CAIN = COGNITIVE ARTIFICIAL INTELLIGENCE NETWORK
CAIN governs consequential actions with a closed-loop runtime trust system that evaluates authority and risk before execution, enforces decisions at the action boundary, verifies what actually happened, and updates future control from cryptographically linked evidence.
CAIN AUTONOMOUS TRUST CONTROL LOOP
OBSERVE Β· EXPECT Β· DECIDE Β· ENFORCE Β· EXECUTE Β· RECONCILE Β· TRUST DELTA Β· ADAPT Β· REPEAT
Send an action through the fabric and watch it decide. This is production, not a mock β you get back a real Trust Decision and an evidence record you can verify.
WHY CAIN IS DIFFERENT
1. Expectation / Outcome Reconciliation
CAIN records expected outcomes before execution and compares them with observed outcomes afterward. Observed facts remain distinct from inferred explanations.
2. Trust Delta
Verified behavior can strengthen or reduce Trust State. Malicious behavior reduces trust. Unknown subjects fail closed. Trust can never override hard policy.
3. Trajectory + Trust Fusion
Authorization considers accumulated agent behavior and trajectory, not merely the current isolated request. A trusted agent can still be blocked when its trajectory violates policy or safety constraints.
4. Response-Side Defense
CAIN evaluates tool responses before they influence subsequent agent actions, detecting response-side prompt injection, credential leakage, malicious instructions, and dangerous output.
5. Cryptographic Trust Chain
Trust-state transitions are cryptographically linked with sequence numbers and previous-state hashes so tampering can be detected through chain verification.
6. Fail-Closed Enforcement
Unknown, invalid, revoked, unverifiable, or errored authorization states cannot silently become ALLOW. Consequential actions require an authoritative decision and an enforced boundary.
7. Shadow-Mode Safety
CAIN distinguishes what would have executed from what actually executed and explicitly exposes enforcement/protection state so observation cannot be mistaken for enforcement.
What Makes CAIN Different
1. Expectation Engine
Before every consequential action, CAIN records the expected outcome, risk profile, resource impact, and trajectory in a signed expectation record. This creates a measurable standard for post-execution comparison.
Pre-action: Expected outcome vs actual outcome become verifiable.
2. Outcome Reconciliation
After execution, CAIN compares observed behavior against expected behavior. Observed facts remain distinct from inferred explanations. Deviations trigger alerts and can reduce trust scores.
Post-action: What happened vs what was supposed to happen.
3. Trust Delta
CAIN continuously computes Trust Delta from verified evidence. Good behavior increases trust. Malicious behavior or violations decrease trust. Trust changes influence future authorization β within hard policy bounds.
Verified evidence becomes the basis for future control decisions.
CAIN does not merely ask whether an action is allowed. CAIN is a continuous runtime trust state machine that observes, predicts, decides, enforces, reconciles outcomes, updates trust, and safely adapts future authority.
CAIN IS NOT JUST AN AUTHORIZATION CHECK. CAIN IS A CONTINUOUS RUNTIME TRUST STATE MACHINE.
CAIN Trust Dynamics Engine β The Canonical Loop
OBSERVE
EXPECT
DECIDE
ENFORCE
EXECUTE
RECONCILE
TRUST DELTA
TRUST STATE
ADAPT
REPEAT
The canonical primitive: ACTION β OUTCOME β RECONCILIATION β TRUST DELTA β TRUST STATE TRANSITION β AUTHORITY UPDATE β NEXT ACTION
Trust Dynamics Engine β Formal Properties
Formal Trust State Machine
7 explicit states: Quarantined β Probation β Cooldown β Untrusted β Neutral β Trusted β Highly Trusted. No silent mutations. Every transition requires evidence and produces a cryptographic hash.
Trust Vector (12 Dimensions)
Multi-dimensional trust: identity_trust, authority_trust, behavioral_trust, trajectory_trust, security_trust, outcome_trust, memory_trust, evidence_trust, policy_compliance, resource_trust, delegation_trust, execution_trust. Aggregate is derived, never primary.
Monotonic Authority Invariant
EFFECTIVE_AUTHORITY = HARD_POLICY β§ IDENTITY β§ TRAJECTORY β§ TRUST β§ BLAST_RADIUS β§ BUDGET β§ SECURITY. Trust can ONLY reduce authority. Proven mathematically. Verified by 16 adversarial conformance tests.
Composition-Aware Trust
Detects dangerous action combinations: READ_SECRET + SEND_EXTERNAL, CREATE_CREDENTIAL + ESCALATE_PERMISSION, APPROVE_PAYMENT + CHANGE_RECIPIENT. Actions evaluated in sequence, not independently.
Trust Replay + Graph
Reconstruct exact trust transitions. Query: WHY did trust change? WHAT caused authority reduction? WHICH action caused the transition? WHAT evidence supports it?
Counterfactual Simulation
What-if analysis without production mutation. Simulate: If action allowed, trust becomes? If response malicious, authority remains? If repeated 100x, trust evolves? Delegation max authority?
Decay + Recovery + Quarantine
Trust decays over time without fresh evidence. Recovery requires verified successful behavior. Quarantine immediately revokes all authority. Compromise cannot be instantly erased by later successes.
Blast Radius Monotonicity
When trust degrades, blast radius can only decrease. Modeled: current authority, reachable resources, trajectory depth, delegation chain, tool combinations, financial exposure, data exposure.
CAIN Security Invariants β Proved by Adversarial Conformance Suite
Why CAIN Is Different
Traditional AI Gateway
Controls traffic or tools, but typically does not maintain a continuous trust-state feedback loop.
Observability Platform
Records events, but generally does not enforce authorization at the consequential action boundary.
Policy Engine
Evaluates policy, but typically does not provide complete execution provenance and post-execution trust reconciliation.
Security Filter
Screens inputs or outputs, but typically does not unify identity, trajectory, authority, execution evidence, and adaptive trust.
CAIN
Unifies identity, authority, policy, risk, trajectory, verification, enforcement, execution evidence, outcome reconciliation, cryptographic trust state, and future control in one runtime loop.
What CAIN Does NOT Claim
CAIN is defense-in-depth. Every security system can be bypassed. Claims are bounded by publicly verifiable evidence. Limitations are disclosed.
CAIN Studio is the hosted deployment of CAIN Trust Fabric: the managed control plane and enforcement boundary, operated by us on a subscription. 99+ services behind one API key β nothing to install, nothing to maintain, your evidence stored alongside ours.
Prefer to run it yourself? MCPGate is the self-hosted deployment of the same fabric β same architecture, same trust domains, perpetual license instead of subscription, your traffic and evidence never leave your infrastructure. Either one unlocks the other.
CAIN Runtime Trust Control Loop
EXPECT β VERIFY β DECIDE β ENFORCE β EXECUTE β OBSERVE β RECONCILE β TRUST UPDATE β FUTURE CONTROL
CAIN does not merely log actions after they happen. It evaluates expected outcomes before execution, observes actual outcomes after, reconciles expected versus actual behavior, distinguishes observed facts from inferred explanations, updates Trust State from verified evidence, and uses that Trust State within hard policy boundaries to influence subsequent authorization.
CAIN governs consequential autonomous actions before, during, and after execution β combining identity, authority, policy, risk, trajectory, enforcement, execution evidence, and continuous trust-state updates in one closed loop.
OBSERVE Β· ASSESS TRUST Β· PREDICT RISK Β· DECIDE Β· ENFORCE Β· EXECUTE Β· RECONCILE Β· UPDATE TRUST Β· ADAPT CONTROL
Most AI security systems provide point controls such as gateways, filters, authorization, or logging. CAIN connects these controls into a continuous runtime trust loop where verified execution outcomes become evidence for future trust and control decisions.
Novel Architecture Claim
To our knowledge, no other publicly documented platform currently demonstrates this complete combination of pre-execution expectation, post-execution reconciliation, trajectory-aware trust, response-side defense, fail-closed enforcement, cryptographically linked trust-state transitions, and evidence-backed adaptive control as one unified runtime trust fabric.
See the full architecture β Β· 99+ services across the fabric's trust domains.
CAIN evaluates whether a proposed action satisfies identity, policy, authorization, risk, and verification requirements.
CAIN sits in the execution path and prevents unauthorized or unsafe actions from reaching the downstream tool or system.
CAIN preserves evidence describing the decision, policy, execution, outcome, and relevant verification data.
Monitoring tells you what happened. CAIN can decide whether it is allowed to happen and enforce that decision.
DON'T TRUST CAIN. VERIFY CAIN.
Everything important can be verified. Run a synthetic test, inspect evidence, verify integrity, check conformance.
Verify CAIN βThe more consequential the action, the more important it becomes to have a deterministic decision, enforceable boundary, and durable evidence trail.
99+ hosted services β sandboxed execution, secret leak prevention, drift detection, fairness audits, and more. One API key, nothing to deploy.
Start building βMCPGate β the same fabric, running inside your own infrastructure under a perpetual license. Your traffic and evidence never leave your network.
See MCPGate βProduction-ready products built on CAIN Trust Fabric
# Install the CAIN CLI pip install cain # Create a free account (no card required) cain signup # Initialize for your runtime cain init # Protect your first action cain protect # Or add MCPGate as a free MCP server claude mcp add --transport http mcpgate https://mcpgate.online/mcp
CAIN TRUST FABRIC · in ten seconds
CAIN = COGNITIVE ARTIFICIAL INTELLIGENCE NETWORK. CAIN Trust Fabric sits between your agents and the things they do. Before an action runs, it validates trust through 16 execution stages, then enforces that decision and preserves evidence.
What is CAIN? CAIN = COGNITIVE ARTIFICIAL INTELLIGENCE NETWORK. The AI Infrastructure Validated Trust Runtime for Autonomous Systems. CAIN is NOT: a chatbot, dashboard, LLM gateway, policy store, or identity provider. CAIN is the continuously validated trust state between AI agents and consequential actions.
Works with what you already use. Works with any agent runtime -- LangChain, LangGraph, LlamaIndex, CrewAI, OpenAI, Google, Microsoft, AWS or your own loop -- because it's reached over plain HTTPS and MCP. No rewrite, no SDK lock-in.
Two ways to run it. You're on CAIN Studio, the hosted deployment; MCPGate is the other one. Two ways to run it: CAIN Studio (hosted, subscription, nothing to install) or MCPGate (self-hosted, perpetual license, your network and your evidence). Either one unlocks the other.
Verify CAIN, don't trust CAIN. Run a live test at Verify CAIN -- see the evidence chain, check the conformance, prove it works before you buy.
Quickstart
Your function keeps its code. CAIN decides whether each consequential action is allowed, blocks it before it runs if not, and records the decision. Everything below has been run; nothing is sample output.
pip install caincain-trust) is not published to PyPI yet, so there is no one-line install today. Until it is, contact support@cainstudio.online for the install package, or use the hosted API below.X-API-Key header. Security is never a paid feature.from cain import guard
@guard(resource="customer_inbox", intent="notify customer", action="send_email")
def send_email(to, subject):
return f"sent to {to}"
@guard(resource="policy_store", intent="loosen limits", action="modify_policy")
def modify_policy(rule):
return "policy changed"send_email -> sent to a@example.com modify_policy -> BLOCKED: CainActionBlockedException CAIN Trust Fabric DENIED execution of action 'modify_policy' on 'policy_store'. Reason: Self-authoring trust modification strictly prohibited by CAIN Trust Fabric.
Not yet in the CLI: cain protect, cain explain and an evidence viewer. They are planned, not available. Run the no-account sandbox above to see a decision with its evidence record.
CAIN Studio is the managed deployment of CAIN Trust Fabric. We run the control plane, maintain the infrastructure, and keep the evidence secure β you get the same trust guarantees without the operational burden.
One API key, 99+ services. Your agents are protected in minutes, not days. No Docker, no Kubernetes, no infrastructure to manage.
Every decision recorded, every verdict signed. Evidence persists alongside your account β retrievable for incident review, compliance audits, or customer demos.
We run the identity service, policy engine, and decision verification. You focus on your agents; we focus on their safety.
New trust domains, updated policy libraries, improved detection β you get the latest CAIN Trust Fabric capabilities without lifting a finger.
Your CAIN Studio subscription grants free access to 13 of the 19 self-hosted tools on MCPGate β same trust fabric, your choice of deployment.
Security is never a paid feature: every plan gets the full decision path. Plans differ by volume, agents, retention and operations.
Free — $0, no card, no expiry. Professional — see pricing/month. Enterprise — see pricing/month.
Checkout is Stripe's hosted page; we never see your card number. See the refund policy. Limits and what is not included are listed on the pricing page.
CAIN Trust Fabric is one platform with two deployment models, not two products. CAIN Studio — this site — is the hosted deployment: the control plane and enforcement boundary run on our infrastructure under a subscription, so you get everything with nothing to operate. MCPGate is the self-hosted deployment: same architecture, same trust domains, a perpetual license instead of a subscription, your traffic and evidence never leave your network. Same fabric, different operator — and a license or subscription on either one unlocks the other. Which you pick is an operational decision, not a decision about which products you get.
Access is enforced on every request, not just at login, and verification tools like VerifyGate grade work honestly — proven, tested, heuristic, or unverified — instead of one fake checkmark. AI you can verify, not just trust.
Any CAIN Studio subscription grants free access to 13 of the 19 self-hosted tools on MCPGate β the full bundle plus MCPiverse β in one click from your dashboard. The other tools aren't excluded to upsell you: ProbeGate and MCP Security Scanner are already free.
One click from your dashboard to unlock all 13 self-hosted tools.
Go to Dashboard βEvery service is reachable over HTTPS and MCP β no SDK required, no lock-in. Your agents keep working even if you switch away from CAIN.
Loading catalogβ¦