{
  "bundle_id": "cain37-evidence-fabric-public-evidence",
  "bundle_version": "1.0.0",
  "generated_at": "2026-09-17T23:35:00Z",
  "title": "CAIN 37.0 Autonomous Evidence Fabric -- Public Evidence Bundle",
  "purpose": "A real, cryptographically-chained evidence log built from three genuine, live PBFT commits on CAIN's 4-node Byzantine test cluster this session, plus the exact forensic trace of why this evidence still cannot be reached via the literal cainstudio.online / mcpgate.online domains. Independently verifiable offline: the included verifier recomputes every content hash, chain link, and Merkle root itself.",
  "how_to_verify_independently": "Download cain_37_independent_verifier.py, cain37_evidence_chain.jsonl, and cain37_evidence_checkpoints.jsonl from this bundle. Run: python3 cain_37_independent_verifier.py verify-chain cain37_evidence_chain.jsonl (expect verdict VALID, checked: 3). Then: python3 cain_37_independent_verifier.py verify-checkpoint cain37_evidence_chain.jsonl cain37_evidence_checkpoints.jsonl (expect verdict VALID). Then try tampering any field inside one evidence object in a copy of the .jsonl file and re-running verify-chain -- it MUST report VERIFICATION_FAILURE or CHAIN_INTEGRITY_FAILURE. See HOW_TO_VERIFY.md for a copy-pasteable walkthrough including the negative-control commands.",
  "honest_scope_note": "This bundle documents CAIN 37's NEW evidence-chain layer (3 real evidence objects derived from real live AuthorizationProofObjects minted this session, chained + Merkle-sealed). It does NOT claim: a full Proof Graph API (/proof-graph/{id}, /claims/{id} are not implemented), witness-plane independence beyond CAIN 35's existing code/key independence, hardware attestation, formal verification, or that this evidence is reachable via the literal public domain names -- see CAIN_37_CONNECTIVITY_FORENSICS.json in this same bundle for the full, itemized reason why, including a real unauthenticated-firewall-exposure finding made and partially remediated during this session's own forensic investigation.",
  "artifacts": [
    {
      "filename": "cain_37_independent_verifier.py",
      "sha256": "0b3e74e6227ca1de8046beccb879362ff06817cfd1fb0e74b16dc3af8c8c9512",
      "description": "The actual zero-import verifier -- download and run it yourself. Never imports cain_evidence_fabric_37.py (the production module that minted this chain)."
    },
    {
      "filename": "cain37_evidence_chain.jsonl",
      "sha256": "307134036fb50d43683816507bf1de9c8d9309807d46811316de8c83ca3aaf3d",
      "description": "3 real Universal Evidence Objects, each derived from a genuine live PBFT commit (auth-76c09f4d67984a96, auth-51e5d826ce254339, auth-087f2f40aa8e4ce8) on this session's 4-node cluster, hash-chained.",
      "classification": "LIVE-VERIFIED"
    },
    {
      "filename": "cain37_evidence_checkpoints.jsonl",
      "sha256": "8bf3184686ff8a84f7f27fbeda0ee28705e42209fda5f05d57a1df559227460a",
      "description": "One sealed Merkle checkpoint over all 3 evidence objects."
    },
    {
      "filename": "CAIN_37_BASELINE.json",
      "sha256": "a8a0b8e96b51f0c730aa11502c06e638cacacd54e8eaa23918bdba6d7533e498",
      "description": "Point-in-time forensic freeze of this session's own VPS at the time this bundle was produced."
    },
    {
      "filename": "CAIN_37_CONNECTIVITY_FORENSICS.json",
      "sha256": "d215e6e59c7637830683efafc1dccff1b7a4dbf6d1d1dd65a77494a4756dd136",
      "description": "Full network trace explaining exactly why this evidence is not reachable via the literal public domain, plus a real unauthenticated-firewall-exposure finding this session discovered. Updated 2026-09-18: this file's ROOT-CAUSE-2 entry now carries a status_update_2026_09_18 field recording that the firewall fix WAS subsequently applied live (verified via iptables), superseding this bundle's original 'staged, not applied' finding -- the original finding is preserved, not deleted, and the update is clearly dated."
    }
  ]
}
