counts as a denial. Each decision shows the check (certificate hash, signers), and GET /fabric/decisions/{id}/integrity re-checks a STORED decision against the commitment the quorum signed (consensus_anchor); every stored decision record is also Ed25519-signed by a key kept outside the database (GET /fabric/decision-signing-key). | LIVE VERIFIED |
| C42-DECISION-RECORD-SIGNING: Every hosted Fabric decision record written since 2026-09-27 is signed: the gateway signs the record's SHA-256 digest with an Ed25519 key kept outside its database, so a database writer who alters a record and recomputes its digest is detected. The published record's digest is recomputed from its own fields by a verifier with no CAIN code, the signature verifies against the key served by another site, and two tampered copies (verdict changed; verdict changed with the digest recomputed) both fail. | LIVE VERIFIED |
| C42-HARDWARE-ATTESTATION: Hardware-backed attestation of nodes or agents. | NOT ESTABLISHED |
| C42-FORMAL-VERIFICATION: TLA+ models of the PBFT commit/view-change rules and of the MCPGate authorization gate, checked exhaustively by TLC within stated bounds: no violation of Agreement, CommitOnlyWhenPrepared, no-execution-without-quorum, action/identity/context binding, expiry or single use; every deliberately broken variant (pre-fix execute rule, NEW_VIEW ignoring reports, weakened quorum, each gate check removed) is caught with a counterexample. | OFFLINE VERIFIED |
| C42-SOAK-72H: 72-hour adversarial soak (dedicated 4-node cluster, fast path + DAG, crash/restart every 10 min, started 2026-09-25T00:10Z): FAILED. PBFT stopped committing at sequence 4094 about 11 h in (2 replicas in view 39, 2 in view 40, every node HEALTHY, every later request denied), and the harness itself was killed when the host ran out of memory (last checkpoint 0024 at 24.15 h). Safety held: 0 cross-node divergences in 5,154 checks. Cause: no progress timer (only an unreachable primary triggered a view change) and NEW_VIEW replies were dropped, so a lagging replica never caught up; fixed in the engine with a regression test that reproduces the split. A new soak on the fixed build has not run. | FAILED |
| C42-SOAK-72H-MULTIREGION: 72-hour soak on the live multi-region cluster cain-mr-01 on the fixed build (continuous writes, a random replica killed every 20 minutes, hourly signed hash-chained checkpoints each with an MCPGate-enforced authorization and its refused replay): FAILED by its own pre-committed rule. Checkpoint 0032 (hour 32, 2026-09-28T05:42Z) carries no MCPGate enforcement evidence -- its checkpoint authorization did not commit (CONSENSUS_TIMEOUT) -- and the verifier requires it in every checkpoint, so no later hour can turn the verdict into PASS. At 37.7 h: 107 replica kills / 107 restarts, 0 divergences, 0 anomalies, 37 of 38 checkpoints valid (48 quorum certificates each). The soak keeps running to ~2026-09-29 21:40Z for the record. | FAILED |
| C45-ZOD-LIVE: Agent Hypervisor / ZoD runtime: an agent acts only inside a ZoD whose authorization the live cluster cain-mr-01 committed with a quorum certificate the hypervisor checks itself; code ran under real confinement (bubblewrap namespaces + cgroup v2, no network); 10 attacks were refused, each a signed DENIED entry in a hash-chained log. | LIVE VERIFIED |
| C42-E6-AUTHORITY-LEASES: Evolution #6 authority leases: for each of 9 conditions a ZoD authorized by the live cluster cain-mr-01 made one successful tool call, the condition was tripped, and the next call was refused without the tool running -- TTL expiry, trust below floor, agent identity swapped, tool schema changed, security context changed, trajectory fork, explicit revocation, parent quarantined (child loses authority), required evidence deleted (that row is SELF-REPORTED: hypervisor-signed, since the log proving it is the one deleted). | LIVE VERIFIED |
| C42-E7-AUTHORITY-LAPSE: Evolution #7: authority granted by the live cluster cain-mr-01 lapses -- the next tool call is refused and the tool never runs -- when the policy root changes or cannot be read, when the risk or blast-radius budget is spent, and when a delegate has spent its parent's budget (delegates are charged up the whole chain, so splitting work cannot multiply authority). Every ZoD is bound to the cluster's real membership configuration, recomputed and quorum-agreed, re-read before every action; a changed epoch, a changed membership or an unknown membership refuses. | LIVE VERIFIED |
| C42-E8-GOVERNED-EVOLUTION: Evolutions #8/#9: a policy -- the authority ceiling for a tenant's ZoDs -- becomes active only when the live cluster cain-mr-01 commits its activation; an expansion needs a registered human who is not the proposer (an agent's self-approved expansion was refused and never reached the cluster); a restriction needs no human and revoked a running ZoD's authority; a ZoD above the ceiling was refused. A world-model prediction, a simulated ALLOW citing a real certified sequence, a 10-agent signed vote and a replayed memory were each presented as the basis for authority and each refused because the live cluster had not certified it. | LIVE VERIFIED |
| C42-CAG-L5-HOSTED-GOVERNOR: The CAG-L5 system governor runs in the production gateway (CAIN_SYSTEM_GOVERNOR=1): /fabric/mcp/enforce refuses every tenant without a registered, governance-signed system manifest and every request not signed by the agent's registered key, and for a registered system applies policy precedence, the agent/delegator/system/lease authority intersection, model identity, tool registry, emergency controls and cluster-certified governance state. On the live gateway, through all three public domains: 13/13 cases as expected (in-scope read allowed on each domain; unregistered tenant, unsigned, key substitution, replay, outside system authority, model swap, subagent WRITE, unlisted tool and emergency freeze refused; one-operator recovery refused, two-operator recovery restored service); governance state certified by cain-mr-01 (3 signers); 8/8 decision signatures valid; 18-event chain verifies. | LIVE VERIFIED |
| C42-CAG-L5-SYSTEM-GOVERNANCE: The CAG-L5 system-governance library composes emergency freeze, 2f+1 governance-state quorum, attested state, a signed system manifest, model identity, tool registry, exact-capability resource checks, deterministic policy precedence, authority intersection, trajectory authorization and graph-derived blast radius with two-operator step-up; Part 41 Tests A-N all behave as specified, and a clean-room verifier recomputes policy, authority, blast radius, quorum and step-up for every decision and rejects a CAIN-signed but unjustified ALLOW. | IMPLEMENTED |
| C42-L5-TRAJECTORY-GOVERNANCE: Continuous trajectory governance: a lease authorizes only if signed by a governance key (never the agent's), bound to the agent and trajectory, time-bounded (<= 1 h) and fully scoped; only ACTIVE/LIMITED trajectories act; containment only tightens; plan, intent, action, parameters, resource and context must match the governance-bound plan; subagent risk is charged to every ancestor. A clean-room verifier recomputes the decision and 9 adversarial requests (43/43 VALID). | IMPLEMENTED |
| C42-L5-TRAJECTORY-FAIL-OPEN-FOUND: Negative evidence: the first continuous-authorization implementation (uncommitted, published earlier on 2026-09-28) failed 13 of 13 probes -- self-signed, unsigned, foreign or unbounded leases, empty scope, missing policy/context, PAUSED/ESCALATED/REAUTHORIZATION_REQUIRED trajectories and unchecked plan binding were ALLOWed; containment could revive a TERMINATED trajectory. 5 of its 15 invariants were the constant True. All fixed in 040cee2 with regression tests. | IMPLEMENTED |
| C42-L5-IDENTITY-AUTHORITY: Agent identity and dynamic authority: signed versioned agent identities with key lifecycle; capability-, resource- and time-bounded grants; non-escalating delegation; explainable authorization decisions. Two separately written clean-room verifiers return VALID on the published bundle and refuse 25 attack classes. | IMPLEMENTED |
| C42-L5-UNIFIED-V1-SUPERSEDED: SUPERSEDED: the l5-governance-2026-09-28 unified bundle's trajectory ALLOW and its 15/15 trajectory invariants. The ALLOW came from the fail-open authorizer and 5 invariants were constant True. The bundle stays byte-identical for history; the replacement is C42-L5-TRAJECTORY-GOVERNANCE. | NOT ESTABLISHED |
| C42-LEGACY-SELF-ASSERTED: Seven older files still served on the sites assert strong statuses that no evidence in this registry supports: CAIN42_BYZANTINE_CERTIFICATION.json (CERTIFIED), CAIN42_ENTERPRISE_PERMANENT_MEMORY.json (A_PLUS_ENTERPRISE_CERTIFIED), CAIN42_RELEASE_MANIFEST.json (PRODUCTION_HARDENED) on clawx.click/evidence/; CAIN_13_STATUS.json and v13/CAIN_13_STATUS.json (OPERATIONAL_PROVEN), cain_14_agentic_trust_evidence.json and v2/kernel-self-defense-evidence.json (OPERATIONAL_AND_VERIFIED) on /proof/bundle/. They are kept for history; their statuses are SUPERSEDED by this registry and must not be read as current claims. | NOT ESTABLISHED |
| C42-L5-ADAPTIVE-EVOLUTION: Governed adaptive evolution (Prompt 6): a proposed change to an agent's memory, skills, tools or model routing becomes active only through an evolution gate; a clean-room verifier recomputes all 11 recorded evolution decisions (1 ACCEPT, 1 REQUIRE_APPROVAL deployed only with operator approval, 6 REJECT, 3 QUARANTINE), 143 checks VALID, and rejects a CAIN-signed but unjustified ACCEPT plus 10 tamper classes. Negative evidence: the first version was fail-open on 32 of 32 independent probes (and an earlier 33/33 invariant result was measured against it); fixed in 71eecdb, 0 open. | SIMULATED |
| C42-L5-ADAPTIVE-HOSTED-EVOLUTION: The Prompt 6 evolution gate is wired into the production gateway and MCPGate: after registration an agent's model and MCP tool configuration change only through it (agent-signed proposal, tenant-evaluator-signed report, operator approval that is never the proposer), and a deployed change gives a new capability commitment, so the old cluster certificate and every lease stop authorizing until cain-mr-01 certifies the new commitment and a lease is re-issued. Live, through all three public domains: 17/17 enforcement cases as expected (model swapped outside the gate, old lease after a capability change, the disabled tool on each domain and the rolled-back model refused; the enabled tool, the upgraded model and the restored version allowed); gate refusals: no evaluator report REJECT, authority-widening tool change QUARANTINE and undeployable, unapproved model REJECT, deploy without approval or with the agent's own approval refused, agent-signed rollback refused; 4 cain-mr-01 certifications (sequences 22515, 22517, 22518, 22517) whose own records carry each certified commitment; 42-event chain verifies; a clean-room verifier recomputes all 5 hosted evolution decisions (VALID). Found and fixed on the way: the certified governance state did not cover the MCP tool map or per-agent tool configuration. | LIVE VERIFIED |
| C42-TRUST-INTEGRITY-LIVE: A caught attacker no longer gains autonomy on the production gateway. Before 2026-09-28 a new account that sent two prompt injections (both BLOCKED) fell from UNKNOWN to DEGRADED trust, which the matrix answered more permissively than UNKNOWN, so its $250,000 transfer, rm -rf / and DROP TABLE came back ALLOWED. Now the trust matrix is monotone with a runtime floor (no state carrying negative evidence beats UNKNOWN), the independent verifier builds its table from a published spec instead of copying production, every action is scored by tool class, destructiveness, amount and target (high and critical go to a human), deny rules match every spelling of a path, trust is per agent and capped by its key, a trust hold is queued for approval, an approval binds the call's arguments, and an account can mint agent keys so the agent asks and the owner approves. Live, with a fresh free account on each of cainstudio.online, mcpgate.online and clawx.click: every case as specified, including the solo-developer path (agent held, cannot approve itself, owner approves, retry runs, its next low-risk call runs with no approval, a critical action is still held), and all 48 decisions match cain-mr-01's own public record (decision id, verdict, commitment, 3-of-4 commit certificate); clean-room verifier VALID. | LIVE VERIFIED |
| C42-E15-SPATIAL-PHYSICAL: Evolution 15 (spatial + physical intelligence governance) is a TESTED library that brings sensor observations, world state, world-model output, simulation, trajectories and physical actions into CAIN-42's governed trust path. Signed sensor observations are admitted through the E12 evidence layer; the world state is versioned, hash-chained and replayable and binds every ingested observation; a world model's output is PREDICTED evidence bound to its model, configuration, world state and scenario, never authority; a trajectory is a proposal until a signed approval binds it; every physical action binds nine digests (world state, trajectory, decision, capability, authority, policy, risk, consequence, authorization), crosses the E8 commit boundary and reaches an actuator adapter only with a single-use, short-lived permit for that exact command; material reality drift invalidates the authorization and forces re-evaluation or a safe state. P1-P36 36/36 hold; the CAIN-42-E15-Spatial-Physical-Bench contains 55/55 attacks; the 19-step end-to-end run and all 7 deliberate mutations behave as specified; digital, physical and hybrid agents converge on one path; clean-room verifier INTACT. | SIMULATED |
| C42-E17-MULTI-AGENT: Evolution 17 (governed multi-agent world action fabric) is a TESTED library that governs action by autonomous agent teams as a first-class system object: a collective is not the sum of its members and a collective action is not the sum of member actions. Collective authority is a constrained INTERSECTION of the governing grant, the mission capabilities, policy and live member authority, never a sum; majority, consensus, negotiation, contracts, roles, membership, coalitions, delegation, subagents, emergence and self-improvement cannot create or amplify authority; a material mission/membership/world-state/causal/topology drift forces reauthorization or a safer decision; dissent is preserved; a world-state fork blocks authorization until reconciliation; a collective trajectory is a proposal; and one action that would fan out to many agents is pre-authorized. Every consequential collective action binds fifteen digests and reaches the E8 governance kernel, and the boundary itself enforces the risk, policy, world-state, authority, decision and consequence verdicts it binds (a consistently re-signed refusal is still refused). Q01-Q61 61/61 hold; the CAIN-42-E17-Multi-Agent-Bench contains 91/91 entries (88 distinct attacks); the 18-step end-to-end run and all 12 deliberate mutations behave as specified; the clean-room verifier returns INTACT (92 checks, no CAIN imports). | SIMULATED |
| C42-E18-4D-SPATIAL: Evolution 18 (4D spatial autonomy fabric) is a TESTED library that governs proposals from autonomous systems across a predictive 4D world: entity state at (X,Y,Z,T) with uncollapsed uncertainty; reachable / policy-permitted / authorized sets kept distinct; probabilistic intent; multiple predicted trajectories; an interaction graph and a conflict field that is not distance-only; time-to-consequence with uncertainty; dynamic signed geofences; governed airspace and roadspace; spatial policy that yields ELIGIBILITY not authorization; multimodal sensor fusion; world-model arbitration that never simply picks the highest confidence; counterfactual future trees; actionability states; a conserved uncertainty budget; a micro-authorization loop; and a reality-gap monitor. Every consequential spatial action binds sixteen digests and reaches the E8 governance kernel, and the boundary itself enforces the policy, actionability, authority, risk and uncertainty verdicts it binds (a consistently re-signed refusal is still refused); AUTHORIZATION IS A FUNCTION OF WORLD STATE and if a material input changes it must be revalidated. Q01-Q89 89/89 hold; the CAIN-42-E18-Spatial-Autonomy-Bench contains 123/123 entries (109 distinct attacks plus 14 invariants re-run as scenarios); the 20-step end-to-end run, its unmutated control and all 12 deliberate mutations behave as specified; the clean-room verifier returns INTACT (111 checks, no CAIN imports). ACTIONABILITY IS NOT AUTHORIZATION. REACHABILITY IS NOT PERMISSION. PREDICTION IS NOT REALITY. | SIMULATED |
| C42-E19-GOVERNED-AUTONOMY: Evolution 19 (governed autonomy operating fabric) is a TESTED library that governs the evolving state of an autonomous system: identity, mission, goals, beliefs, memory, models, learning, authority, world, outcomes and recovery are hash-chained governed state; effective authority is the intersection of sixteen factors (a missing factor is UNKNOWN and empties it; confidence, peer agreement, learning, plans, predictions and compute are not factors); autonomy levels are derived from evidence; a subgoal never exceeds its parent or its mission; memory never becomes policy or authority; a learned change to authority needs a constitutional quorum; and every consequential action carries a sixteen-field action contract that any material state change invalidates and whose verdicts the gate enforces itself before the E8 kernel commits it -- a consistently re-signed refusal is still refused. G1-G108 108/108 hold; the CAIN-42-E19-Governed-Autonomy-Bench contains 189/189 entries (177 distinct attacks); a mutation self-test shows that removing any of four defenses is caught; the 19-stage end-to-end run and all 20 stage attacks behave as specified; the clean-room verifier returns INTACT (117 checks, no CAIN imports). AUTONOMY IS NOT AUTHORITY. | SIMULATED |
| C42-E20-AGENTIC-INSTITUTIONS: Evolution 20 (governed agentic civilization fabric) is a TESTED library that governs agents, collectives and machine-native institutions -- formation, membership, delegation, negotiation, contracts, resources, spawning, termination, reputation, trust, federation, disputes, evolution and recovery -- without allowing coordination, capability, economic activity or organizational growth to manufacture authority: institutional authority is an intersection (constitution boundary, founding authority, parent, autonomy-state ceiling) and member authority is the grant plus delegations bounded by their delegator, never a sum; membership, votes, consensus, reputation, trust, wealth, market wins, rewards and model capability are not inputs; a contract or negotiated agreement authorizes nothing by itself; a spawned child is bounded in seven independent dimensions; terminated agents and dissolved institutions cannot resurrect; and every institutional action is judged by E20, then by the E19 action-contract gate, and committed only by the E8 kernel -- a re-signed refusal is still refused. I1-I118 118/118 hold; the CAIN-42-E20-Agentic-Institutions-Bench contains 334/334 entries (328 distinct attacks); a mutation self-test shows that removing any of six defenses is caught; the 20-step end-to-end run detects and contains all 7 hostile events and then recovers and re-authorizes; the clean-room verifier returns INTACT (179 checks, no CAIN imports). Every economy in it is SIMULATED. COLLECTIVE INTELLIGENCE IS NOT INSTITUTIONAL AUTHORITY. | SIMULATED |
| C42-E21-OPEN-ENDED-INTELLIGENCE: Evolution 21 (governed open-ended intelligence fabric) is a TESTED library that governs autonomous research -- questions, competing hypotheses, experiments, simulations, observations, replication, peer review, adversarial challenge, knowledge, causal claims, benchmarks, model and strategy evolution, research-agent creation and discovery-to-capability promotion -- so that discovery never silently becomes truth, authority or execution: epistemic state is computed from signed evidence whose method class (simulation, synthetic, controlled, real-world, independent replication, third-party) is bound into its signature and grouped by independence key (one controller, environment, dataset and model count once); research authority (charter actions within role) is disjoint from execution authority and no authority function takes a discovery, confidence, vote, benchmark score, knowledge, curiosity or information value as input; a capability leaves quarantine only after validation, an independent adversary, a security review and a governance quorum that excludes the researchers, and a promotion is necessary but never sufficient -- every action is still judged by E20, the E19 action contract and the E8 kernel; revoked evidence invalidates dependent knowledge, policies and capabilities; failed experiments are retained; a discovered governance weakness can only be disclosed. D1-D155 155/155 hold; the CAIN-42-E21-Open-Ended-Intelligence-Bench contains 298/298 entries (290 distinct attacks) and answers NO to 'can a discovered loophole be used to acquire permission to exploit it'; a 17-stage research demonstration refuses all 16 self-authorization attempts; removing any of seven defenses is caught; the clean-room verifier returns INTACT (218 checks, no CAIN imports) and catches all 16 re-signed tamperings. DISCOVERY IS NOT TRUTH IS NOT AUTHORITY IS NOT EXECUTION. | SIMULATED |
| C42-E23-META-INTELLIGENCE: Evolution 23 (governed meta-intelligence fabric) is a TESTED library in which the system models its own architecture, searches and proposes changes, sandboxes and red-teams them, and can never authorize them: promotion needs a proof by an evaluator key, a canary, a board quorum that excludes the proposer and a human approval, and execution still goes through the E19 action contract and E8. 253/253 invariants hold; 545/545 adversarial scenarios across 80 families are contained; removing any of 7 defenses is caught; 609 tests pass; the clean-room verifier returns INTACT (733 checks, no CAIN imports). | SIMULATED |
| C42-E24-AGENTIC-INTERNET: Evolution 24 (governed agentic internet fabric) is a TESTED library for agents of different organizations and trust domains across thirteen protocol classes: a fourteen-dimension trust vector that is never collapsed, capability claims that stay CLAIMED until attested, signed negotiation and contracts that are never authority, child-subset delegation, cross-domain authority as the intersection of ten factors, quarantine, revocation and a firebreak; one consequential path E24 -> E19 -> E8. 305/305 invariants hold; 756/756 adversarial scenarios across 68 families are contained; removing any of 8 defenses is caught; 806 tests pass; the clean-room verifier returns INTACT (1,952 checks). | SIMULATED |
| C42-E25-MACHINE-AGENCY: Evolution 25 (universal machine agency fabric) is a TESTED library that turns any consequential machine action into one protocol-neutral envelope signed by the agent instance, authorized by a compiled policy and delegation chain and committed only through the E8 Action Commit boundary, across eighteen protocol adapters that each pass a sixteen-check conformance contract; the agent never holds a raw secret. 517/517 invariants hold; 1,055/1,055 adversarial scenarios across 35 families are contained; every mutant is caught; 60 tests pass; the clean-room verifier returns INTACT (2,977 checks). | SIMULATED |
| C42-E26-AGENCY-TRUST: Evolution 26 (universal machine agency trust fabric) is a TESTED library adding portable signed trust objects, a seventeen-dimension trust vector that never collapses into one score, continuous attestation with explicit levels (hardware stays UNKNOWN), transaction-bound authorization that refuses reuse, attenuating delegation with receipts, revocation epochs, transaction finality and SPIFFE/AuthZEN/COAZ adapters. 532/532 invariants hold; 1,192/1,192 adversarial scenarios (137 specific to E26) are contained; 30 tests pass; the clean-room verifier returns INTACT (3,115 checks). | IMPLEMENTED |
| C42-E27-CONTROL-PLANE: Evolution 27 (agentic internet control plane) is a TESTED library that coordinates registry, discovery, routing, policy distribution, cross-domain decisions, contracts, negotiation, inference budgets, incident propagation, emergency policy, edge nodes, conformance and certificates over E25/E26 without becoming a source of authority. 765/765 invariants hold and 1,533/1,533 adversarial scenarios are contained (both cumulative with E26; 341 scenarios specific to E27); 28 tests pass; the clean-room verifier returns INTACT (4,001 checks). | SIMULATED |
| C42-E28-EXECUTION-IDENTITY: Evolution 28 (portable machine agency and execution identity) is a TESTED library: any agent can connect (register with proof of possession, attest, declare capabilities) and receive a signed, versioned, time-bounded execution identity whose envelope travels byte-identically over 23 protocol carriers, while authority never travels -- every receiving domain recomputes it (requested AND federated AND local sponsor AND home ceiling), delegation is a subset of the parent on 16 dimensions, model/runtime/prompt/tool/memory/key changes invalidate authority until re-evaluated, every action is bound to one transaction and reaches the E8 Action Commit boundary, and every decision leaves a signed hash-chained receipt with identity events in an RFC 6962 transparency log. 90/90 invariants hold; 442/442 adversarial scenarios across 8 categories are contained; the mutation self-test kills 9 of 10 mutants (the survivor is explained); conformance 17/17; 11 tests pass; the clean-room verifier returns INTACT (243/243 checks, no CAIN imports). | SIMULATED |
| C42-E29-MACHINE-TRANSACTIONS: Evolution 29 (governed agentic internet transaction fabric) is a TESTED library: a machine transaction runs through twelve separately gated, signed stages and two signed envelopes binding 24 attributes; authority is computed per transaction (delegation, lease, separate economic authority, organization path, contract, counterparty risk with no score, consequence vector, firebreak, partition mode); value moves only through a sealed treasury executor inside the E8 commit boundary and every ledger entry names its committed request; escrow releases only on evidence, never on a claim. 106/106 invariants hold; 258/258 adversarial scenarios contained; mutation 10/10; 0 false allows in ten catastrophe scenarios; 12 tests pass; the clean-room verifier returns INTACT (300/300 checks, no CAIN imports). | SIMULATED |
| C42-E33-OPERATING-FABRIC: Evolution 33 (governed agentic operating fabric) is a TESTED library: 22 kinds of agent operation run one explicit 16-state lifecycle; executed operations pass the E32 overlay, E30, E28, E25 and E8 and carry an E31 proof; state-changing operations run inside sealed executors behind E8; governance mutations are routed to their governing engine and never executed; a signed, versioned ABI and a stdio sidecar let an agent that imports nothing from CAIN be governed. 581/581 invariants hold; 2029/2029 scenarios held; mutation 12/12 (targeted); a 27-step loop passes; 11 tests pass; the clean-room verifier returns INTACT (2603/2603 checks, no CAIN imports). | SIMULATED |
| C42-E34-PROOF-CARRYING-AGENCY: Evolution 34 (proof-carrying machine agency) is a TESTED library: every governed operation yields one signed, chained GovernanceProofEnvelope binding identity, capability, delegation, authority, policy, evidence, risk, decision, the E8 commit, the enforcement boundary, execution and outcome, and stating what remains UNKNOWN or outside the boundary; fourteen statuses, per-layer proof primitives, an enforcement proof that separates decision from authorization, commit, enforcement, execution and outcome, attenuation-checked delegation proofs, RFC 6962 selective disclosure, denials and incident proofs; a proof is never permission. 629/629 invariants hold; 2664/2664 scenarios held; mutation 12/12; 22 forged objects rejected; 13 tests pass; the clean-room verifier returns INTACT (3286/3286 checks, no CAIN imports). | SIMULATED |
| C42-E39-AGENT-FACTORY: Evolution 39 (governed agent factory) is a TESTED library: a mission compiles into a bounded specification whose authority envelope never exceeds the sponsoring principal, a minimal machine organization in which every agent's authority is a subset of the mission envelope and every child's a subset of its parent's, and a workflow whose consequential tasks are gated; agents are red-teamed and evaluated independently (self-certification refused), promoted only by CAIN, provisioned as real governed identities, and their consequential tasks run through the kernel and E8 with E38 action proofs; a retired agent cannot act. 4 real agents provisioned and 3 tasks executed in the 16-step loop; 1041/1041 invariants hold; 3441/3441 adversarial scenarios held; mutation 16/16; conformance 13/13; 19 tests pass; the clean-room verifier returns INTACT (3307/3307 checks, no CAIN imports). | SIMULATED |
| C42-E38-PROOF-CARRYING-AGENCY: Evolution 38 (portable proof-carrying machine agency) is a TESTED library: every real governed action (kernel + E8 commit + E34 envelope + E37 receipt) yields twelve signed layer proofs and one action proof binding identity, delegation, authority, policy, risk, evidence, authorization, the E8 commit, the enforcement boundary, execution, outcome and environment, with no secrets. A verifier with no CAIN code recomputes VALID / INVALID / INCOMPLETE / STALE / REVOKED / UNKNOWN for every published proof case. A proof is never authority: partial, stale, revoked, simulated, confused or unbound proofs are never VALID; revocation propagation is measured and its exposure window counted; translation declares every lost field; handshakes and federation never create or merge authority. 5 real action proofs and 41 proof cases; 1030/1030 invariants hold; 2141/2141 adversarial scenarios held; mutation 15/15; 0 of 19 injected faults made proof state more permissive; 20 tests pass; the clean-room verifier returns INTACT (509/509 checks, no CAIN imports). | SIMULATED |
| C42-E37-AUTONOMOUS-EXECUTION-MESH: Evolution 37 (autonomous execution mesh) is a TESTED library: every governed execution runs IDENTITY -> CAPABILITY -> AUTHORITY -> POLICY -> CONTEXT -> EXECUTION ENVIRONMENT -> ACTION -> E8 -> ENFORCEMENT -> OUTCOME -> PROOF -> REASSESSMENT over the real kernel, sealed executor, E8 commit boundary and E34 proof envelope, and leaves a signed receipt whose E8 commit matches the envelope. Moving an execution (node, runtime, model, region, container, credential) is a governed state transition: authority can only shrink, a material change needs a new epoch, continuity tokens cannot exceed existing authority, and risk, spent budget, revocations, transaction limits, evidence, reputation and incident state cannot be reset. UNKNOWN, OBSERVED and MONITORED never become ENFORCED; claims take the weakest boundary. 71 signed execution receipts; 1132/1132 invariants hold; 2720/2720 adversarial scenarios held; mutation 17/17; chaos 16/16 faults contained with 0 false allows; 16 forged objects rejected; 21 tests pass; the clean-room verifier returns INTACT (2627/2627 checks, no CAIN imports). | SIMULATED |
| C42-E39-GOVERNED-AGENT-FACTORY: Evolution 39 (governed agent factory) is a TESTED library: a mission compiles into a bounded specification whose authority envelope never exceeds the sponsoring principal, a minimal machine organization in which every agent's authority is a subset of the mission envelope and every child's a subset of its parent's, and a workflow whose consequential tasks are gated; agents are red-teamed and evaluated independently (self-certification refused), promoted only by CAIN, provisioned as real governed identities, and their consequential tasks run through the kernel and E8 with E38 action proofs; a retired agent cannot act. 4 real agents provisioned and 3 tasks executed in the 16-step loop; 1041/1041 invariants hold; 3441/3441 adversarial scenarios held; mutation 16/16; conformance 13/13; 19 tests pass; the clean-room verifier returns INTACT (3307/3307 checks, no CAIN imports). | SIMULATED |
| C42-E36-MACHINE-AGENCY-EXCHANGE: Evolution 36 (machine agency exchange) is a TESTED library: a governed exchange where machine services are discovered, verified, negotiated with, contracted, hired and transacted with along the lifecycle DISCOVER -> IDENTIFY -> VERIFY -> EVALUATE -> NEGOTIATE -> CONTRACT -> AUTHORIZE -> EXECUTE -> PROVE -> SETTLE -> RATE -> REASSESS -> RENEW_OR_REVOKE. Governability-aware discovery never upgrades UNKNOWN to MATCH; a service chain produces identity/authority/contract/capability/execution/proof/settlement proof chains; a subcontractor's authority cannot exceed its parent's. No economic object is authority: CONTRACT != AUTHORITY, REPUTATION != AUTHORITY, PAYMENT != AUTHORITY. CAIN is not a bank, custodian or regulator; settlement units are SYNTHETIC. 842/842 invariants hold; 3340/3340 economic/governance scenarios held; mutation 15/15; a 13-step exchange lifecycle passes; 15 forged objects rejected; 14 tests pass; the clean-room verifier returns INTACT (3601/3601 checks, no CAIN imports). | SIMULATED |
| C42-E35-GOVERNANCE-INTELLIGENCE: Evolution 35 (continuous governance intelligence) is a TESTED library placed deliberately outside the trusted authorization root: it observes with provenance, scores risk across dimensions without ever collapsing into one number, predicts with explicit confidence, assumptions, horizon and unknowns, calibrates by dimension, explores counterfactuals that are never facts, and recommends; a learned control is deployed only after a deterministic review and a canary, and the reviewed action still passes the kernel and E8. Learning never creates authority. 799/799 invariants hold; 3544/3544 scenarios held; mutation 15/15; a 23-step loop passes; 16 forged objects rejected; 12 tests pass; the clean-room verifier returns INTACT (3810/3810 checks, no CAIN imports). | SIMULATED |
| C42-E32-GOVERNED-LEARNING: Evolution 32 (governed autonomy learning fabric) is a TESTED library: a 17-step learning loop over real governed actions mines failures, compiles restrict-only candidate rules, sandboxes them in fresh worlds, scores them on a 15-dimension vector against a hidden set committed in advance, self-plays, diffs, canaries and promotes only through a signed gate with a registered human approval; no learning path can widen authority, and a deny-everything strawman is rejected. In a SIMULATED run, harm that got through fell from 41 to 3. 303/303 invariants hold; 1013/1013 scenarios held; mutation 12/12; 13 tests pass; the clean-room verifier returns INTACT (1420/1420 checks, no CAIN imports). | SIMULATED |
| C42-E31-PROOF-OF-GOVERNANCE: Evolution 31 (universal proof-of-governance fabric) is a TESTED library: every allowed action run through the proof kernel yields a signed GovernanceProof bound to 16 action fields and to four independently signed or hash-chained artifacts (E30 action receipt, E28 governance receipt, E25 execution receipt, E8 kernel evidence), every refusal yields a signed failure proof, the five enforcement layers are recomputed from the artifacts and never collapsed, proofs sit in an append-only RFC 6962 log, and a proof is evidence, never authority. 252/252 invariants hold; 1269/1269 scenarios held; mutation 12/12; conformance G8 on CAIN's internal profile; 15 tests pass; the TypeScript verifier returns INTACT and detects tampering; the clean-room verifier returns INTACT (1676/1676 checks, no CAIN imports) and rejects all 88 forged proofs. | SIMULATED |
| C42-E30-MACHINE-AUTONOMY: Evolution 30 (governed machine autonomy fabric) is a TESTED integration library: every consequential agent action is normalized into a 20-field universal machine action, checked against autonomy state, autonomy level, a signed budget ledger, containment, environment, perception, memory and intent, executed only through E28 -> E25 -> E8, and recorded in a signed, hash-chained universal action receipt whether it was allowed or refused; no agent can promote its own autonomy level, self-improvement passes a staged firewall with a human review and canary, and a coverage map reports UNCONTROLLED and UNKNOWN paths. 166/166 invariants hold; 889/889 scenarios held; mutation 11/11; a 28-step end-to-end run passes; 11 tests pass; the TypeScript verifier returns INTACT and detects tampering; the clean-room verifier returns INTACT (1187/1187 checks, no CAIN imports). | SIMULATED |
| C42-MCPGATE-SCHEMA-RESIDENCY: An authorization-aware MCPGate router library keeps tool schemas in PINNED, HOT, WARM, COLD or EVICTED context residency by a deterministic score (frequency, recency, task similarity, dependencies, tenant affinity) and never lets residency decide a call: every call's schema is the canonical, digest-checked one, the CAIN authorizer receives no residency information and its DENY is final even for a flooded HOT tool, an evicted tool is still callable only through full authorization, canonical schemas are never deleted, every decision is hash-chained evidence, and limits produce backpressure. Measured on one host: active context 6-31x smaller than exposing every schema (50-1,000 tools). It is wired into the MCPGate proxy (cain/mcp_proxy.py) behind CAIN_MCP_RESIDENCY: with residency on and off every tools/call decision is identical, and 20 of 20 bypass tests pass. | SIMULATED |
| C42-PUBLIC-PROOF-FABRIC: The CAIN-42 public proof fabric is published and verifiable by anyone: a build manifest and per-file artifact list of the running gateway (990 source files, 958 byte-identical to the commit, the other 32 named), a CycloneDX SBOM (177 installed distributions with content hashes) and a dependency-drift record, a deployment attestation (deployment id, configuration hash of non-secret switches, running code == artifact, hardware attestation NOT AVAILABLE), a test manifest from a real run with its JUnit XML, 76 public test vectors, a provenance graph, a failure ledger, and Byzantine and performance indexes, all signed by the evidence-root key; a clean-room verifier recomputes every value. | LIVE VERIFIED |
| C42-TEST-SUITE-RUN: A real run of the defined CAIN-42 suites (site, l5-governance, hypervisor, mcp-enforcement, byzantine, gateway): 1857 tests, 1842 passed, 0 failed, 0 errors, 7 skipped, 8 expected failures (documented known gaps). Each test is listed with its purpose, category, file hash and JUnit evidence. | IMPLEMENTED |
| C42-THIRD-PARTY-REVIEW: Independent third-party review or certification (SOC 2, ISO 27001, FedRAMP, ...). | NOT ESTABLISHED |
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem