{
 "claim_taxonomy": {
  "categories": [
   "ARCHITECTURE",
   "SECURITY",
   "CRYPTOGRAPHY",
   "CONSENSUS",
   "BYZANTINE RESILIENCE",
   "AUTHORIZATION",
   "TRUST",
   "TRAJECTORY GOVERNANCE",
   "L5 GOVERNANCE",
   "MCP ENFORCEMENT",
   "EVIDENCE",
   "PERFORMANCE",
   "AVAILABILITY",
   "RECOVERY",
   "CHAOS",
   "SUPPLY CHAIN",
   "DEPLOYMENT",
   "COMPLIANCE"
  ],
  "rules": [
   {
    "category": "L5 GOVERNANCE",
    "pattern": "CAG-L5|L5-IDENTITY|L5-ADAPTIVE"
   },
   {
    "category": "TRAJECTORY GOVERNANCE",
    "pattern": "TRAJECTOR"
   },
   {
    "category": "MCP ENFORCEMENT",
    "pattern": "MCPGATE"
   },
   {
    "category": "PERFORMANCE",
    "pattern": "LATENCY|BENCH|FAIRNESS"
   },
   {
    "category": "CHAOS",
    "pattern": "SOAK"
   },
   {
    "category": "BYZANTINE RESILIENCE",
    "pattern": "PARTITION|BYZANTINE|FAILURE-DOMAINS|DEGRADED"
   },
   {
    "category": "RECOVERY",
    "pattern": "DISASTER|ROLLBACK|RESTORE|RECOVERY|STORAGE"
   },
   {
    "category": "CONSENSUS",
    "pattern": "PBFT|DAG|FAST-PATH|CONSENSUS|MULTI-REGION|CLUSTER"
   },
   {
    "category": "SUPPLY CHAIN",
    "pattern": "SUPPLY|RELEASE|REPRODUCIBLE-BUILD"
   },
   {
    "category": "DEPLOYMENT",
    "pattern": "HARDWARE|ATTEST"
   },
   {
    "category": "AUTHORIZATION",
    "pattern": "AGENTS|AUTHORITY|LEASE|GOVERNED|ZOD|E6|E7|E8"
   },
   {
    "category": "SECURITY",
    "pattern": "FORMAL|INVARIANT"
   },
   {
    "category": "SECURITY",
    "pattern": "PRIVACY|SECCOMP|CONFINE|SECURITY"
   },
   {
    "category": "EVIDENCE",
    "pattern": "DECISION|SIGNING|EVIDENCE|CLAIMS|LEGACY"
   },
   {
    "category": "COMPLIANCE",
    "pattern": "THIRD-PARTY|REVIEW|CERT"
   },
   {
    "category": "AVAILABILITY",
    "pattern": "PROVIDER"
   },
   {
    "category": "EVIDENCE",
    "pattern": "PROOF-FABRIC|TEST-SUITE"
   },
   {
    "category": "ARCHITECTURE",
    "pattern": "."
   }
  ]
 },
 "claims": [
  {
   "artifacts": [
    {
     "bundle": "pbft-evolution2-2026-09-24",
     "cluster_ids": [
      "cain42-pbft-qc-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "f96088a8edf710b38b3cf22a7c25dd04e2758f7ff7ae9583b8eddf4b04cb2dde"
    },
    {
     "bundle": "pbft-evolution2-2026-09-24",
     "cluster_ids": [
      "cain42-pbft-qc-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "verify_pbft_qc_bundle.py.txt",
     "sha256": "ba452ce42528f11f7f5235727a65cae25a34072bc52b4711fd72581615d06009"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-PBFT-QC",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "disposable cluster on one host",
   "public_label": "DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "A 4-node CAIN-42 PBFT cluster produced authentic quorum certificates (>= 3 of 4 pinned Ed25519 members) with an identical decision chain on every node across a primary failover.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json  (or index.html in a browser)"
  },
  {
   "artifacts": [
    {
     "bundle": "pbft-evolution3-2026-09-24",
     "cluster_ids": [
      "cain42-pbft-qc-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "43e1c61004d3d53a1f76d96f72a7241ef59793a2f77d9beda5f6b40559e9c9a4"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-FAST-PATH",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "bounded model (single slot, 3 views); not deployed live",
   "public_label": "DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "The Evolution 3 fast path commits only with all 4 members' votes and its view-change rule was model-checked (the naive rule was shown unsafe); a real run produced FAST_COMMIT_QCs that verify.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json"
  },
  {
   "artifacts": [],
   "category": "PERFORMANCE",
   "claim_id": "C42-FAST-PATH-LATENCY",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "declared: A/B benchmark on the disposable single-host cluster; no artifact published",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "negative result; host CPU-bound",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "The fast path did NOT produce a measurable latency improvement on this host (paired A/B, 95% CI includes 0).",
   "status": "BENCHMARKED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/pbft_ab_bench.py (results in the certification)"
  },
  {
   "artifacts": [
    {
     "bundle": "dag-evolution4-2026-09-24",
     "cluster_ids": [
      "cain42-dag-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "DAG_CLUSTER_EVIDENCE.json",
     "sha256": "10c08dab4e70a7a5782b9aafe92e7c88e63038085cce3a8a143abb660797bc09"
    },
    {
     "bundle": "dag-evolution4-2026-09-24",
     "cluster_ids": [
      "cain42-dag-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "verify_dag_bundle.py.txt",
     "sha256": "f544555b9275d412bdd2b459cf780d351058b3755792f44dfb7f8377a5d58fd5"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-DAG-ORDER",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "disposable cluster; ordering bias removed in Evolution 5 (measured), fairness beyond position bias not measured",
   "public_label": "DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "DAG data is availability-certified (3 of 4), anchored only through PBFT, and ordered identically on all 4 nodes including a crash-restarted one; the verifier recomputes the order.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_dag_bundle.py DAG_CLUSTER_EVIDENCE.json"
  },
  {
   "artifacts": [
    {
     "bundle": "mcpgate-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "manifest.json",
     "sha256": "8196297a5ae5ac11dc3d44f4a27618a5631699ed5d2dd40056b76eef47f66ca6"
    },
    {
     "bundle": "mcpgate-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "calls.json",
     "sha256": "d841d64bd89933e273487790396ffec5a930bf9c668348248ade276f19443cbf"
    },
    {
     "bundle": "mcpgate-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "gate_proofs.json",
     "sha256": "bbba0255296226ee3bf5d0856e49a20f6977ee5993f3d7cfdde9f45f3cf8d644"
    },
    {
     "bundle": "mcpgate-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "mcp_server_executed.json",
     "sha256": "460a1fb18f541c589126001227ec36760a7ba9db1347aa13b1cbc63125bb6747"
    },
    {
     "bundle": "cain42-proof-package-2026-09-24",
     "cluster_ids": [
      "cain42-dag-evidence",
      "cain42-proof-package"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "manifest.json",
     "sha256": "c50397779c5aed594357a3f295362b2c5c69f074fd7f096a23db2e3d995f0b26"
    }
   ],
   "category": "MCP ENFORCEMENT",
   "claim_id": "C42-MCPGATE-ENFORCES",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE",
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "self-attested run by the operator; the downstream is a sandbox key-value MCP server; cainstudio.online does not route customer tool calls through this gate",
   "public_label": "LIVE + DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "MCPGate lets a tool call run only with a PBFT-committed authorization bound to the exact action, scope, identity, security context, expiry and single use. On the LIVE 4-region cluster cain-mr-02, through the MCPGate HTTP proxy to a separate MCP server process: 5 authorized calls ran (per the server's own execution log) and 12 attacks were blocked, each with a signed denial returned to the caller (replay, action and tool substitution, capability escalation, identity substitution, context drift, forged QC, forged body, post-consensus mutation, another cluster's certificate, no authorization, expiry).",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verifiers/cain_proof_verify.py .   (see mcpgate-live-2026-09-27/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "cain42-agent-proof-package-2026-09-24",
     "cluster_ids": [
      "evo6"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "manifest.json",
     "sha256": "9ccb5e68a06d51df8c5d02e2c0fd520a627ed09333523f750a8c6f5636a9677e"
    },
    {
     "bundle": "cain42-agent-proof-package-2026-09-24",
     "cluster_ids": [
      "evo6"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "agents.json",
     "sha256": "f10ea2027694d51543995f3668b087dd87585b2df2a9f4e92bb04d0b743e0998"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-AGENTS-CANNOT-SELF-AUTHORIZE",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "scripted agents, not LLMs; attestation SIMULATED; in-process",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Agents propose; only PBFT authorizes. Plan mutation, model update or tool swap after consensus forces reauthorization; undeclared actions, impersonation, replay, forged trajectories, delegation escalation and aggregate-policy (salami) attacks are blocked.",
   "status": "SIMULATED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verifiers/cain_proof_verify.py ."
  },
  {
   "artifacts": [
    {
     "bundle": "final-2026-09-24",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_FINAL_INVARIANTS_RUN.json",
     "sha256": "cdf56006ccb193195e9ccdf765620ff78be8b67a52e4894c881368874265d2e9"
    }
   ],
   "category": "SECURITY",
   "claim_id": "C42-INVARIANTS",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "executable tests, not formal verification; see each invariant's coverage/gap",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "28 executable CAIN-42 invariants (I001-I028: no quorum -> no consensus -> no authorization -> no execution; agents, memory, DAG, delegation, trust and AI predictions cannot create authority; replay, expiry, substitution, tampering rejected) pass on the real code; 22 with full coverage, 6 partial with the gap named.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/cain42_invariants.py"
  },
  {
   "artifacts": [
    {
     "bundle": "final-2026-09-24",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E6_TRAJECTORY_LAB.json",
     "sha256": "3ad3cadaf3e820adb78731ccfcefdd336bbc3467f0573f1be74ea9d22765c460"
    }
   ],
   "category": "TRAJECTORY GOVERNANCE",
   "claim_id": "C42-1000-TRAJECTORIES",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "in-process; scripted agents",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "1,000 agent trajectories (9 kinds incl. 380 attacks) all ended as expected; all 620 allowed actions carry complete, re-verified proof chains; a 1,000-step trajectory accepted 0 stale authorizations.",
   "status": "SIMULATED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/agentic_trajectory_lab.py"
  },
  {
   "artifacts": [
    {
     "bundle": "final-2026-09-24",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E5_ORDERING_FAIRNESS.json",
     "sha256": "32204ce929ad2c04451c67be344ced464c71e9372c551a9906692771819766e6"
    }
   ],
   "category": "PERFORMANCE",
   "claim_id": "C42-ORDERING-FAIRNESS",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "position bias only; censorship and economic bias not measured",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "DAG within-round order is seeded by committed PBFT history: validator-position bias measured before (chi-square 542) and after (1.75).",
   "status": "BENCHMARKED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/dag_fairness_lab.py"
  },
  {
   "artifacts": [],
   "category": "CONSENSUS",
   "claim_id": "C42-LIVE-CLUSTER-EVO2",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "declared: about the live cain-vc cluster; its API is private, hence UNVERIFIED",
   "evidence_level": 1,
   "evidence_level_meaning": "implementation evidence",
   "limits": "live cluster API is private; its first two decisions predate certificates",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "The live cain-vc cluster runs the Evolution 2 engine (upgraded node by node, state preserved).",
   "status": "UNVERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "not publicly reachable"
  },
  {
   "artifacts": [],
   "category": "SECURITY",
   "claim_id": "C42-PRIVACY-FIREWALL",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "declared: a pattern scanner run over the published bundles",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "pattern-based; not a guarantee against every leak class",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Every published evidence bundle passes the public-evidence privacy firewall (keys, tokens, credentials, private IPs, internal URLs, server paths, source).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/public_evidence_firewall.py"
  },
  {
   "artifacts": [
    {
     "bundle": "four-server-cluster-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "0ed32a92d4c58c3517679c6c0ca7c318a45960c01b5b63e7ce87db677b6a3b71"
    },
    {
     "bundle": "four-server-cluster-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "verify_host_loss_bundle.py.txt",
     "sha256": "0f26f9c82d40d9c3da44d878ee25ecfab59413475765515475a314019a15b6cf"
    }
   ],
   "category": "BYZANTINE RESILIENCE",
   "claim_id": "C42-INDEPENDENT-FAILURE-DOMAINS",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "one provider (Vultr) and one operator: a provider-wide outage or operator compromise is not covered",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Consensus runs on independent geographic failure domains: cain-mr-02 has 4 replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; every server was taken offline in turn and the cluster kept committing, and with two down it refused to commit.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_host_loss_bundle.py PBFT_QC_BUNDLE.json"
  },
  {
   "artifacts": [],
   "category": "AVAILABILITY",
   "claim_id": "C42-MULTI-PROVIDER",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "declared: a statement about the live topology (every server on one provider)",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "every server is on Vultr; needs a second provider account",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Replicas on more than one infrastructure provider.",
   "status": "NOT_IMPLEMENTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "-"
  },
  {
   "artifacts": [
    {
     "bundle": "multi-region-cluster-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "393d88099d4d62686abff3bf0da841808741717a0978626b04d34e678f35fd4b"
    },
    {
     "bundle": "hourly-proof-mr02",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "proof-000000.json",
     "sha256": "cfc616620eae2ddd7371b0393ca269edb07eb6cb704f17deea9be51d4bba9847"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-LIVE-MULTI-REGION",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "region placement is stated by the operator",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-01T06:35:55Z",
   "statement": "Two live multi-region clusters: cain-mr-01 (4 replicas, 3 regions, WireGuard) and cain-mr-02 (4 servers, 4 regions); each publishes a 30-minute signed proof of its live state, and every decision carries signatures from at least 2 regions.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; python3 verify_hourly_proofs.py <base>"
  },
  {
   "artifacts": [
    {
     "bundle": "partition-test-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "1f1d7d4a3af89f9f710aedc574a191048a5c1d7655513c185443f4135ea478c8"
    },
    {
     "bundle": "asymmetric-partition-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "3618882fe6ed8653886a92daed66009ec5d08e64c46476891f245eb70cdf97e6"
    },
    {
     "bundle": "byzantine-test-2026-09-26",
     "cluster_ids": [
      "cain-byz-01"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "940ed6cf99124c78d57d1c49f0813a5b5dc061390303a90d8a8cce646a874994"
    }
   ],
   "category": "BYZANTINE RESILIENCE",
   "claim_id": "C42-PARTITION-BYZANTINE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE",
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "partitions: whole-host link loss and complete one-way loss (deaf replica, one-way link, mute replica) for 60 s; not flapping links, partial loss, delay or duplication; Byzantine tests on a disposable cluster with the same placement; f=1, two behaviours",
   "public_label": "LIVE + DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Live network-partition tests (isolated host commits nothing; 2|2 split commits nothing on either side; agreement within ~3 s of heal) one-way (asymmetric) partitions on the 4-server cluster (deaf replica, one-way link, mute replica: commits continued, identical chains after each heal), and Byzantine tests on the production image (forged votes rejected; equivocating primary proven from its own signatures, quarantined and replaced).",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py / verify_byzantine_bundle.py"
  },
  {
   "artifacts": [
    {
     "bundle": "degraded-network-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "405e189d2ab18bbb435f10380174afc2db354d45f062ac4fe663ee2448f2d562"
    },
    {
     "bundle": "degraded-network-948b189-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "401686a4a9ad475a09f786d02760b8871336c3da61cc9bfd340b12d3e270f9f9"
    }
   ],
   "category": "BYZANTINE RESILIENCE",
   "claim_id": "C42-DEGRADED-NETWORK",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "VERIFIED is for safety only; throughput under loss is a measured weakness, not a pass; one impairment profile, one client host",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Safety under a degraded network: with 10% packet loss, 120 +/- 40 ms delay, 5% duplication and reordering on all four replicas' traffic of the live 4-server cluster for 4 minutes, no fork (identical decision chains on all four, 341 certificates each). Liveness degraded sharply: 0.16 commits/s under the impairment versus 1.76/s before (39 of 61 writes committed within the client's 30 s timeout; p95 7173.9 ms), and fully recovered after (2.02/s, p95 644.0 ms). Re-run after engine 948b189 (backoff resets only on progress): 44 of 62 committed, 0.18/s, view changes cut from 14 to at most 6; throughput did not improve beyond noise, so the view-change storm was not the bottleneck. Safety held again.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json"
  },
  {
   "artifacts": [
    {
     "bundle": "storage-loss-drill-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "987c53f1dc8af84aa8243e08a6d0b1e3661e6d774adf53055ef91651b6bed74d"
    },
    {
     "bundle": "restore-drill-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "94162b7304d9484402c253dcdb881bc30665150a9cd0845d213eb4f3e3a30969"
    },
    {
     "bundle": "restore-validation",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "validation-2026-09-27.json",
     "sha256": "e6f9a8811e14bf880ba09ef6842a271ba89d3340932ee74e1be374bb4ed8bc8c"
    }
   ],
   "category": "RECOVERY",
   "claim_id": "C42-DISASTER-RECOVERY",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "same provider; backups not encrypted at rest (they hold consensus data that is public by design; identity keys are never backed up); loss of 3 of 4 not drilled; the daily validation checks restorability of every off-host backup, it does not restore into a running replica",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-01T06:35:55Z",
   "statement": "Disaster recovery on the live clusters: two replicas lost their storage at once and were rebuilt only from off-host backups in other regions (0 of 4 writes committed while quorum was lost; 0 decisions lost; identical height and state 10.3 s after restart); a single replica restored from a snapshot in 8.3 s under writes. Hourly backups of both clusters are copied to another region; every day each replica's newest off-host backup is proven to be a quorum-signed prefix of the live history.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; daily: python3 verify_restore_validation.py <latest.json> --key <evidence-root.pub.json>"
  },
  {
   "artifacts": [
    {
     "bundle": "rollback-drill-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "ROLLBACK.json",
     "sha256": "cdf5e71eadcdd18ff55eca385990ff7ac1f3f07e2b3f94f85641a960760a76de"
    }
   ],
   "category": "RECOVERY",
   "claim_id": "C42-ROLLBACK",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 3,
   "evidence_level_meaning": "cryptographic verification",
   "limits": "both engines share one storage format",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Live rollback to the previous engine and forward again, one replica at a time with the primary last; every replica caught up in 10-14 s, cluster HEALTHY 4/4 after each direction.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "VERIFIED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "compare the per-step status in ROLLBACK.json"
  },
  {
   "artifacts": [
    {
     "bundle": "release-cain-mr-02-948b189",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "RELEASE_MANIFEST.json",
     "sha256": "bfbfcaf45ea8622f75a459fc516803efa878bf713a5f138255e3635ffcc95f89"
    },
    {
     "bundle": "release-cain-mr-02-948b189",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "verify_release_manifest.py.txt",
     "sha256": "4353e1d0c31b2b50248c3c531ce20825f82eb90ee66223331932745719a7a0ec"
    },
    {
     "bundle": "release-cain-mr-02-521f84c",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "RELEASE_MANIFEST.json",
     "sha256": "284998cc743ded062fd6845933c3beec2ac75716642da3069347e0824e99eb6c"
    }
   ],
   "category": "SUPPLY CHAIN",
   "claim_id": "C42-REPRODUCIBLE-RELEASE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "source not published: the rebuild is reproducible by the operator; outsiders can check the manifest signature and digests",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "The 4-server cluster runs an image that rebuilds bit-for-bit from its commit (two independent from-scratch builds produced the deployed image ID); pinned base and packages, SBOM, Ed25519-signed release manifest.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_release_manifest.py RELEASE_MANIFEST.json"
  },
  {
   "artifacts": [
    {
     "bundle": "hosted-consensus-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "decision.json",
     "sha256": "f9e53b72eeaedfc256eb5b7b0e426321c6aaeb63c2b5ea1e54da1fba93cdf27e"
    },
    {
     "bundle": "hosted-consensus-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qc.json",
     "sha256": "4314a03ae57da8075806951a4a999d170c5215c3cd8680a3e5633f1bc22d85ba"
    },
    {
     "bundle": "hosted-consensus-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_hosted_decision.py.txt",
     "sha256": "e3a4ceff12c81987af5672cf047ab9935e0e0d95a1ec7b61bf14e39091b1f3f1"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-HOSTED-CONSENSUS",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "enforce mode is the default for every tenant since 2026-09-27 (GET /fabric/status: mode enforce); a tenant may opt down to shadow mode (logged), in which case its verdicts are recorded but not enforced",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "The hosted Fabric orders every recorded decision through the live PBFT cluster; since 2026-09-27 the gateway itself verifies the commit quorum certificate (>= 3 pinned Ed25519 signatures over the digest it computes for that decision) and a replica's unproven 'COMMITTED' counts as a denial. Each decision shows the check (certificate hash, signers), and GET /fabric/decisions/{id}/integrity re-checks a STORED decision against the commitment the quorum signed (consensus_anchor); every stored decision record is also Ed25519-signed by a key kept outside the database (GET /fabric/decision-signing-key).",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_hosted_decision.py --live https://cainstudio.online membership.json  (see REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "decision-signing-2026-09-27",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "record.json",
     "sha256": "36472edfcda70ee1f29276daf3b7f7ed392ddbbce2f9b342b7b57deb4c0f59aa"
    },
    {
     "bundle": "decision-signing-2026-09-27",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "signing-key.json",
     "sha256": "e506f192a4f946518b781458d5fa9315451ec10138333fa37a86779d8c0ac016"
    },
    {
     "bundle": "decision-signing-2026-09-27",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "verify_decision_record.py.txt",
     "sha256": "78051196a7a7a7e288020d037366fad0a3c4f83c176d8b4469687c50547a64c6"
    }
   ],
   "category": "EVIDENCE",
   "claim_id": "C42-DECISION-RECORD-SIGNING",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "does not protect against root on the gateway host, which holds both key and database; records before 2026-09-27 are unsigned; the full row of a live decision is not public (the demo shows the gateway's own check)",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Every hosted Fabric decision record written since 2026-09-27 is signed: the gateway signs the record's SHA-256 digest with an Ed25519 key kept outside its database, so a database writer who alters a record and recomputes its digest is detected. The published record's digest is recomputed from its own fields by a verifier with no CAIN code, the signature verifies against the key served by another site, and two tampered copies (verdict changed; verdict changed with the digest recomputed) both fail.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_decision_record.py record.json --key https://mcpgate.online/fabric/decision-signing-key --self-test  (see REPRODUCE.txt)"
  },
  {
   "artifacts": [],
   "category": "DEPLOYMENT",
   "claim_id": "C42-HARDWARE-ATTESTATION",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "declared: a statement about the live servers (no TPM, SEV or TDX present)",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); attestation fields in security contexts are declared hashes, not hardware quotes; needs servers with that hardware",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Hardware-backed attestation of nodes or agents.",
   "status": "NOT_IMPLEMENTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "-"
  },
  {
   "artifacts": [
    {
     "bundle": "formal-2026-09-27",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAINPBFTCommitSafety.tla.txt",
     "sha256": "4b5dbbeda5bd6db9be9707a6e5f9dda1f0ea89656b9040e4ad018e1b134ce238"
    },
    {
     "bundle": "formal-2026-09-27",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAINPBFTCommitSafety.tlc.json",
     "sha256": "078d1bc438d8ac7bcf3113c4e8c2ed95799e8a6dcc6bece9f7a28a34536e7fcb"
    },
    {
     "bundle": "formal-2026-09-27",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAINMCPGateAuthorization.tla.txt",
     "sha256": "6a53f85d2ce4d0ac749d556cf0932dee99dbf429b27797285c0e69feb7415fbb"
    },
    {
     "bundle": "formal-2026-09-27",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAINMCPGateAuthorization.tlc.json",
     "sha256": "611048f422608b0ce3399d78dd437bc45c8638198e06b71eadc64e9901a8d712"
    }
   ],
   "category": "SECURITY",
   "claim_id": "C42-FORMAL-VERIFICATION",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "bounded models (N=4, f<=1, one sequence, two views; small action/identity/context/time domains), not a proof about the Python code; no machine-checked proof for unbounded parameters",
   "public_label": "OFFLINE VERIFIED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "TLA+ models of the PBFT commit/view-change rules and of the MCPGate authorization gate, checked exhaustively by TLC within stated bounds: no violation of Agreement, CommitOnlyWhenPrepared, no-execution-without-quorum, action/identity/context binding, expiry or single use; every deliberately broken variant (pre-fix execute rule, NEW_VIEW ignoring reports, weakened quorum, each gate check removed) is caught with a counterexample.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "java -cp tla2tools.jar tlc2.TLC -deadlock <spec> (see formal-2026-09-27/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "soak-72h-2026-09-25",
     "cluster_ids": [
      "cain42-soak72-1b28cf3"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "verify_soak.py.txt",
     "sha256": "deed0270d115ba2cf509820cc7ec464fa835c76420971921558d4e14ac1e0cb4"
    },
    {
     "bundle": "soak-72h-2026-09-25",
     "cluster_ids": [
      "cain42-soak72-1b28cf3"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "REPRODUCE.txt",
     "sha256": "afacde250be9afcf3112a6050b2eec0f67e0b77224ea985e57e6f844928c6d1d"
    },
    {
     "bundle": "soak-72h-2026-09-25",
     "cluster_ids": [
      "cain42-soak72-1b28cf3"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "checkpoint-0024.json",
     "sha256": "07cec42fd5b8456bf6b5b83560dfd4e8c18e18aa84012e7a37216c57adb1ac63"
    }
   ],
   "category": "CHAOS",
   "claim_id": "C42-SOAK-72H",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 3,
   "evidence_level_meaning": "cryptographic verification",
   "limits": "liveness failure, not a safety failure; one host; not the production cluster; the soak nodes ran image soak72-1b28cf3, without the fix; a passing 72-hour run on the fixed build is still required",
   "public_label": "FAILED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "72-hour adversarial soak (dedicated 4-node cluster, fast path + DAG, crash/restart every 10 min, started 2026-09-25T00:10Z): FAILED. PBFT stopped committing at sequence 4094 about 11 h in (2 replicas in view 39, 2 in view 40, every node HEALTHY, every later request denied), and the harness itself was killed when the host ran out of memory (last checkpoint 0024 at 24.15 h). Safety held: 0 cross-node divergences in 5,154 checks. Cause: no progress timer (only an unreachable primary triggered a view change) and NEW_VIEW replies were dropped, so a lagging replica never caught up; fixed in the engine with a regression test that reproduces the split. A new soak on the fixed build has not run.",
   "status": "FAILED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": "FAILED",
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_soak.py https://clawx.click/evidence/soak-72h-2026-09-25/  (prints VERDICT: FAIL)"
  },
  {
   "artifacts": [
    {
     "bundle": "soak-multiregion-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "REPRODUCE.txt",
     "sha256": "a981f6a68fd3104bc64f85cdc773f2f77add11d8cae7b0fcfeee35e6bccdbfef"
    },
    {
     "bundle": "soak-multiregion-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_soak.py.txt",
     "sha256": "8d9f0a48faf4fea54c38c3795d8b76103cf3dfb3bc92ffe0709a5c9825c7141d"
    },
    {
     "bundle": "soak-multiregion-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "checkpoint-0032.json",
     "sha256": "5d347d80796fff7d3c87c4ac47c8652dfa9d287930db2c7b1d5548377c25249d"
    },
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "soak_verification_transcript.txt",
     "sha256": "6620c4d6b382644169d1ffce552e0c6aa3acbc08d27c188cfe9b98b8c9a3d834"
    }
   ],
   "category": "CHAOS",
   "claim_id": "C42-SOAK-72H-MULTIREGION",
   "claim_version": 2,
   "evidence_environment": [
    "LIVE",
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 3,
   "evidence_level_meaning": "cryptographic verification",
   "limits": "one missing hourly enforcement proof, not a safety failure: consensus agreement held throughout; the cause of the hour-32 timeout is not yet diagnosed; a 72-hour run in which every checkpoint carries enforcement evidence is still required",
   "public_label": "FAILED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "72-hour soak on the live multi-region cluster cain-mr-01 on the fixed build (continuous writes, a random replica killed every 20 minutes, hourly signed hash-chained checkpoints each with an MCPGate-enforced authorization and its refused replay): FAILED by its own pre-committed rule. Checkpoint 0032 (hour 32, 2026-09-28T05:42Z) carries no MCPGate enforcement evidence -- its checkpoint authorization did not commit (CONSENSUS_TIMEOUT) -- and the verifier requires it in every checkpoint, so no later hour can turn the verdict into PASS. At 37.7 h: 107 replica kills / 107 restarts, 0 divergences, 0 anomalies, 37 of 38 checkpoints valid (48 quorum certificates each). The soak keeps running to ~2026-09-29 21:40Z for the record.",
   "status": "FAILED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": "FAILED",
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_soak.py https://clawx.click/evidence/soak-multiregion-2026-09-26/  (prints INVALID checkpoint-0032.json and VERDICT: FAIL)"
  },
  {
   "artifacts": [
    {
     "bundle": "cain45-zod-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "ZOD_RUN.json",
     "sha256": "6617e0f77463f836e03689ad44ca4a997e5a2b906484c75c7e387b7b4338ee2a"
    },
    {
     "bundle": "cain45-zod-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "EVIDENCE_CHAIN.json",
     "sha256": "9b8f04be9dad7f9519157e7cfff94f424cb1144f41d4d0bcb403b6789670ce2b"
    },
    {
     "bundle": "cain45-zod-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qcs.json",
     "sha256": "bed43b640eee07e3d7713a2955b7271c15b4661709d3592c7ca86376c93ac1fc"
    },
    {
     "bundle": "cain45-zod-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_cain45_zod.py.txt",
     "sha256": "2695e2faea451abc5d699e436f449958c93de492146caa7632d156a73f0568a4"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C45-ZOD-LIVE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "the hypervisor ran as a library on the gateway host, operator-run, not as a deployed service in front of customer agents; the approval is the operator's; software measurement only (no TPM/TEE); no seccomp filter; egress is deny-all only (no allowlist)",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Agent Hypervisor / ZoD runtime: an agent acts only inside a ZoD whose authorization the live cluster cain-mr-01 committed with a quorum certificate the hypervisor checks itself; code ran under real confinement (bubblewrap namespaces + cgroup v2, no network); 10 attacks were refused, each a signed DENIED entry in a hash-chained log.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_cain45_zod.py .  (see cain45-zod-live-2026-09-27/REPRODUCE.txt; expect 10 PASS and VERIFIED)"
  },
  {
   "artifacts": [
    {
     "bundle": "e6-live-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "LEASE_RUN.json",
     "sha256": "ed1d621e60927d8d8c3507fc35eb90df16467365329f2a6d747cbb9df822b4e2"
    },
    {
     "bundle": "e6-live-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "EVIDENCE_CHAINS.json",
     "sha256": "bc9fc9c697889499d556ebe7287a2de1c54041df3a9ff302963e69f490930786"
    },
    {
     "bundle": "e6-live-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qcs.json",
     "sha256": "a290fb7d1ef584def0c585c4bf8fd175f342777f285255d695aa4823ccdd77b7"
    },
    {
     "bundle": "e6-live-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_e6_lease.py.txt",
     "sha256": "8ddcee34f1b1bbedd4682229079d3d458cc58006a51ab49ad1b8bc576d4e8b70"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E6-AUTHORITY-LEASES",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "the invalidation logic runs in the hypervisor library on the gateway host, not on the cluster nodes -- the cluster supplies the authority being invalidated; invalidation on policy, epoch or membership change and risk/blast-radius budgets are NOT implemented; the separate 4-node 'authoritative state' layer in cain45/ is SIMULATED and not used here",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Evolution #6 authority leases: for each of 9 conditions a ZoD authorized by the live cluster cain-mr-01 made one successful tool call, the condition was tripped, and the next call was refused without the tool running -- TTL expiry, trust below floor, agent identity swapped, tool schema changed, security context changed, trajectory fork, explicit revocation, parent quarantined (child loses authority), required evidence deleted (that row is SELF-REPORTED: hypervisor-signed, since the log proving it is the one deleted).",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e6_lease.py .  (see e6-live-lease-2026-09-28/REPRODUCE.txt; expect 48/48 checks, VERIFIED)"
  },
  {
   "artifacts": [
    {
     "bundle": "e7-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "LEASE_RUN.json",
     "sha256": "f556b47e040ce60164e803b1398bc0037ba03118ae925e11bad4deed38bddd96"
    },
    {
     "bundle": "e7-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "EVIDENCE_CHAINS.json",
     "sha256": "cd180b374770996e27db226de6053a49bb0e238a697b784565d730979665cd03"
    },
    {
     "bundle": "e7-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qcs.json",
     "sha256": "150c876ed848d7ffed71ea5e538a008e0f4529f56e08030e23f8822978dbbd58"
    },
    {
     "bundle": "e7-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_e7_lease.py.txt",
     "sha256": "26bac3bae9673597e41a63fa40f523f2347977c54c00c67d90e400c610168039"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E7-AUTHORITY-LAPSE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "the 3 membership/epoch trips are INJECTED into the hypervisor's view (the live cluster was not re-keyed); the policy and budget trips are real; enforcement is the hypervisor library on the gateway host, not the cluster nodes; only CALL_MCP_TOOL budgets were exercised live (classes C0-C4 unit-tested)",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Evolution #7: authority granted by the live cluster cain-mr-01 lapses -- the next tool call is refused and the tool never runs -- when the policy root changes or cannot be read, when the risk or blast-radius budget is spent, and when a delegate has spent its parent's budget (delegates are charged up the whole chain, so splitting work cannot multiply authority). Every ZoD is bound to the cluster's real membership configuration, recomputed and quorum-agreed, re-read before every action; a changed epoch, a changed membership or an unknown membership refuses.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e7_lease.py .  (see e7-lease-2026-09-28/REPRODUCE.txt; expect 60/60 checks, VERIFIED)"
  },
  {
   "artifacts": [
    {
     "bundle": "e8-governance-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "GOVERNANCE_RUN.json",
     "sha256": "88aab8c5ecba00a23fb587de273fd883e676f2b18bde610d2288334397c12e94"
    },
    {
     "bundle": "e8-governance-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "EVIDENCE_CHAIN.json",
     "sha256": "fb44b81bddbaa2e42a993333f78f851f20c22d63a4efa52d29bbc7271409cbb9"
    },
    {
     "bundle": "e8-governance-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qcs.json",
     "sha256": "0e1bea55cebc3f67f40ec5dee89cc5b4b1db2b5785fbb0dad1b53c7ae5f91e3f"
    },
    {
     "bundle": "e8-governance-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_e8_governance.py.txt",
     "sha256": "0fd608899c72c9209b797f23be415ee2076e0301c160ce2e32f52939b1210958"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E8-GOVERNED-EVOLUTION",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "scripted identities, not a real LLM agent; CAIN contains no world model, digital twin or learning memory -- the run shows that such OUTPUTS cannot become authority; governor and hypervisor are a library on the gateway host, the cluster orders and certifies",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "Evolutions #8/#9: a policy -- the authority ceiling for a tenant's ZoDs -- becomes active only when the live cluster cain-mr-01 commits its activation; an expansion needs a registered human who is not the proposer (an agent's self-approved expansion was refused and never reached the cluster); a restriction needs no human and revoked a running ZoD's authority; a ZoD above the ceiling was refused. A world-model prediction, a simulated ALLOW citing a real certified sequence, a 10-agent signed vote and a replayed memory were each presented as the basis for authority and each refused because the live cluster had not certified it.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e8_governance.py .  (see e8-governance-2026-09-28/REPRODUCE.txt; expect 19/19 checks, VERIFIED)"
  },
  {
   "artifacts": [
    {
     "bundle": "cag-l5-hosted-governor-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_CAG_L5_HOSTED_LIVE_RUN.json",
     "sha256": "105c50c212700461c76fcb5373872785983add85ec9450ef0fb0383a4b3015ed"
    },
    {
     "bundle": "cag-l5-hosted-governor-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_hosted_governor_run.py.txt",
     "sha256": "e07672365742b6b916c15b711d18ef2a5551a4e4b7d95d48278b91c764930561"
    },
    {
     "bundle": "cag-l5-hosted-governor-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_CAG_L5_VERIFICATION_MATRIX.json",
     "sha256": "ff1d184b1c8c34d562c73eea205eaf887bb568372b9f5c7ae032f9db3b75cf97"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-CAG-L5-HOSTED-GOVERNOR",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "operator self-test tenant and a scripted agent -- no customer and no LLM agent governed end to end; the endpoint returns a signed verdict and commitment, the caller's gate executes; CAG-L5 is CAIN's own governance designation, not SAE Level 5; see the matrix for which capabilities are only PARTIAL",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "The CAG-L5 system governor runs in the production gateway (CAIN_SYSTEM_GOVERNOR=1): /fabric/mcp/enforce refuses every tenant without a registered, governance-signed system manifest and every request not signed by the agent's registered key, and for a registered system applies policy precedence, the agent/delegator/system/lease authority intersection, model identity, tool registry, emergency controls and cluster-certified governance state. On the live gateway, through all three public domains: 13/13 cases as expected (in-scope read allowed on each domain; unregistered tenant, unsigned, key substitution, replay, outside system authority, model swap, subagent WRITE, unlisted tool and emergency freeze refused; one-operator recovery refused, two-operator recovery restored service); governance state certified by cain-mr-01 (3 signers); 8/8 decision signatures valid; 18-event chain verifies.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_hosted_governor_run.py CAIN42_CAG_L5_HOSTED_LIVE_RUN.json --live  (see cag-l5-hosted-governor-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAIN42_CAG_L5_SYSTEM_BUNDLE.json",
     "sha256": "11cb0a33b7e737b5c08b686c7aac8463e86a6d145c05bc014a86819dd2969c42"
    },
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "verify_system_bundle.py.txt",
     "sha256": "bfe8a4b017f9c762444214b42814487c859c24398980c5cee2446bb87377df4f"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-CAG-L5-SYSTEM-GOVERNANCE",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "reference system with ephemeral keys, run in one process; the live counterpart is C42-CAG-L5-HOSTED-GOVERNOR",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "The CAG-L5 system-governance library composes emergency freeze, 2f+1 governance-state quorum, attested state, a signed system manifest, model identity, tool registry, exact-capability resource checks, deterministic policy precedence, authority intersection, trajectory authorization and graph-derived blast radius with two-operator step-up; Part 41 Tests A-N all behave as specified, and a clean-room verifier recomputes policy, authority, blast radius, quorum and step-up for every decision and rejects a CAIN-signed but unjustified ALLOW.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_system_bundle.py CAIN42_CAG_L5_SYSTEM_BUNDLE.json  (expect 148/148 VALID)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAIN42_L5_TRAJECTORY_BUNDLE.json",
     "sha256": "760d5744b6cf861a3a274f2b694aa5503b5018b3950396a2759471d6dfd8e68d"
    },
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "verify_l5_unified.py.txt",
     "sha256": "231435515c65bea6e2285ab658024fef05e788a3f9b7509b06ec51643e833418"
    }
   ],
   "category": "TRAJECTORY GOVERNANCE",
   "claim_id": "C42-L5-TRAJECTORY-GOVERNANCE",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "library; ephemeral keys; the hosted governor uses it for every decision but long live trajectories were not run",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Continuous trajectory governance: a lease authorizes only if signed by a governance key (never the agent's), bound to the agent and trajectory, time-bounded (<= 1 h) and fully scoped; only ACTIVE/LIMITED trajectories act; containment only tightens; plan, intent, action, parameters, resource and context must match the governance-bound plan; subagent risk is charged to every ancestor. A clean-room verifier recomputes the decision and 9 adversarial requests (43/43 VALID).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": [
    "C42-L5-UNIFIED-V1-SUPERSEDED"
   ],
   "verification_method": "python3 verify_l5_unified.py CAIN42_L5_TRAJECTORY_BUNDLE.json  (expect 43/43 VALID)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAIN42_L5_TRAJECTORY_FAIL_OPEN_PROBES.json",
     "sha256": "a4facfb8103b1bfa87e228426b9dc1a9449c2a1abd791b0a29775f73c622cce1"
    },
    {
     "bundle": "l5-governance-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SUPERSEDED.txt",
     "sha256": "80a2a239868c3dffaca1d4a72cedf37b1b3ab72b01fb78b0011c8d38d87eb42e"
    }
   ],
   "category": "TRAJECTORY GOVERNANCE",
   "claim_id": "C42-L5-TRAJECTORY-FAIL-OPEN-FOUND",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE",
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "the 'before' column is the recorded probe output, not re-runnable from git history",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Negative evidence: the first continuous-authorization implementation (uncommitted, published earlier on 2026-09-28) failed 13 of 13 probes -- self-signed, unsigned, foreign or unbounded leases, empty scope, missing policy/context, PAUSED/ESCALATED/REAUTHORIZATION_REQUIRED trajectories and unchecked plan binding were ALLOWed; containment could revive a TERMINATED trajectory. 5 of its 15 invariants were the constant True. All fixed in 040cee2 with regression tests.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "tests/test_cain42_l5_trajectory_prompt3.py::test_R01..R13 (the pre-fix code was never committed; its outputs are the recorded probe run)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-authority-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAIN42_L5_AUTHORITY_BUNDLE.json",
     "sha256": "1d9554a3731801cba457b949487413a4a2cbefc3fc9c7716c334ed7cb7194557"
    },
    {
     "bundle": "l5-authority-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "verify_authority_bundle.py.txt",
     "sha256": "0996d6ca0ca6b65b17196bb051e09d168b94fa5d0a375ed44c86beee9492479a"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-L5-IDENTITY-AUTHORITY",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "library; the hosted L5 identity router is opt-in (CAIN_L5_GATEWAY) and off",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Agent identity and dynamic authority: signed versioned agent identities with key lifecycle; capability-, resource- and time-bounded grants; non-escalating delegation; explainable authorization decisions. Two separately written clean-room verifiers return VALID on the published bundle and refuse 25 attack classes.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_authority_bundle.py CAIN42_L5_AUTHORITY_BUNDLE.json"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-governance-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SUPERSEDED.txt",
     "sha256": "80a2a239868c3dffaca1d4a72cedf37b1b3ab72b01fb78b0011c8d38d87eb42e"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-L5-UNIFIED-V1-SUPERSEDED",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "kept for history; must not be read as a current claim",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "SUPERSEDED: the l5-governance-2026-09-28 unified bundle's trajectory ALLOW and its 15/15 trajectory invariants. The ALLOW came from the fail-open authorizer and 5 invariants were constant True. The bundle stays byte-identical for history; the replacement is C42-L5-TRAJECTORY-GOVERNANCE.",
   "status": "UNVERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "SUPERSEDED",
    "superseded_by": [
     "C42-L5-TRAJECTORY-GOVERNANCE"
    ]
   },
   "supersedes": null,
   "verification_method": "-"
  },
  {
   "artifacts": [],
   "category": "EVIDENCE",
   "claim_id": "C42-LEGACY-SELF-ASSERTED",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "declared: a statement about files published by earlier releases; nothing was run",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "self-asserted by earlier releases; no certification body, no reproducible verifier; found by the public evidence inventory (CAIN42_PUBLIC_EVIDENCE_INVENTORY.json)",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Seven older files still served on the sites assert strong statuses that no evidence in this registry supports: CAIN42_BYZANTINE_CERTIFICATION.json (CERTIFIED), CAIN42_ENTERPRISE_PERMANENT_MEMORY.json (A_PLUS_ENTERPRISE_CERTIFIED), CAIN42_RELEASE_MANIFEST.json (PRODUCTION_HARDENED) on clawx.click/evidence/; CAIN_13_STATUS.json and v13/CAIN_13_STATUS.json (OPERATIONAL_PROVEN), cain_14_agentic_trust_evidence.json and v2/kernel-self-defense-evidence.json (OPERATIONAL_AND_VERIFIED) on /proof/bundle/. They are kept for history; their statuses are SUPERSEDED by this registry and must not be read as current claims.",
   "status": "UNVERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "-"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-adaptive-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_L5_ADAPTIVE_BUNDLE.json",
     "sha256": "f08123b921803c4c87aaab29e6cadf1f36ea42a9d24860424b0884fa64725cc1"
    },
    {
     "bundle": "l5-adaptive-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_adaptive_bundle.py.txt",
     "sha256": "f8a9c356c140196a660efa43c214e3e3a9c0005e031dbca3f73767799afc66c8"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-L5-ADAPTIVE-EVOLUTION",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "in-process library, NOT wired into the hosted gateway or MCPGate; deterministic reference runner, no LLM; no multi-day run; role keys are generated fresh for each build, so the bundle shows internal consistency and decision correctness, not provenance, and it is not signed by the evidence-root key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Governed adaptive evolution (Prompt 6): a proposed change to an agent's memory, skills, tools or model routing becomes active only through an evolution gate; a clean-room verifier recomputes all 11 recorded evolution decisions (1 ACCEPT, 1 REQUIRE_APPROVAL deployed only with operator approval, 6 REJECT, 3 QUARANTINE), 143 checks VALID, and rejects a CAIN-signed but unjustified ACCEPT plus 10 tamper classes. Negative evidence: the first version was fail-open on 32 of 32 independent probes (and an earlier 33/33 invariant result was measured against it); fixed in 71eecdb, 0 open.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_adaptive_bundle.py CAIN42_L5_ADAPTIVE_BUNDLE.json  (expect VALID, 143 checks, 11 decisions recomputed)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-hosted-evolution-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN.json",
     "sha256": "1487c342a84d125a14eca9131bf8a30d98e61c7a5e0dc1ed60460e6e548272b7"
    },
    {
     "bundle": "l5-hosted-evolution-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN_EXPORT.json",
     "sha256": "a23711b93139e00ac87dcb0fda5124d63d80a81c30212c4da1d8f4ab924dac77"
    },
    {
     "bundle": "l5-hosted-evolution-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_hosted_evolution_run.py.txt",
     "sha256": "7e1a0271b43f343f52658b32741ebdd5ef5092d1ee8424c447e2061df8d37a6e"
    },
    {
     "bundle": "l5-hosted-evolution-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_adaptive_bundle.py.txt",
     "sha256": "f8a9c356c140196a660efa43c214e3e3a9c0005e031dbca3f73767799afc66c8"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-L5-ADAPTIVE-HOSTED-EVOLUTION",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "operator self-test tenant, scripted agent and scripted evaluator -- no customer and no LLM agent; hosted evolution covers MODEL and TOOL_CONFIGURATION only (authority is never evolvable; memory/skill/model-router registries are not hosted); rollback is operator-signed, automatic regression rollback is not wired; the evaluator's raw measurements are not recomputed; PRE-PRODUCTION",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "The Prompt 6 evolution gate is wired into the production gateway and MCPGate: after registration an agent's model and MCP tool configuration change only through it (agent-signed proposal, tenant-evaluator-signed report, operator approval that is never the proposer), and a deployed change gives a new capability commitment, so the old cluster certificate and every lease stop authorizing until cain-mr-01 certifies the new commitment and a lease is re-issued. Live, through all three public domains: 17/17 enforcement cases as expected (model swapped outside the gate, old lease after a capability change, the disabled tool on each domain and the rolled-back model refused; the enabled tool, the upgraded model and the restored version allowed); gate refusals: no evaluator report REJECT, authority-widening tool change QUARANTINE and undeployable, unapproved model REJECT, deploy without approval or with the agent's own approval refused, agent-signed rollback refused; 4 cain-mr-01 certifications (sequences 22515, 22517, 22518, 22517) whose own records carry each certified commitment; 42-event chain verifies; a clean-room verifier recomputes all 5 hosted evolution decisions (VALID). Found and fixed on the way: the certified governance state did not cover the MCP tool map or per-agent tool configuration.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_hosted_evolution_run.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN.json --live ; python3 verify_adaptive_bundle.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN_EXPORT.json  (see l5-hosted-evolution-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "trust-integrity-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_TRUST_INTEGRITY_LIVE_RUN.json",
     "sha256": "cf2b275c0e552e142185d8fc50fafbfe469c323522eb9fe439243c32666b43cc"
    },
    {
     "bundle": "trust-integrity-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_trust_integrity_run.py.txt",
     "sha256": "45b98bc0ac2ef600ae5210059512ebf07b94f24adfa1ce228672289926df6b0c"
    },
    {
     "bundle": "trust-integrity-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_transcript.txt",
     "sha256": "8d7f21a7ee39eb0197e88ec2c259d3b7fa5690a08ff7ddbb037be393438cfccf"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-TRUST-INTEGRITY-LIVE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "action risk reads the tool name and arguments the agent declares, so a tool whose name hides what it does is scored on its arguments only; decision latency is unchanged (about 1.2 to 14 s in this run); signup has no email delivery or captcha; operator-run accounts, no customer traffic; no third-party review; PRE-PRODUCTION",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "A caught attacker no longer gains autonomy on the production gateway. Before 2026-09-28 a new account that sent two prompt injections (both BLOCKED) fell from UNKNOWN to DEGRADED trust, which the matrix answered more permissively than UNKNOWN, so its $250,000 transfer, rm -rf / and DROP TABLE came back ALLOWED. Now the trust matrix is monotone with a runtime floor (no state carrying negative evidence beats UNKNOWN), the independent verifier builds its table from a published spec instead of copying production, every action is scored by tool class, destructiveness, amount and target (high and critical go to a human), deny rules match every spelling of a path, trust is per agent and capped by its key, a trust hold is queued for approval, an approval binds the call's arguments, and an account can mint agent keys so the agent asks and the owner approves. Live, with a fresh free account on each of cainstudio.online, mcpgate.online and clawx.click: every case as specified, including the solo-developer path (agent held, cannot approve itself, owner approves, retry runs, its next low-risk call runs with no approval, a critical action is still held), and all 48 decisions match cain-mr-01's own public record (decision id, verdict, commitment, 3-of-4 commit certificate); clean-room verifier VALID.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_trust_integrity_run.py CAIN42_TRUST_INTEGRITY_LIVE_RUN.json --live  (see trust-integrity-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e15-spatial-physical-intelligence-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_EVOLUTION15_MASTER_PROOF.json",
     "sha256": "9957445a94cf14ba3817b77de59414ee14c53b234f1dfcaa4d620f94d1ac75e1"
    },
    {
     "bundle": "e15-spatial-physical-intelligence-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "b1cce09fef6e2d253932ee6505291ce93c280a7e9eeed162430bd57e3031ea37"
    },
    {
     "bundle": "e15-spatial-physical-intelligence-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END_DEMO.json",
     "sha256": "d41592e1ad486eaac4c5962055140931456484f25f4291077fb47c1ea7e34359"
    },
    {
     "bundle": "e15-spatial-physical-intelligence-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e15.py.txt",
     "sha256": "314b76e83aa2b16a333bf18dbdbc1258137fd3275a69bbcabc5d6d176bbec7ae"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E15-SPATIAL-PHYSICAL",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against a REFERENCE robot adapter and a reference kinematic simulator; CAIN-42 is not a vehicle or a robot, drives nothing and does not guarantee physical safety; no real sensor, vehicle, robot or actuator integration (NOT_IMPLEMENTED); sensor keys are software keys (hardware attestation UNKNOWN); world-model accuracy and sim-to-real fidelity UNKNOWN; real-world attack validation NOT_PERFORMED; not hosted; single host; proof signed with an ephemeral build key; no third-party review; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Evolution 15 (spatial + physical intelligence governance) is a TESTED library that brings sensor observations, world state, world-model output, simulation, trajectories and physical actions into CAIN-42's governed trust path. Signed sensor observations are admitted through the E12 evidence layer; the world state is versioned, hash-chained and replayable and binds every ingested observation; a world model's output is PREDICTED evidence bound to its model, configuration, world state and scenario, never authority; a trajectory is a proposal until a signed approval binds it; every physical action binds nine digests (world state, trajectory, decision, capability, authority, policy, risk, consequence, authorization), crosses the E8 commit boundary and reaches an actuator adapter only with a single-use, short-lived permit for that exact command; material reality drift invalidates the authorization and forces re-evaluation or a safe state. P1-P36 36/36 hold; the CAIN-42-E15-Spatial-Physical-Bench contains 55/55 attacks; the 19-step end-to-end run and all 7 deliberate mutations behave as specified; digital, physical and hybrid agents converge on one path; clean-room verifier INTACT.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e15.py <bundle dir>  (see e15-spatial-physical-intelligence-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_EVOLUTION17_MASTER_PROOF.json",
     "sha256": "5cdf9171a4ae94eff42b0d881b523fee95c5a99dd5e5a4506a451312ed45b66a"
    },
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "9f8b2347d9abde8f7123ea5485ad8a8e8cd3197a1e3503ef8bb8b16043b6e1fc"
    },
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END_DEMO.json",
     "sha256": "d26833da1cda93a401ab7e74000a2e1bf99c9c6d2077818e996911e8c2b13c83"
    },
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "COMMIT_EXAMPLES.json",
     "sha256": "e1e42cb0813731a78e2cee3c1c710ea5d9b58a08d36a3c56261de376bfa3a671"
    },
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e17.py.txt",
     "sha256": "ee97fe461d2653e48890a0e3ce0cdc75007840bd4326963f42c3c89e5c2be401"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E17-MULTI-AGENT",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against a governed REFERENCE collective; CAIN-42 deploys no fleet, robot, drone, vehicle or customer collective and drives nothing; no real sensor/actuator integration and no deployed multi-agent collective (NOT_IMPLEMENTED); no hardware attestation (UNKNOWN); Sybil-detection completeness and the semantic truth of observations, predictions or causal claims are UNKNOWN; world-model accuracy and sim-to-real fidelity UNKNOWN; real-world attack validation and third-party review NOT_PERFORMED; not hosted; single host; proof signed with an ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Evolution 17 (governed multi-agent world action fabric) is a TESTED library that governs action by autonomous agent teams as a first-class system object: a collective is not the sum of its members and a collective action is not the sum of member actions. Collective authority is a constrained INTERSECTION of the governing grant, the mission capabilities, policy and live member authority, never a sum; majority, consensus, negotiation, contracts, roles, membership, coalitions, delegation, subagents, emergence and self-improvement cannot create or amplify authority; a material mission/membership/world-state/causal/topology drift forces reauthorization or a safer decision; dissent is preserved; a world-state fork blocks authorization until reconciliation; a collective trajectory is a proposal; and one action that would fan out to many agents is pre-authorized. Every consequential collective action binds fifteen digests and reaches the E8 governance kernel, and the boundary itself enforces the risk, policy, world-state, authority, decision and consequence verdicts it binds (a consistently re-signed refusal is still refused). Q01-Q61 61/61 hold; the CAIN-42-E17-Multi-Agent-Bench contains 91/91 entries (88 distinct attacks); the 18-step end-to-end run and all 12 deliberate mutations behave as specified; the clean-room verifier returns INTACT (92 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e17.py <bundle dir>  (see e17-multi-agent-world-action-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_EVOLUTION18_MASTER_PROOF.json",
     "sha256": "44c91636b6c8ca33c062b82a79c3e0d25efa65ac891991555a4435fe3320e640"
    },
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "67e05c757e714c2a132f0a1082263ae05f38180d28001c2f99ad331d9f3211ef"
    },
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END_DEMO.json",
     "sha256": "618ac511016dfee612b2dbbdb834356a367810f01a7a579d5582def4c0ea8728"
    },
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "COMMIT_EXAMPLES.json",
     "sha256": "46816dcd70c6f5255ffea609dfaa049061e0b9cffb1ac5316d12c32f6dc67cd4"
    },
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e18.py.txt",
     "sha256": "9de07433810550c84dc523ee1966d10e7f8dbc458586f71db2024adb05857dcb"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E18-4D-SPATIAL",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against a governed REFERENCE 4D world; CAIN-42 contains no autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack and drives nothing; no real vehicle / drone / robot / sensor / actuator / airspace integration (NOT_IMPLEMENTED); no physical safety guarantee and no certified autonomy (NOT_IMPLEMENTED); hardware attestation (UNKNOWN); world-model and prediction accuracy and sim-to-real fidelity (UNKNOWN); real sensor validation and real-world adversarial validation (NOT_PERFORMED); third-party review (NOT_PERFORMED); not hosted; single host; proof signed with an ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Evolution 18 (4D spatial autonomy fabric) is a TESTED library that governs proposals from autonomous systems across a predictive 4D world: entity state at (X,Y,Z,T) with uncollapsed uncertainty; reachable / policy-permitted / authorized sets kept distinct; probabilistic intent; multiple predicted trajectories; an interaction graph and a conflict field that is not distance-only; time-to-consequence with uncertainty; dynamic signed geofences; governed airspace and roadspace; spatial policy that yields ELIGIBILITY not authorization; multimodal sensor fusion; world-model arbitration that never simply picks the highest confidence; counterfactual future trees; actionability states; a conserved uncertainty budget; a micro-authorization loop; and a reality-gap monitor. Every consequential spatial action binds sixteen digests and reaches the E8 governance kernel, and the boundary itself enforces the policy, actionability, authority, risk and uncertainty verdicts it binds (a consistently re-signed refusal is still refused); AUTHORIZATION IS A FUNCTION OF WORLD STATE and if a material input changes it must be revalidated. Q01-Q89 89/89 hold; the CAIN-42-E18-Spatial-Autonomy-Bench contains 123/123 entries (109 distinct attacks plus 14 invariants re-run as scenarios); the 20-step end-to-end run, its unmutated control and all 12 deliberate mutations behave as specified; the clean-room verifier returns INTACT (111 checks, no CAIN imports). ACTIONABILITY IS NOT AUTHORIZATION. REACHABILITY IS NOT PERMISSION. PREDICTION IS NOT REALITY.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e18.py <bundle dir>  (see e18-4d-spatial-autonomy-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E19_EVIDENCE_BUNDLE.json",
     "sha256": "1b1a8c688b635423af17cc344e68be009cba36dd25fcc874961777770073287e"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "0a7f826fcfe5d8239ea2e22a239383a39d5012d8632a9cf69f1217e691a1a4a4"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "3c65e7413b96502cbcb29a17543076893588b84e49c103f9e8da6fb718347a31"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END_RESULTS.json",
     "sha256": "2eda80387a458f82558e00864e369754657335020a69e4c98e9a3c0e8948c88b"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "8594220cd7cdf9d65f923978de2d2d084294e2cc64d7c5fd85f0b88cd9afe89d"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e19.py.txt",
     "sha256": "f2cd70a3a51ef8bdb1678a1d375d12de9b1b6169ef71ac06fb8edf2606e5a29c"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E19-GOVERNED-AUTONOMY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against a governed REFERENCE system (a digital agent, a vehicle abstraction, a drone abstraction, a collective and a human in the E18 4D world); execution in the scenario is SIMULATED; CAIN-42 drives, flies and controls nothing and guarantees no physical safety (NOT_IMPLEMENTED); not hosted (NOT_IMPLEMENTED); semantic truth of beliefs and outcomes and hardware attestation UNKNOWN; multi-host behaviour UNVERIFIED; real-world adversarial validation and third-party review NOT_PERFORMED; single host; proof signed with an ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Evolution 19 (governed autonomy operating fabric) is a TESTED library that governs the evolving state of an autonomous system: identity, mission, goals, beliefs, memory, models, learning, authority, world, outcomes and recovery are hash-chained governed state; effective authority is the intersection of sixteen factors (a missing factor is UNKNOWN and empties it; confidence, peer agreement, learning, plans, predictions and compute are not factors); autonomy levels are derived from evidence; a subgoal never exceeds its parent or its mission; memory never becomes policy or authority; a learned change to authority needs a constitutional quorum; and every consequential action carries a sixteen-field action contract that any material state change invalidates and whose verdicts the gate enforces itself before the E8 kernel commits it -- a consistently re-signed refusal is still refused. G1-G108 108/108 hold; the CAIN-42-E19-Governed-Autonomy-Bench contains 189/189 entries (177 distinct attacks); a mutation self-test shows that removing any of four defenses is caught; the 19-stage end-to-end run and all 20 stage attacks behave as specified; the clean-room verifier returns INTACT (117 checks, no CAIN imports). AUTONOMY IS NOT AUTHORITY.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e19.py <bundle dir>  (see e19-governed-autonomy-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "MANIFEST.json",
     "sha256": "eae407b62ada12d041469ca7bf152d60c920300674f245eeed02d352c8f71894"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "BUILD_MANIFEST.json",
     "sha256": "73c2eef47cfd125f20569f16eb6d67dd7bae8d6e8de327ae9f153024c488a1b5"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "DEPLOYMENT_ATTESTATION.json",
     "sha256": "1f024bd40627590c096262ffa3d604e2b69c7b35f312216835ac478479cf4834"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "SBOM.cdx.json",
     "sha256": "06fd9361f4fae497042e534409f491a9e4f2fe6fc2b6593598a847effb2e5a22"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "TEST_VECTORS.json",
     "sha256": "31dd775521e4694fe22a90289d8df9a6890aec74e12350126dc60b2307b75253"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "verify_proof_fabric.py.txt",
     "sha256": "c5788943a71a73a049a1eb3616a5ad98092c12b03f8f1bc09b7a1188b56dc816"
    }
   ],
   "category": "EVIDENCE",
   "claim_id": "C42-PUBLIC-PROOF-FABRIC",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "software measurement by the operator, not hardware attestation; the gateway has no build step and its source is not public, so the artifact can be hash-checked but not rebuilt by a stranger; the performance index shows every published benchmark lacks at least one required condition",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "The CAIN-42 public proof fabric is published and verifiable by anyone: a build manifest and per-file artifact list of the running gateway (990 source files, 958 byte-identical to the commit, the other 32 named), a CycloneDX SBOM (177 installed distributions with content hashes) and a dependency-drift record, a deployment attestation (deployment id, configuration hash of non-secret switches, running code == artifact, hardware attestation NOT AVAILABLE), a test manifest from a real run with its JUnit XML, 76 public test vectors, a provenance graph, a failure ledger, and Byzantine and performance indexes, all signed by the evidence-root key; a clean-room verifier recomputes every value.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric-2026-09-28/  (see its REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "TEST_MANIFEST.json",
     "sha256": "53e44b5cfcc4343a5a495c2671ce545c55cba6d8bc0a143d60eb3a39209645da"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "verify_proof_fabric.py.txt",
     "sha256": "c5788943a71a73a049a1eb3616a5ad98092c12b03f8f1bc09b7a1188b56dc816"
    }
   ],
   "category": "EVIDENCE",
   "claim_id": "C42-TEST-SUITE-RUN",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "operator-run on the gateway host, not independent CI; the suites need the repository, which is not public",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-10-29T06:35:55Z",
   "statement": "A real run of the defined CAIN-42 suites (site, l5-governance, hypervisor, mcp-enforcement, byzantine, gateway): 1857 tests, 1842 passed, 0 failed, 0 errors, 7 skipped, 8 expected failures (documented known gaps). Each test is listed with its purpose, category, file hash and JUnit evidence.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric-2026-09-28/  (checks the totals against the published JUnit XML)"
  },
  {
   "artifacts": [],
   "category": "COMPLIANCE",
   "claim_id": "C42-THIRD-PARTY-REVIEW",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "declared: no review exists; nothing to observe",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "none exists",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-12-28T06:35:55Z",
   "statement": "Independent third-party review or certification (SOC 2, ISO 27001, FedRAMP, ...).",
   "status": "NOT_IMPLEMENTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "-"
  }
 ],
 "evidence_root_public_key_b64": "t1I4vBpOasgbBSWYTN2g7xL1En7qZ6lhgbt6n2OpeG8=",
 "git_commit": "bcd6ba358f0f4ab0bc41d647ff76ccec69cbef17",
 "issued_at": "2026-09-29T06:35:57Z",
 "key_epoch": 1,
 "label_rule": "public_label = f(status, evidence_environment): FAILED; UNVERIFIED/NOT_IMPLEMENTED -> NOT ESTABLISHED; SIMULATED; VERIFIED/REPRODUCIBLE -> '<environments> VERIFIED'; otherwise IMPLEMENTED. A claim past revalidate_by is STALE until re-issued from fresh evidence.",
 "live_clusters": [
  "cain-mr-01",
  "cain-mr-02"
 ],
 "live_topology": {
  "cain-mr-01": {
   "key_fingerprint": "2f46fc4814549cfa551ac58182edca4245e47c3c38251ee11dc847d54bab8e28",
   "members": [
    {
     "node_id": "cain-mr-node-1",
     "provider": "vultr",
     "public_key_b64": "vxjpwp7HlNHusE21m1bcLDy8CwNbErxp9FtJCrctbdE=",
     "region": "atl"
    },
    {
     "node_id": "cain-mr-node-2",
     "provider": "vultr",
     "public_key_b64": "riT7vpUegPEUR8orAqgcpEpdY8YI2mGYXHdkIpju3KE=",
     "region": "lax"
    },
    {
     "node_id": "cain-mr-node-3",
     "provider": "vultr",
     "public_key_b64": "05ABjKsgxxCqhgfZJ9DtjnDENO8kSd82WqLfrRUq6Qw=",
     "region": "lax"
    },
    {
     "node_id": "cain-mr-node-4",
     "provider": "vultr",
     "public_key_b64": "QO/JXphJ858ZBu0wpCXTHcskThjkid68PfsfBjHhaZ0=",
     "region": "mia"
    }
   ],
   "membership_url": "https://cainstudio.online/api/v1/live-cluster/membership?cluster=cain-mr-01",
   "providers": [
    "vultr"
   ],
   "regions": [
    "atl",
    "lax",
    "mia"
   ]
  },
  "cain-mr-02": {
   "key_fingerprint": "5676a770d81add674e35e7765dc935519672099cb10c4ed8745e5284cc2c05ab",
   "members": [
    {
     "node_id": "cain-mr2-node-1",
     "provider": "vultr",
     "public_key_b64": "8P4PCtI04O2rvGpeOufwkU1RJnPdjMjth+L/UcerxI4=",
     "region": "atl"
    },
    {
     "node_id": "cain-mr2-node-2",
     "provider": "vultr",
     "public_key_b64": "u3OhqYRLR2Rys0byPlSE1vHcjPWVSLt3j4XzMv2EwGs=",
     "region": "lax"
    },
    {
     "node_id": "cain-mr2-node-3",
     "provider": "vultr",
     "public_key_b64": "+x/1i4xlleDAdLt6vNaNfFaGVn8yo/N35Ax0mYAv2F8=",
     "region": "mia"
    },
    {
     "node_id": "cain-mr2-node-4",
     "provider": "vultr",
     "public_key_b64": "SqIx0XEixGU8RzpKPmVxA9P6k4udhRFeMx4CPTedc+o=",
     "region": "sjc"
    }
   ],
   "membership_url": "https://cainstudio.online/api/v1/live-cluster/membership?cluster=cain-mr-02",
   "providers": [
    "vultr"
   ],
   "regions": [
    "atl",
    "lax",
    "mia",
    "sjc"
   ]
  }
 },
 "registry": "CAIN42/PUBLIC-CLAIMS/v2",
 "registry_digest": "d5468d2e84a500f0689b7c919b34748535b7116bde87c476315049fe028ca79c",
 "registry_locations": [
  "https://cainstudio.online/proof/bundle/claims/",
  "https://mcpgate.online/proof/bundle/claims/",
  "https://clawx.click/evidence/claims/"
 ],
 "signature_b64": "X6l5c+XXeBSvbls3tH8CE3YFTUVzmJcGZ5XwJP/umNtFo+WFfycKK9SHqpS68JMTo36ujoav54MNtQgdC4HlCg==",
 "sites": {
  "cainstudio.online": "/proof/bundle/",
  "clawx.click": "/evidence/",
  "mcpgate.online": "/proof/bundle/"
 },
 "status_model": {
  "rule": "CLAIMED: asserted, no evidence; TESTED: automated tests (a FAILED result stays TESTED with result FAILED); VERIFIED: checked; REPRODUCIBLE: VERIFIED and a public verifier anyone can run is published; SUPERSEDED: replaced, kept for history; INDEPENDENTLY_VERIFIED: only by a distinct external process -- none exists",
  "states": [
   "DRAFT",
   "CLAIMED",
   "TESTED",
   "VERIFIED",
   "INDEPENDENTLY_VERIFIED",
   "REPRODUCIBLE",
   "SUPERSEDED",
   "REVOKED"
  ]
 }
}