CAIN-42 evidence library
CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency
Evidence bundle for evolution E38: 8 claims, 24 of 24 invariants held, 2141 attack scenarios held.
Last reviewed 2026-10-01
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Product lines built here
- CAIN Agent Passport — A signed passport that says who an agent is and what it may do.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Conformance — Conformance testing for any system that claims to govern agents.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Enterprise Verification — Independent checking of an enterprise's whole agent estate.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Federation — Separate CAIN deployments that trust each other's decisions.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Governance Audit — Audit an organisation's agent governance end to end.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Governance Certificates — Signed certificates that an agent passed defined checks.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Governance Evidence Cloud — Long-term storage for signed governance evidence.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Governance Gateway — A gateway that applies governance to any agent traffic.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Governance Receipts — A receipt for every governed action.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Governance SDK — Libraries for building governance into your own products.
TESTED library - CAIN Proof API — An API to fetch and check proofs.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Trust Network — A network of organisations that trust each other's agents.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Verify — One-click verification of any CAIN evidence.
TECHNICAL FOUNDATION (not a product, not deployed)
Claims (8)
| Claim | Level |
|---|---|
| C42-E38-ACTION-PROOF: every real governed action (kernel + E8 + E34 + E37) yields twelve signed layer proofs and one action proof binding identity, delegation, authority, policy, risk, evidence, authorization, the E8 commit, the enforcement boundary, execution, outcome and environment; a refused action yields none | TESTED |
| C42-E38-CLEANROOM: an independent verifier with no CAIN imports recomputes VALID / INVALID / INCOMPLETE / STALE / REVOKED / UNKNOWN for every published proof case and agrees with CAIN | REPRODUCIBLE |
| C42-E38-REVOCATION: revocation propagation is measured (p50/p95/p99) and a delayed domain's exposure window is counted, never hidden; no instantaneous global revocation is claimed | TESTED |
| C42-E38-TRANSLATION: translation to 8 formats declares every field PRESERVED / TRANSFORMED / DROPPED / UNKNOWN, never broadens scope and never upgrades a verification status | TESTED |
| C42-E38-FEDERATION: a second (reference) domain verifies proofs across a bridge and recognizes them as evidence only; issuer and audience confusion are refused; authority is never merged | TESTED |
| C42-E38-BENCH: 2141 of 2141 adversarial scenarios held; 1030 of 1030 invariants held; mutation 15 of 15; chaos: 0 of 19 faults made proof state more permissive | TESTED |
| C42-E38-CONFORMANCE: the 17-test conformance suite detects exactly the built-in defects of 11 reference (mock) implementations | TESTED |
| C42-E38-ZK: zero-knowledge proofs | NOT_VERIFIED |
Invariants: 24 of 24 held
Rules the code must never break, each checked across many scenarios. See all 24 on one page.
Attacks tried
| Category | Held |
|---|---|
| authority | 12 of 12 |
| certificate | 7 of 7 |
| completeness | 91 of 91 |
| composition | 152 of 152 |
| conformance | 187 of 187 |
| coverage | 52 of 52 |
| cross_domain | 176 of 176 |
| delegation | 1 of 1 |
| dependency | 19 of 19 |
| disclosure | 14 of 14 |
| economic | 4 of 4 |
| federation | 64 of 64 |
| freshness | 22 of 22 |
| governance | 22 of 22 |
| handshake | 63 of 63 |
| identity | 16 of 16 |
| law | 42 of 42 |
| manifest | 35 of 35 |
| negotiation | 53 of 53 |
| physical_hybrid | 36 of 36 |
| proof | 381 of 381 |
| protocol | 90 of 90 |
| receipt | 38 of 38 |
| recovery | 6 of 6 |
| revocation | 32 of 32 |
| runtime | 6 of 6 |
| secrecy | 31 of 31 |
| status | 226 of 226 |
| supply_chain | 5 of 5 |
| translation | 131 of 131 |
| transparency | 38 of 38 |
| trust_state | 66 of 66 |
| world | 23 of 23 |
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Known limitations
- In-process TESTED library on one host; the second trust domain and the eleven conformance counterparts are reference/mock implementations, not real vendors.
- CAIN-GIP v2 is a reference interchange layer carried in MCP/A2A/HTTP/... messages in-process; it is not an Internet, MCP or A2A standard and no live MCP/A2A server integration was tested.
- Zero-knowledge proofs are NOT IMPLEMENTED; selective disclosure is salted commitments + RFC 6962 inclusion.
- Hardware attestation is UNKNOWN (no TEE on this host); third-party verification is NOT AVAILABLE.
- Revocation propagation is measured in-process across subscriber domains; network propagation is NOT TESTED.
- Action proofs bind governance conditions and provenance; they do not show that an action was safe, correct or truthful.
- Claim graph: 10 of 64 public claims are fully linked; the rest are NOT FULLY VERIFIED, mostly because older bundles carry no source commitments or test results.
- Not hosted, no customers, not third-party reviewed.
The bundle's own README
CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency#
Here is the governance proof. Verify it yourself. Every governed action carries signed layer proofs and one action proof that another machine can check without trusting CAIN: who acted, what they were allowed to do, which policy applied, which boundary enforced it, whether E8 committed it, what executed, and whether the proof is still valid. A proof is never authority. Status: TESTED library, pre-production.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem