CAIN-42 evidence library
CAIN-42 Evolution 31 -- Universal Proof-of-Governance Fabric
Evidence bundle for evolution E31: 7 claims, 252 of 252 invariants held.
Last reviewed 2026-10-01
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Claims (7)
| Claim | Level |
|---|---|
| C42-E31-PROOF: every allowed action run through the proof kernel yields a signed GovernanceProof bound to 16 action fields and to four independently signed or hash-chained artifacts (E30 UAR, E28 receipt, E25 receipt, E8 evidence entry); refusals yield signed failure proofs | TESTED |
| C42-E31-LAYERS: decision, authorization, enforcement, execution and outcome are verified separately from the artifacts; outcome stays UNKNOWN until a registered observer records the postcondition | TESTED |
| C42-E31-LOG: proofs are registered in an append-only RFC 6962 log with signed heads, inclusion and consistency proofs; revocation and supersession are log entries, never edits | TESTED |
| C42-E31-BENCH: 1269 of 1269 adversarial and conformance scenarios held; 252 of 252 invariants; mutation 12 of 12 | TESTED |
| C42-E31-CLEANROOM: a Python verifier with no CAIN imports and a TypeScript verifier re-check the published proofs; every entry in MALICIOUS_PROOFS.json is rejected | TESTED |
| C42-E31-CONFORMANCE: the reference agent reaches G8 on CAIN's internal G0-G8 profile (not an industry standard); coverage is reported per dimension and is not universal | TESTED |
| C42-E31-SCALE: synthetic in-process runs: 10 to 10,000 real agents, 1,000 and 10,000 real proofs, 100,000 proofs with real crypto over synthetic content, 1,000,000 log leaves hashing only | SIMULATED |
Invariants: 252 of 252 held
Rules the code must never break, each checked across many scenarios. See all 252 on one page.
| Niche | Held |
|---|---|
| Policy, law & governance | 65 of 65 |
| Evidence, receipts & proofs | 59 of 59 |
| Identity, authority & delegation | 52 of 52 |
| Tools, MCP, protocols & adapters | 24 of 24 |
| Transactions, markets & economics | 20 of 20 |
| Benchmarks, coverage & performance | 15 of 15 |
| Trust & reputation | 15 of 15 |
| Attacks, threats & containment | 2 of 2 |
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Known limitations
- An in-process TESTED library; not hosted; not wired into the gateway, MCPGate or the clusters.
- Witnesses and the dispute engine run in the same process as CAIN: diverse code and separate keys, not separate organizations. No third party has verified any proof.
- CAIN-GIP carriers are in-process reference adapters; no protocol has a network wire implementation. Agent runtimes, model runtimes and workflow engines have no carrier (NOT IMPLEMENTED).
- Trust anchors are published in the same bundle as the proofs: a verifier checks internal consistency against them, not that they belong to a real operator.
- Postconditions are observations by a registered observer key; they say nothing about physical truth.
- World-state version and trajectory are recorded as UNKNOWN: E31 does not bind a world model.
- No trusted time source: validity windows use the issuer's clock; partition behaviour is not addressed.
- Hardware attestation UNKNOWN; zero-knowledge proofs NOT IMPLEMENTED; no external review.
- Scale rows are synthetic and in-process; the 100,000-proof row uses real crypto over synthetic content and the 1,000,000 row is hashing only.
- cain-json-v1 canonicalization is not RFC 8785 JCS.
The bundle's own README
CAIN-42 Evolution 31 -- Universal Proof-of-Governance Fabric#
Every allowed action run through the proof kernel yields a signed GovernanceProof bound to the exact action and to four artifacts that already exist and are independently signed or hash-chained (E30 action receipt, E28 governance receipt, E25 execution receipt, E8 kernel evidence). Refusals yield signed failure proofs. A proof is evidence, never authority. Verify with verify_e31.py.txt or the TypeScript SDK (see REPRODUCTION.md). Status: TESTED, pre-production.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem