CAIN-42 evidence library
CAIN-42 Evolution 37 -- Autonomous Execution Mesh
Evidence bundle for evolution E37: 9 claims, 27 of 27 invariants held, 2720 attack scenarios held.
Last reviewed 2026-10-01
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Product lines built here
- CAIN Agent Hosting — Host your agents on CAIN, governed by default.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Agent Runtime — A runtime where every agent action passes through CAIN.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Autonomous DevOps — Let agents run deployments, with every change checked and reversible.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Compute Governance — Limits on how much compute an agent may use, and for what.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Edge — CAIN decisions on devices at the edge, close to where agents act.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Execution Conformance — Proves an action ran exactly the way it was approved.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Execution Mesh — A network of governed places where agent actions run.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Execution Observatory — One view of every agent action across many systems.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Execution Proof — Proof of what an action actually did, not just what was asked.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Governance BOM — A bill of materials listing every model, tool and rule an agent depends on.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Governance Sidecar — A sidecar container that governs an agent without code changes.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Mobility — Governance for agents that drive, fly or move things.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Recovery — Undo and recover safely after an agent mistake.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Runtime Passport — A passport issued at runtime for each agent session.
PRODUCT SPECIFICATION (not deployed, no customers)
Claims (9)
| Claim | Level |
|---|---|
| C42-E37-MESH: every governed execution runs the 12-stage chain IDENTITY -> ... -> REASSESSMENT over the real kernel, E25 sealed executor, E8 commit and E34 envelope, and yields a signed execution proof and receipt whose E8 commit matches the envelope | TESTED |
| C42-E37-MIGRATION: migration is a governed state transition: identity, authority, capability, policy token, destination, security, resources, carried state and epoch are all checked; risk, budget, revocations, transaction limits, evidence, reputation and incident state cannot be reset | TESTED |
| C42-E37-CONTINUITY: continuity is never assumed: a material change needs a new epoch, authorizations bound to old epochs are stale, continuity tokens cannot exceed existing authority | TESTED |
| C42-E37-COVERAGE: UNKNOWN, OBSERVED and MONITORED never become ENFORCED; every claim takes the weakest relevant boundary | TESTED |
| C42-E37-ADMISSION: runtime admission verifies a measured code digest and probes; a runtime that only claims compliance is not admitted; hardware attestation stays UNKNOWN on this host | TESTED |
| C42-E37-BENCH: 2720 of 2720 adversarial scenarios held across 31 categories; 1132 of 1132 invariants held; mutation 17 of 17 | TESTED |
| C42-E37-CHAOS: 16 of 16 injected fault classes contained with 0 false allows; self-test 14/14 | TESTED |
| C42-E37-SCALE: single-host in-process scale runs (identities/epochs/tokens up to 100,000 agents; 1,000,000 virtual fast-path executions) | SIMULATED |
| C42-E37-ADAPTERS: 18 adapter protocols declared with security specifications; the governed-execution contract passes against a reference harness; live protocol integration not tested | ARCHITECTURE |
Invariants: 27 of 27 held
Rules the code must never break, each checked across many scenarios. See all 27 on one page.
Attacks tried
| Category | Held |
|---|---|
| adapter | 151 of 151 |
| anomaly | 37 of 37 |
| certificate | 192 of 192 |
| clock | 28 of 28 |
| computer_use | 274 of 274 |
| conflict | 141 of 141 |
| continuity | 110 of 110 |
| corpus | 4 of 4 |
| coverage | 102 of 102 |
| credential | 33 of 33 |
| data_movement | 7 of 7 |
| drift | 105 of 105 |
| economic | 65 of 65 |
| edge_partition | 46 of 46 |
| gap | 5 of 5 |
| law | 50 of 50 |
| migration | 332 of 332 |
| perimeter | 100 of 100 |
| plan | 21 of 21 |
| policy_compiler | 51 of 51 |
| proof_replay | 37 of 37 |
| quorum | 35 of 35 |
| recovery_failover | 38 of 38 |
| residency | 92 of 92 |
| scheduler | 27 of 27 |
| software | 165 of 165 |
| spawn | 101 of 101 |
| substitution | 280 of 280 |
| supply_chain | 46 of 46 |
| topology | 10 of 10 |
| world | 35 of 35 |
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Known limitations
- In-process TESTED library: the mesh, its nodes, regions and clouds are governance records in one process on one VPS; there is no multi-cloud or multi-node deployment of E37.
- Only this host is measured (environment passport); declared destinations are not measured.
- Hardware attestation is UNKNOWN: no TEE on this host; the admission attestation probe has nothing to call.
- Adapters were tested against a reference in-process harness; no live MCP/A2A/HTTP/gRPC server integration.
- Federated cloud targets (AWS/Azure/GCP/private/bare metal/edge/hybrid) are ARCHITECTURE only.
- The governance quorum is in-process (3f+1 keys, no network); it is not the networked PBFT cluster.
- Event-log tail truncation is detectable only against a signed checkpoint.
- Executions run on the E33 reference executors; their effects are in-process, not in an external system.
- Scale numbers are single-host, in-process; 1M virtual executions exercise the fence+fingerprint fast path only (SIMULATION).
- Competitor capabilities were not assessed; research radar items are unimplemented proposals.
- Not hosted, no customers, not third-party reviewed.
The bundle's own README
CAIN-42 Evolution 37 -- Autonomous Execution Mesh#
The machine may move; the governance must not disappear. E37 makes every move of an execution (node, runtime, model, region, container, credential) a governed state transition: identity, authority, capability, policy, destination, security, resources and carried state (risk, budget, revocations, limits, evidence, reputation, incidents) are re-checked, and authority never moves unchecked. Verify with verify_e37.py.txt (see REPRODUCTION.md). Status: TESTED library, pre-production, in-process on one host.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem