CAIN-42 · For large organisations
Self-hosted CAIN
Run CAIN inside your own network, next to your agents.
Last reviewed 2026-10-01
Live Core platform · Platform feature
What it is
Run the CAIN gateway inside your own network next to your agents.
Where it fits
Part of For large organisations: Compliance, private deployment, SIEM and advisory. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.
Use it
- Documentation
https://cainstudio.online/docs/self-hosted
Live now
Checked from your browser when this page opened, not from a cached list.
Fire a real decision
Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.
For AI engineers
Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.
Python (zero dependencies)
pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=... # free key: https://cainstudio.online/signup
import cainstudio
@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
... # runs only if CAIN allows this call, with these arguments
try:
transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
print("CAIN unreachable: not run") # fail-closedSee a real decision with no account
cainstudio try # live pipeline, stage by stage
cainstudio try --list # the other attack scenariosMCP clients (Claude Code, Cursor)
claude mcp add --transport http cain https://cainstudio.online/mcpMore: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key
Tested guarantees in this area
Every rule in these niches has its own page with its recorded result.
- Policy, law & governance: 966 tested invariants — The rules agents must follow, and how they are enforced.
- Transactions, markets & economics: 664 tested invariants — Agents that buy, sell, bid and pay, within limits.
Related
- Actuarial Cyber Insurance Underwriting Protocol — A protocol for scoring AI-agent risk the way insurers score cyber risk (prototype, no insurer yet).
- Continuous Regulatory Compliance-as-a-Service (EU AI Act & ISO 42001) — Ongoing EU AI Act and ISO 42001 evidence, delivered as a service.
- MCPGate Sovereign Enterprise Appliance (Air-Gapped Kubernetes) — MCPGate as a private appliance for your own Kubernetes or air-gapped network.
- SIEM, chat & alert forwarding — Sends every block and hold to Sentinel, Datadog, Slack or Teams, signed.
- Single sign-on & SCIM — Sign in with your company login (Okta, Entra, Google) and keep users in sync automatically.
- UsageLedger — Usage metering, tiered pricing and invoices for AI services.
- Autonomous Swarm Fleet Quarantine & Emergency Kill-Switch SLAs — Stop a whole fleet of agents at once, with an agreed response time.
- Confidential Computing Hardware Enclave Remote Attestation Notary — Prove an agent ran inside trusted hardware (planned; no hardware enclave behind it yet).
- Enterprise SIEM & SOC Connectors — Connectors that feed CAIN events into your security operations center.
- Governed Agent Memory & Vector Sanitization Service — Cleans agent memory and vector stores of planted instructions, as a service.
Full documentation
The complete reference, also at /docs/self-hosted.
Self-Hosted MCPGate#
MCPGate brings CAIN's policy enforcement, agent security verification, and auditable execution directly into your own infrastructure.
Deployment Model#
CAIN is delivered in two deployment models with identical trust control logic:
- CAIN Studio (
https://cainstudio.online): Hosted AI infrastructure runtime and managed trust control plane. - MCPGate (
https://mcpgate.online): Self-hosted AI infrastructure runtime and self-hosted enforcement boundary operating within your private VPC or on-premise network.
In the self-hosted model, all prompt traffic, agent tool calls, policy evaluations, and evidence records remain entirely within your security boundary.
Architecture#
Autonomous AI Agent
│
▼ (Tool Call / Consequential Action)
┌──────────────────────────────────────────────┐
│ MCPGate Self-Hosted Enforcement Boundary │
│ │
│ ├─ Moat #1: Trust State Engine │
│ ├─ Moat #2: Security Context Continuity │
│ ├─ Moat #3: Trust Graph Reachability │
│ ├─ Moat #4: Execution Provenance │
│ ├─ Moat #5: Predictive Trust & Blast Radius │
│ ├─ Moat #6: Adversarial Engine │
│ └─ Moat #7: Autonomous Sentinel Control │
└──────────────────────┬───────────────────────┘
│
┌───────────────┴───────────────┐
▼ ▼
ALLOW BLOCK
│ │
▼ ▼
Downstream Tool / MCP Server Execution Terminated
(Action Executed & Recorded) (Evidence Preserved)
Prerequisites#
- Linux OS (Ubuntu 22.04+ / RHEL 9+ recommended)
- Container Runtime: Docker Engine 24.0+ and Docker Compose v2, or Kubernetes 1.28+
- Network: Local port 8000/8420 for enforcement boundary; no outbound internet required for air-gapped environments
- Hardware: 2 CPU cores, 4 GB RAM minimum
Quickstart Deployment (Docker Compose)#
1. Clone or download your licensed MCPGate bundle:
git clone https://github.com/cain-trust/mcpgate.git cd mcpgate
2. Configure your environment:
cp .env.example .env # Edit .env with your cluster secret and signing key parameters chmod 0600 .env
3. Launch the enforcement boundary:
docker compose -f docker-compose.prod.yml up -d
4. Verify operational health:
curl -f http://localhost:8000/health
Expected output:
{"status": "healthy", "service": "platform-gateway"}
Air-Gapped & Fail-Closed Semantics#
MCPGate operates under strict fail-closed security principles:
- NO AUTHORIZATION → NO EXECUTION: An action is never permitted without explicit policy allowance.
- UNKNOWN and ERROR never become ALLOW or TRUSTED: If a dependency, database, or policy service is unavailable or times out, the gate immediately returns
BLOCK/DENY. - Tamper-Evident Evidence Chain: All decisions generate SHA-256 chained audit records stored in local SQLite or external WORM volumes.
Integration#
Point your agent framework or MCP client directly to your local MCPGate instance:
from cain import trust
# Route consequential tool execution through your local boundary
@trust(gateway_url="http://localhost:8000", action="execute_query", resource="prod_db")
def run_query(sql: str):
...
Verifying Conformance#
Run the built-in conformance suite against your local instance to verify all 7 moats:
cain test --runtime --mcp
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem