CAIN hosted decision records are signed, 2026-09-27.

record.json is one complete stored row of the hosted Fabric's decision table (cainstudio.online), from a
public demo decision on a throwaway tenant (cus_demo_649a89350451). The gateway signs each record's SHA-256
digest with an Ed25519 key kept outside its database; the public key is served at /fabric/decision-signing-key
on every site (signing-key.json is a snapshot, key id 8fcdf85b4a675f0e).

Verify (Python 3.8+, pip install cryptography, no CAIN code):
  B=https://clawx.click/evidence/decision-signing-2026-09-27
  curl -so record.json "$B/record.json"
  curl -so verify_decision_record.py "$B/verify_decision_record.py.txt"
  python3 verify_decision_record.py record.json --key https://mcpgate.online/fabric/decision-signing-key --self-test

The verifier recomputes the digest from the record's own fields, checks the key id, verifies the signature,
and (--self-test) requires two tampered copies to fail: a changed verdict (DIGEST fails) and a changed verdict
with the digest recomputed, as a database writer without the key would do (SIGNATURE fails).

For a decision made right now, POST https://cainstudio.online/fabric/try?scenario=safe-read and read
evidence.integrity.record_signature (the gateway's own check; the full row of a live decision is not public).

Your own decisions (customers): export the stored signed row and check it with the same verifier:
  curl -s -H "X-API-Key: $KEY" https://cainstudio.online/fabric/decisions/<decision_id>/signed-record > record.json
  python3 verify_decision_record.py record.json --key https://mcpgate.online/fabric/decision-signing-key

Not claimed: protection against someone with root on the gateway host, which holds both the key and the
database; records written before 2026-09-27 are unsigned and reported as unsigned.
