FIRME AI inventions behind CAIN-42
FIRME AI, an artificial intelligence company based in San Francisco, California, invented and built the mechanisms below. They are what make CAIN-42 a Byzantine Governed Autonomous Control Fabric: security for AI agents, with tamper-proof records backed by Byzantine consensus.
Patent-candidate inventions (22)
| # | Invention | What it does |
|---|---|---|
| 1 | Quorum-committed authorization snapshots | Four independent servers agree in advance on what an AI agent may do, so approvals arrive in under a millisecond and still carry the signatures of a Byzantine quorum. |
| 2 | Mission goal-attenuation lattice (E38) | Every sub-goal an AI agent creates must hold equal or less power than the goal above it; predicted rewards and model confidence can never add authority. |
| 3 | Continuously conditioned authorization | A permission carries its own conditions with it and stays valid only while those conditions keep holding, not just at the moment it was granted. |
| 4 | Dependency-driven authorization invalidation with blast radius | When something an approval relies on changes, every approval built on it is cancelled automatically, and the reach of the change is shown. |
| 5 | Authority non-transfer across governance domains (E37) | Evidence from another organization can inform a decision, but it can never become permission inside yours. |
| 6 | Failure-atomic governance with race-safe revocation | A revoked permission cannot slip through in the moment before a tool starts, and a failure never leaves a half-granted state. |
| 7 | Bounded assurance with continuous invalidation | Confidence is capped by its weakest input and drops automatically when the evidence behind it goes stale. |
| 8 | Comparative control-selection proof | The record shows which safety controls were chosen and which alternatives were rejected, so the choice itself can be audited. |
| 9 | Independence-aware Byzantine quorum | Votes from servers that share a weakness are counted as one, so a majority cannot hide a common failure. |
| 10 | Quorum-certified programmable governance (GOV-IR) | Governance rules written in a small canonical language are safety-checked by every server, approved by constitutional authorities and a Byzantine quorum, and replay byte-for-byte. |
| 11 | Quorum-authorized kernel execution | A Byzantine quorum authorizes one exact, scope-narrowed kernel program and workload, and the signed receipt commits to what the kernel actually observed. |
| 12 | Prediction-bounded authorization | A model's prediction is a signed hypothesis bound to a certified world state, and it can only make a decision stricter, never looser. |
| 13 | Authority Continuity Protocol | An action runs only after every server re-checks its authority at the same agreed position and the tool confirms its arguments are exactly the ones approved. |
| 14 | Uncertainty-contracting authority horizon | The more uncertain the world, the less an agent may do before it must be re-authorized; prediction errors can only tighten this, never loosen it. Live in the decision path: POST /fabric/try?scenario=horizon-exhausted. |
| 15 | Autonomy vector with certificates and leases | Autonomy is measured on 12 separate dimensions, each capped by policy and trust, and bound to one exact agent configuration by a signed, expiring certificate. |
| 16 | Self-evolution that cannot self-authorize | Any change the system proposes to itself must pass simulation, attack testing, proof and canary release; adaptation never becomes authority. |
| 17 | Mission-to-organization compiler | Turns a mission into a team of agents whose roles and authority are all derived from, and bounded by, that mission. |
| 18 | 4D reachability-bounded trajectory authorization | For robots, drones and vehicles: where a machine could go is never permission to go there, and any material change forces re-authorization. |
| 19 | Governance contract fabric | One signed, versioned contract binds who may act, with what capability, under which conditions and with what evidence, across every CAIN product, and anyone can verify it offline. |
| 20 | Continuous governance attestation | A verification that held yesterday is not trusted today: any change to what it depended on automatically demotes it. |
| 21 | Governance research fabric | Governance is attacked systematically with multi-step attack graphs and an independent oracle, and every failure found becomes a permanent regression test. |
| 22 | Liveness-bound signed public claims | Any public claim that the system is running is automatically withdrawn unless a fresh, signed proof shows the cluster actually committed work in the last two hours. |
Engineering innovations (46)
| # | Innovation | What it does |
|---|---|---|
| 23 | Continuous Autonomy Integrity Object (E35) | A signed, continuously refreshed statement of what an autonomous agent is running and whether that has changed. |
| 24 | Cryptographic Autonomy Integrity Root (E35) | One fingerprint that covers an agent's model, tools, runtime and policy together. |
| 25 | Continuous Integrity Proof Chain (E35) | A hash-linked history of an agent's integrity that can be checked step by step. |
| 26 | Byzantine Integrity Fork Detection (E35) | Detects when an agent presents different histories to different parties. |
| 27 | Integrity-Governed Autonomous Recovery (E35) | Recovery after a fault that never grants more authority than existed before it. |
| 28 | Authority-Non-Amplifying Collective Composition (E36) | A group of agents can never hold more power together than its members were given. |
| 29 | Collective Integrity Root (E36) | One verifiable fingerprint for the integrity of a whole group of agents. |
| 30 | Common-Dependency Independence Analysis (E36) | Finds hidden shared dependencies that make supposedly independent agents fail together. |
| 31 | Collective Revocation and Reconstitution (E36) | Removes a compromised member from a group and rebuilds the group's authority safely. |
| 32 | Cross-Domain Governance Negotiation (E37) | Two organizations agree on terms for their agents to work together without either giving up control. |
| 33 | Federated Governance Proof (E37) | A proof that a cross-organization action was authorized locally, bound to the local state at that moment. |
| 34 | Cross-Domain MCP Enforcement (E37) | Tool calls arriving from another organization are enforced at your own boundary. |
| 35 | CATCP protocol and conformance vectors | A draft wire protocol for agent trust and control objects, with test vectors for independent implementations. |
| 36 | Byzantine Mission Integrity (E38) | Long-running agent missions whose state and history are hash-chained, replayable and checked for drift. |
| 37 | Quorum-governed execution leases and reservations | Nothing executes without quorum-certified governance state, from proposal through lease, execution and verified commit. |
| 38 | Zone-of-Decision agent hypervisor | An agent never holds execution authority; its only two paths to an effect re-check authority on every use. |
| 39 | Governed stopping | Stop, wait and escalate decisions carry no authority and can only make an action more restrictive. |
| 40 | No-single-node authoritative state | No single server can manufacture authoritative state; only a Byzantine quorum can. |
| 41 | Proof-carrying machine interaction with anti-Sybil independence | A receiving machine verifies the sender's governance proof without trusting its code, and colluding sources count once. |
| 42 | Counterfactual control quorum | Alternative strategies are simulated and judged by independent evaluators before acting, and the rejected options are kept on record. |
| 43 | Taint-surviving intent provenance | A message only becomes an instruction once its source is verified, and untrusted origins stay marked through every transformation. |
| 44 | Governed capability supply chain | Discovering a tool, trusting it, granting it authority and authorizing a call are four separate, checked steps. |
| 45 | Decision-integrity governance | Reasoning may propose; evidence must support it before a decision can carry authority. |
| 46 | Governed scientific discovery | Hypotheses and experiments run by AI stay inside explicit authority. |
| 47 | Machine-native institutions | Organizations of agents with governed membership, missions and cross-institution coordination. |
| 48 | Continuous trajectory governance | Authorization covers an agent's whole evolving course of action, not one isolated call. |
| 49 | Governed learning loop | Learning from real governed actions never turns into permission. |
| 50 | 4D causal world intelligence | Cause-and-effect over space and time, used to govern decisions rather than to make them. |
| 51 | Spatial and physical trust path | Governs the path from what a physical system perceives to what it is allowed to do. |
| 52 | Governance compiler | Turns a written governance document into a typed, canonical program that enforcement points run exactly. |
| 53 | Mandatory governance packages | Compiled governance cannot be skipped at boundaries that declare it required. |
| 54 | Predictive contract forecasting | Before a use is authorized, forecasts what could happen next and how sure that forecast is. |
| 55 | Governance learning | Learns which attack would break governance next and proposes tighter rules, which must still be approved. |
| 56 | Differential governance assurance | Replays decisions under old and new rules to show exactly what a change would alter. |
| 57 | Sentinel autonomous containment | Watches trust signals continuously and contains a misbehaving agent automatically, with signed receipts. |
| 58 | Epistemic Byzantine swarm defense | Stops groups of agents from manufacturing false consensus about what is true. |
| 59 | Kernel self-defense | The trust kernel checks its own integrity and refuses to run in a tampered state. |
| 60 | DAG-assisted Byzantine consensus with causal evidence | Spreads data through a certified graph so consensus stays fast and every decision keeps its causal history. |
| 61 | Economic mandate fabric with continuous red team | Autonomous spending is allowed only under an explicit, scoped mandate, and the mandate rules are attacked continuously. |
| 62 | Action-bound approval cards | A human approval covers one exact action, never a whole conversation. |
| 63 | Channel-bound identity with verified linking | Who someone is on one messaging channel never carries over to another without verification. |
| 64 | Structural message injection firewall | Messages are screened by structure first, so instructions hidden in content do not become commands. |
| 65 | Failure-domain quorum-independence proof | Proves that no single provider, region or host failure can take out enough servers to break the quorum. |
| 66 | Software measurement of running replicas | Checks that each running consensus server is executing exactly the expected code. |
| 67 | Byzantine-member consensus fuzzer | Attacks the consensus engine with a malicious member that holds a real key, the strongest possible insider. |
| 68 | Trust debt ledger | Lost trust becomes a recorded debt that is repaid only through governed, evidenced recovery. |
CAIN products built on these inventions
| Product | What it does | Inventions it uses | Status |
|---|---|---|---|
| CAIN Studio | Hosted control plane: every consequential action an AI agent proposes is decided before it runs, with signed evidence. | Quorum-committed authorization snapshots; E38 mission goal-attenuation lattice (live); uncertainty-contracting authority horizon (live); liveness-bound signed public claims (live) | Live (hosted) |
| MCPGate | The enforcement boundary in front of MCP tools: only the exact approved call gets through. | Failure-atomic governance with race-safe revocation; Authority Continuity Protocol; mandatory governance packages; cross-domain MCP enforcement | Live (hosted) + self-hosted Helm package |
| CLAWX | The proof layer: every decision published with a signature and checkable in your browser; plus agent messaging and economic controls. | Liveness-bound signed public claims; proof-carrying machine interaction; economic mandate fabric; action-bound approval cards; channel-bound identity; structural message injection firewall | Live (proof portal) |
| CAIN-42 Byzantine consensus clusters | Two 4-server PBFT clusters across Atlanta, Los Angeles, Miami and San Jose that back every permit. | Quorum-committed authorization snapshots; independence-aware Byzantine quorum; DAG-assisted consensus with causal evidence; fault-domain quorum-independence proof; Byzantine-member consensus fuzzer | Live |
| Hosted labs and live demos | No-signup demos and labs where anyone can watch the inventions decide. | E38 mission integrity; E7 uncertainty horizon; E37 Byzantine federation | Live |
| cainstudio Python SDK | Add CAIN governance to an existing agent: guard a tool call, route MCP through the gate, verify evidence. | Uses the hosted decision pipeline and its evidence formats | Hosted wheel (PyPI listing pending) |
| Clean-room verifiers | Verifiers that import none of CAIN’s code, so anyone can check the evidence independently. | Quorum receipts; governance contract fabric verifier; GOV-IR proofs | Published |
The CAIN hosted service catalog (105 services, 104 listed live)
- ActionProof (2): action-firewall, actionproof (not deployed)
- Authorization (3): cainbudget, cainpay, human-in-loop
- Build & ship code (7): talos-coder, talos-evolve, taloscode-migrate, taloscode-review, talosdev-archdiff, talosdev-refactor, visual-ide
- Commerce & distribution (2): agent-marketplace, quorum-oaas
- Evidence (7): agent-debugger, attestation, cainwitness, content-provenance, decision-intelligence, multi-agent-failure-tracer, zkproofvault
- Execution Enforcement (2): swarm-orchestrator, talos-shield
- Governance (4): blizzard-governance, guardian-scorecard, lexisguardian, talosops-governance
- Identity (5): a2a-guard, agent-id, cainaccounts, taloscrypt-keymgmt, taloscrypt-pqc
- Industry applications (6): arbitrage, caingrid, cainloan, cainroute, talosfin-earningsai, talosfin-statarb
- Memory, retrieval & knowledge (5): knowledge-graph, memorymesh, nexusmind, talos-rag, talos-vectorsearch
- Model & ML infrastructure (8): edge-optimizer, model-compressor, omegarouter, sparselogic-compiler, synthetic-fine-tuner, talosai-quantize, training-sandbox, weight-alchemist
- Observability (3): latent-inspector, observability, talosops-selfheal
- Platform operations (2): experimentation-notebook, feedback-engine
- Policy (6): caingovern, compliance-engine, legal-auditor, quorum-i18n, talosdoc-contract, taloslegal-caselaw
- Reasoning, planning & orchestration (8): autonomous-task-engine, causal-intelligence, causal-network, counterfactual-intelligence, echoworkforce, mcts-engine, spatial-synthesizer, stcn
- Risk (10): bias-detector, caindrift, contamination-scanner, context-health, hallucination-firewall, memory-integrity, metacognitive-enhancer, sentinel, talosdata-quality, trust-state-engine
- Security (13): adversarial-fuzzer, pii-redactor, secops-patcher, shadow-agent-scanner, talos-redteam, taloscode-security, taloscrypt-audit, taloscrypt-mesh, taloscrypt-store, taloscrypt-vault, talosguard-intel, talosguard-logiq, talosguard-siem
- Unmapped (1): tee-verifier
- Verification (11): cainbench, cainschema, crucible, derivation-copilot, rag-verifier, talos-verify, taloslogic-proof, topological-data-analysis, trajectorygate, vericoding-gate, veritasengine
The CAIN products and services are how these inventions reach customers. Together with the inventions they make up FIRME AI, worth about $2.4 million (investor) to $3.5 million (strategic acquirer) by its own forensic valuation (internal estimate). Service status is read from the live catalog at cainstudio.online/catalog.
IP value: today and maximum defensible
| Invention | Estimated today | Maximum defensible | Reached only after |
|---|---|---|---|
| GOV-IR programmable governance | ~$22k | $120k | patent filed; running live in the hosted gateway |
| Quorum-authorized kernel execution | ~$22k | $110k | patent filed; running on a server with hardware attestation |
| Authority Continuity Protocol | ~$14k | $70k | patent filed; running on the live clusters |
| Prediction-bounded authorization | ~$12k | $60k | patent filed; connected to a real model in a pilot |
| 6 new engineering innovations (combined) | ~$20k | $80k | documented trade secrets; used in a paying deployment |
| Uncertainty-contracting authority horizon (live since 2026-10-06) | ~$30k | $80k | patent filed; used by a paying customer |
| Autonomy vector with certificates and leases | ~$10k | $60k | patent filed; used by a customer's agents |
| Self-evolution that cannot self-authorize | ~$10k | $60k | patent filed; running on the hosted platform |
| Mission-to-organization compiler | ~$8k | $50k | patent filed; used in a pilot |
| 4D reachability-bounded trajectory authorization | ~$10k | $70k | patent filed; connected to a real robot or drone pilot |
| 9 further engineering innovations (combined) | ~$7k | $30k | documented trade secrets; used in a paying deployment |
| Governance contract fabric | ~$15k | $80k | patent filed; used by a paying customer |
| Continuous governance attestation | ~$10k | $60k | patent filed; running on the hosted platform |
| Governance research fabric | ~$10k | $60k | patent filed; findings independently reproduced |
| 9 further engineering innovations (combined; Sentinel containment runs in production) | ~$20k | $70k | documented trade secrets; used in a paying deployment |
| Liveness-bound signed public claims (live in production; withdrew and restored the live-cluster claims on its own during the 2026-10-03–05 outage) | ~$20k | $50k | patent filed; adopted as a published practice by others |
| 8 further engineering innovations (combined) | ~$12k | $60k | documented trade secrets; used in a paying deployment |
| Whole FIRME AI IP portfolio | ~$490k | ~$1.7M | all patents filed, key inventions live, at least one paying customer |
Internal analytical estimates from FIRME AI’s own forensic valuation. They are not independently appraised, not a financing valuation, and not a guarantee. “Maximum defensible” is the most a buyer could reasonably pay after the listed steps happen; it is not the current value.
See them work. The E37 and E38 engines run live: /api/v1/hosted-lab/e37 and /api/v1/hosted-lab/e38. Signed evidence: E37 + E38 hosted lab · valuation summary.
Status, stated plainly. Each item is described by what it does, not how; implementation details are FIRME AI trade secrets. “Patent-candidate” is FIRME AI’s own classification for review by patent counsel: no patent application has been filed yet, and none has been granted. Same-project tests only; no third-party review. PRE-PRODUCTION.