Evidence library · family
Supply chain
38 tested rules in the 'supply_chain' family, 38 held.
Last reviewed 2026-10-01
38 of 38 held niche Evidence, receipts & proofs
What this family tests
Every rule the CAIN-42 test suites recorded under the family supply_chain, across 4 evidence bundles. Each rule links to its own page with the recorded result and an in-browser check of the file it came from.
| ID | Rule | Bundle | Result |
|---|---|---|---|
| I-SUPPLY-model | part model | E27 | held |
| I-SUPPLY-weights | part weights | E27 | held |
| I-SUPPLY-adapter | part adapter | E27 | held |
| I-SUPPLY-quantization | part quantization | E27 | held |
| I-SUPPLY-runtime | part runtime | E27 | held |
| I-SUPPLY-prompt | part prompt | E27 | held |
| I-SUPPLY-system_config | part system_config | E27 | held |
| I-SUPPLY-fine_tuning | part fine_tuning | E27 | held |
| I-SUPPLY-retrieval | part retrieval | E27 | held |
| I-SUPPLY-tools | part tools | E27 | held |
| E30-BOM-model | a changed or known-malicious 'model' is detected | E30 | held |
| E30-BOM-weights | a changed or known-malicious 'weights' is detected | E30 | held |
| E30-BOM-runtime | a changed or known-malicious 'runtime' is detected | E30 | held |
| E30-BOM-package | a changed or known-malicious 'package' is detected | E30 | held |
| E30-BOM-tool | a changed or known-malicious 'tool' is detected | E30 | held |
| E30-BOM-mcp_server | a changed or known-malicious 'mcp_server' is detected | E30 | held |
| E30-BOM-skill | a changed or known-malicious 'skill' is detected | E30 | held |
| E30-BOM-plugin | a changed or known-malicious 'plugin' is detected | E30 | held |
| E30-BOM-dataset | a changed or known-malicious 'dataset' is detected | E30 | held |
| E30-BOM-memory | a changed or known-malicious 'memory' is detected | E30 | held |
| E30-BOM-prompt | a changed or known-malicious 'prompt' is detected | E30 | held |
| E30-BOM-code | a changed or known-malicious 'code' is detected | E30 | held |
| E30-BOM-container | a changed or known-malicious 'container' is detected | E30 | held |
| E30-BOM-dependency | a changed or known-malicious 'dependency' is detected | E30 | held |
| E33-BOM-code | a compromised code is traced to operations | E33 | held |
| E33-BOM-package | a compromised package is traced to operations | E33 | held |
| E33-BOM-model | a compromised model is traced to operations | E33 | held |
| E33-BOM-dataset | a compromised dataset is traced to operations | E33 | held |
| E33-BOM-prompt_template | a compromised prompt_template is traced to operations | E33 | held |
| E33-BOM-tool | a compromised tool is traced to operations | E33 | held |
| E33-BOM-plugin | a compromised plugin is traced to operations | E33 | held |
| E33-BOM-connector | a compromised connector is traced to operations | E33 | held |
| E33-BOM-runtime | a compromised runtime is traced to operations | E33 | held |
| E33-BOM-container | a compromised container is traced to operations | E33 | held |
| E33-BOM-infrastructure | a compromised infrastructure is traced to operations | E33 | held |
| E33-BOM-policy | a compromised policy is traced to operations | E33 | held |
| E33-BOM-governance_module | a compromised governance_module is traced to operations | E33 | held |
| supply_chain | every 'supply chain' invariant in this bundle (13 of 13 held) | E39 | held |
Other families in this niche
domain · moat · packet · receipt · envelope · research · certificate · state_machine · agency_graph · envelope_binding · telemetry · integrity · graph · proof · radar · risk · event_kind · action_binding · proof_carrying_action · ip · failure_class · status · environment_query · attestation
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem