CAIN-42 · Coming next
CAIN Autonomous DevOps
Let agents run deployments, with every change checked and reversible.
Last reviewed 2026-10-01
In development Product lines in development · Product line
Where it fits
Part of Coming next: Product lines in development. Tested code, not yet sold or hosted. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Evidence bundle
https://clawx.click/evidence/e37-autonomous-execution-mesh-2026-09-30/
Not available yet. Recorded status: PRODUCT SPECIFICATION (not deployed, no customers), from evolution E37. This means tested code exists; it is not hosted or sold. The evidence below is what was tested.
Evidence behind it
| Bundle | Claims | Invariants held |
|---|---|---|
| CAIN-42 Evolution 37 -- Autonomous Execution Mesh | 9 | 27 of 27 |
What E37 claims, and how far each claim goes
- C42-E37-MESH
TESTED: every governed execution runs the 12-stage chain IDENTITY -> ... -> REASSESSMENT over the real kernel, E25 sealed executor, E8 commit and E34 envelope, and yields a signed execution proof and receipt whose E8 commit matches the envelope - C42-E37-MIGRATION
TESTED: migration is a governed state transition: identity, authority, capability, policy token, destination, security, resources, carried state and epoch are all checked; risk, budget, revocations, transaction limits, evidence, reputation and incident state cannot be reset - C42-E37-CONTINUITY
TESTED: continuity is never assumed: a material change needs a new epoch, authorizations bound to old epochs are stale, continuity tokens cannot exceed existing authority - C42-E37-COVERAGE
TESTED: UNKNOWN, OBSERVED and MONITORED never become ENFORCED; every claim takes the weakest relevant boundary - C42-E37-ADMISSION
TESTED: runtime admission verifies a measured code digest and probes; a runtime that only claims compliance is not admitted; hardware attestation stays UNKNOWN on this host - C42-E37-BENCH
TESTED: 2720 of 2720 adversarial scenarios held across 31 categories; 1132 of 1132 invariants held; mutation 17 of 17 - C42-E37-CHAOS
TESTED: 16 of 16 injected fault classes contained with 0 false allows; self-test 14/14 - C42-E37-SCALE
SIMULATED: single-host in-process scale runs (identities/epochs/tokens up to 100,000 agents; 1,000,000 virtual fast-path executions) - C42-E37-ADAPTERS
ARCHITECTURE: 18 adapter protocols declared with security specifications; the governed-execution contract passes against a reference harness; live protocol integration not tested
Known limits of E37
- In-process TESTED library: the mesh, its nodes, regions and clouds are governance records in one process on one VPS; there is no multi-cloud or multi-node deployment of E37.
- Only this host is measured (environment passport); declared destinations are not measured.
- Hardware attestation is UNKNOWN: no TEE on this host; the admission attestation probe has nothing to call.
- Adapters were tested against a reference in-process harness; no live MCP/A2A/HTTP/gRPC server integration.
- Federated cloud targets (AWS/Azure/GCP/private/bare metal/edge/hybrid) are ARCHITECTURE only.
- The governance quorum is in-process (3f+1 keys, no network); it is not the networked PBFT cluster.
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Autonomy, control loops & recovery: 407 tested invariants — Agents acting on their own, and how CAIN keeps them in bounds and recovers.
- Transactions, markets & economics: 664 tested invariants — Agents that buy, sell, bid and pay, within limits.
Related
- CAIN Agent Builder — Build new agents with governance designed in from the start.
- CAIN Agent Conformance — Check an agent against a published conformance standard.
- CAIN Agent Evaluation — Deep evaluation of agents before they are trusted with real work.
- CAIN Agent Factory — Produce many governed agents from one approved template.
- CAIN Agent Hosting — Host your agents on CAIN, governed by default.
- CAIN Agent Lab — A safe lab to try agent ideas before they touch anything real.
- CAIN Agent Labor — Rules for agents doing paid work: who did what, and who gets credit.
- CAIN Agent Marketplace — Find and hire governed agents built by others.
- CAIN Agent Organization — Teams of agents with roles, a constitution and recorded decisions.
- CAIN Agent Passport — A signed passport that says who an agent is and what it may do.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem