CAIN-42 CAIN Studio

CAIN-42 · Prove it to anyone

CAIN Proof

Turns every decision into a signed receipt anyone can check.

Last reviewed 2026-10-01

Live   Core platform · security

What it is

ActionProof verification for AI agent decisions.

Where it fits

Part of Prove it to anyone: Signed records your auditor, regulator or customer can check without trusting us. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.

Use it

Recorded status: PRODUCTION. "Live" on this page means its link answered when the catalog was last checked (2026-10-01T18:22 UTC).

Live now

Checked from your browser when this page opened, not from a cached list.

Fire a real decision

Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.

For AI engineers

Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.

Python (zero dependencies)

pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=...   # free key: https://cainstudio.online/signup

import cainstudio

@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
    ...  # runs only if CAIN allows this call, with these arguments

try:
    transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
    print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
    print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
    print("CAIN unreachable: not run")   # fail-closed

See a real decision with no account

cainstudio try          # live pipeline, stage by stage
cainstudio try --list   # the other attack scenarios

MCP clients (Claude Code, Cursor)

claude mcp add --transport http cain https://cainstudio.online/mcp

More: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key

Tested guarantees in this area

Every rule in these niches has its own page with its recorded result.

Related

Full documentation

The complete reference, also at /docs/evidence.

Evidence#

Every decision is written to a durable, tenant-scoped record with the stage-by-stage verdicts that produced it. The purpose is the incident review six months later, not a dashboard today.

What is recorded#

identity, intent, action, resource, tenant, policy and policy version, risk, verification, approval, decision, enforcement, execution, result, timestamp, correlation id.

Retrieving it#

cain inspect                       # recent decisions
cain inspect --chain <cor_...>     # one correlated agent run, in order
cain explain <decision-id>         # stage by stage, with the policy version
cain audit --decision <id>         # the signature covering it
cain audit                         # who has read evidence

Searchable by decision id, agent, tenant, action, time, resource and correlation id.

Correlation#

Calls made during one agent run share a correlation id, so a run reads as a sequence rather than scattered rows. cain inspect --chain reports the outcome, where it stopped, and -- importantly -- would_block_if_enforcing: what a shadow deployment would have refused.

Signatures#

cain audit --decision <id>

Decisions are signed so alteration is detectable. Signing is deterministic: the same decision signs identically every time, which is what makes a changed signature meaningful.

This is tamper-evidence, not tamper-proofing, and not third-party notarisation. The API response says so in its own scope_note field.

Reading evidence is itself recorded#

"Who looked at this decision" is the second question an investigation asks. cain audit shows that log, including which credential type was used.

A failure to write an access-audit row never fails the read -- turning a logging fault into an outage would be worse than the gap it closes.

Retention#

evidence:
  enabled: true
  retain_days: 90

Decisions are retained for the life of the account by default so they remain available for review. See the DPA for deletion.

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem