CAIN-42 hosted decisions are ordered by a PBFT quorum, 2026-09-27.

Every recorded decision of the hosted Fabric (cainstudio.online) is ordered through the live multi-region
cluster cain-mr-01, and the gateway verifies the commit quorum certificate itself before counting it.
decision.json is one public demo decision; qc.json its certificate; membership.json the cluster's 4 pinned
Ed25519 keys. The verifier recomputes the digest from the decision's own fields, so a certificate for any
other decision, or an altered verdict, fails.

Verify (Python 3.8+, pip install cryptography, no CAIN code):
  BASE=https://cainstudio.online/proof/bundle/hosted-consensus-2026-09-27
  for f in decision.json qc.json membership.json; do curl -so $f "$BASE/$f"; done
  for v in verify_hosted_decision verify_pbft_qc_bundle; do curl -so $v.py "$BASE/$v.py.txt"; done
  python3 verify_hosted_decision.py decision.json qc.json membership.json
  python3 verify_hosted_decision.py --live https://cainstudio.online membership.json    # a fresh decision, now

Not claimed: that the verdict is enforced for every tenant -- it blocks only for tenants in enforce mode (a
paid tier); free tenants run in shadow mode. The cluster sees only a commitment to the decision, not its content.
