CAIN-42 CAIN Studio

FIRME AI inventions behind CAIN-42

FIRME AI, an artificial intelligence company based in San Francisco, California, invented and built the mechanisms below. They are what make CAIN-42 a Byzantine Governed Autonomous Control Fabric: security for AI agents, with tamper-proof records backed by Byzantine consensus.

Patent-candidate inventions (22)

#InventionWhat it does
1Quorum-committed authorization snapshotsFour independent servers agree in advance on what an AI agent may do, so approvals arrive in under a millisecond and still carry the signatures of a Byzantine quorum.
2Mission goal-attenuation lattice (E38)Every sub-goal an AI agent creates must hold equal or less power than the goal above it; predicted rewards and model confidence can never add authority.
3Continuously conditioned authorizationA permission carries its own conditions with it and stays valid only while those conditions keep holding, not just at the moment it was granted.
4Dependency-driven authorization invalidation with blast radiusWhen something an approval relies on changes, every approval built on it is cancelled automatically, and the reach of the change is shown.
5Authority non-transfer across governance domains (E37)Evidence from another organization can inform a decision, but it can never become permission inside yours.
6Failure-atomic governance with race-safe revocationA revoked permission cannot slip through in the moment before a tool starts, and a failure never leaves a half-granted state.
7Bounded assurance with continuous invalidationConfidence is capped by its weakest input and drops automatically when the evidence behind it goes stale.
8Comparative control-selection proofThe record shows which safety controls were chosen and which alternatives were rejected, so the choice itself can be audited.
9Independence-aware Byzantine quorumVotes from servers that share a weakness are counted as one, so a majority cannot hide a common failure.
10Quorum-certified programmable governance (GOV-IR)Governance rules written in a small canonical language are safety-checked by every server, approved by constitutional authorities and a Byzantine quorum, and replay byte-for-byte.
11Quorum-authorized kernel executionA Byzantine quorum authorizes one exact, scope-narrowed kernel program and workload, and the signed receipt commits to what the kernel actually observed.
12Prediction-bounded authorizationA model's prediction is a signed hypothesis bound to a certified world state, and it can only make a decision stricter, never looser.
13Authority Continuity ProtocolAn action runs only after every server re-checks its authority at the same agreed position and the tool confirms its arguments are exactly the ones approved.
14Uncertainty-contracting authority horizonThe more uncertain the world, the less an agent may do before it must be re-authorized; prediction errors can only tighten this, never loosen it. Live in the decision path: POST /fabric/try?scenario=horizon-exhausted.
15Autonomy vector with certificates and leasesAutonomy is measured on 12 separate dimensions, each capped by policy and trust, and bound to one exact agent configuration by a signed, expiring certificate.
16Self-evolution that cannot self-authorizeAny change the system proposes to itself must pass simulation, attack testing, proof and canary release; adaptation never becomes authority.
17Mission-to-organization compilerTurns a mission into a team of agents whose roles and authority are all derived from, and bounded by, that mission.
184D reachability-bounded trajectory authorizationFor robots, drones and vehicles: where a machine could go is never permission to go there, and any material change forces re-authorization.
19Governance contract fabricOne signed, versioned contract binds who may act, with what capability, under which conditions and with what evidence, across every CAIN product, and anyone can verify it offline.
20Continuous governance attestationA verification that held yesterday is not trusted today: any change to what it depended on automatically demotes it.
21Governance research fabricGovernance is attacked systematically with multi-step attack graphs and an independent oracle, and every failure found becomes a permanent regression test.
22Liveness-bound signed public claimsAny public claim that the system is running is automatically withdrawn unless a fresh, signed proof shows the cluster actually committed work in the last two hours.

Engineering innovations (46)

#InnovationWhat it does
23Continuous Autonomy Integrity Object (E35)A signed, continuously refreshed statement of what an autonomous agent is running and whether that has changed.
24Cryptographic Autonomy Integrity Root (E35)One fingerprint that covers an agent's model, tools, runtime and policy together.
25Continuous Integrity Proof Chain (E35)A hash-linked history of an agent's integrity that can be checked step by step.
26Byzantine Integrity Fork Detection (E35)Detects when an agent presents different histories to different parties.
27Integrity-Governed Autonomous Recovery (E35)Recovery after a fault that never grants more authority than existed before it.
28Authority-Non-Amplifying Collective Composition (E36)A group of agents can never hold more power together than its members were given.
29Collective Integrity Root (E36)One verifiable fingerprint for the integrity of a whole group of agents.
30Common-Dependency Independence Analysis (E36)Finds hidden shared dependencies that make supposedly independent agents fail together.
31Collective Revocation and Reconstitution (E36)Removes a compromised member from a group and rebuilds the group's authority safely.
32Cross-Domain Governance Negotiation (E37)Two organizations agree on terms for their agents to work together without either giving up control.
33Federated Governance Proof (E37)A proof that a cross-organization action was authorized locally, bound to the local state at that moment.
34Cross-Domain MCP Enforcement (E37)Tool calls arriving from another organization are enforced at your own boundary.
35CATCP protocol and conformance vectorsA draft wire protocol for agent trust and control objects, with test vectors for independent implementations.
36Byzantine Mission Integrity (E38)Long-running agent missions whose state and history are hash-chained, replayable and checked for drift.
37Quorum-governed execution leases and reservationsNothing executes without quorum-certified governance state, from proposal through lease, execution and verified commit.
38Zone-of-Decision agent hypervisorAn agent never holds execution authority; its only two paths to an effect re-check authority on every use.
39Governed stoppingStop, wait and escalate decisions carry no authority and can only make an action more restrictive.
40No-single-node authoritative stateNo single server can manufacture authoritative state; only a Byzantine quorum can.
41Proof-carrying machine interaction with anti-Sybil independenceA receiving machine verifies the sender's governance proof without trusting its code, and colluding sources count once.
42Counterfactual control quorumAlternative strategies are simulated and judged by independent evaluators before acting, and the rejected options are kept on record.
43Taint-surviving intent provenanceA message only becomes an instruction once its source is verified, and untrusted origins stay marked through every transformation.
44Governed capability supply chainDiscovering a tool, trusting it, granting it authority and authorizing a call are four separate, checked steps.
45Decision-integrity governanceReasoning may propose; evidence must support it before a decision can carry authority.
46Governed scientific discoveryHypotheses and experiments run by AI stay inside explicit authority.
47Machine-native institutionsOrganizations of agents with governed membership, missions and cross-institution coordination.
48Continuous trajectory governanceAuthorization covers an agent's whole evolving course of action, not one isolated call.
49Governed learning loopLearning from real governed actions never turns into permission.
504D causal world intelligenceCause-and-effect over space and time, used to govern decisions rather than to make them.
51Spatial and physical trust pathGoverns the path from what a physical system perceives to what it is allowed to do.
52Governance compilerTurns a written governance document into a typed, canonical program that enforcement points run exactly.
53Mandatory governance packagesCompiled governance cannot be skipped at boundaries that declare it required.
54Predictive contract forecastingBefore a use is authorized, forecasts what could happen next and how sure that forecast is.
55Governance learningLearns which attack would break governance next and proposes tighter rules, which must still be approved.
56Differential governance assuranceReplays decisions under old and new rules to show exactly what a change would alter.
57Sentinel autonomous containmentWatches trust signals continuously and contains a misbehaving agent automatically, with signed receipts.
58Epistemic Byzantine swarm defenseStops groups of agents from manufacturing false consensus about what is true.
59Kernel self-defenseThe trust kernel checks its own integrity and refuses to run in a tampered state.
60DAG-assisted Byzantine consensus with causal evidenceSpreads data through a certified graph so consensus stays fast and every decision keeps its causal history.
61Economic mandate fabric with continuous red teamAutonomous spending is allowed only under an explicit, scoped mandate, and the mandate rules are attacked continuously.
62Action-bound approval cardsA human approval covers one exact action, never a whole conversation.
63Channel-bound identity with verified linkingWho someone is on one messaging channel never carries over to another without verification.
64Structural message injection firewallMessages are screened by structure first, so instructions hidden in content do not become commands.
65Failure-domain quorum-independence proofProves that no single provider, region or host failure can take out enough servers to break the quorum.
66Software measurement of running replicasChecks that each running consensus server is executing exactly the expected code.
67Byzantine-member consensus fuzzerAttacks the consensus engine with a malicious member that holds a real key, the strongest possible insider.
68Trust debt ledgerLost trust becomes a recorded debt that is repaid only through governed, evidenced recovery.

CAIN products built on these inventions

ProductWhat it doesInventions it usesStatus
CAIN StudioHosted control plane: every consequential action an AI agent proposes is decided before it runs, with signed evidence.Quorum-committed authorization snapshots; E38 mission goal-attenuation lattice (live); uncertainty-contracting authority horizon (live); liveness-bound signed public claims (live)Live (hosted)
MCPGateThe enforcement boundary in front of MCP tools: only the exact approved call gets through.Failure-atomic governance with race-safe revocation; Authority Continuity Protocol; mandatory governance packages; cross-domain MCP enforcementLive (hosted) + self-hosted Helm package
CLAWXThe proof layer: every decision published with a signature and checkable in your browser; plus agent messaging and economic controls.Liveness-bound signed public claims; proof-carrying machine interaction; economic mandate fabric; action-bound approval cards; channel-bound identity; structural message injection firewallLive (proof portal)
CAIN-42 Byzantine consensus clustersTwo 4-server PBFT clusters across Atlanta, Los Angeles, Miami and San Jose that back every permit.Quorum-committed authorization snapshots; independence-aware Byzantine quorum; DAG-assisted consensus with causal evidence; fault-domain quorum-independence proof; Byzantine-member consensus fuzzerLive
Hosted labs and live demosNo-signup demos and labs where anyone can watch the inventions decide.E38 mission integrity; E7 uncertainty horizon; E37 Byzantine federationLive
cainstudio Python SDKAdd CAIN governance to an existing agent: guard a tool call, route MCP through the gate, verify evidence.Uses the hosted decision pipeline and its evidence formatsHosted wheel (PyPI listing pending)
Clean-room verifiersVerifiers that import none of CAIN’s code, so anyone can check the evidence independently.Quorum receipts; governance contract fabric verifier; GOV-IR proofsPublished

The CAIN hosted service catalog (105 services, 104 listed live)

The CAIN products and services are how these inventions reach customers. Together with the inventions they make up FIRME AI, worth about $2.4 million (investor) to $3.5 million (strategic acquirer) by its own forensic valuation (internal estimate). Service status is read from the live catalog at cainstudio.online/catalog.

IP value: today and maximum defensible

InventionEstimated todayMaximum defensibleReached only after
GOV-IR programmable governance~$22k$120kpatent filed; running live in the hosted gateway
Quorum-authorized kernel execution~$22k$110kpatent filed; running on a server with hardware attestation
Authority Continuity Protocol~$14k$70kpatent filed; running on the live clusters
Prediction-bounded authorization~$12k$60kpatent filed; connected to a real model in a pilot
6 new engineering innovations (combined)~$20k$80kdocumented trade secrets; used in a paying deployment
Uncertainty-contracting authority horizon (live since 2026-10-06)~$30k$80kpatent filed; used by a paying customer
Autonomy vector with certificates and leases~$10k$60kpatent filed; used by a customer's agents
Self-evolution that cannot self-authorize~$10k$60kpatent filed; running on the hosted platform
Mission-to-organization compiler~$8k$50kpatent filed; used in a pilot
4D reachability-bounded trajectory authorization~$10k$70kpatent filed; connected to a real robot or drone pilot
9 further engineering innovations (combined)~$7k$30kdocumented trade secrets; used in a paying deployment
Governance contract fabric~$15k$80kpatent filed; used by a paying customer
Continuous governance attestation~$10k$60kpatent filed; running on the hosted platform
Governance research fabric~$10k$60kpatent filed; findings independently reproduced
9 further engineering innovations (combined; Sentinel containment runs in production)~$20k$70kdocumented trade secrets; used in a paying deployment
Liveness-bound signed public claims (live in production; withdrew and restored the live-cluster claims on its own during the 2026-10-03–05 outage)~$20k$50kpatent filed; adopted as a published practice by others
8 further engineering innovations (combined)~$12k$60kdocumented trade secrets; used in a paying deployment
Whole FIRME AI IP portfolio~$490k~$1.7Mall patents filed, key inventions live, at least one paying customer

Internal analytical estimates from FIRME AI’s own forensic valuation. They are not independently appraised, not a financing valuation, and not a guarantee. “Maximum defensible” is the most a buyer could reasonably pay after the listed steps happen; it is not the current value.

See them work. The E37 and E38 engines run live: /api/v1/hosted-lab/e37 and /api/v1/hosted-lab/e38. Signed evidence: E37 + E38 hosted lab · valuation summary.

Status, stated plainly. Each item is described by what it does, not how; implementation details are FIRME AI trade secrets. “Patent-candidate” is FIRME AI’s own classification for review by patent counsel: no patent application has been filed yet, and none has been granted. Same-project tests only; no third-party review. PRE-PRODUCTION.