CAIN-42 · Protect identities, keys & data
CAIN Private
A private space for your agents with governed memory, tools and MCP connections.
Last reviewed 2026-10-01
Live Core platform · agent
What it is
Private AI agent environment with governed memory, tools, and MCP connectivity.
Where it fits
Part of Protect identities, keys & data: Who the agent is, what it may touch, and what it must never leak. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Open it
https://cainstudio.online/private - Documentation
https://cainstudio.online/docs/private - API endpoint:
https://cainstudio.online/list-agents— needs your API key (get a free key)
Recorded status: PRODUCTION. "Live" on this page means its link answered when the catalog was last checked (2026-10-01T18:22 UTC).
Live now
Checked from your browser when this page opened, not from a cached list.
Fire a real decision
Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.
For AI engineers
Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.
Python (zero dependencies)
pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=... # free key: https://cainstudio.online/signup
import cainstudio
@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
... # runs only if CAIN allows this call, with these arguments
try:
transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
print("CAIN unreachable: not run") # fail-closedSee a real decision with no account
cainstudio try # live pipeline, stage by stage
cainstudio try --list # the other attack scenariosMCP clients (Claude Code, Cursor)
claude mcp add --transport http cain https://cainstudio.online/mcpMore: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Memory, data & privacy: 92 tested invariants — What agents remember and what must never leak.
- Identity, authority & delegation: 964 tested invariants — Who an agent is, what it may do, and who allowed it.
Related
- CAIN Context — Controls what information an agent sees before it decides.
- CAIN Identity — Gives every agent and person a verifiable identity, so CAIN always knows who is acting.
- CAIN Memory — Long-term memory for agents that cannot be poisoned or quietly rewritten.
- Credential broker — Agents use your API keys without ever seeing them, so a hijacked agent cannot steal them.
- LeakGuard — Stops passwords, keys and personal data from leaving in text sent to an AI tool.
Full documentation
The complete reference, also at /docs/private.
CAIN Private Documentation#
Status: PRIVATE PREVIEW#
CAIN Private is in private preview. Not all features are production-ready.
What is CAIN Private?#
CAIN Private is a private AI agent environment where:
- You control the agent - its instructions, memory, and tools
- CAIN governs every action - consequential actions require authorization
- Evidence is recorded - every decision leaves a traceable record
CAIN Private is not a chatbot. It is governed autonomous AI that can take real actions in your systems.
Core proposition: Your AI. Your data. Your infrastructure. Your rules.
Architecture#
┌─────────────────────────────────────────────────────────────────┐ │ CAIN Private │ ├─────────────────────────────────────────────────────────────────┤ │ Agent Runtime │ │ ├── System instructions │ │ ├── Model configuration │ │ ├── Tool registry (MCP, API, custom) │ │ └── Memory (agent, user, workspace) │ │ │ │ CAIN Enforcement Layer │ │ ├── Identity verification │ │ ├── Policy evaluation │ │ ├── Authorization │ │ ├── Risk assessment │ │ └── Decision (ALLOW/DENY/REQUIRE_APPROVAL) │ │ │ │ Evidence Chain │ │ └── Signed records of all decisions │ └─────────────────────────────────────────────────────────────────┘
Deployment Models#
CAIN Private Hosted (CAIN Studio)#
| What CAIN Studio Operates | What You Control |
| Agent runtime | Agent configuration |
| CAIN enforcement | Tool permissions |
| Evidence storage | Your data/memory |
| Credential vault | API access |
Privacy claim: Your agent's memory and data are isolated per tenant.
CAIN Private Self-Hosted (MCPGate) - COMING SOON#
| What You Operate | What CAIN Studio Receives |
| Everything | Nothing (air-gapped option) |
| Agent runtime | Decision requests (optional) |
| Evidence | Usage for billing only |
| Credentials | Nothing |
Agent Management#
Create Agent#
curl -X POST https://cainstudio.online/private/agents \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key" \
-d '{
"name": "data-processor",
"description": "Processes data with CAIN protection"
}'
Response:
{
"agent_id": "agent:abc123...",
"name": "data-processor",
"state": "created"
}
Configure Agent#
# Set allowed tools
curl -X PATCH https://cainstudio.online/private/agents/{agent_id} \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key" \
-d '{"allowed_tools": ["read_record", "write_record"]}'
Agent States#
| State | Meaning |
created | Agent created, not running |
initializing | Agent initializing |
running | Agent active |
paused | Agent paused |
stopped | Agent stopped |
error | Error state |
Memory#
Memory Types#
| Type | Visibility | Use Case |
agent | Agent + audit | Agent's working memory |
user | User only | Sensitive user data |
workspace | Configurable | Shared workspace |
Set Memory#
curl -X POST https://cainstudio.online/private/agents/{agent_id}/memory \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key" \
-d '{
"memory_type": "agent",
"key": "current_task",
"value": "Processing customer orders"
}'
List Memory#
curl https://cainstudio.online/private/agents/{agent_id}/memory \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key"
Clear Memory#
# Clear all agent memory
curl -X DELETE https://cainstudio.online/private/agents/{agent_id}/memory \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key"
# Clear specific type
curl "https://cainstudio.online/private/agents/{agent_id}/memory?memory_type=agent" \
-X DELETE \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key"
Tools#
Register Tool#
curl -X POST https://cainstudio.online/private/agents/{agent_id}/tools \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key" \
-d '{
"tool_name": "read_customer_record",
"tool_type": "api",
"risk_level": "low"
}'
Risk Levels#
| Level | Requires Approval | Example |
low | No | Read data |
medium | No | Write data |
high | Yes | Delete records |
critical | Yes | Financial transactions |
Enable/Disable Tool#
curl -X PATCH https://cainstudio.online/private/tools/{tool_id}/enabled \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key" \
-d '{"enabled": false}'
Credentials#
Store Credential#
curl -X POST https://cainstudio.online/private/agents/{agent_id}/credentials \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key" \
-d '{
"name": "database-api-key",
"credential_type": "api_key",
"encrypted_value": "your-encrypted-value"
}'
Important: Credentials are encrypted. The raw value is NEVER returned after storage.
List Credentials#
curl https://cainstudio.online/private/agents/{agent_id}/credentials \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key"
Response (values redacted):
[{
"credential_id": "cred:abc123",
"name": "database-api-key",
"credential_type": "api_key",
"encrypted_value": "***REDACTED***"
}]
CAIN Enforcement#
Execute Action with Enforcement#
curl -X POST https://cainstudio.online/private/agents/{agent_id}/execute \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key" \
-d '{
"action": "read_customer_record",
"resource": "customer-12345"
}'
Decision Outcomes#
| Outcome | Meaning | Action Taken |
allow | Policy permits | Executed |
deny | Policy forbids | Blocked |
require_approval | High-risk | Blocked until approved |
unknown | Cannot determine | Blocked (fail-closed) |
error | System error | Blocked (fail-closed) |
ALLOW Example#
{
"decision_id": "cain:abc123",
"result": "allow",
"reason": "Action permitted by policy",
"executed": true,
"evidence_id": "ev:def456",
"timestamp": "2026-09-02T12:00:00Z"
}
DENY Example#
{
"decision_id": "cain:abc124",
"result": "deny",
"reason": "Tool 'delete_all' is blocked for this agent",
"executed": false,
"evidence_id": null,
"timestamp": "2026-09-02T12:01:00Z"
}
REQUIRE_APPROVAL Example#
{
"decision_id": "cain:abc125",
"result": "require_approval",
"reason": "Tool 'transfer_funds' requires approval due to risk level 'critical'",
"executed": false,
"evidence_id": null,
"timestamp": "2026-09-02T12:02:00Z"
}
Approvals#
List Pending Approvals#
curl https://cainstudio.online/private/approvals?status=pending \ -H "X-Tenant-ID: your-tenant" \ -H "X-API-Key: your-key"
Resolve Approval#
curl -X POST https://cainstudio.online/private/approvals/{approval_id}/resolve \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key" \
-d '{
"approved": true,
"resolver": "admin@example.com",
"notes": "Approved after verification"
}'
Evidence & Auditing#
List Decision History#
curl https://cainstudio.online/private/agents/{agent_id}/decisions \
-H "X-Tenant-ID: your-tenant" \
-H "X-API-Key: your-key"
Decision Record#
[{
"decision_id": "cain:abc123",
"action": "read_customer_record",
"resource": "customer-12345",
"result": "allow",
"reason": "Action permitted by policy",
"risk_score": 0.3,
"timestamp": "2026-09-02T12:00:00Z"
}]
Security Model#
Verified Properties#
| Property | Status |
| Tenant isolation | Tested |
| Authentication | Implemented |
| Authorization | Implemented |
| Fail-closed (UNKNOWN/ERROR → DENY) | Implemented |
| Credential protection | Implemented |
| Secret redaction | Implemented |
| IDOR resistance | Implemented |
Fail-Closed Behavior#
Only ALLOW permits execution. All other outcomes block the action.
Feature Status#
| Feature | Status |
| Agent creation | LIVE + FUNCTIONAL |
| Memory management | LIVE + FUNCTIONAL |
| Tool registration | LIVE + FUNCTIONAL |
| CAIN enforcement | LIVE + FUNCTIONAL |
| Credential storage | LIVE + FUNCTIONAL |
| Decision auditing | LIVE + FUNCTIONAL |
| Approval workflow | LIVE + FUNCTIONAL |
| Automation | STUB |
| MCP integration | NOT DEPLOYED |
| Evidence signing | HEALTH-CHECK ONLY |
| Self-hosted deployment | DOCUMENTATION ONLY |
Limitations#
1. No automated execution - Schedules can be created but not automatically run 2. No MCP integration - MCP tools not yet connected to CAIN enforcement 3. No evidence signatures - Decisions recorded but not cryptographically signed 4. Self-hosted not available - Documentation only
Privacy#
CAIN Studio Hosted#
We receive:
- Decision requests (action, resource)
- Decision outcomes (allow/deny)
- Usage for billing
We do NOT receive:
- Your memory data
- Your credentials (encrypted, unreadable)
- Your internal configurations
Self-Hosted (COMING SOON)#
When self-hosted, you control everything. CAIN Studio receives nothing by default.
Troubleshooting#
Action returns DENY#
1. Check if tool is in blocked_tools 2. Check if tool is in allowed_tools (if list is non-empty) 3. Check agent state is running
Action returns ERROR#
1. Check agent exists 2. Check tenant ID is correct 3. Check API key is valid
401 Unauthorized#
1. Verify X-API-Key header is present 2. Verify API key is valid for the tenant
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem