CAIN-42 evidence library
CAIN-42 Evolution 39 -- Governed Agent Factory
Evidence bundle for evolution E39: 5 claims, 27 of 27 invariants held, 3441 attack scenarios held.
Last reviewed 2026-10-01
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Product lines built here
- CAIN Agent Builder — Build new agents with governance designed in from the start.
TECHNICAL FOUNDATION (not deployed) - CAIN Agent Conformance — Check an agent against a published conformance standard.
TECHNICAL FOUNDATION (not deployed) - CAIN Agent Evaluation — Deep evaluation of agents before they are trusted with real work.
TECHNICAL FOUNDATION (not deployed) - CAIN Agent Factory — Produce many governed agents from one approved template.
TECHNICAL FOUNDATION (not deployed) - CAIN Agent Hosting — Host your agents on CAIN, governed by default.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Agent Marketplace — Find and hire governed agents built by others.
TECHNICAL FOUNDATION (not deployed) - CAIN Agent Organization — Teams of agents with roles, a constitution and recorded decisions.
TECHNICAL FOUNDATION (not deployed) - CAIN Agent Passport — A signed passport that says who an agent is and what it may do.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Agent Red Team — Agents that attack your agents, so you find weaknesses first.
TECHNICAL FOUNDATION (not deployed) - CAIN Enterprise Agent Factory — Agent factory with company approvals built in.
TECHNICAL FOUNDATION (not deployed) - CAIN Governance Proof — Proof that governance was applied, not just configured.
TECHNICAL FOUNDATION (not deployed) - CAIN Mission Compiler — Turn a goal into a checked plan an agent must follow.
TECHNICAL FOUNDATION (not deployed) - CAIN Mission Digital Twin — Rehearse a mission in simulation before agents do it for real.
TECHNICAL FOUNDATION (not deployed)
Claims (5)
| Claim | Level |
|---|---|
| C42-E39-PIPELINE: a mission compiles into a bounded specification, a minimal organization and a gated workflow; real governed agents are provisioned (authority <= mission envelope <= sponsor), their consequential tasks run through the kernel and E8 with E38 action proofs, and a retired agent cannot act | TESTED |
| C42-E39-NO-SELF-CERTIFICATION: evaluation is independent (self-certification refused), promotion is decided by CAIN on a registered passed evaluation plus proof, policy, risk, envelope and lifecycle gates; the factory cannot certify its own output | TESTED |
| C42-E39-BENCH: 3441 of 3441 adversarial scenarios held; 1041 of 1041 invariants; mutation 16 of 16; chaos 15 of 15 faults kept authority bounded | TESTED |
| C42-E39-CLEANROOM: an independent verifier with no CAIN imports re-derives minimum authority, organization delegation, workflow gating, evaluation and promotion evidence, and the factory proof from the published material | REPRODUCIBLE |
| C42-E39-SCALE: in-process scale runs (missions, agent records, simulated decisions) | SIMULATED |
Invariants: 27 of 27 held
Rules the code must never break, each checked across many scenarios. See all 27 on one page.
| Niche | Held |
|---|---|
| Supply chain, registry & lifecycle | 8 of 8 |
| Autonomy, control loops & recovery | 6 of 6 |
| Core guarantees | 4 of 4 |
| Evidence, receipts & proofs | 3 of 3 |
| Attacks, threats & containment | 2 of 2 |
| Policy, law & governance | 1 of 1 |
| Memory, data & privacy | 1 of 1 |
| Identity, authority & delegation | 1 of 1 |
| Tools, MCP, protocols & adapters | 1 of 1 |
Attacks tried
| Category | Held |
|---|---|
| architecture | 433 of 433 |
| canary | 61 of 61 |
| composition | 76 of 76 |
| conformance | 21 of 21 |
| continuity | 10 of 10 |
| economic | 9 of 9 |
| evaluation | 88 of 88 |
| evolution | 97 of 97 |
| factory_proof | 71 of 71 |
| health | 30 of 30 |
| interrupt | 36 of 36 |
| law | 40 of 40 |
| lifecycle | 221 of 221 |
| memory | 18 of 18 |
| mission | 366 of 366 |
| organization | 132 of 132 |
| pipeline | 300 of 300 |
| population | 19 of 19 |
| promotion | 13 of 13 |
| provenance | 2 of 2 |
| red_team | 504 of 504 |
| replacement | 13 of 13 |
| replanning | 120 of 120 |
| retirement | 1 of 1 |
| rollback | 130 of 130 |
| routing | 150 of 150 |
| search | 91 of 91 |
| spawn | 267 of 267 |
| supply_chain | 52 of 52 |
| template | 3 of 3 |
| twin | 14 of 14 |
| workflow | 32 of 32 |
| world | 21 of 21 |
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Known limitations
- In-process TESTED library. The world run provisions a handful of real governed agents in one process; the scale runs create blueprints and lifecycle records, not onboarded identities.
- The mission compiler is deterministic keyword/structure analysis, not an LLM; it escalates what it cannot parse rather than guessing.
- Model routing works over registry entries, not live inference endpoints.
- Digital twins are SIMULATED and never real-world validation; 1M generated actions are SIMULATED decisions; 10M is PROJECTED.
- The factory API routes are specified and routed in-process only; nothing is hosted.
- Conformance counterparts are reference factories with one deliberate defect each (mocks).
- Hardware attestation UNKNOWN; not third-party reviewed; no customers.
The bundle's own README
CAIN-42 Evolution 39 -- Governed Agent Factory#
A human defines the mission; CAIN compiles the governance; the factory designs the machine organization; agents propose; independent evaluators test; verifiers check; CAIN decides; E8 commits; E38 proves. No machine turns its own proposal into authority. Status: TESTED library, pre-production.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem