CAIN-42 automated restore validation (daily, 04:25 UTC).

Every day, for each of the 8 replicas of the two live multi-region clusters, the newest OFF-HOST backup
(held on a server in another region) is fetched from that server and checked: files match the backup
manifest; every committed sequence in it has a commit certificate with >= 3 of the 4 pinned Ed25519
signatures (checked by the clean-room verifier); the certificates chain from genesis with no gap; and
the backup's newest decision equals the live cluster's decision at that height, read from a different
replica. Tampered backups fail even if their manifest is re-hashed (tested with a forged signature and
a deleted sequence). The result is signed with the CAIN-42 evidence-root key.

Verify (Python 3.8+, pip install cryptography, no CAIN code):
  curl -so verify_restore_validation.py https://cainstudio.online/proof/bundle/restore-validation/verify_restore_validation.py.txt
  python3 verify_restore_validation.py https://cainstudio.online/proof/bundle/restore-validation/latest.json --key https://mcpgate.online/proof/bundle/claims/evidence-root.pub.json

Not claimed: a restore into a running replica (see storage-loss-drill-2026-09-27); backups on another
provider; encryption at rest.
