πŸ† AUTONOMOUS AI TRUST RUNTIME VERIFY PROOF β†’
Checking platform status…

CAIN = COGNITIVE ARTIFICIAL INTELLIGENCE NETWORK

Trust Infrastructure for Autonomous Software

CAIN governs consequential actions with a closed-loop runtime trust system that evaluates authority and risk before execution, enforces decisions at the action boundary, verifies what actually happened, and updates future control from cryptographically linked evidence.

CAIN AUTONOMOUS TRUST CONTROL LOOP

OBSERVE Β· EXPECT Β· DECIDE Β· ENFORCE Β· EXECUTE Β· RECONCILE Β· TRUST DELTA Β· ADAPT Β· REPEAT

Try it. Right now, no account.

Send an action through the fabric and watch it decide. This is production, not a mock β€” you get back a real Trust Decision and an evidence record you can verify.

WHY CAIN IS DIFFERENT

1. Expectation / Outcome Reconciliation

CAIN records expected outcomes before execution and compares them with observed outcomes afterward. Observed facts remain distinct from inferred explanations.

2. Trust Delta

Verified behavior can strengthen or reduce Trust State. Malicious behavior reduces trust. Unknown subjects fail closed. Trust can never override hard policy.

3. Trajectory + Trust Fusion

Authorization considers accumulated agent behavior and trajectory, not merely the current isolated request. A trusted agent can still be blocked when its trajectory violates policy or safety constraints.

4. Response-Side Defense

CAIN evaluates tool responses before they influence subsequent agent actions, detecting response-side prompt injection, credential leakage, malicious instructions, and dangerous output.

5. Cryptographic Trust Chain

Trust-state transitions are cryptographically linked with sequence numbers and previous-state hashes so tampering can be detected through chain verification.

6. Fail-Closed Enforcement

Unknown, invalid, revoked, unverifiable, or errored authorization states cannot silently become ALLOW. Consequential actions require an authoritative decision and an enforced boundary.

7. Shadow-Mode Safety

CAIN distinguishes what would have executed from what actually executed and explicitly exposes enforcement/protection state so observation cannot be mistaken for enforcement.

What Makes CAIN Different

1. Expectation Engine

Before every consequential action, CAIN records the expected outcome, risk profile, resource impact, and trajectory in a signed expectation record. This creates a measurable standard for post-execution comparison.

Pre-action: Expected outcome vs actual outcome become verifiable.

2. Outcome Reconciliation

After execution, CAIN compares observed behavior against expected behavior. Observed facts remain distinct from inferred explanations. Deviations trigger alerts and can reduce trust scores.

Post-action: What happened vs what was supposed to happen.

3. Trust Delta

CAIN continuously computes Trust Delta from verified evidence. Good behavior increases trust. Malicious behavior or violations decrease trust. Trust changes influence future authorization β€” within hard policy bounds.

Verified evidence becomes the basis for future control decisions.

CAIN does not merely ask whether an action is allowed. CAIN is a continuous runtime trust state machine that observes, predicts, decides, enforces, reconciles outcomes, updates trust, and safely adapts future authority.

CAIN IS NOT JUST AN AUTHORIZATION CHECK. CAIN IS A CONTINUOUS RUNTIME TRUST STATE MACHINE.

CAIN Trust Dynamics Engine β€” The Canonical Loop

OBSERVE

β†’

EXPECT

β†’

DECIDE

β†’

ENFORCE

β†’

EXECUTE

β†’

RECONCILE

β†’

TRUST DELTA

β†’

TRUST STATE

β†’

ADAPT

β†’

REPEAT

The canonical primitive: ACTION β†’ OUTCOME β†’ RECONCILIATION β†’ TRUST DELTA β†’ TRUST STATE TRANSITION β†’ AUTHORITY UPDATE β†’ NEXT ACTION

Trust Dynamics Engine β€” Formal Properties

Formal Trust State Machine

7 explicit states: Quarantined β†’ Probation β†’ Cooldown β†’ Untrusted β†’ Neutral β†’ Trusted β†’ Highly Trusted. No silent mutations. Every transition requires evidence and produces a cryptographic hash.

Trust Vector (12 Dimensions)

Multi-dimensional trust: identity_trust, authority_trust, behavioral_trust, trajectory_trust, security_trust, outcome_trust, memory_trust, evidence_trust, policy_compliance, resource_trust, delegation_trust, execution_trust. Aggregate is derived, never primary.

Monotonic Authority Invariant

EFFECTIVE_AUTHORITY = HARD_POLICY ∧ IDENTITY ∧ TRAJECTORY ∧ TRUST ∧ BLAST_RADIUS ∧ BUDGET ∧ SECURITY. Trust can ONLY reduce authority. Proven mathematically. Verified by 16 adversarial conformance tests.

Composition-Aware Trust

Detects dangerous action combinations: READ_SECRET + SEND_EXTERNAL, CREATE_CREDENTIAL + ESCALATE_PERMISSION, APPROVE_PAYMENT + CHANGE_RECIPIENT. Actions evaluated in sequence, not independently.

Trust Replay + Graph

Reconstruct exact trust transitions. Query: WHY did trust change? WHAT caused authority reduction? WHICH action caused the transition? WHAT evidence supports it?

Counterfactual Simulation

What-if analysis without production mutation. Simulate: If action allowed, trust becomes? If response malicious, authority remains? If repeated 100x, trust evolves? Delegation max authority?

Decay + Recovery + Quarantine

Trust decays over time without fresh evidence. Recovery requires verified successful behavior. Quarantine immediately revokes all authority. Compromise cannot be instantly erased by later successes.

Blast Radius Monotonicity

When trust degrades, blast radius can only decrease. Modeled: current authority, reachable resources, trajectory depth, delegation chain, tool combinations, financial exposure, data exposure.

CAIN Security Invariants β€” Proved by Adversarial Conformance Suite

Hard policy cannot be overridden by trust Trust cannot self-inflate UNKNOWN cannot become ALLOW Trust cannot cross tenants Delegation cannot expand authority Shadow mode cannot authorize State cannot roll backward Evidence cannot be substituted

Why CAIN Is Different

Traditional AI Gateway

Controls traffic or tools, but typically does not maintain a continuous trust-state feedback loop.

Observability Platform

Records events, but generally does not enforce authorization at the consequential action boundary.

Policy Engine

Evaluates policy, but typically does not provide complete execution provenance and post-execution trust reconciliation.

Security Filter

Screens inputs or outputs, but typically does not unify identity, trajectory, authority, execution evidence, and adaptive trust.

CAIN

Unifies identity, authority, policy, risk, trajectory, verification, enforcement, execution evidence, outcome reconciliation, cryptographic trust state, and future control in one runtime loop.

What CAIN Does NOT Claim

No universal uniqueness Not the only platform Not mathematically safe Not unhackable Not zero risk No SOC 2/ISO (not certified) No independent validation (not performed) No 100% coverage (67% proven)

CAIN is defense-in-depth. Every security system can be bypassed. Claims are bounded by publicly verifiable evidence. Limitations are disclosed.

CAIN Studio is the hosted deployment of CAIN Trust Fabric: the managed control plane and enforcement boundary, operated by us on a subscription. 99+ services behind one API key β€” nothing to install, nothing to maintain, your evidence stored alongside ours.

Prefer to run it yourself? MCPGate is the self-hosted deployment of the same fabric β€” same architecture, same trust domains, perpetual license instead of subscription, your traffic and evidence never leave your infrastructure. Either one unlocks the other.

CAIN Runtime Trust Control Loop

EXPECT β†’ VERIFY β†’ DECIDE β†’ ENFORCE β†’ EXECUTE β†’ OBSERVE β†’ RECONCILE β†’ TRUST UPDATE β†’ FUTURE CONTROL

CAIN does not merely log actions after they happen. It evaluates expected outcomes before execution, observes actual outcomes after, reconciles expected versus actual behavior, distinguishes observed facts from inferred explanations, updates Trust State from verified evidence, and uses that Trust State within hard policy boundaries to influence subsequent authorization.

CAIN governs consequential autonomous actions before, during, and after execution β€” combining identity, authority, policy, risk, trajectory, enforcement, execution evidence, and continuous trust-state updates in one closed loop.

OBSERVE Β· ASSESS TRUST Β· PREDICT RISK Β· DECIDE Β· ENFORCE Β· EXECUTE Β· RECONCILE Β· UPDATE TRUST Β· ADAPT CONTROL

Most AI security systems provide point controls such as gateways, filters, authorization, or logging. CAIN connects these controls into a continuous runtime trust loop where verified execution outcomes become evidence for future trust and control decisions.

Novel Architecture Claim

To our knowledge, no other publicly documented platform currently demonstrates this complete combination of pre-execution expectation, post-execution reconciliation, trajectory-aware trust, response-side defense, fail-closed enforcement, cryptographically linked trust-state transitions, and evidence-backed adaptive control as one unified runtime trust fabric.

  1. The agent proposes. Any runtime β€” LangChain, LangGraph, LlamaIndex, CrewAI, OpenAI, Google, Microsoft, AWS, or your own loop β€” submits an intended action over HTTP or MCP.
  2. CAIN decides. Identity, policy, risk and plan verification produce one verdict. This is our job β€” we run the control plane.
  3. CAIN Studio enforces. This site. The boundary in the call path β€” sandboxed, size-limited, injection-screened tool execution, operated by us.
  4. The system executes. Authorized calls reach the upstream tool. Blocked ones never do.
  5. Evidence remembers. QuorumSeal's signed decision trail and each tool's own audit log, stored with your account.

See the full architecture β†’ Β· 99+ services across the fabric's trust domains.

What CAIN actually does

1. Decide

CAIN evaluates whether a proposed action satisfies identity, policy, authorization, risk, and verification requirements.

2. Enforce

CAIN sits in the execution path and prevents unauthorized or unsafe actions from reaching the downstream tool or system.

3. Prove

CAIN preserves evidence describing the decision, policy, execution, outcome, and relevant verification data.

Monitoring tells you what happened. CAIN can decide whether it is allowed to happen and enforce that decision.

DON'T TRUST CAIN. VERIFY CAIN.

Everything important can be verified. Run a synthetic test, inspect evidence, verify integrity, check conformance.

Verify CAIN β†’

When does this matter?

The more consequential the action, the more important it becomes to have a deterministic decision, enforceable boundary, and durable evidence trail.

sending an email moving money modifying production infrastructure accessing sensitive data calling an external API executing code changing permissions deploying software modifying customer records invoking an MCP tool

CAIN Products

Production-ready products built on CAIN Trust Fabric

Private Preview
CAIN Private
Your AI. Your data. Your infrastructure. Your rules. Private AI agent environment with CAIN governance, identity verification, and evidence.
● Live
Explore CAIN Private β†’
Production
CAIN Identity
Verifiable identity for agents, humans, and services. SPIFFE-compatible URNs, Ed25519 keys, delegation chains, and revocation that blocks enforcement.
● Live
Explore CAIN Identity β†’
Production
CAIN Control
Control what AI agents are allowed to do. Agent controls, tool permissions, policy management, and emergency kill switch.
● Live
Explore CAIN Control β†’
Self-Hosted
MCPGate
The same CAIN Trust Fabric, running inside your own infrastructure. Your traffic and evidence never leave your network.
● Live
Explore MCPGate β†’
Production
CAIN Trajectory
Govern the entire path, not just the next action. Monitor and verify the sequence of actions taken by an AI agent.
● Live
Explore CAIN Trajectory β†’
Production
CAIN Agent Security
Protect AI agents from the inside out. Real-time threat detection, credential protection, and runtime enforcement.
● Live
Explore CAIN Agent Security β†’
Production
CAIN Trace
See everything your AI agent did. Reconstruct complete execution history from identity through decision, security, trajectory, enforcement and evidence.
● Live
Explore CAIN Trace β†’
Production
CAIN Budget
Hard spending limits for autonomous AI agents. Real-time financial governance enforced before every action executes.
● Live
Explore CAIN Budget β†’
Production
CAIN Governance
Organizational rules, authorities, and approval workflows for autonomous AI. Coordinate policies, budgets, and security across your AI estate.
● Live
Explore CAIN Governance β†’
Production
CAIN Memory
Governed persistent memory for autonomous AI agents. Trust levels, admission control, poisoning defense, and tenant isolation for what agents remember.
● Live
Explore CAIN Memory β†’
Production
CAIN Observability
Understand every consequential agent action, decision, execution, and evidence event across the Trust Fabric.
● Live
Explore CAIN Observability β†’
Production
CAIN Compliance
Continuously evaluate agent controls against organizational and regulatory requirements using real execution evidence.
● Live
Explore CAIN Compliance β†’
cain setup
# Install the CAIN CLI
pip install cain

# Create a free account (no card required)
cain signup

# Initialize for your runtime
cain init

# Protect your first action
cain protect

# Or add MCPGate as a free MCP server
claude mcp add --transport http mcpgate https://mcpgate.online/mcp

CAIN TRUST FABRIC · in ten seconds

AI agents can now act. We make every action provable, governed, and enforceable.

CAIN = COGNITIVE ARTIFICIAL INTELLIGENCE NETWORK. CAIN Trust Fabric sits between your agents and the things they do. Before an action runs, it validates trust through 16 execution stages, then enforces that decision and preserves evidence.

The 16-Step Execution PathObserve → Identify → Authorize → Build Context → Load State → Snapshot → Validate → Certify → Decide → Enforce → Execute → Observe Effect → Attest → Record → Update Trust → Revalidate
The 7 Moats (Canonical Architecture)1. TRUST STATE · 2. SECURITY-CONTEXT CONTINUITY · 3. TRUST GRAPH · 4. EXECUTION PROVENANCE · 5. PREDICTIVE TRUST · 6. ADVERSARIAL TRUST ENGINE · 7. AUTONOMOUS TRUST CONTROL LOOP
Enforcement in the call pathNot a dashboard that tells you afterwards -- a boundary that can stop the call, hosted by us or self-hosted by you.
Evidence you can produce laterEvery decision stored with its stage-by-stage verdicts and retrievable by id.

What is CAIN? CAIN = COGNITIVE ARTIFICIAL INTELLIGENCE NETWORK. The AI Infrastructure Validated Trust Runtime for Autonomous Systems. CAIN is NOT: a chatbot, dashboard, LLM gateway, policy store, or identity provider. CAIN is the continuously validated trust state between AI agents and consequential actions.

Works with what you already use. Works with any agent runtime -- LangChain, LangGraph, LlamaIndex, CrewAI, OpenAI, Google, Microsoft, AWS or your own loop -- because it's reached over plain HTTPS and MCP. No rewrite, no SDK lock-in.

Two ways to run it. You're on CAIN Studio, the hosted deployment; MCPGate is the other one. Two ways to run it: CAIN Studio (hosted, subscription, nothing to install) or MCPGate (self-hosted, perpetual license, your network and your evidence). Either one unlocks the other.

Verify CAIN, don't trust CAIN. Run a live test at Verify CAIN -- see the evidence chain, check the conformance, prove it works before you buy.

Quickstart

Protect your first AI action.

Your function keeps its code. CAIN decides whether each consequential action is allowed, blocks it before it runs if not, and records the decision. Everything below has been run; nothing is sample output.

01!Do not run pip install cain
That installs a different, unrelated project. The CAIN package (cain-trust) is not published to PyPI yet, so there is no one-line install today. Until it is, contact support@cainstudio.online for the install package, or use the hosted API below.
02$curl -X POST https://cainstudio.online/subscribe/free/signup
Creates a free account and returns an API key. No card, no expiry. Save the key; use it as the X-API-Key header. Security is never a paid feature.
03#demo.py
With the package installed, guard any function. An allowed action runs; a prohibited one raises before its body executes.
from cain import guard

@guard(resource="customer_inbox", intent="notify customer", action="send_email")
def send_email(to, subject):
    return f"sent to {to}"

@guard(resource="policy_store", intent="loosen limits", action="modify_policy")
def modify_policy(rule):
    return "policy changed"
04$python demo.py
Real output from running the code above:
send_email -> sent to a@example.com
modify_policy -> BLOCKED: CainActionBlockedException CAIN Trust Fabric DENIED
  execution of action 'modify_policy' on 'policy_store'. Reason: Self-authoring
  trust modification strictly prohibited by CAIN Trust Fabric.

Not yet in the CLI: cain protect, cain explain and an evidence viewer. They are planned, not available. Run the no-account sandbox above to see a decision with its evidence record.


Why CAIN Studio

Nothing to operate. Everything to trust.

CAIN Studio is the managed deployment of CAIN Trust Fabric. We run the control plane, maintain the infrastructure, and keep the evidence secure β€” you get the same trust guarantees without the operational burden.

β†’

Nothing to deploy

One API key, 99+ services. Your agents are protected in minutes, not days. No Docker, no Kubernetes, no infrastructure to manage.

∞

Unlimited evidence storage

Every decision recorded, every verdict signed. Evidence persists alongside your account β€” retrievable for incident review, compliance audits, or customer demos.

⚑

Managed control plane

We run the identity service, policy engine, and decision verification. You focus on your agents; we focus on their safety.

↻

Automatic updates

New trust domains, updated policy libraries, improved detection β€” you get the latest CAIN Trust Fabric capabilities without lifting a finger.

πŸ”—

Unlocks MCPGate

Your CAIN Studio subscription grants free access to 13 of the 19 self-hosted tools on MCPGate β€” same trust fabric, your choice of deployment.


Pricing

Free to prove it. Pay when you operate it at scale.

Security is never a paid feature: every plan gets the full decision path. Plans differ by volume, agents, retention and operations.

Free$0, no card, no expiry. Professionalsee pricing/month. Enterprisesee pricing/month.

Every new account gets 7 days of full Enterprise limits, no card. After that it continues on Free unless you choose a plan. First paid charge refundable within 7 days.
Compare plans

Checkout is Stripe's hosted page; we never see your card number. See the refund policy. Limits and what is not included are listed on the pricing page.

CAIN Trust Fabric is one platform with two deployment models, not two products. CAIN Studio — this site — is the hosted deployment: the control plane and enforcement boundary run on our infrastructure under a subscription, so you get everything with nothing to operate. MCPGate is the self-hosted deployment: same architecture, same trust domains, a perpetual license instead of a subscription, your traffic and evidence never leave your network. Same fabric, different operator — and a license or subscription on either one unlocks the other. Which you pick is an operational decision, not a decision about which products you get.

Access is enforced on every request, not just at login, and verification tools like VerifyGate grade work honestly — proven, tested, heuristic, or unverified — instead of one fake checkmark. AI you can verify, not just trust.


mcpgate.online

Your subscription also unlocks self-hosted tools

Any CAIN Studio subscription grants free access to 13 of the 19 self-hosted tools on MCPGate β€” the full bundle plus MCPiverse β€” in one click from your dashboard. The other tools aren't excluded to upsell you: ProbeGate and MCP Security Scanner are already free.

Already subscribed? Claim MCPGate access

One click from your dashboard to unlock all 13 self-hosted tools.

Go to Dashboard β†’

Catalog

99+ services across the trust fabric

Every service is reachable over HTTPS and MCP β€” no SDK required, no lock-in. Your agents keep working even if you switch away from CAIN.

Loading catalog…