CAIN-42 Prompt 3 + Prompt 4 evidence (2026-09-28) ================================================= Python 3 + `cryptography`. The two verifiers import NOTHING from CAIN. python3 verify_l5_unified.py CAIN42_L5_TRAJECTORY_BUNDLE.json # continuous trajectory governance python3 verify_system_bundle.py CAIN42_CAG_L5_SYSTEM_BUNDLE.json # CAG-L5 system governance, Tests A..M (save the .py.txt files as .py first) What they recompute rather than trust: lease signature/binding/TTL, plan binding, material change, and 9 adversarial requests (trajectory); policy precedence, authority intersection, tool/resource/model checks, governance quorum, blast radius, two-operator step-up, commitments and gate log (system). What this is NOT: third-party review, hardware attestation, or the hosted gateway path (the system governor is a library wired into the MCPGate SDK hook, opt-in, default OFF). CAG-L5 is CAIN's own governance designation, not SAE Level 5. Keys in the bundles are ephemeral.