CAIN-42 CAIN Studio

CAIN-42 · Prove it to anyone

CAIN Compliance

Keeps a running check of your agents against the EU AI Act, NIST AI RMF and ISO 42001.

Last reviewed 2026-10-01

Live   Core platform · governance

What it is

Continuous compliance with EU AI Act, NIST AI RMF, ISO/IEC 42001, and custom frameworks.

Where it fits

Part of Prove it to anyone: Signed records your auditor, regulator or customer can check without trusting us. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.

Use it

Recorded status: PRODUCTION. "Live" on this page means its link answered when the catalog was last checked (2026-10-01T18:22 UTC).

Live now

Checked from your browser when this page opened, not from a cached list.

Fire a real decision

Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.

For AI engineers

Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.

Python (zero dependencies)

pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=...   # free key: https://cainstudio.online/signup

import cainstudio

@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
    ...  # runs only if CAIN allows this call, with these arguments

try:
    transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
    print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
    print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
    print("CAIN unreachable: not run")   # fail-closed

See a real decision with no account

cainstudio try          # live pipeline, stage by stage
cainstudio try --list   # the other attack scenarios

MCP clients (Claude Code, Cursor)

claude mcp add --transport http cain https://cainstudio.online/mcp

More: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key

Tested guarantees in this area

Every rule in these niches has its own page with its recorded result.

Related

Full documentation

The complete reference, also at /docs/conformance.

CAIN conformance#

cain test

Runs two suites: conformance (does the fabric behave the way the contract says?) and red team (attempt the attack; pass only if it was refused).

The suite can fail#

That is the requirement it was built against. A suite that cannot fail is marketing. On a fresh or partly-configured deployment cain test typically reports several failures, and those failures are real.

A skip is not a pass#

If a conformance check cannot run, it returns SKIP, and any skip downgrades the overall result to INCOMPLETE:

resultmeaning
PASSEDevery conformance check ran and passed
INCOMPLETEnothing failed, but something could not be verified
FAILEDat least one check failed

INCOMPLETE is not PASSED. Silently counting "could not test" as "fine" is exactly how a green suite comes to mean nothing.

**A deployment must not be described as CAIN-conformant unless cain test reports PASSED.**

What is checked#

Conformance

suitechecks
identitycredential resolves to a principal; an anonymous request resolves to none
authorizationa decision can be obtained; every stage reports a typed verdict; authorization is enforcing
policypolicy reports a version; a decision records the version that produced it
enforcementmode is reported; deployment is enforcing; no stage claims to enforce with nothing loaded
evidencedecision persisted with an id; retrievable; signed; signing deterministic
isolationan unknown decision id returns not-found, not forbidden; evidence listing is tenant-scoped
failureUNKNOWN/ERROR/REQUIRE_APPROVAL/DENY are never authorized; unrecognised verdicts become UNKNOWN; degraded allow is UNKNOWN under strict; unreachable is ERROR
mcpdeclared servers; path enforcement (SKIP from the client side)

Red team -- each one performs the attack:

Selecting suites#

cain test --suite redteam
cain test --suite isolation --verbose
cain test --json | jq '.conformance, .critical_failures'

Exit code 0 only when the result is PASSED.

Interpreting an injection failure#

If a payload is not flagged, the suite says the risk stage "ran and did not flag it -- treat the risk stage as unproven, not as a prompt-injection defence." That wording is deliberate. The blocklist behind that stage is populated by fuzzing campaigns against a deployment; an empty blocklist matches nothing, and cain doctor reports patterns_loaded alongside enforcing so the two are never confused.

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem