CAIN-42 evidence library
CAIN-42 External Review Core Bundle (v2)
Evidence bundle: 0 claims, 0 of 0 invariants held.
Last reviewed 2026-10-09
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
The bundle's own README
CAIN-42 External Review Core Bundle (v2)#
Package cain42-review-core · version 2026.10.09 · published 2026-10-09T16:42:06Z Source commit 4b16f6b0cd73000afb7088ac0b7d17436cffa1c3 · release 4.0.0.
One complete, small bundle. Read it top to bottom. It separates seven categories and never treats them as equivalent:
1. Publisher authentication -> PUBLISHER_ATTESTATION.json, PUBLISHER_KEY.json 2. Artifact integrity -> MANIFEST.json + SHA256SUMS 3. Report consistency -> TEST_RECONCILIATION.md, EVIDENCE_CATEGORIES.json 4. Recomputed artifact semantics -> verifier source + verifier output 5. Re-executed implementation tests-> TEST_RECONCILIATION.md (SOURCE REQUIRED) 6. Live deployment observations -> STATUS.json 7. Independent reproduction -> NOT ESTABLISHED (none exists)
Files#
- PUBLISHER_ATTESTATION.json / PUBLISHER_KEY.json — who signed this bundle (self-attested key).
- MANIFEST.json / SHA256SUMS — every file and its hash.
- QUORUM_CERTIFICATE.json — one authorization certificate with its COMMIT_QC/PREPARE_QC.
- REPLICA_KEYS.json / MEMBERSHIP.json — trusted membership and public keys.
- CERTIFICATE_SCHEMA.json / CANONICALIZATION.md — what is signed and how.
- NEGATIVE_FIXTURES.md — the rejections the verifier must produce.
- verify_pbft_qc_bundle.py — standalone, zero-CAIN-import certificate verifier.
- PBFT_QC_BUNDLE.json — the full run the verifier consumes (QUORUM_CERTIFICATE.json is a single-certificate excerpt).
- TEST_RECONCILIATION.md — the 1,963/1,978 figure and all remaining outcomes.
- FORMAL_SUMMARY.md — the 7.3M-state result, per run, with limits.
- ENFORCEMENT_BOUNDARY.md — what the boundary does and does not cover.
- SOAK_VERDICT.json — current soak verdict (NOT_ESTABLISHED while running).
- E42_VERIFIER_V2.py + E42_VERIFIER_REPORT.json + E42_VERIFIER_ASSURANCE.json — corrected E42 verifier and its self-attacks.
- EVIDENCE_CATEGORIES.json — separate totals; not one aggregate "verified" count.
- KNOWN_LIMITATIONS.md — what none of this establishes.
IP / disclosure#
Verification artefacts only. Implementation source, private keys, tenant data, host IPs and overlay addresses are withheld. You can reproduce the verification of this evidence; you cannot rebuild CAIN from it.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem