CAIN-42 claim
C42-E28-RECEIPTS
every governed action, allowed or refused, gets a signed hash-chained receipt; identity events go to an RFC 6962 transparency log
Last reviewed 2026-10-01
TESTED
The claim
every governed action, allowed or refused, gets a signed hash-chained receipt; identity events go to an RFC 6962 transparency log
Level TESTED is how far the evidence goes: TESTED means a test suite exercised it, LIVE means it was observed on the hosted system. Nothing is claimed beyond its level.
Evidence files
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Limitations of this bundle
- E28 is an in-process library. It is not wired into the hosted gateway, MCPGate or the PBFT clusters; nothing on the three public sites runs it live.
- The identity envelope is a CAIN experimental reference protocol, not a standard. STANDARDS maps it to external work; no external party has adopted or reviewed it.
- Zero-knowledge authorization proofs are NOT implemented. Selective disclosure uses salted hash commitments (the SD-JWT idea): undisclosed values are hidden, but nothing about them is proven.
- Hardware attestation is UNKNOWN everywhere. 'Attestation level 1' means CAIN compared self-reported measurements with registered values; it is not a measured boot or TEE quote.
- Fork and clone detection only sees what it is told. Without an exclusivity declaration and located, session-tagged observations the verdict is UNKNOWN.
- Cross-domain revocation does not propagate: if domain A revokes an identity, domain B's local identity made from it stays valid until B revokes it or its B-local lease/delegation expires.
- Key rotation bumps the identity version but does not re-key the underlying E25 instance, so a rotated identity cannot act until it is re-registered.
- Receipt-chain truncation (dropping the newest receipts) is only detectable against an anchored head (an AGGREGATE receipt or a transparency-log tree head the verifier already holds).
- Research radar, TypeScript SDK, OAuth integration, hosted/private deployment profiles and a live HTTP endpoint for E28 were not built in this evolution.
- Scale numbers are synthetic, in one process on a shared 3 GB VPS; 100k is registry+log+lineage only.
- Nothing here is externally reviewed, formally verified, certified or production-ready.
From CAIN-42 Evolution 28 -- Portable Machine Agency & Execution Identity.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem