CAIN-42 · Coming next
CAIN Edge
CAIN decisions on devices at the edge, close to where agents act.
Last reviewed 2026-10-01
In development Product lines in development · Product line
Where it fits
Part of Coming next: Product lines in development. Tested code, not yet sold or hosted. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Evidence bundle
https://clawx.click/evidence/e37-autonomous-execution-mesh-2026-09-30/
Not available yet. Recorded status: PRODUCT SPECIFICATION (not deployed, no customers), from evolution E37, E42. This means tested code exists; it is not hosted or sold. The evidence below is what was tested.
Evidence behind it
| Bundle | Claims | Invariants held |
|---|---|---|
| CAIN-42 Evolution 37 -- Autonomous Execution Mesh | 9 | 27 of 27 |
| CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform | 8 | 438 of 438 |
What E37 claims, and how far each claim goes
- C42-E37-MESH
TESTED: every governed execution runs the 12-stage chain IDENTITY -> ... -> REASSESSMENT over the real kernel, E25 sealed executor, E8 commit and E34 envelope, and yields a signed execution proof and receipt whose E8 commit matches the envelope - C42-E37-MIGRATION
TESTED: migration is a governed state transition: identity, authority, capability, policy token, destination, security, resources, carried state and epoch are all checked; risk, budget, revocations, transaction limits, evidence, reputation and incident state cannot be reset - C42-E37-CONTINUITY
TESTED: continuity is never assumed: a material change needs a new epoch, authorizations bound to old epochs are stale, continuity tokens cannot exceed existing authority - C42-E37-COVERAGE
TESTED: UNKNOWN, OBSERVED and MONITORED never become ENFORCED; every claim takes the weakest relevant boundary - C42-E37-ADMISSION
TESTED: runtime admission verifies a measured code digest and probes; a runtime that only claims compliance is not admitted; hardware attestation stays UNKNOWN on this host - C42-E37-BENCH
TESTED: 2720 of 2720 adversarial scenarios held across 31 categories; 1132 of 1132 invariants held; mutation 17 of 17 - C42-E37-CHAOS
TESTED: 16 of 16 injected fault classes contained with 0 false allows; self-test 14/14 - C42-E37-SCALE
SIMULATED: single-host in-process scale runs (identities/epochs/tokens up to 100,000 agents; 1,000,000 virtual fast-path executions) - C42-E37-ADAPTERS
ARCHITECTURE: 18 adapter protocols declared with security specifications; the governed-execution contract passes against a reference harness; live protocol integration not tested
Known limits of E37
- In-process TESTED library: the mesh, its nodes, regions and clouds are governance records in one process on one VPS; there is no multi-cloud or multi-node deployment of E37.
- Only this host is measured (environment passport); declared destinations are not measured.
- Hardware attestation is UNKNOWN: no TEE on this host; the admission attestation probe has nothing to call.
- Adapters were tested against a reference in-process harness; no live MCP/A2A/HTTP/gRPC server integration.
- Federated cloud targets (AWS/Azure/GCP/private/bare metal/edge/hybrid) are ARCHITECTURE only.
- The governance quorum is in-process (3f+1 keys, no network); it is not the networked PBFT cluster.
What E42 claims, and how far each claim goes
- C42-E42-PLATFORM
TESTED: one canonical governance kernel routes every consequential action through a single authorization path (IDENTITY..E8_COMMIT) and returns exactly one decision; an UNKNOWN stage is never ALLOW - C42-E42-ABI
TESTED: one canonical governance ABI (Identity, Intent, Action, Capability, Policy, Authority, Risk, Evidence, Authorization, Execution, Outcome, Receipt, Incident, Evolution) is versioned, canonically serialized, hashed and signed, and fails closed on a bad version - C42-E42-COVERAGE
TESTED: the coverage compiler never upgrades a weaker class: an UNKNOWN, OBSERVED or MONITORED path can never be claimed as ENFORCED - C42-E42-INTEGRATION
TESTED: a machine-readable registry maps every prior evolution (E7-E41) to its module and bundle and reports honestly which are present - C42-E42-BENCH
TESTED: 1302 of 1302 platform scenarios across 16 categories held; 438 of 438 invariants; mutation 8 of 8 - C42-E42-CLEANROOM
TESTED: an independent verifier that imports none of CAIN re-derives the E42 invariants and rejects every crafted forgery - C42-E42-TRUTH
TESTED: a public truth engine scans public surfaces and flags unsupported claims (universal control, guaranteed safety, certified, customers, revenue) unless negated; it never auto-edits - C42-E42-HONEST-SCOPE
TESTED: E42 is an in-process TESTED integration library; no hosted platform, no external system integration, no customers or revenue is claimed
Known limits of E42
- E42 is an in-process TESTED integration library. It wires existing modules into one canonical kernel, ABI, action, evidence and receipt path; it does not make external systems behave.
- The integration registry maps each evolution to its module and bundle and reports what is present; presence is not a claim that a layer is correct or hosted.
- There is no live ERP/CRM/cloud integration, no real money, no external organization and no customer.
- The canonical kernel composes the decisions that the existing layers produce; it does not itself host the deterministic E8 commit boundary or any enforcement boundary.
- The public truth engine flags unsupported claims for human review; it never auto-edits and does not guarantee that every surface is covered.
- Moat and product maps are technical foundations only; no market moat, customers, revenue or adoption is claimed.
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Autonomy, control loops & recovery: 407 tested invariants — Agents acting on their own, and how CAIN keeps them in bounds and recovers.
- Transactions, markets & economics: 664 tested invariants — Agents that buy, sell, bid and pay, within limits.
Related
- CAIN Agent Builder — Build new agents with governance designed in from the start.
- CAIN Agent Conformance — Check an agent against a published conformance standard.
- CAIN Agent Evaluation — Deep evaluation of agents before they are trusted with real work.
- CAIN Agent Factory — Produce many governed agents from one approved template.
- CAIN Agent Hosting — Host your agents on CAIN, governed by default.
- CAIN Agent Lab — A safe lab to try agent ideas before they touch anything real.
- CAIN Agent Labor — Rules for agents doing paid work: who did what, and who gets credit.
- CAIN Agent Marketplace — Find and hire governed agents built by others.
- CAIN Agent Organization — Teams of agents with roles, a constitution and recorded decisions.
- CAIN Agent Passport — A signed passport that says who an agent is and what it may do.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem