CAIN-42 · Coming next
CAIN Conformance
Conformance testing for any system that claims to govern agents.
Last reviewed 2026-10-01
In development Product lines in development · Product line
Where it fits
Part of Coming next: Product lines in development. Tested code, not yet sold or hosted. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Evidence bundle
https://clawx.click/evidence/e38-proof-carrying-machine-agency-2026-09-30/
Not available yet. Recorded status: TECHNICAL FOUNDATION (not a product, not deployed), from evolution E38, E42. This means tested code exists; it is not hosted or sold. The evidence below is what was tested.
Evidence behind it
| Bundle | Claims | Invariants held |
|---|---|---|
| CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency | 8 | 24 of 24 |
| CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform | 8 | 438 of 438 |
What E38 claims, and how far each claim goes
- C42-E38-ACTION-PROOF
TESTED: every real governed action (kernel + E8 + E34 + E37) yields twelve signed layer proofs and one action proof binding identity, delegation, authority, policy, risk, evidence, authorization, the E8 commit, the enforcement boundary, execution, outcome and environment; a refused action yields none - C42-E38-CLEANROOM
REPRODUCIBLE: an independent verifier with no CAIN imports recomputes VALID / INVALID / INCOMPLETE / STALE / REVOKED / UNKNOWN for every published proof case and agrees with CAIN - C42-E38-REVOCATION
TESTED: revocation propagation is measured (p50/p95/p99) and a delayed domain's exposure window is counted, never hidden; no instantaneous global revocation is claimed - C42-E38-TRANSLATION
TESTED: translation to 8 formats declares every field PRESERVED / TRANSFORMED / DROPPED / UNKNOWN, never broadens scope and never upgrades a verification status - C42-E38-FEDERATION
TESTED: a second (reference) domain verifies proofs across a bridge and recognizes them as evidence only; issuer and audience confusion are refused; authority is never merged - C42-E38-BENCH
TESTED: 2141 of 2141 adversarial scenarios held; 1030 of 1030 invariants held; mutation 15 of 15; chaos: 0 of 19 faults made proof state more permissive - C42-E38-CONFORMANCE
TESTED: the 17-test conformance suite detects exactly the built-in defects of 11 reference (mock) implementations - C42-E38-ZK
NOT_VERIFIED: zero-knowledge proofs
Known limits of E38
- In-process TESTED library on one host; the second trust domain and the eleven conformance counterparts are reference/mock implementations, not real vendors.
- CAIN-GIP v2 is a reference interchange layer carried in MCP/A2A/HTTP/... messages in-process; it is not an Internet, MCP or A2A standard and no live MCP/A2A server integration was tested.
- Zero-knowledge proofs are NOT IMPLEMENTED; selective disclosure is salted commitments + RFC 6962 inclusion.
- Hardware attestation is UNKNOWN (no TEE on this host); third-party verification is NOT AVAILABLE.
- Revocation propagation is measured in-process across subscriber domains; network propagation is NOT TESTED.
- Action proofs bind governance conditions and provenance; they do not show that an action was safe, correct or truthful.
What E42 claims, and how far each claim goes
- C42-E42-PLATFORM
TESTED: one canonical governance kernel routes every consequential action through a single authorization path (IDENTITY..E8_COMMIT) and returns exactly one decision; an UNKNOWN stage is never ALLOW - C42-E42-ABI
TESTED: one canonical governance ABI (Identity, Intent, Action, Capability, Policy, Authority, Risk, Evidence, Authorization, Execution, Outcome, Receipt, Incident, Evolution) is versioned, canonically serialized, hashed and signed, and fails closed on a bad version - C42-E42-COVERAGE
TESTED: the coverage compiler never upgrades a weaker class: an UNKNOWN, OBSERVED or MONITORED path can never be claimed as ENFORCED - C42-E42-INTEGRATION
TESTED: a machine-readable registry maps every prior evolution (E7-E41) to its module and bundle and reports honestly which are present - C42-E42-BENCH
TESTED: 1302 of 1302 platform scenarios across 16 categories held; 438 of 438 invariants; mutation 8 of 8 - C42-E42-CLEANROOM
TESTED: an independent verifier that imports none of CAIN re-derives the E42 invariants and rejects every crafted forgery - C42-E42-TRUTH
TESTED: a public truth engine scans public surfaces and flags unsupported claims (universal control, guaranteed safety, certified, customers, revenue) unless negated; it never auto-edits - C42-E42-HONEST-SCOPE
TESTED: E42 is an in-process TESTED integration library; no hosted platform, no external system integration, no customers or revenue is claimed
Known limits of E42
- E42 is an in-process TESTED integration library. It wires existing modules into one canonical kernel, ABI, action, evidence and receipt path; it does not make external systems behave.
- The integration registry maps each evolution to its module and bundle and reports what is present; presence is not a claim that a layer is correct or hosted.
- There is no live ERP/CRM/cloud integration, no real money, no external organization and no customer.
- The canonical kernel composes the decisions that the existing layers produce; it does not itself host the deterministic E8 commit boundary or any enforcement boundary.
- The public truth engine flags unsupported claims for human review; it never auto-edits and does not guarantee that every surface is covered.
- Moat and product maps are technical foundations only; no market moat, customers, revenue or adoption is claimed.
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Autonomy, control loops & recovery: 407 tested invariants — Agents acting on their own, and how CAIN keeps them in bounds and recovers.
- Transactions, markets & economics: 664 tested invariants — Agents that buy, sell, bid and pay, within limits.
Related
- CAIN Agent Builder — Build new agents with governance designed in from the start.
- CAIN Agent Conformance — Check an agent against a published conformance standard.
- CAIN Agent Evaluation — Deep evaluation of agents before they are trusted with real work.
- CAIN Agent Factory — Produce many governed agents from one approved template.
- CAIN Agent Hosting — Host your agents on CAIN, governed by default.
- CAIN Agent Lab — A safe lab to try agent ideas before they touch anything real.
- CAIN Agent Labor — Rules for agents doing paid work: who did what, and who gets credit.
- CAIN Agent Marketplace — Find and hire governed agents built by others.
- CAIN Agent Organization — Teams of agents with roles, a constitution and recorded decisions.
- CAIN Agent Passport — A signed passport that says who an agent is and what it may do.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem