CAIN-42 claim
C45-ZOD-LIVE
Agent Hypervisor / ZoD runtime: an agent acts only inside a ZoD whose authorization the live cluster cain-mr-01 committed with a quorum certificate the hypervisor checks itself; code ran under real confinement (bubblewrap namespaces + cgroup v2, no network); 10 attacks were refused, each a signed DENIED entry in a hash-chained log.
Last reviewed 2026-10-01
LIVE VERIFIED
The claim
Agent Hypervisor / ZoD runtime: an agent acts only inside a ZoD whose authorization the live cluster cain-mr-01 committed with a quorum certificate the hypervisor checks itself; code ran under real confinement (bubblewrap namespaces + cgroup v2, no network); 10 attacks were refused, each a signed DENIED entry in a hash-chained log.
Level LIVE VERIFIED is how far the evidence goes: TESTED means a test suite exercised it, LIVE means it was observed on the hosted system. Nothing is claimed beyond its level.
| category | AUTHORIZATION |
|---|---|
| status | VERIFIED |
| evidence level meaning | reproducible public verification |
| limits | the hypervisor ran as a library on the gateway host, operator-run, not as a deployed service in front of customer agents; the approval is the operator's; software measurement only (no TPM/TEE); no seccomp filter; egress is deny-all only (no allowlist) |
| verification method | python3 verify_cain45_zod.py . (see cain45-zod-live-2026-09-27/REPRODUCE.txt; expect 10 PASS and VERIFIED) |
| revalidate by | 2026-10-31T03:20:13Z |
| claim version | 1 |
Evidence files
- cain45-zod-live-2026-09-27/ZOD_RUN.json
- cain45-zod-live-2026-09-27/EVIDENCE_CHAIN.json
- cain45-zod-live-2026-09-27/qcs.json
- cain45-zod-live-2026-09-27/verify_cain45_zod.py.txt
Verify this signed claim in your browser
Checks the whole registry's Ed25519 signature against the published evidence-root key, then re-hashes this claim's artifact files. Same algorithm as the standalone verify_claims.py.
From CAIN-42 signed public claims registry.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem