CAIN-42 CAIN Studio

CAIN-42 · For large organisations

Self-hosted CAIN

Run CAIN inside your own network, next to your agents.

Last reviewed 2026-10-01

Live   Core platform · Platform feature

What it is

Run the CAIN gateway inside your own network next to your agents.

Where it fits

Part of For large organisations: Compliance, private deployment, SIEM and advisory. Every CAIN-42 product runs behind the same rule: an AI agent's action is checked before it runs (identity, authority, policy, risk), decided as allow, hold for a human, or block, and recorded as signed evidence. Unknown or error never becomes allow.

Use it

Live now

Checked from your browser when this page opened, not from a cached list.

Fire a real decision

Send an action through the live CAIN-42 pipeline from this page, with no account, and watch every stage decide. This is the same pipeline every product here sits behind; it runs for a throwaway demo tenant and is rate limited.

For AI engineers

Every product sits behind one decision path: your agent proposes an action with the exact arguments, CAIN runs it through identity, authority, policy, risk, trust and quorum consensus, and answers ALLOW, REQUIRE_APPROVAL or DENY with an Ed25519-signed record. A timeout, outage or unknown verdict never becomes ALLOW. A brand-new agent has no trust history, so its first actions usually come back REQUIRE_APPROVAL.

Python (zero dependencies)

pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl
export CAIN_API_KEY=...   # free key: https://cainstudio.online/signup

import cainstudio

@cainstudio.guard()
def transfer(amount_usd: float, to: str) -> str:
    ...  # runs only if CAIN allows this call, with these arguments

try:
    transfer(5000, "acme")
except cainstudio.ApprovalRequired as e:
    print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
    print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
    print("CAIN unreachable: not run")   # fail-closed

See a real decision with no account

cainstudio try          # live pipeline, stage by stage
cainstudio try --list   # the other attack scenarios

MCP clients (Claude Code, Cursor)

claude mcp add --transport http cain https://cainstudio.online/mcp

More: Python SDK · TypeScript SDK · framework integrations · AI quickstart · decision signing key

Tested guarantees in this area

Every rule in these niches has its own page with its recorded result.

Related

Full documentation

The complete reference, also at /docs/self-hosted.

Self-Hosted MCPGate#

MCPGate brings CAIN's policy enforcement, agent security verification, and auditable execution directly into your own infrastructure.

Deployment Model#

CAIN is delivered in two deployment models with identical trust control logic:

In the self-hosted model, all prompt traffic, agent tool calls, policy evaluations, and evidence records remain entirely within your security boundary.

Architecture#

Autonomous AI Agent
        │
        ▼ (Tool Call / Consequential Action)
┌──────────────────────────────────────────────┐
│ MCPGate Self-Hosted Enforcement Boundary     │
│                                              │
│  ├─ Moat #1: Trust State Engine              │
│  ├─ Moat #2: Security Context Continuity     │
│  ├─ Moat #3: Trust Graph Reachability        │
│  ├─ Moat #4: Execution Provenance            │
│  ├─ Moat #5: Predictive Trust & Blast Radius │
│  ├─ Moat #6: Adversarial Engine              │
│  └─ Moat #7: Autonomous Sentinel Control     │
└──────────────────────┬───────────────────────┘
                       │
       ┌───────────────┴───────────────┐
       ▼                               ▼
    ALLOW                           BLOCK
       │                               │
       ▼                               ▼
Downstream Tool / MCP Server    Execution Terminated
(Action Executed & Recorded)    (Evidence Preserved)

Prerequisites#

Quickstart Deployment (Docker Compose)#

1. Clone or download your licensed MCPGate bundle:

git clone https://github.com/cain-trust/mcpgate.git
cd mcpgate

2. Configure your environment:

cp .env.example .env
# Edit .env with your cluster secret and signing key parameters
chmod 0600 .env

3. Launch the enforcement boundary:

docker compose -f docker-compose.prod.yml up -d

4. Verify operational health:

curl -f http://localhost:8000/health

Expected output:

{"status": "healthy", "service": "platform-gateway"}

Air-Gapped & Fail-Closed Semantics#

MCPGate operates under strict fail-closed security principles:

Integration#

Point your agent framework or MCP client directly to your local MCPGate instance:

from cain import trust

# Route consequential tool execution through your local boundary
@trust(gateway_url="http://localhost:8000", action="execute_query", resource="prod_db")
def run_query(sql: str):
    ...

Verifying Conformance#

Run the built-in conformance suite against your local instance to verify all 7 moats:

cain test --runtime --mcp

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem