CAIN-42 evidence library
CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform
Evidence bundle for evolution E42: 8 claims, 438 of 438 invariants held, 1302 attack scenarios held.
Last reviewed 2026-10-01
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Product lines built here
- CAIN Conformance — Conformance testing for any system that claims to govern agents.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Edge — CAIN decisions on devices at the edge, close to where agents act.
PRODUCT SPECIFICATION (not deployed, no customers) - CAIN Enterprise — One package of CAIN for a whole organisation.
ARCHITECTURE / TESTED library (not deployed) - CAIN Evolution — Lets CAIN improve its own rules, only with signed approval.
ARCHITECTURE / TESTED library (not deployed) - CAIN Gateway — A packaged CAIN gateway for any network.
ARCHITECTURE / TESTED library (not deployed) - CAIN Passport — Passports that let agents carry trust from one system to another.
ARCHITECTURE / TESTED library (not deployed) - CAIN Research — Open research on governing autonomous AI.
ARCHITECTURE / TESTED library (not deployed) - CAIN Studio — The next generation of CAIN Studio.
ARCHITECTURE / TESTED library (not deployed) - CAIN Transactions — Governed transactions between agents.
ARCHITECTURE / TESTED library (not deployed) - CAIN Trust Network — A network of organisations that trust each other's agents.
TECHNICAL FOUNDATION (not a product, not deployed) - CAIN Verify — One-click verification of any CAIN evidence.
TECHNICAL FOUNDATION (not a product, not deployed) - ClawX — The next CLAWX: proof and onboarding for agent builders.
ARCHITECTURE / TESTED library (not deployed) - MCPGate — The next MCPGate: a packaged enforcement gate.
ARCHITECTURE / TESTED library (not deployed)
Claims (8)
| Claim | Level |
|---|---|
| C42-E42-PLATFORM: one canonical governance kernel routes every consequential action through a single authorization path (IDENTITY..E8_COMMIT) and returns exactly one decision; an UNKNOWN stage is never ALLOW | TESTED |
| C42-E42-ABI: one canonical governance ABI (Identity, Intent, Action, Capability, Policy, Authority, Risk, Evidence, Authorization, Execution, Outcome, Receipt, Incident, Evolution) is versioned, canonically serialized, hashed and signed, and fails closed on a bad version | TESTED |
| C42-E42-COVERAGE: the coverage compiler never upgrades a weaker class: an UNKNOWN, OBSERVED or MONITORED path can never be claimed as ENFORCED | TESTED |
| C42-E42-INTEGRATION: a machine-readable registry maps every prior evolution (E7-E41) to its module and bundle and reports honestly which are present | TESTED |
| C42-E42-BENCH: 1302 of 1302 platform scenarios across 16 categories held; 438 of 438 invariants; mutation 8 of 8 | TESTED |
| C42-E42-CLEANROOM: an independent verifier that imports none of CAIN re-derives the E42 invariants and rejects every crafted forgery | TESTED |
| C42-E42-TRUTH: a public truth engine scans public surfaces and flags unsupported claims (universal control, guaranteed safety, certified, customers, revenue) unless negated; it never auto-edits | TESTED |
| C42-E42-HONEST-SCOPE: E42 is an in-process TESTED integration library; no hosted platform, no external system integration, no customers or revenue is claimed | TESTED |
Invariants: 438 of 438 held
Rules the code must never break, each checked across many scenarios. See all 438 on one page.
| Niche | Held |
|---|---|
| Policy, law & governance | 123 of 123 |
| Benchmarks, coverage & performance | 96 of 96 |
| Evidence, receipts & proofs | 53 of 53 |
| Core guarantees | 40 of 40 |
| Supply chain, registry & lifecycle | 36 of 36 |
| Identity, authority & delegation | 24 of 24 |
| Prediction, world models & simulation | 23 of 23 |
| Tools, MCP, protocols & adapters | 19 of 19 |
| Autonomy, control loops & recovery | 15 of 15 |
| Transactions, markets & economics | 4 of 4 |
| Attacks, threats & containment | 2 of 2 |
| Memory, data & privacy | 2 of 2 |
| Trust & reputation | 1 of 1 |
Attacks tried
| Category | Held |
|---|---|
| abi | 162 of 162 |
| action | 214 of 214 |
| coverage | 44 of 44 |
| dedup | 10 of 10 |
| evolution | 28 of 28 |
| false_completion | 24 of 24 |
| graph | 54 of 54 |
| kernel | 132 of 132 |
| law | 320 of 320 |
| proof | 50 of 50 |
| receipt | 44 of 44 |
| registry | 24 of 24 |
| reject | 60 of 60 |
| scale | 30 of 30 |
| time_machine | 10 of 10 |
| truth | 96 of 96 |
Measured performance
| Mechanism | p50 ms | p95 ms | p99 ms |
|---|---|---|---|
| abi_wrap | 0.1694 | 4.477 | 4.477 |
| coverage | 0.0025 | 0.8209 | 0.8209 |
| kernel_authorize | 0.9514 | 13.3405 | 13.3405 |
| receipt | 0.0847 | 1.8004 | 1.8004 |
in-process; composition of existing modules; no external dependency
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Known limitations
- E42 is an in-process TESTED integration library. It wires existing modules into one canonical kernel, ABI, action, evidence and receipt path; it does not make external systems behave.
- The integration registry maps each evolution to its module and bundle and reports what is present; presence is not a claim that a layer is correct or hosted.
- There is no live ERP/CRM/cloud integration, no real money, no external organization and no customer.
- The canonical kernel composes the decisions that the existing layers produce; it does not itself host the deterministic E8 commit boundary or any enforcement boundary.
- The public truth engine flags unsupported claims for human review; it never auto-edits and does not guarantee that every surface is covered.
- Moat and product maps are technical foundations only; no market moat, customers, revenue or adoption is claimed.
- Mutation self-testing runs each mutant against the bench subset that exercises the mutated component.
- Scale rows reuse the E33 synthetic in-process benchmark; the platform adds a 200-authorization row.
- No third party has independently verified anything in this bundle.
The bundle's own README
CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform#
The final integration: one canonical kernel, ABI, action, evidence and receipt path unifying E7..E41. Verify with verify_e42.py.txt. Status: TESTED integration library, pre-production.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem