CAIN-42 invariant · E26
I-REASSESS-security_event: trigger security_event
Held · CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric
Last reviewed 2026-10-01
held niche Core guarantees · family reassessment
What this rule means
CAIN-42 must always satisfy: trigger security_event. It is one of 532 invariants checked for CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric. An invariant is a rule the system may never break, whatever an agent or attacker does; the test suite tries to break it across many scenarios and records the result.
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Check it yourself
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Scope: {"limitation": "In-process trust layer over the E25 fabric. No third-party agent, MCP server or A2A peer has consumed a CAIN trust object.", "status": "SCOPE"}
Related rules
- I-HW-TPM-unknown: TPM without verifier is UNKNOWN
- I-HW-TEE-unknown: TEE without verifier is UNKNOWN
- I-HW-CONFIDENTIAL_VM-unknown: CONFIDENTIAL_VM without verifier is UNKNOWN
- I-HW-PLATFORM-unknown: PLATFORM without verifier is UNKNOWN
- I-HW-GPU-unknown: GPU without verifier is UNKNOWN
- I-HW-DPU-unknown: DPU without verifier is UNKNOWN
- I-HW-SMARTNIC-unknown: SMARTNIC without verifier is UNKNOWN
- I-HW-CLOUD_PROVIDER-unknown: CLOUD_PROVIDER without verifier is UNKNOWN
← I-REASSESS-environment_change · all 532 · I-REASSESS-credential_compromise →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem