CAIN-42 CAIN Studio

CAIN-42 evidence library

CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency

Evidence bundle for evolution E38: 8 claims, 24 of 24 invariants held, 2141 attack scenarios held.

Last reviewed 2026-10-01

Browse the raw bundle · How to reproduce it · SHA-256 manifest

Product lines built here

Claims (8)

ClaimLevel
C42-E38-ACTION-PROOF: every real governed action (kernel + E8 + E34 + E37) yields twelve signed layer proofs and one action proof binding identity, delegation, authority, policy, risk, evidence, authorization, the E8 commit, the enforcement boundary, execution, outcome and environment; a refused action yields noneTESTED
C42-E38-CLEANROOM: an independent verifier with no CAIN imports recomputes VALID / INVALID / INCOMPLETE / STALE / REVOKED / UNKNOWN for every published proof case and agrees with CAINREPRODUCIBLE
C42-E38-REVOCATION: revocation propagation is measured (p50/p95/p99) and a delayed domain's exposure window is counted, never hidden; no instantaneous global revocation is claimedTESTED
C42-E38-TRANSLATION: translation to 8 formats declares every field PRESERVED / TRANSFORMED / DROPPED / UNKNOWN, never broadens scope and never upgrades a verification statusTESTED
C42-E38-FEDERATION: a second (reference) domain verifies proofs across a bridge and recognizes them as evidence only; issuer and audience confusion are refused; authority is never mergedTESTED
C42-E38-BENCH: 2141 of 2141 adversarial scenarios held; 1030 of 1030 invariants held; mutation 15 of 15; chaos: 0 of 19 faults made proof state more permissiveTESTED
C42-E38-CONFORMANCE: the 17-test conformance suite detects exactly the built-in defects of 11 reference (mock) implementationsTESTED
C42-E38-ZK: zero-knowledge proofsNOT_VERIFIED

Invariants: 24 of 24 held

Rules the code must never break, each checked across many scenarios. See all 24 on one page.

NicheHeld
Evidence, receipts & proofs7 of 7
Core guarantees4 of 4
Policy, law & governance2 of 2
Identity, authority & delegation2 of 2
Tools, MCP, protocols & adapters2 of 2
Benchmarks, coverage & performance1 of 1
Supply chain, registry & lifecycle1 of 1
Attacks, threats & containment1 of 1
Consensus & distributed systems1 of 1
Transactions, markets & economics1 of 1
Memory, data & privacy1 of 1
Trust & reputation1 of 1

Attacks tried

CategoryHeld
authority12 of 12
certificate7 of 7
completeness91 of 91
composition152 of 152
conformance187 of 187
coverage52 of 52
cross_domain176 of 176
delegation1 of 1
dependency19 of 19
disclosure14 of 14
economic4 of 4
federation64 of 64
freshness22 of 22
governance22 of 22
handshake63 of 63
identity16 of 16
law42 of 42
manifest35 of 35
negotiation53 of 53
physical_hybrid36 of 36
proof381 of 381
protocol90 of 90
receipt38 of 38
recovery6 of 6
revocation32 of 32
runtime6 of 6
secrecy31 of 31
status226 of 226
supply_chain5 of 5
translation131 of 131
transparency38 of 38
trust_state66 of 66
world23 of 23

Verify it in your browser

Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).

Known limitations

The bundle's own README

CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency#

Here is the governance proof. Verify it yourself. Every governed action carries signed layer proofs and one action proof that another machine can check without trusting CAIN: who acted, what they were allowed to do, which policy applied, which boundary enforced it, whether E8 committed it, what executed, and whether the proof is still valid. A proof is never authority. Status: TESTED library, pre-production.

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem