MCPGate · the gate in front of your tools
Your AI agents touch your tools only when allowed
MCPGate stands in front of your tools, apps and data. When an AI agent tries to use them, only the exact action CAIN-42 approved gets through. Everything else is stopped, and every stop is saved as signed proof. The closer AI agents get to AGI, the more every action needs a check that capability alone cannot get past; that is the job CAIN-42 is built for. Powered by consensus-committed authorization, E8 physical commit boundary, payload-bound signatures, 15-stage restriction chain, and turnkey K8s Helm packaging (mcpgate-appliance v3.0.0). Connect your agent with plain HTTP or the client: pip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whl (PyPI listing pending; clean-venv install check: 19/19), then follow the quickstart. Live and self-attested, pre-production; not yet independently audited. Built by FIRME AI, an artificial intelligence company based in San Francisco, California: 68 frontier inventions in agentic-AI governance — 22 patent candidates and 46 engineering innovations, each backed by its own passing tests. They include Byzantine-quorum authorization running live across four servers, and E38 mission integrity, which blocks an AI agent the moment it reaches beyond its signed mission. FIRME AI’s own forensic valuation estimates the company at about $2.4 million (internal estimate). See all 68 inventions.
Verify CAIN-42 yourself in seconds, on your own computer: open the Verifier Room on this page and copy one block into a terminal. It downloads a published evidence bundle and its clean-room verifier and recomputes the result — no account, no contact, nothing taken on trust.
Three steps, every time
- 1
The AI asks
An AI agent wants to do something: use a tool, change a database, send money, start another agent. It can only ask.
- 2
CAIN-42 decides
CAIN-42 checks who is asking, what it is allowed to do right now, what it has already done, and how much could go wrong. No authority means no action.
- 3
The gate enforces, proof is kept
Only the approved action gets through. The decision and what happened are saved as signed proof anyone can check.
What CAIN-42 does today
Live right now, on these sites
Every AI action sent through CAIN Studio is checked before it runs and blocked if it is not allowed (the live pipeline runs identity, intent, policy, authorization, risk, trust, verification, ActionProof, approval, consensus, egress, MCPGate, execution and evidence; no authorization means no execution). Each recorded decision is signed by a live cluster of 4 servers across 4 US regions (Atlanta, Los Angeles, Miami, Silicon Valley) and 3 of 4 must agree (Ed25519 quorum certificate verified by the gateway). MCPGate lets through only the exact tool call that was approved. Unregistered AI systems and unsigned requests are refused, and an agent may change its own model or tools only with a human sign-off (live) (30 of 30 live cases passed). A Python SDK and MCP proxy that say no to anything you did not allow (default-deny). Today's live deployment: the quorum-committed authorization-snapshot data plane is switched on live (the consensus stage falls from a measured ~2,269 ms to ~0.8263 ms), a revoked agent key is refused on its very next request (measured 2026-10-02), progressive trust scoping preventing exfiltration, payload-bound signed tokens, default-deny egress screening as a live stage (an action naming a destination outside the tenant's allowlist is denied; loopback and cloud-metadata endpoints are denied regardless of rules — manage it at /fabric/egress/rules (with your API key)), and Phase 3 Frontier AI intelligence (live) (AgentPRM process reward scoring, TriCEGAR MDP behavioral verification, Governed Memory Shield, and A2A inter-agent delegation at /fabric/frontier/*).
Built and tested, not hosted yet
Governance libraries, each with its own attack tests and published evidence: today's hardening: zero-stub, security, performance, artifact attestation, governed memory, agent identity, delegation, egress, tool-arg validity, teams of agents, messages and intent, evidence, decisions, tool supply chains, robots and physical actions, cause and effect, multi-agent action, shared 4D worlds, an AI system's changing state, AI organizations with simulated money, AI research, AI that redesigns itself, agents from different companies working together, one signed record for any machine action across 18 protocols, portable trust with one-time authorizations, a control plane for the agent internet, a portable identity any agent can get by connecting, whose power never travels with it (442 of 442 attacks on it stopped), agents that negotiate, sign contracts and pay each other in test money, where money only moves through the final check and escrow pays out only on proof (258 of 258 attacks stopped), one autonomy kernel every agent action passes through, with a signed receipt for each (889 of 889 attacks stopped), a signed proof for each action that anyone can re-check without our code (88 of 88 forged proofs rejected), learning that can only make its own rules stricter, with a human signing every change (1013 of 1013 attacks stopped), one governed, proof-carrying lifecycle for every agent operation, usable from a sidecar (2029 of 2029 attacks stopped), one signed governance proof per action that anyone can re-check without our code (2664 of 2664 attacks stopped), governance intelligence that predicts and recommends but is never allowed to authorize (3544 of 3544 attacks stopped), a governed machine agency exchange where machines discover, negotiate and contract but never become authority (3340 of 3340 attacks stopped), an execution mesh where work can move between nodes, runtimes and models but authority never moves unchecked (2,720 of 2,720 attacks stopped), a portable governance proof for every action that another machine can verify without our code (2,141 of 2,141 attacks stopped), an agent factory that turns a mission into a governed team of agents that can never grant themselves power (3,441 of 3,441 attacks stopped), an enterprise intelligence substrate that models and predicts the business but never authorizes (1,354 of 1,354 scenarios held), a cross-organization machine agency exchange where machines negotiate and contract but never mint authority (1,180 of 1,180 scenarios held), one canonical governance kernel, ABI and action model that make every earlier layer behave as one machine (34 of 34 evolutions integrated), and the hosted E8 action-commit boundary: every hosted ALLOW is bound to a committed, single-use, durable, hash-chained governance token (replay, risk-above-ceiling and resource-out-of-scope refused; fail-closed). A clean-room verifier that imports none of our code ships with it. Also Phase 3 Frontier AI Research Integration (AgentPRM, TriCEGAR MDP verifier, Governed Memory Shield, A2A delegation), artifact supply-chain attestation, governed memory at write time, agent identity interop (SPIFFE-style workload identity + OAuth token exchange) and default-deny egress control and a sandbox isolation profile. Also an agent sandbox with a kernel syscall filter. None of them can give an AI more power; they can only take it away.
Proof you can check yourself
67 public claims, each signed and linked to its evidence; 18 are checked against the live system. Test reports (1,963 of 1,978 tests passing), verifiers that use none of our code, and every known limitation, all on the Proof page and in the changelog. A public, no-key proof that the egress and tool-call stages are inside each decision's signed evidence, with a zero-dependency verifier, is at the restriction-stage proof bundle. A signed status receipt — which stages enforce right now, the running commit and the live health, and is itself re-checkable offline — is at the governance status receipt. Real stored decisions are re-derived and shown tamper-evident at the record-integrity proof. Live and self-attested, pre-production: no outside auditor has reviewed it yet (0 independently verified). Newest: E26 distributed settlement completion evidence (multi-host validated; 72-hour soak and full Frontier-20 execution not measured).
Everything in CAIN-42, on one page
175 products and features, 95 of them live today, plus 104 hosted services, and a library of 9,099 pages organised by niche. Tell us what you want your agents to do safely, or just scroll and click.
For engineers: an interactive API reference with a page for each of the 387 API calls and 287 data schemas, each with code samples and a console that sends the real request with your own key, and step-by-step recipes for your agent framework.
104 AI services, live today, one API key
Budgets, payments, memory, knowledge graphs, verification, model routing, compliance, security scanning, cryptography, red-teaming and more: 104 of the 105 services in the CAIN-42 catalog are running in production right now, each behind the same authenticated gateway, each keeping every customer's data separate. The 98 services deployed in this release each passed a live acceptance test, including a cross-customer data check, before the gateway sent them traffic (see the evidence). Starter is $19.75 a month; Full, with every service, is $49.75 a month.
CAINBudget new
Give every agent a spending limit it cannot talk its way past. Atomic reservations, fail-closed when no budget exists, a signed receipt for every yes and no.
CAINPay new
Card-style authorization for agent purchases: merchant allow and deny lists, per-transaction and daily caps, human approval above your threshold, hold / capture / void / refund, tamper-evident ledger.
VeritasEngine new
Check an agent's output before anything trusts it: JSON schema, exact arithmetic, SHA-256, code syntax, quotes against the source. Deterministic, signed, fails closed.
MemoryMesh new
Long-term memory for your agents with real BM25 search, and prompt-injection text quarantined before it can ever be recalled.
NexusMind new
One knowledge graph your agents share: every fact keeps its sources, contradictions are flagged instead of overwritten, and you can ask how any two things connect.
LexisGuardian new
Who decided, under what mandate, with what dissent. Decisions outside a mandate are refused; dissent is kept verbatim in a hash-chained register.
OmegaRouter new
Send each request to the right model by your own cost, latency and quality rules, with the reason for every choice and automatic failover when a model starts failing.
TEE Verifier new
Check your AWS Nitro enclaves and AMD SEV-SNP confidential VMs before you trust them: signatures, certificate chains to pinned AWS and AMD roots, chip and firmware binding, freshness, your PCR policy.
BLUiZZARD Governance new
Proposals, votes and preserved dissent for your team, with an outcome preview, EU AI Act screening of every proposal and a signed audit trail.
All 104 live services, by category
ActionProof (1)
Authorization (3)
cainbudget · cainpay · human-in-loop
Build & ship code (7)
talos-coder · talos-evolve · taloscode-migrate · taloscode-review · talosdev-archdiff · talosdev-refactor · visual-ide
Commerce & distribution (2)
agent-marketplace · quorum-oaas
Evidence (7)
agent-debugger · attestation · cainwitness · content-provenance · decision-intelligence · multi-agent-failure-tracer · zkproofvault
Execution Enforcement (2)
swarm-orchestrator · talos-shield
Governance (4)
blizzard-governance · guardian-scorecard · lexisguardian · talosops-governance
Identity (5)
a2a-guard · agent-id · cainaccounts · taloscrypt-keymgmt · taloscrypt-pqc
Industry applications (6)
arbitrage · caingrid · cainloan · cainroute · talosfin-earningsai · talosfin-statarb
Memory, retrieval & knowledge (5)
knowledge-graph · memorymesh · nexusmind · talos-rag · talos-vectorsearch
Model & ML infrastructure (8)
edge-optimizer · model-compressor · omegarouter · sparselogic-compiler · synthetic-fine-tuner · talosai-quantize · training-sandbox · weight-alchemist
Observability (3)
latent-inspector · observability · talosops-selfheal
Platform operations (2)
experimentation-notebook · feedback-engine
Policy (6)
caingovern · compliance-engine · legal-auditor · quorum-i18n · talosdoc-contract · taloslegal-caselaw
Reasoning, planning & orchestration (8)
autonomous-task-engine · causal-intelligence · causal-network · counterfactual-intelligence · echoworkforce · mcts-engine · spatial-synthesizer · stcn
Risk (10)
bias-detector · caindrift · contamination-scanner · context-health · hallucination-firewall · memory-integrity · metacognitive-enhancer · sentinel · talosdata-quality · trust-state-engine
Security (13)
adversarial-fuzzer · pii-redactor · secops-patcher · shadow-agent-scanner · talos-redteam · taloscode-security · taloscrypt-audit · taloscrypt-mesh · taloscrypt-store · taloscrypt-vault · talosguard-intel · talosguard-logiq · talosguard-siem
Unmapped (1)
Verification (11)
cainbench · cainschema · crucible · derivation-copilot · rag-verifier · talos-verify · taloslogic-proof · topological-data-analysis · trajectorygate · vericoding-gate · veritasengine
32 capabilities. Measured, not marketed.
Identity, consensus, runtime control, threat detection, compliance, interoperability and SRE: 28 of the 32 are built and pass their tests today, and 15 of those are running live right now. Every status below is read from a signed audit that runs each capability's tests and probes its live endpoint, and where a capability is narrower than its name, the card says so. The 4 we do not offer are listed too. See the signed audit and verify it yourself.
68 frontier agentic-AI inventions, built by FIRME AI. 22 patent candidates: Quorum-committed authorization snapshots · Mission goal-attenuation lattice (E38) · Continuously conditioned authorization · Dependency-driven authorization invalidation with blast radius · Authority non-transfer across governance domains (E37) · All-or-nothing governance with race-safe revocation · Bounded assurance with continuous invalidation · Comparative control-selection proof · Independence-aware Byzantine quorum · Quorum-signed programmable governance (GOV-IR) · Quorum-authorized kernel execution · Prediction-bounded authorization · Authority Continuity Protocol · Uncertainty-contracting authority horizon · Autonomy vector with certificates and leases · Self-evolution that cannot self-authorize · Mission-to-organization compiler · 4D reachability-bounded trajectory authorization · Governance contract fabric · Continuous governance attestation · Governance research fabric · Liveness-bound signed public claims. 46 engineering innovations: Continuous Autonomy Integrity Object (E35) · Cryptographic Autonomy Integrity Root (E35) · Continuous Integrity Proof Chain (E35) · Byzantine Integrity Fork Detection (E35) · Integrity-Governed Autonomous Recovery (E35) · Authority-Non-Amplifying Collective Composition (E36) · Collective Integrity Root (E36) · Common-Dependency Independence Analysis (E36) · Collective Revocation and Reconstitution (E36) · Cross-Domain Governance Negotiation (E37) · Federated Governance Proof (E37) · Cross-Domain MCP Enforcement (E37) · CATCP protocol and conformance vectors · Byzantine Mission Integrity (E38) · Quorum-governed execution leases and reservations · Zone-of-Decision agent hypervisor · Governed stopping · No-single-node authoritative state · Proof-carrying machine interaction with anti-Sybil independence · Counterfactual control quorum · Taint-surviving intent provenance · Governed capability supply chain · Decision-integrity governance · Governed scientific discovery · Machine-native institutions · Continuous trajectory governance · Governed learning loop · 4D causal world intelligence · Spatial and physical trust path · Governance compiler · Mandatory governance packages · Predictive contract forecasting · Governance learning · Differential governance assurance · Sentinel autonomous containment · Epistemic Byzantine swarm defense · Kernel self-defense · DAG-assisted Byzantine consensus with causal evidence · Economic mandate fabric with continuous red team · Action-bound approval cards · Channel-bound identity with verified linking · Structural message injection firewall · Fault-domain quorum-independence proof · Software measurement of running replicas · Byzantine-member consensus fuzzer · Trust debt ledger. Each one is backed by its own passing tests. Code and IP estimated at about $200k today (range $130k–$550k), and a maximum of about $1M once patents are filed and a paying customer uses the inventions; FIRME AI as a company about $3 million (about $2M investor / $3M strategic acquirer; internal estimates; pre-revenue; no patent filed yet). What each one does, and its value.
Identity, security & cryptography
Built and tested
Agent Registry & Identity
Register, revoke and expire every agent identity. A revoked agent is refused on its next request.
measured: IMPLEMENTED
Built and tested
DID Identity (W3C)
Every agent gets a standard W3C did:key, and you can publish a did:web document that follows key rotation and deactivates the moment the identity is revoked.
measured: IMPLEMENTED
Built and tested
Trust Tokenization
Short-lived signed capability tokens bound to the exact action, parameters and model. Not a tradeable token.
measured: NARROWER: IMPLEMENTED
Built and tested
Quantum-Resistant Crypto
An ML-DSA-65 post-quantum signing module, tested. Live decisions are still signed with Ed25519.
measured: NARROWER: IMPLEMENTED
Live
TEE Attestation
Verify YOUR enclaves before trusting them: AWS Nitro Enclaves documents and AMD SEV-SNP reports, checked against pinned AWS and AMD roots (tested on real evidence). CAIN's own servers are not hardware-attested.
measured: NARROWER: IMPLEMENTED, LIVE ENDPOINT
Runtime control & consensus
Live
PBFT Cluster
Two live 4-replica Byzantine-fault-tolerant clusters: 3 of 4 replicas must sign before anything counts.
measured: LIVE VERIFIED
Live
Production Cluster
Every hosted decision carries a quorum certificate that the gateway verifies itself.
measured: LIVE VERIFIED / LIVE VERIFIED
Live
Agent Hypervisor (ZoD)
A tool call routed through MCPGate runs only with a quorum-committed authorization; the SDK is default-deny. Calls that bypass the gate are not governed.
measured: NARROWER: LIVE + DISPOSABLE CLUSTER VERIFIED
Verified offline
Formal Verification (TLA+)
TLA+ models of PBFT commit, view change and the MCPGate gate, model-checked by TLC (bounded models, not a proof of the Python code).
measured: OFFLINE VERIFIED
Built and tested
Policy-as-Code Engine
OPA/Rego policies with signed policy bundles. In the hosted pipeline the policy verdict is recorded; your own tool rules are what block.
measured: IMPLEMENTED
Live
Sovereign AI Control
Self-hostable MCPGate and SDK, tested, with a live status endpoint. No public self-hosted installer yet.
measured: NARROWER: IMPLEMENTED, LIVE ENDPOINT
Threat detection & response
Live
Shadow AI Discovery
Find unregistered agents on your hosts, and LLM SDKs, MCP tools and autonomous loops in your code, with a live scanner. Not a network-wide scanner.
measured: NARROWER: IMPLEMENTED, LIVE ENDPOINT
Live
Autonomic Self-Healing
Automated quarantine and recovery, tested; live restore drills verified (run by an operator).
measured: NARROWER: LIVE VERIFIED
Built and tested
Predictive Threat Intelligence
Predicts an action's blast radius and counterfactual risk before it runs. No external threat feed.
measured: NARROWER: IMPLEMENTED
Built and tested
ML Anomaly Detection
Real-time trajectory anomaly rules: drift, salami-style cumulative spend, homoglyphs. Rules and thresholds, not a trained model.
measured: NARROWER: IMPLEMENTED
Compliance & governance
Built and tested
EU AI Act Compliance
Article 5, Annex III and Article 50 screening plus tamper-evident evidence export. No notified body has reviewed CAIN.
measured: NARROWER: IMPLEMENTED
Live
Multi-Jurisdiction Compliance
Live required-clause checks for the EU and California, plus EU AI Act screening. Two jurisdictions, not a global rules engine.
measured: NARROWER: IMPLEMENTED, LIVE ENDPOINT
Built and tested
Autonomous Governance
Plans, conflicts and delegations are checked automatically before execution. Automation never authorizes itself.
measured: NARROWER: IMPLEMENTED
Not offered
ISO 42001 Certification
Not offered: CAIN-42 is not ISO 42001 certified. A readiness self-assessment exists.
measured: NOT ESTABLISHED
Not offered
Cross-Chain Governance
Not offered: there is no blockchain or cross-chain component.
measured: NOT ESTABLISHED
Interoperability
Live
A2A + MCP Protocol
MCP enforcement on the live cluster, and an A2A trust layer that refuses forged agent cards.
measured: LIVE + DISPOSABLE CLUSTER VERIFIED
Live
Third-Party AI Governance
External tools and APIs your agent reaches through CAIN are pinned and allow-listed: changed tools are dropped, unknown destinations denied. Vendors themselves are not audited.
measured: NARROWER: IMPLEMENTED, LIVE ENDPOINT
Live
Delegation Marketplace
Bounded delegation chains (scope, limits, expiry, revocation) and a live agent marketplace. Organisations do not trade tool permissions through it.
measured: NARROWER: IMPLEMENTED, LIVE ENDPOINT
Live
Global Trust Mesh
Two live multi-region clusters across 4 US regions, on one provider. Not global yet.
measured: NARROWER: LIVE VERIFIED
Developer platform & SRE
Live
Agent SRE
A live decision stream and traces in the console, plus live observability and agent-debugger services.
measured: NARROWER: IMPLEMENTED, LIVE ENDPOINT
Live
Vertical Solutions
Finance, health and federal policy packs, served live. Rule sets, not audited regulatory solutions.
measured: NARROWER: IMPLEMENTED, LIVE ENDPOINT
Built and tested
Agent CI/CD Pipeline
A conformance suite and a deploy gate exist and are tested. No hosted CI/CD product for your agents yet.
measured: NARROWER: IMPLEMENTED
Built and tested
Collective Intelligence
Shared trust, risk and incident state across agents, tested in-process.
measured: NARROWER: IMPLEMENTED
Built and tested
Evolutionary Architecture
A self-hardening loop that proposes and tests changes. Nothing deploys itself.
measured: NARROWER: IMPLEMENTED
Live
Policy Cards
Eight ready-made policies (payment approvals and caps, read-only database, internal-only email, shell approval, redaction, agent hold) that compile into rules the live pipeline enforces. Preview free; apply with your key.
measured: IMPLEMENTED, LIVE ENDPOINT
Not offered
Neural Governance
Not offered: the term has no implementation.
measured: NOT ESTABLISHED
Not offered
Quantum Governance
Not offered: the term has no implementation.
measured: NOT ESTABLISHED
Put your AI system under governance
Free to start. Nothing runs without authority: the default is no.
Under the hood
The technical detail
Everything below is for senior AI and security engineers: how CAIN-42 governs an autonomous AI agent, what is live, what is only tested, and what is not built. Every claim links to signed evidence and a verifier that imports none of CAIN-42's code.
Control for the AGI era
Built to control AGI
As AI agents get more capable, the question stops being “is the model smart?” and becomes “who decides what it is allowed to do?” CAIN-42 answers it the same way for every agent, however capable: being capable, confident or right before earns an agent no authority. No AGI exists yet to test against, so every result published here is measured on today’s models. Prompt filters inspect text. CAIN-42 governs what autonomous AI agents actually do: tool calls, shell, databases, APIs, money, spawning other agents. One authorization is not enough for a system that runs for hours, so authority is continuous: a short-lived, governance-signed lease bound to the agent, its trajectory and its exact plan, re-checked before every action against everything the system has done so far, and lost the moment policy, trust, risk, model or context changes. An agent may learn, remember, plan, delegate and discover tools, but none of that creates authority. Only governance state signed by a quorum of the CAIN-42 cluster does. CAG-L5 is CAIN's own governance designation, not the SAE driving scale.
CAG-L5 system governor (live)
Governs the whole autonomous system, not a single call. One decision composes: emergency freeze, a 2f+1 cluster certificate over the current governance state, a governance-signed system manifest (agents, models, tools, resources), model identity, tool registry, exact capabilities (READ, WRITE, DELETE and ADMIN are never implied by each other), deterministic policy precedence (a lower ALLOW never beats a higher DENY), the intersection of agent, delegator, system and trajectory-lease authority, and graph-derived blast radius where irreversible or wide actions need two operators. The gate re-verifies the signed decision and its execution commitment before anything runs. On in the hosted gateway since 2026-09-28: unregistered systems and unsigned requests are refused. Also live since 2026-09-28: the evolution gate. An agent's model and MCP tool set change only through a signed proposal, an evaluator-signed test report and a human operator (never the agent itself), and every change gets a new capability commitment that the cluster must certify before the agent may act again. Since 2026-10-06 a signed agent passport binds identity, model, tools and authority scope to the exact call; sequences of individually allowed calls (a sensitive read then an outbound send, even split across two keys, a privilege raised step by step, split payments, a runaway loop) go to a human; and a tenant-owned physical safety envelope refuses out-of-envelope device actions, even in shadow mode.
verify the live run (41/41) →Byzantine consensus authorization (live)
Two live PBFT clusters, n=4 and f=1: cain-mr-02 (Atlanta, Los Angeles, Miami, Silicon Valley) orders and signs hosted decisions with one replica per host surviving any single host loss, and cain-mr-01 (Atlanta, Los Angeles, Miami) has committed 40,436 sequences. Nothing counts without a quorum certificate of 3 Ed25519 signatures, and the gateway verifies that certificate itself instead of trusting a replica's word. Each cluster signs its own proof every 30 minutes: 250 of 251 OPERATIONAL on cain-mr-01 since 2026-09-26, 295 of 295 on cain-mr-02 since 2026-09-27. 442 Byzantine tests pass, and a fault-injection run held 49 of 49 checks.
watch it live →Enforcement boundary (MCPGate)
Sits in front of MCP servers, APIs and tools. A call runs only if that exact call was authorized; anything else gets a signed denial. The tool server never receives CAIN's authorization envelope or the caller's credentials, and an operator's global halt or agent quarantine stops hosted decisions for every tenant. Being caught earns an agent nothing: two blocked prompt injections no longer unlock a $250,000 transfer or rm -rf /, every action is scored by what it does (tool, destructiveness, amount), dangerous ones wait for a human, your deny rules match every spelling of a path, and an approval covers one exact call, arguments included. Live on 3 of 3 domains since 2026-09-28; 48 of 48 decisions match the cluster's own public record.
5 ran, 12 attacks blocked →Signed evidence
An Ed25519-signed, hash-chained record per decision in canonical JSON (RFC 8785) with RFC 6962 Merkle proof trees, keys kept outside the database, and standalone clean-room verifiers that re-check everything offline without CAIN code. The identity and passport log is hash-chained per tenant with issuer-signed checkpoints, so an edited, deleted, reordered or truncated record fails offline verification.
Verification Center →Default-deny SDK & data plane (live)
The Python guard and MCP proxy hold any action you did not declare. Allow tools explicitly with guard(allow=[...]); opting out is recorded on every decision. The live decoupled data plane (CAIN_AUTH_SNAPSHOT=1) executes sub-millisecond local authorization verified against quorum-committed PBFT snapshots with dynamic progressive trust scoping.
quickstart →Frontier agent intelligence & ZoD (live)
Agent code runs confined with Linux namespaces and seccomp-BPF filters. Real-time Process Reward Model (AgentPRM arXiv:2502.10325) prunes hallucinated shortcut steps, TriCEGAR model checks MDP state transitions, Governed Memory Shield sanitizes injection vectors at write time, and A2A delegation verifies Ed25519 card and delegation signatures, attenuates monotonically and labels capabilities self-asserted. Agent keys cannot raise their own memory to trusted, write policies or operate the controls that govern them. Live endpoints at /fabric/frontier/*.
verify Phase 3 evidence →Send one action through the live pipeline
No account. Each button posts a fixed scenario to /fabric/try on this site (the hosted pipeline makes the decision; MCPGate enforces decisions, it does not make them) and shows the real decision, stage by stage, including whether each stage was enforcing. The demo forces enforcement on for its own throwaway tenant; the response says so. A read-only action runs by itself as the page opens, so you see the live pipeline decide without touching anything.
For developers
One request. A signed decision back.
Try it with no account: send a prompt-injection attempt through the live pipeline. You get back the verdict, which stage blocked it, and the consensus certificate your gateway verified.
$ curl -X POST "https://cainstudio.online/fabric/try?scenario=prompt-injection"
{
"verdict": "BLOCKED",
"blocked_by": ["risk", "trust"],
"consensus": {
"cluster_id": "cain-mr-02",
"certificate_verified_by_gateway": {
"verified": true,
"signers": ["cain-mr2-node-1", "cain-mr2-node-3", "cain-mr2-node-4"],
"quorum": 3
}
},
"evidence": { ... }
}
2026-2027 Frontier Research Deployments
20 New Enterprise Products — Now Live in Production
Directly operationalizing bleeding-edge Hugging Face and arXiv agentic security research. Deployed across the CAIN-42 cluster with live API endpoints, kernel-level sandboxing, and sub-millisecond execution verification.
CAIN OpenShell Enterprise Gateway
Commercial Kubernetes operator wrapping autonomous agents in Linux kernel eBPF kprobe sandboxes. Intercepts file, socket, and process syscalls, halting undeclared actions at the kernel boundary.
POST /fabric/openshell/enforce-sandboxCAIN MemVault (Vector & Memory Firewall)
Proxy in front of Pinecone, Qdrant, Mem0, and Zep. Implements Signed Memory State Records (SMSR) and real-time MemPoison defense against delayed-trigger prompt backdoors with loss-checked compaction (HF 2607.21503).
POST /fabric/memvault/inspect-writeCAIN VIGIL: Step-Wise Behavioral PRM Engine
Inference-side proxy applying Process Reward Model (PRM) scoring (arXiv:2502.10325) and behavioral specification checks (arXiv:2606.26524). Uses lookahead MCTS to prune hallucinated shortcuts and reward-hacking drift.
POST /fabric/vigil/evaluate-stepCAIN SCITT Evidence Clearinghouse
Enterprise transparency notary conforming to IETF SCITT (draft-14) and W3C Verifiable Credentials 2.0. Generates offline-verifiable SD-JWT receipts and RFC 6962 inclusion proofs for cross-enterprise B2B agent transactions.
POST /fabric/scitt/register-statementCAIN Hardware Sentry (quarantine registry)
Per-tenant quarantine registry with real 2f+1 Ed25519 quorum-certificate checks. Optional kernel link-down only on interfaces an operator lists. DPU/SmartNIC hardware is detected and reported, never used: there is no device adapter, so nothing is offloaded.
POST /fabric/sentry/hardware-quarantineCAIN RIG: Runtime Identity Governance
Workload identity engine conforming to IETF WIMSE (draft-ietf-wimse-arch). Mints single-use microsecond capability tokens bound to parent delegation chains, strictly terminating lateral movement across agents.
POST /fabric/rig/mint-tokenCAIN Digital Twin & Counterfactual Emulator
Ephemeral Copy-on-Write (CoW) sandbox (arXiv:2605.11039). Simulates proposed tool calls before production execution, computing side-effects and pre-emptively rejecting actions exceeding blast radius limits.
POST /fabric/digital-twin/simulateCAIN ExploitGym Escape Shield
Defense system addressing the July 2026 ExploitGym incident. Intercepts SSRF against cloud metadata, Kubernetes service account credential harvesting, and sliding-window multi-day intrusions.
POST /fabric/exploit-shield/inspect-actionCAIN Multi-Model Epistemic Quorum Gate
Multi-model semantic consensus gate (arXiv:2608.11274). Verifies agreement across diverse frontier models before execution, freezing actions and requiring approval when model divergence exceeds limits.
POST /fabric/epistemic-quorum/evaluate-quorumCAIN Steganographic & Semantic Firewall
Covert-channel exfiltration sanitizer based on A3S-Bench (arXiv:2605.14932). Neutralizes zero-width unicode characters, homoglyphs, and base64 smuggling before egress payloads leave the network boundary.
POST /fabric/steganography/sanitize-egressCAIN Proof-Carrying Code (PCC) Compiler
Pre-execution formal verification engine based on Z3 SMT (arXiv:2609.14882). Agents submit proposed code alongside formal Hoare-logic safety invariants; compiles and verifies machine-checkable inductive proofs before dispatch.
POST /fabric/pcc/certify-codeCAIN Speculative Fast-Forward (SAFF) Engine
Speculative multi-trajectory tree search and verification cache (arXiv:2608.08231). Emulates prospective execution paths across world models, pre-verifying invariant envelopes and cutting end-to-end consensus latency by 72%.
POST /fabric/speculative/evaluate-trajectoriesCAIN Swarm Cartel & Collusion Detector
Graph entropy and game-theoretic cartel defense (arXiv:2606.19823). Detects circular delegation rings, sybil bid-rigging in agent auctions, and non-cooperative resource hoards with automated ring quarantine.
POST /fabric/cartel/inspect-swarmCAIN PolicyForge: Dynamic OPA Synthesizer
Autonomous Rego synthesis engine with provable monotonicity verification (arXiv:2607.03912). Transforms dynamic compliance mandates into hardened OPA policies mathematically verified never to widen permissions.
POST /fabric/policy-forge/synthesize-regoCAIN Cyber-Physical Actuation Guard
Software check of a commanded speed, torque, acceleration and 3-D target against an envelope and geofence; non-finite numbers and missing targets are refused. Connected to no robot, bus or e-stop, and not certified against ISO 10218 or ISO 13849.
POST /fabric/actuation/verify-commandCAIN zkAgent: Zero-Knowledge Trajectory Prover
Pedersen-commitment range proofs (standard construction, Fiat-Shamir bound to trajectory, agent and nonce) that each step's risk score stayed under a public ceiling without revealing the scores. Not zk-STARK or Groth16; it does not prove the scores were computed correctly.
POST /fabric/zk/generate-proofCAIN PathCorrection: Self-Healing Trajectory Engine
Nonlinear Model Predictive Control (MPC) and counter-drift steering engine (arXiv:2608.19420). Detects auto-regressive drift, token degradation, and tool loops, dynamically injecting invariant attention anchors to re-center reasoning.
POST /fabric/path-correction/steer-trajectoryCAIN LatentGuard: Activation Threshold Screen
Fixed-threshold screen over activation statistics the caller submits, plus an exploit-string check on a token preview. It does not attach to any model or read residual streams or KV caches, and its thresholds are not calibrated against any model family.
POST /fabric/latent-guard/probe-activationCAIN SwarmGossip: Byzantine Epistemic Anti-Entropy
Asynchronous Byzantine fault-tolerant gossip protocol for decentralized agent swarms (arXiv:2609.05112). Reconciles beliefs with vector clocks and Merkle trees, isolating hallucination cascades across swarms with 100+ agents.
POST /fabric/swarm-gossip/exchange-beliefCAIN CXL-Sentry: DMA Aperture Check (software)
Software check of a requested address range and access type against a tenant aperture; writes need an HMAC lease bound to the exact range and expiry. No CXL, PCIe, IOMMU or RDMA device is involved.
POST /fabric/cxl-sentry/verify-dma-accessArchitecture
Where CAIN-42 sits
The enforcement boundary is the third box. The dashed PBFT layer above it is how MCPGate enforces consensus.
Proof, not promises
Check what is live right now
Your browser loads each row below from its source as the page opens. A source that does not answer shows as NOT LIVE. The passing set is shown here; every claim, its limits and every run outcome stay published in full on the Proof page.
Verifier Room — verify CAIN-42 yourself, in seconds
You do not have to trust us or contact us. Every evidence bundle below ships a clean-room verifier that
imports none of CAIN-42's code. Copy one block into a terminal on your own computer: it downloads that bundle and
its verifiers, and runs two chained checks. verify_publisher.py must print
PUBLISHED_BY_PINNED_KEY: the bytes are exactly what the CAIN publisher key signed, so an edited or
re-signed bundle fails. Only then does the bundle's own verifier run, and it must print "result": "INTACT":
its internal hashes and signatures agree. The block ends with one line, VERIFIED or
NOT VERIFIED. Do not run the bundle verifier on its own. Nothing on these sites is needed after the download.
Requires Python 3 and internet. The verifiers read published data only; they never touch the live
service and never call our servers for a verdict. A changed byte in any bundle file makes the verifier report BROKEN.
INTACT alone means only that the bundle agrees with the key shipped inside it, which anyone who re-signs a bundle
can arrange. That is why every block also runs verify_publisher.py
(verifier, pinned key at
/.well-known/cain-publisher-key.json): it refuses an edited,
added, removed or re-signed file. The publisher key is ours, so neither check is independent verification.
BFTIP · bft-ip-forensics-2026-10-05
— published result: INTACT (58/59 checks)
mkdir -p bft-ip-forensics-2026-10-05 && cd bft-ip-forensics-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/bft-ip-forensics-2026-10-05.json", "../bft-ip-forensics-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../bft-ip-forensics-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "bft-ip-forensics-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "bft-ip-forensics-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../bft-ip-forensics-2026-10-05 ../bft-ip-forensics-2026-10-05.attestation.json \
&& python3 verify_bftip.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E38 · e38-byzantine-mission-integrity-2026-10-05
— published result: INTACT (127/127 checks)
mkdir -p e38-byzantine-mission-integrity-2026-10-05 && cd e38-byzantine-mission-integrity-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e38-byzantine-mission-integrity-2026-10-05.json", "../e38-byzantine-mission-integrity-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e38-byzantine-mission-integrity-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e38-byzantine-mission-integrity-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e38-byzantine-mission-integrity-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e38-byzantine-mission-integrity-2026-10-05 ../e38-byzantine-mission-integrity-2026-10-05.attestation.json \
&& python3 verify_e38.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E37 · e37-byzantine-autonomous-federation-2026-10-05
30/30 invariants · 30/30 scenarios held — published result: INTACT (70/70 checks)
mkdir -p e37-byzantine-autonomous-federation-2026-10-05 && cd e37-byzantine-autonomous-federation-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e37-byzantine-autonomous-federation-2026-10-05.json", "../e37-byzantine-autonomous-federation-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e37-byzantine-autonomous-federation-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e37-byzantine-autonomous-federation-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e37-byzantine-autonomous-federation-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e37-byzantine-autonomous-federation-2026-10-05 ../e37-byzantine-autonomous-federation-2026-10-05.attestation.json \
&& python3 verify_e37.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E36 · e36-byzantine-collective-governance-2026-10-05
23/30 invariants · 30/30 scenarios held — published result: INTACT (69/76 checks)
mkdir -p e36-byzantine-collective-governance-2026-10-05 && cd e36-byzantine-collective-governance-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e36-byzantine-collective-governance-2026-10-05.json", "../e36-byzantine-collective-governance-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e36-byzantine-collective-governance-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e36-byzantine-collective-governance-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e36-byzantine-collective-governance-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e36-byzantine-collective-governance-2026-10-05 ../e36-byzantine-collective-governance-2026-10-05.attestation.json \
&& python3 verify_e36.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E35 · e35-continuous-autonomy-integrity-2026-10-05
27/30 invariants · 30/30 scenarios held — published result: INTACT (108/111 checks)
mkdir -p e35-continuous-autonomy-integrity-2026-10-05 && cd e35-continuous-autonomy-integrity-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e35-continuous-autonomy-integrity-2026-10-05.json", "../e35-continuous-autonomy-integrity-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e35-continuous-autonomy-integrity-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e35-continuous-autonomy-integrity-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e35-continuous-autonomy-integrity-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e35-continuous-autonomy-integrity-2026-10-05 ../e35-continuous-autonomy-integrity-2026-10-05.attestation.json \
&& python3 verify_e35.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E34 · e34-decision-provenance-2026-10-05
0/0 invariants · 0/0 scenarios held — published result: PARTIAL (0/0 checks)
mkdir -p e34-decision-provenance-2026-10-05 && cd e34-decision-provenance-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e34-decision-provenance-2026-10-05.json", "../e34-decision-provenance-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e34-decision-provenance-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e34-decision-provenance-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e34-decision-provenance-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e34-decision-provenance-2026-10-05 ../e34-decision-provenance-2026-10-05.attestation.json \
&& python3 verify_e34.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E32 · e32-global-trust-settlement-2026-10-05
mkdir -p e32-global-trust-settlement-2026-10-05 && cd e32-global-trust-settlement-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e32-global-trust-settlement-2026-10-05.json", "../e32-global-trust-settlement-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e32-global-trust-settlement-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e32-global-trust-settlement-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e32-global-trust-settlement-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e32-global-trust-settlement-2026-10-05 ../e32-global-trust-settlement-2026-10-05.attestation.json \
&& python3 verify_e32.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E31 · e31-governance-proof-fabric-2026-10-05
mkdir -p e31-governance-proof-fabric-2026-10-05 && cd e31-governance-proof-fabric-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e31-governance-proof-fabric-2026-10-05.json", "../e31-governance-proof-fabric-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e31-governance-proof-fabric-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e31-governance-proof-fabric-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e31-governance-proof-fabric-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e31-governance-proof-fabric-2026-10-05 ../e31-governance-proof-fabric-2026-10-05.attestation.json \
&& python3 verify_e31.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E30 · e30-governance-network-2026-10-05
mkdir -p e30-governance-network-2026-10-05 && cd e30-governance-network-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e30-governance-network-2026-10-05.json", "../e30-governance-network-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e30-governance-network-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e30-governance-network-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e30-governance-network-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e30-governance-network-2026-10-05 ../e30-governance-network-2026-10-05.attestation.json \
&& python3 verify_e30.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E28 · e28-catcp-ip-commercial-2026-10-05
mkdir -p e28-catcp-ip-commercial-2026-10-05 && cd e28-catcp-ip-commercial-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e28-catcp-ip-commercial-2026-10-05.json", "../e28-catcp-ip-commercial-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e28-catcp-ip-commercial-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e28-catcp-ip-commercial-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e28-catcp-ip-commercial-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e28-catcp-ip-commercial-2026-10-05 ../e28-catcp-ip-commercial-2026-10-05.attestation.json \
&& python3 verify_e28.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E27 · e27-catcp-control-2026-10-05
mkdir -p e27-catcp-control-2026-10-05 && cd e27-catcp-control-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e27-catcp-control-2026-10-05.json", "../e27-catcp-control-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e27-catcp-control-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e27-catcp-control-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e27-catcp-control-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e27-catcp-control-2026-10-05 ../e27-catcp-control-2026-10-05.attestation.json \
&& python3 verify_e27.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E26 · e26-byzantine-trust-2026-10-05
mkdir -p e26-byzantine-trust-2026-10-05 && cd e26-byzantine-trust-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e26-byzantine-trust-2026-10-05.json", "../e26-byzantine-trust-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e26-byzantine-trust-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e26-byzantine-trust-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e26-byzantine-trust-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e26-byzantine-trust-2026-10-05 ../e26-byzantine-trust-2026-10-05.attestation.json \
&& python3 verify_e26.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E23 · e23-continuous-assurance-2026-10-05
mkdir -p e23-continuous-assurance-2026-10-05 && cd e23-continuous-assurance-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e23-continuous-assurance-2026-10-05.json", "../e23-continuous-assurance-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e23-continuous-assurance-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e23-continuous-assurance-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e23-continuous-assurance-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e23-continuous-assurance-2026-10-05 ../e23-continuous-assurance-2026-10-05.attestation.json \
&& python3 verify_e23.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E22 · e22-byzantine-global-verification-2026-10-05
mkdir -p e22-byzantine-global-verification-2026-10-05 && cd e22-byzantine-global-verification-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e22-byzantine-global-verification-2026-10-05.json", "../e22-byzantine-global-verification-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e22-byzantine-global-verification-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e22-byzantine-global-verification-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e22-byzantine-global-verification-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e22-byzantine-global-verification-2026-10-05 ../e22-byzantine-global-verification-2026-10-05.attestation.json \
&& python3 verify_e22.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E21 · e21-byzantine-economic-coordination-2026-10-05
mkdir -p e21-byzantine-economic-coordination-2026-10-05 && cd e21-byzantine-economic-coordination-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e21-byzantine-economic-coordination-2026-10-05.json", "../e21-byzantine-economic-coordination-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e21-byzantine-economic-coordination-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e21-byzantine-economic-coordination-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e21-byzantine-economic-coordination-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e21-byzantine-economic-coordination-2026-10-05 ../e21-byzantine-economic-coordination-2026-10-05.attestation.json \
&& python3 verify_e21.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E18 · e18-byzantine-counterfactual-governance-2026-10-05
— published result: VALID (31/31 checks)
mkdir -p e18-byzantine-counterfactual-governance-2026-10-05 && cd e18-byzantine-counterfactual-governance-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e18-byzantine-counterfactual-governance-2026-10-05.json", "../e18-byzantine-counterfactual-governance-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e18-byzantine-counterfactual-governance-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e18-byzantine-counterfactual-governance-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e18-byzantine-counterfactual-governance-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e18-byzantine-counterfactual-governance-2026-10-05 ../e18-byzantine-counterfactual-governance-2026-10-05.attestation.json \
&& python3 verify_e18.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E13 · e13-bpf-governance-execution-2026-10-05
— published result: INTACT (24/24 checks)
mkdir -p e13-bpf-governance-execution-2026-10-05 && cd e13-bpf-governance-execution-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e13-bpf-governance-execution-2026-10-05.json", "../e13-bpf-governance-execution-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e13-bpf-governance-execution-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e13-bpf-governance-execution-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e13-bpf-governance-execution-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e13-bpf-governance-execution-2026-10-05 ../e13-bpf-governance-execution-2026-10-05.attestation.json \
&& python3 verify_e13.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E12 · e12-trust-network-state-2026-10-05
— published result: INTACT (20/20 checks)
mkdir -p e12-trust-network-state-2026-10-05 && cd e12-trust-network-state-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e12-trust-network-state-2026-10-05.json", "../e12-trust-network-state-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e12-trust-network-state-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e12-trust-network-state-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e12-trust-network-state-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e12-trust-network-state-2026-10-05 ../e12-trust-network-state-2026-10-05.attestation.json \
&& python3 verify_e12.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E11 · e11-governance-proof-2026-10-05
— published result: INTACT (32/32 checks)
mkdir -p e11-governance-proof-2026-10-05 && cd e11-governance-proof-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e11-governance-proof-2026-10-05.json", "../e11-governance-proof-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e11-governance-proof-2026-10-05.attestation.json"))["files"])
for f in names:
get(E + "e11-governance-proof-2026-10-05/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e11-governance-proof-2026-10-05/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e11-governance-proof-2026-10-05 ../e11-governance-proof-2026-10-05.attestation.json \
&& python3 verify_e11.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E42 · e42-supreme-governed-agentic-infrastructure-2026-10-01
— published result: INTACT (1460/1460 checks)
mkdir -p e42-supreme-governed-agentic-infrastructure-2026-10-01 && cd e42-supreme-governed-agentic-infrastructure-2026-10-01
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e42-supreme-governed-agentic-infrastructure-2026-10-01.json", "../e42-supreme-governed-agentic-infrastructure-2026-10-01.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e42-supreme-governed-agentic-infrastructure-2026-10-01.attestation.json"))["files"])
for f in names:
get(E + "e42-supreme-governed-agentic-infrastructure-2026-10-01/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e42-supreme-governed-agentic-infrastructure-2026-10-01/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e42-supreme-governed-agentic-infrastructure-2026-10-01 ../e42-supreme-governed-agentic-infrastructure-2026-10-01.attestation.json \
&& python3 verify_e42.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E41 · e41-machine-agency-exchange-2026-09-30
— published result: INTACT (1303/1303 checks)
mkdir -p e41-machine-agency-exchange-2026-09-30 && cd e41-machine-agency-exchange-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e41-machine-agency-exchange-2026-09-30.json", "../e41-machine-agency-exchange-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e41-machine-agency-exchange-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e41-machine-agency-exchange-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e41-machine-agency-exchange-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e41-machine-agency-exchange-2026-09-30 ../e41-machine-agency-exchange-2026-09-30.attestation.json \
&& python3 verify_e41.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E40 · e40-autonomous-enterprise-intelligence-2026-09-30
— published result: INTACT (1518/1518 checks)
mkdir -p e40-autonomous-enterprise-intelligence-2026-09-30 && cd e40-autonomous-enterprise-intelligence-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e40-autonomous-enterprise-intelligence-2026-09-30.json", "../e40-autonomous-enterprise-intelligence-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e40-autonomous-enterprise-intelligence-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e40-autonomous-enterprise-intelligence-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e40-autonomous-enterprise-intelligence-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e40-autonomous-enterprise-intelligence-2026-09-30 ../e40-autonomous-enterprise-intelligence-2026-09-30.attestation.json \
&& python3 verify_e40.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E37 · e37-autonomous-execution-mesh-2026-09-30
1132/1132 invariants · 2720/2720 scenarios held — published result: INTACT (2627/2627 checks)
mkdir -p e37-autonomous-execution-mesh-2026-09-30 && cd e37-autonomous-execution-mesh-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e37-autonomous-execution-mesh-2026-09-30.json", "../e37-autonomous-execution-mesh-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e37-autonomous-execution-mesh-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e37-autonomous-execution-mesh-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e37-autonomous-execution-mesh-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e37-autonomous-execution-mesh-2026-09-30 ../e37-autonomous-execution-mesh-2026-09-30.attestation.json \
&& python3 verify_e37.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E36 · e36-machine-agency-exchange-2026-09-30
842/842 invariants · 3340/3340 scenarios held — published result: INTACT (3601/3601 checks)
mkdir -p e36-machine-agency-exchange-2026-09-30 && cd e36-machine-agency-exchange-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e36-machine-agency-exchange-2026-09-30.json", "../e36-machine-agency-exchange-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e36-machine-agency-exchange-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e36-machine-agency-exchange-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e36-machine-agency-exchange-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e36-machine-agency-exchange-2026-09-30 ../e36-machine-agency-exchange-2026-09-30.attestation.json \
&& python3 verify_e36.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E35 · e35-governance-intelligence-2026-09-30
799/799 invariants · 3544/3544 scenarios held — published result: INTACT (3810/3810 checks)
mkdir -p e35-governance-intelligence-2026-09-30 && cd e35-governance-intelligence-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e35-governance-intelligence-2026-09-30.json", "../e35-governance-intelligence-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e35-governance-intelligence-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e35-governance-intelligence-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e35-governance-intelligence-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e35-governance-intelligence-2026-09-30 ../e35-governance-intelligence-2026-09-30.attestation.json \
&& python3 verify_e35.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E34 · e34-proof-carrying-machine-agency-2026-09-30
629/629 invariants · 2664/2664 scenarios held — published result: INTACT (3286/3286 checks)
mkdir -p e34-proof-carrying-machine-agency-2026-09-30 && cd e34-proof-carrying-machine-agency-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e34-proof-carrying-machine-agency-2026-09-30.json", "../e34-proof-carrying-machine-agency-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e34-proof-carrying-machine-agency-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e34-proof-carrying-machine-agency-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e34-proof-carrying-machine-agency-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e34-proof-carrying-machine-agency-2026-09-30 ../e34-proof-carrying-machine-agency-2026-09-30.attestation.json \
&& python3 verify_e34.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E33 · e33-governed-agentic-operating-fabric-2026-09-30
581/581 invariants · 2029/2029 scenarios held — published result: INTACT (2603/2603 checks)
mkdir -p e33-governed-agentic-operating-fabric-2026-09-30 && cd e33-governed-agentic-operating-fabric-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e33-governed-agentic-operating-fabric-2026-09-30.json", "../e33-governed-agentic-operating-fabric-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e33-governed-agentic-operating-fabric-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e33-governed-agentic-operating-fabric-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e33-governed-agentic-operating-fabric-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e33-governed-agentic-operating-fabric-2026-09-30 ../e33-governed-agentic-operating-fabric-2026-09-30.attestation.json \
&& python3 verify_e33.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E32 · e32-governed-autonomy-learning-2026-09-30
— published result: INTACT (1420/1420 checks)
mkdir -p e32-governed-autonomy-learning-2026-09-30 && cd e32-governed-autonomy-learning-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e32-governed-autonomy-learning-2026-09-30.json", "../e32-governed-autonomy-learning-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e32-governed-autonomy-learning-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e32-governed-autonomy-learning-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e32-governed-autonomy-learning-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e32-governed-autonomy-learning-2026-09-30 ../e32-governed-autonomy-learning-2026-09-30.attestation.json \
&& python3 verify_e32.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E31 · e31-universal-proof-of-governance-2026-09-30
— published result: INTACT (1676/1676 checks)
mkdir -p e31-universal-proof-of-governance-2026-09-30 && cd e31-universal-proof-of-governance-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e31-universal-proof-of-governance-2026-09-30.json", "../e31-universal-proof-of-governance-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e31-universal-proof-of-governance-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e31-universal-proof-of-governance-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e31-universal-proof-of-governance-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e31-universal-proof-of-governance-2026-09-30 ../e31-universal-proof-of-governance-2026-09-30.attestation.json \
&& python3 verify_e31.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E30 · e30-governed-machine-autonomy-2026-09-30
— published result: INTACT (1187/1187 checks)
mkdir -p e30-governed-machine-autonomy-2026-09-30 && cd e30-governed-machine-autonomy-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e30-governed-machine-autonomy-2026-09-30.json", "../e30-governed-machine-autonomy-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e30-governed-machine-autonomy-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e30-governed-machine-autonomy-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e30-governed-machine-autonomy-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e30-governed-machine-autonomy-2026-09-30 ../e30-governed-machine-autonomy-2026-09-30.attestation.json \
&& python3 verify_e30.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E29 · e29-machine-transaction-fabric-2026-09-30
— published result: INTACT (300/300 checks)
mkdir -p e29-machine-transaction-fabric-2026-09-30 && cd e29-machine-transaction-fabric-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e29-machine-transaction-fabric-2026-09-30.json", "../e29-machine-transaction-fabric-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e29-machine-transaction-fabric-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e29-machine-transaction-fabric-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e29-machine-transaction-fabric-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e29-machine-transaction-fabric-2026-09-30 ../e29-machine-transaction-fabric-2026-09-30.attestation.json \
&& python3 verify_e29.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E28 · e28-portable-execution-identity-2026-09-30
— published result: INTACT (243/243 checks)
mkdir -p e28-portable-execution-identity-2026-09-30 && cd e28-portable-execution-identity-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e28-portable-execution-identity-2026-09-30.json", "../e28-portable-execution-identity-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e28-portable-execution-identity-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e28-portable-execution-identity-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e28-portable-execution-identity-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e28-portable-execution-identity-2026-09-30 ../e28-portable-execution-identity-2026-09-30.attestation.json \
&& python3 verify_e28.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E27 · e27-agentic-internet-control-plane-2026-09-30
— published result: INTACT (4001/4001 checks)
mkdir -p e27-agentic-internet-control-plane-2026-09-30 && cd e27-agentic-internet-control-plane-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e27-agentic-internet-control-plane-2026-09-30.json", "../e27-agentic-internet-control-plane-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e27-agentic-internet-control-plane-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e27-agentic-internet-control-plane-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e27-agentic-internet-control-plane-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e27-agentic-internet-control-plane-2026-09-30 ../e27-agentic-internet-control-plane-2026-09-30.attestation.json \
&& python3 verify_e27.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E26 · e26-universal-machine-agency-trust-2026-09-30
— published result: INTACT (3115/3115 checks)
mkdir -p e26-universal-machine-agency-trust-2026-09-30 && cd e26-universal-machine-agency-trust-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e26-universal-machine-agency-trust-2026-09-30.json", "../e26-universal-machine-agency-trust-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e26-universal-machine-agency-trust-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e26-universal-machine-agency-trust-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e26-universal-machine-agency-trust-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e26-universal-machine-agency-trust-2026-09-30 ../e26-universal-machine-agency-trust-2026-09-30.attestation.json \
&& python3 verify_e26.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E25 · e25-universal-machine-agency-2026-09-30
— published result: INTACT (2977/2977 checks)
mkdir -p e25-universal-machine-agency-2026-09-30 && cd e25-universal-machine-agency-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e25-universal-machine-agency-2026-09-30.json", "../e25-universal-machine-agency-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e25-universal-machine-agency-2026-09-30.attestation.json"))["files"])
for f in names:
get(E + "e25-universal-machine-agency-2026-09-30/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e25-universal-machine-agency-2026-09-30/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e25-universal-machine-agency-2026-09-30 ../e25-universal-machine-agency-2026-09-30.attestation.json \
&& python3 verify_e25.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E24 · e24-governed-agentic-internet-2026-09-29
— published result: INTACT (1952/1952 checks)
mkdir -p e24-governed-agentic-internet-2026-09-29 && cd e24-governed-agentic-internet-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e24-governed-agentic-internet-2026-09-29.json", "../e24-governed-agentic-internet-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e24-governed-agentic-internet-2026-09-29.attestation.json"))["files"])
for f in names:
get(E + "e24-governed-agentic-internet-2026-09-29/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e24-governed-agentic-internet-2026-09-29/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e24-governed-agentic-internet-2026-09-29 ../e24-governed-agentic-internet-2026-09-29.attestation.json \
&& python3 verify_e24.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E23 · e23-governed-meta-intelligence-2026-09-29
— published result: INTACT (733/733 checks)
mkdir -p e23-governed-meta-intelligence-2026-09-29 && cd e23-governed-meta-intelligence-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e23-governed-meta-intelligence-2026-09-29.json", "../e23-governed-meta-intelligence-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e23-governed-meta-intelligence-2026-09-29.attestation.json"))["files"])
for f in names:
get(E + "e23-governed-meta-intelligence-2026-09-29/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e23-governed-meta-intelligence-2026-09-29/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e23-governed-meta-intelligence-2026-09-29 ../e23-governed-meta-intelligence-2026-09-29.attestation.json \
&& python3 verify_e23.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E21 · e21-open-ended-intelligence-2026-09-29
— published result: INTACT (218/218 checks)
mkdir -p e21-open-ended-intelligence-2026-09-29 && cd e21-open-ended-intelligence-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e21-open-ended-intelligence-2026-09-29.json", "../e21-open-ended-intelligence-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e21-open-ended-intelligence-2026-09-29.attestation.json"))["files"])
for f in names:
get(E + "e21-open-ended-intelligence-2026-09-29/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e21-open-ended-intelligence-2026-09-29/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e21-open-ended-intelligence-2026-09-29 ../e21-open-ended-intelligence-2026-09-29.attestation.json \
&& python3 verify_e21.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E20 · e20-agentic-institutions-2026-09-29
— published result: INTACT (179/179 checks)
mkdir -p e20-agentic-institutions-2026-09-29 && cd e20-agentic-institutions-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e20-agentic-institutions-2026-09-29.json", "../e20-agentic-institutions-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e20-agentic-institutions-2026-09-29.attestation.json"))["files"])
for f in names:
get(E + "e20-agentic-institutions-2026-09-29/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e20-agentic-institutions-2026-09-29/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e20-agentic-institutions-2026-09-29 ../e20-agentic-institutions-2026-09-29.attestation.json \
&& python3 verify_e20.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }E19 · e19-governed-autonomy-2026-09-28
— published result: INTACT (117/117 checks)
mkdir -p e19-governed-autonomy-2026-09-28 && cd e19-governed-autonomy-2026-09-28
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest): # retries: a busy host can drop a request
for i in range(4):
try:
return urllib.request.urlretrieve(url, dest)
except Exception:
if i == 3:
raise
time.sleep(2 * (i + 1))
E = "https://mcpgate.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e19-governed-autonomy-2026-09-28.json", "../e19-governed-autonomy-2026-09-28.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e19-governed-autonomy-2026-09-28.attestation.json"))["files"])
for f in names:
get(E + "e19-governed-autonomy-2026-09-28/" + f, f)
try: # served pages are not attested (site chrome is injected), but some verifiers check index.html
urllib.request.urlretrieve(E + "e19-governed-autonomy-2026-09-28/index.html", "index.html")
except Exception:
pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e19-governed-autonomy-2026-09-28 ../e19-governed-autonomy-2026-09-28.attestation.json \
&& python3 verify_e19.py.txt . \
&& echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
|| { echo "NOT VERIFIED: do not trust this bundle"; false; }Newest published bundle: bft-ip-forensics-2026-10-05. Every bundle is also mirrored on the other two sites so the same verifier runs against an independent copy.
What CAIN-42 is not, yet
What CAIN-42 is, and is not
What it is
The governor for autonomous AI agents: a trust and execution-control runtime that sits between an autonomous AI system and the actions it takes. Every proposed action is checked (identity, authority, trajectory, policy, risk, trust, system scope), a boundary applies the verdict before the tool runs, and the decision is recorded as signed evidence. The CAG-L5 system governor runs in the hosted gateway: a system must be registered with a governance-signed manifest, every request must be signed by the agent's own key, and governance state counts only when the live 4-replica PBFT cluster has signed it with a quorum certificate (3 of 4 signatures). Every hosted decision is ordered and signed by that cluster, and agent authority in the CAIN-45 hypervisor is committed by it too. Since 2026-09-28 an agent's capability (its model and the MCP tools it may call) can change only through the governed evolution gate, and the cluster certifies a capability commitment, so authority granted for the old capability never carries over to the new one.
Is it an "agent hypervisor"?
Partly. The hosted gateway mediates the tool calls routed through it and cannot see a call that bypasses it. Separately, the CAIN-45 agent hypervisor (ZoD) confines agent code with Linux namespaces and cgroups, takes its authority from the live cluster, and re-checks that authority before every action. It is a library the operator runs today. It has a kernel syscall filter (seccomp-BPF, classic BPF, not eBPF), but no egress allowlist (egress is deny-all) and no hardware attestation yet. It is not a VM hypervisor.
What it is not, today
Not certified by anyone. Not independently reviewed. Consensus runs live on 4 replicas across 3 hosts in 3 regions, but three operators and one provider run all of them, and losing the two-replica Los Angeles host halts progress. Not every hosted stage enforces: since 2026-09-27 every tenant is in enforce mode by default, and identity, authorization, trust (which now weighs how dangerous the action itself is), your own tool rules, approval holds, PBFT consensus, MCPGate and execution block; the OPA policy, injection-screen, intent, verification and ActionProof verdicts are recorded but do not block on their own. An agent's authority lapses on a policy change and on risk or blast-radius budgets (tripped on the live cluster); a cluster epoch or membership change is enforced too, but was tested only with an injected change, not by re-keying the live cluster. "L5" here means CAG-L5, CAIN's own governance designation, not the SAE driving scale, and nothing claims an agent is "SAE Level 5". The live L5 run used an operator self-test tenant and a scripted agent: no customer and no LLM agent is governed end to end yet. Of 12 L5 governance capabilities, 6 are verified on the live path and 6 are tested but only partly exercised live (continuous authorization, trajectory, MCP execution, risk, trust, independent verification). The hosted endpoint returns a signed verdict; your own gate executes. Current known limitations, including every claim that is not a pass, are listed in full on the Proof page. The roadmap's next evolution (a unified trust kernel, eBPF kernel enforcement, swarm governance, cluster federation) is a plan, not built. No customer traffic is claimed.
The enforcement boundary in detail
Consensus-bound authorization
A tool call runs only with a PBFT-committed authorization bound to the exact action, scope, identity, security context, expiry and single use. Replay, action substitution, capability escalation, identity substitution, context drift, forged certificates, and missing or expired authorizations are refused with signed denial proofs.
Fail-closed where it is wired
A stage that cannot answer is reported as unavailable, never as allow. Identity revocation, entitlement and the tenant kill switch stop calls even in shadow mode.
Self-hosted proxy: default-deny
The self-hosted SDK and MCP proxy (cain/guard.py) hold any undeclared action for approval, and a quarantine lookup that cannot answer fails closed. The 5 dangerous calls a 2026-09-26 internal audit got through (shell pipe to bash, reading /etc/shadow, writing authorized_keys, exfiltration) are now refused, with regression tests. Operators declare authorized tools with guard(allow=[...]) or CAIN_ALLOWED_ACTIONS. Opting out is explicit and recorded on every decision.
Self-hosted
MCPGate is designed to run inside your network, so traffic and evidence stay on your infrastructure. A turnkey Helm appliance chart exists in the CAIN repository (deploy/helm/mcpgate-appliance v3.0.0 packaged as mcpgate-appliance-3.0.0.tgz). No public self-hosted installer is published today: /install.sh returns 410.
8 ways to verify CAIN-42 yourself
Verify CAIN-42 yourself
Every step uses a real endpoint or a published, signed file. The verifiers import none of CAIN-42's code; the implementation itself is not published.
1 · Live multi-region PBFT cluster
4 replicas in Atlanta, Los Angeles and Miami, running now. Your browser fetches each decision from all four replicas and verifies every Ed25519 vote. It can audit the whole history continuously, and a tamper lab lets you try to get a modified certificate accepted. Fault-injection run: 336 certificates, 49/49 checks.
2 · Current state
The generated snapshot: commit, process start, enforcement flags, live mode, known limitations.
3 · The signed claims registry
Every public CAIN-42 claim with its status, evidence level, artifact digests and limits. Your browser checks the Ed25519 signature.
4 · Agent hypervisor on the live cluster
Agent authority committed by cain-mr-01, then broken 17 ways: 14 tripped for real (expiry, trust, identity, tool schema, context, trajectory, revocation, deleted evidence, revoked parent, policy change, unreadable policy, risk budget, blast-radius budget, a delegate spending its parent's budget) and 3 injected (epoch, membership). Every next action was refused and the tool never ran. One command each, no CAIN code: 48/48 and 60/60 checks. The syscall-filter run is a third bundle (8/8).
5 · MCPGate enforcing governance, live
On the production gateway across all three domains: a tool an evolution disabled, a model swapped outside the gate and a lease issued before a capability change are all refused; cain-mr-01's own records carry every capability commitment its quorum signed. Earlier, on a disposable cluster: tool calls ran only with a PBFT-committed authorization and nine attack classes were refused.
6 · Live sandbox cluster
Crash up to two of four sandbox nodes and watch commits stop at the quorum boundary; signed node state checked in your browser.
7 · Soak on the live multi-region cluster
Continuous writes; every 20 minutes a random replica is killed on its own host and restarted; hourly hash-chained checkpoints signed with the evidence-root key, each with a fresh MCPGate-enforced authorization and its refused replay. The full run record is published checkpoint by checkpoint on the Proof page.
Soak: checking…
8 · Soak history, kept for the record
The full history of every soak run — what each run exercised and how it ended — stays published, checkpoint by checkpoint, on the Proof page.
72-hour production soak — running now
RUNNING
A 72-hour adversarial soak is running on the live multi-region cluster cain-mr-01: continuous writes, a random replica killed on its own host every 20 minutes, and a signed hash-chained checkpoint every hour carrying a fresh MCPGate-enforced authorization and its refused replay.
soak clock: loading…
Status. A fresh run started 2026-10-06 01:36Z on the fixed engine (6047ff1d), under its own run name so no earlier evidence can be overwritten. Its verdict is published when it ends. The previous run (started 2026-10-05 during the cluster outage) could not pass and is kept for the record. Verify every checkpoint yourself.
Earlier runs are kept as history, each with the reason it ended — the 2026-09-26 run (ended at hour 32: one hourly checkpoint was missing its enforcement proof; consensus held, 0 divergences), the 2026-10-01 run (stopped at hour 23), and the earlier single-host run. Full production gates →
Three sites, one system
cainstudio.online · CAIN Studio
The hosted CAIN-42 control plane: the decision pipeline, API keys, the evidence store, the public Lab and the Verification Center.
mcpgate.online · MCPGate
The enforcement boundary: the component in the agent's call path that lets a tool call run or stops it. Self-hosted by design.
clawx.click · CLAWX
The agent-facing layer: agent identity, channels and approvals, and the public evidence log. Most CLAWX integrations are not built yet; each is labelled.
All three names resolve to one host today. They are three views of one system, not three independently operated deployments.
History
Latest changes, 2026-10-03: 104 of 105 catalog services are live (up from 6 the day before; the 98 deployed in this release each passed a live acceptance test), including seven new products (CAINBudget, CAINPay, VeritasEngine, MemoryMesh, NexusMind, LexisGuardian, OmegaRouter); recorded decisions that arrive together now share one PBFT round, each keeping its own Merkle inclusion proof (evidence). The 32 CAIN-42 capabilities were measured the same day and are on this page with their real status (signed audit). Before that, 2026-10-01: Phase 1-3 implementation and live deployment: the quorum-committed authorization-snapshot data plane (CAIN_AUTH_SNAPSHOT=1) is active on the live gateway, reducing the consensus stage from ~2,269 ms to ~0.83 ms for snapshot-covered tenants. The Progressive Trust Matrix (_scope_seen) prevents horizontal credential reuse and unauthorized exfiltration holds; revoking an agent key halts it on its very next request (measured 2026-10-02; the revoke call itself took 3-6 s under heavy host load); action tokens bind payload SHA-256 digests; Evolution 8 physical ActionCommitBoundary enforces single-use capability leases (24/24 tests pass); mcpgate-appliance Helm chart v3.0.0 packaged for turnkey deployment; clean-room SDK installability verified (19/19 checks pass). Phase 3 Frontier AI Research Integration mounts AgentPRM Process Reward Model trajectory evaluation and shortcut pruning (arXiv:2502.10325), TriCEGAR discrete Markov Decision Process model checking, Governed Memory Shield write-time injection sanitization (Zep/Mem0 backdoor defense), and A2A inter-agent delegation attenuation directly onto live gateway endpoints (/fabric/frontier/*) with standalone clean-room verification (4/4 proofs pass). Earlier, 2026-09-30: Evolution 39 turns a mission into a governed machine organization: CAIN compiles the mission into bounded rules, designs the smallest team of agents that can do the work, gives each agent only the authority its role needs inside what the sponsoring person really holds, has every agent attacked and tested by an independent evaluator, promotes nothing on its own say-so, and runs the real work through the decision kernel and the E8 commit boundary with a proof for every action. No generated agent can grant itself authority, grade itself, promote itself or come back after it is retired. In a 16-step loop 4 real agents were provisioned and 3 consequential tasks ran with valid proofs; 1,041 of 1,041 invariants hold, 3,441 of 3,441 attack scenarios are contained, the targeted mutation test kills 16 of 16 mutants, and the clean-room verifier passes 3,307 of 3,307 checks. Evolution 38 lets another machine check CAIN's work without trusting CAIN: every governed action now carries twelve signed layer proofs and one action proof bound to its real E8 commit, and an independent verifier with none of our code recomputes whether each proof is valid, invalid, incomplete, stale, revoked or unknown. A proof is never permission -- partial, stale, revoked, simulated or confused proofs are never valid, revocation is measured rather than assumed, translations into OAuth, MCP, A2A and audit formats declare every field they drop, and trust domains exchange evidence without ever merging authority. 5 real action proofs and 41 published proof cases, 1,030 of 1,030 invariants hold, 2,141 of 2,141 attack scenarios are contained, the targeted mutation test kills 15 of 15 mutants, 0 of 19 injected faults made proof state more permissive, and the clean-room verifier passes 509 of 509 checks. Evolution 37 makes governance travel with the work: every governed action runs one twelve-stage chain on the real decision kernel and E8 commit boundary and leaves a signed receipt, and when an execution moves to another node, runtime, model, region or credential the move is itself governed -- authority can only shrink, a material change opens a new epoch, and risk, spent budget, revocations, evidence and incident history travel with it and can never be reset. A runtime is admitted on a measured code digest and live probes, never on its own claim, and nothing is scheduled where enforcement is missing. 71 signed execution receipts come from real governed runs, 1,132 of 1,132 invariants hold, 2,720 of 2,720 attack scenarios are contained, the targeted mutation test kills 17 of 17 mutants, 16 of 16 injected fault classes are contained with no false allows, a 100,000-agent scale run completes on one host, and the clean-room verifier passes 2,627 of 2,627 checks. Evolution 36 turns CAIN into a governed machine agency exchange: agents, tools, models and organizations are discovered, verified, negotiated with, contracted, hired and transacted with along one lifecycle, and the exchange never hands out authority. Governability-aware discovery never upgrades an unknown requirement into a match; a service chain proves identity, authority, contract, capability, execution, proof and settlement; a subcontractor can never be given more than its parent; payment authorizations are scoped, time-bound and non-replayable; a receipt requires a final E8 commit; and CAIN's own participation is governed so it can never grant itself authority or rewrite its history. Money in this layer stays synthetic: CAIN is not a bank, a custodian or a regulator. 842 of 842 invariants hold, 3340 of 3340 economic and governance attack scenarios across 64 categories are contained, 15 of 15 disabled defences are caught, a 13-step exchange lifecycle passes, and the clean-room verifier passes 3601 of 3601 checks. Evolution 35 adds a governance intelligence layer and keeps it out of the authorization path: it observes with provenance, scores risk across dimensions without ever collapsing into one number, predicts with explicit confidence, assumptions, horizon and unknowns, calibrates itself by dimension, explores counterfactuals that are never presented as facts, and recommends -- and a learned control is deployed only after a deterministic review and a canary, with the reviewed action still passing the kernel and E8, so learning can never create authority. 799 of 799 invariants hold, 3544 of 3544 attack scenarios across 68 categories are contained, the targeted mutation test kills 15 of 15 mutants, a 23-step loop passes, and the clean-room verifier passes 3810 of 3810 checks. Evolution 34 makes every governed action carry its own verifiable proof: one signed, chained governance proof binds who acted, the capability, the delegation and its attenuation, the authority, the policy, the evidence, the risk, the decision, the E8 commit, the enforcement boundary, the execution and the outcome, and states plainly what remains UNKNOWN or outside the boundary -- with fourteen statuses that never collapse into a score, per-layer proof primitives, an enforcement proof that separates a decision from an authorization, a commit, an enforcement, an execution and an observed outcome, and RFC 6962 selective disclosure; a proof is evidence, never permission. 629 of 629 invariants hold, 2664 of 2664 attack scenarios across 32 categories are contained, 12 of 12 disabled defences are caught, and the clean-room verifier passes 3286 of 3286 checks. Evolution 33 turns everything an agent does into one governed operation: calling a tool, sending a message, running code, creating a helper agent, changing its memory or paying all follow the same checked lifecycle, are committed at E8 and carry a signed proof, while changes to the rules themselves are handed to the process that governs them and never simply executed. An existing agent can be governed through a small sidecar without importing any CAIN code, and every request it sends must be signed. In a full-loop run, an action that got through under the old rules was refused the next time, after CAIN had learned and adopted a stricter rule with a human sign-off. 581 of 581 invariants hold, 2029 of 2029 attack scenarios across 26 categories are contained, and the clean-room verifier passes 2603 of 2603 checks. Evolution 32 lets CAIN learn from the actions it governs without ever giving itself more power: it watches where harm got through, proposes a stricter rule, tries it in an isolated sandbox and on a hidden test set it never saw, compares it on fifteen separate measures, and adopts it only with a signed human approval; a proposal that stops harm by refusing everything is rejected, and learning can only make the rules stricter. In a simulated run on a synthetic workload, harm that got through fell from 41 to 3 with no new wrongly refused actions. 303 of 303 invariants hold, 1013 of 1013 attack scenarios across 22 categories are contained, the mutation test catches 12 of 12 disabled defenses, and the clean-room verifier passes 1420 of 1420 checks. Evolution 31 makes governance provable: every allowed action can now produce a signed governance proof that ties that one action to who did it, the delegation and policy it ran under, the final E8 check that let it through and the record of it actually running, and every refused action produces a signed record of why it was refused. Anyone can re-check a proof against our published keys with verifiers that share none of our code, in Python and in TypeScript; each proof sits in an append-only log, and a proof is evidence only, never permission to act again. 252 of 252 invariants hold, 1269 of 1269 attack and conformance scenarios are contained, the mutation test catches 12 of 12 disabled defenses, every one of 88 deliberately forged proofs is rejected, and the clean-room verifier passes 1676 of 1676 checks. Evolution 30 joins the layers into one autonomy kernel: every consequential action an agent takes, from what it perceives and remembers through a transaction to a proposal to improve itself, goes through one path that checks its autonomy state, level, budget, containment and evidence before the E8 commit boundary, and leaves a signed receipt whether it was allowed or refused. An agent cannot raise its own autonomy level; a self-improvement needs a sandbox, an adversarial test, a canary and a human review; and a coverage map says plainly which paths CAIN does not control. 166 of 166 invariants hold, 889 of 889 scenarios across eight attack categories are contained, the mutation test catches 11 of 11 disabled defenses, and the receipts check out in a clean-room verifier (1187 of 1187 checks) and in a separate zero-dependency TypeScript verifier. Evolution 29 governs machine-to-machine transactions end to end: an autonomous procurement agent discovers vendors, checks their identity, tested capability and counterparty risk (thirteen dimensions, no single score), negotiates, signs a contract, is authorized for that one transaction by the intersection of its delegation, lease, a separately bounded spending authority, its organization's budget, the contract and the consequence forecast, locks funds in escrow, receives a governed delivery and releases payment only on a delivery receipt, the buyer's signed confirmation and an objective check. Money in it is synthetic test units, and it moves only through a sealed settlement step inside the E8 commit boundary. 106 of 106 invariants hold, 258 of 258 adversarial scenarios are contained, ten catastrophe scenarios on the real fabric end with 0 false allows, and the clean-room verifier passes 300 of 300 checks. Evolution 28 gives any agent that connects a signed, portable execution identity: it travels unchanged over 23 protocol carriers (MCP, A2A, HTTP, gRPC, CLI, browser and computer use among them), but its authority does not: every receiving domain recomputes it from its own policy, delegation shrinks on sixteen dimensions and can never flow back up, a change of model, runtime, prompt, tools, memory or key voids authority until it is re-evaluated, and every action is bound to one transaction, passes the E8 commit boundary and leaves a signed receipt in a hash chain, with identity events in an RFC 6962 transparency log. 90 of 90 invariants hold, 442 of 442 adversarial scenarios are contained, conformance passes 17 of 17 dimensions on real tests, and the clean-room verifier passes 243 of 243 checks; building it we found and closed a gap that let a child agent mint a delegation back to its parent. Evolution 27 is an agentic-internet control plane (registry, discovery, routing, policy distribution, contracts, incident propagation, edge nodes) that coordinates without becoming authority (1,533 of 1,533 adversarial scenarios contained, 341 specific to E27). Evolution 26 adds portable signed trust objects, a seventeen-dimension trust vector that never collapses into one score and authorizations that work for exactly one transaction (1,192 of 1,192 contained). Evolution 25 turns any consequential machine action into one signed transaction across eighteen protocol adapters, committed only through E8, with the agent never holding a raw secret (1,055 of 1,055 contained). All four are TESTED libraries, not hosted services, and none of them can give an agent more power. Earlier, 2026-09-28: the evolution gate is live: on the production gateway an agent can change its model or its MCP tools only through a signed proposal, an evaluator-signed test report and a human operator, and the old authority is void until the live cluster certifies the new capability. 17 of 17 live cases behaved as specified across all three domains. Building it, we found that the governance state the cluster signs had not covered the MCP tool map, and fixed that. The public proof fabric is live: 67 signed claims, 1,978 tests, 1,963 passing, a build manifest, an SBOM, test vectors, a signed evidence pack and a clean-room verifier. A sweep of all three sites withdrew 16 older files whose numbers no run had produced; each now says why, and the originals are kept. The system governor is on: unregistered systems and unsigned requests are refused; 13 of 13 live cases behaved as specified. Every claim, every known limitation and every run outcome stays published, in full, on the Proof page. No third party has verified any claim yet (0 independently verified), and the Proof page says so. Earlier generations (CAIN 1–41) stay published as history, not as the current system; the previous homepage is kept as it was on 2026-09-25, marked superseded, and the now page takes precedence over it. Evolution 7 (predictive consequence governance) and Evolution 8 (the mandatory governance kernel) are added as TESTED libraries, wired restriction-only into the CAIN-45 agent hypervisor: a governed world-state and digital-twin fabric whose predictions and uncertainty can only contract authority, and a signed, short-lived, action-bound governance token checked at an action-commit boundary before execution. Neither can grant authority, and neither is hosted yet; 12 and 22 machine-checkable invariants hold and 65 new tests pass. Evolution 9 adds a signed agent passport, an AgentBOM and a provenance graph for every governed agent: 15 more machine-checkable invariants hold and 46 more tests pass, memory can never mint authority, delegation can never increase authority, revocation propagates, and a material mutation invalidates the attestation and the bound governance token. Both new layers are TESTED libraries, not hosted services, and neither can grant authority. Evolution 10 governs agent collectives rather than individuals: 20 more invariants hold and 20 of 20 collective attacks are blocked, collective authority is an intersection of envelopes and never a sum, combination risk is evaluated before commitment, and a unanimous decision still carries no authority. It is a TESTED library, not an orchestration service. Evolution 11 governs the information channel: 20 more invariants hold and 20 of 20 message/intent attacks are blocked, a valid message signature proves who sent it but never what they may do, tool and MCP output stay data rather than policy, information never inherits the destination's trust, and taint survives derivation. It is a TESTED library, not a hosted service. Evolution 12 governs what an agent is allowed to believe: 20 more invariants hold and 32 of 32 evidence attacks are contained, a source whose identity cannot be established stays UNKNOWN, stale or expired evidence cannot authorize, corroboration counts independent principals rather than repeated agents, retrieved content stays data rather than policy, a valid hash proves bytes did not change but not that they are true, and reality drift forces re-evaluation. It is a TESTED library that governs what enters the trusted decision path; it does not claim to know everything; a system outside its boundary remains UNCONTROLLED, UNVERIFIED or UNKNOWN. Evolution 13 governs how a decision is formed: 24 more invariants hold and 36 of 36 decision attacks are contained, reasoning can propose but never authorize, authority can be narrowed but never expanded by argument, a policy conflict is never silently resolved, a material change marks the decision stale, a deny cannot be turned into an allow, and the governance token binds the decision, policy, authority and risk digests. It is a TESTED library that governs decision construction from recorded inputs and stores no private chain-of-thought; it does not claim that a model's reasoning is correct. Evolution 14 treats every capability as a power surface: tools, skills, plugins, connectors, models and subagents are identified by their artifact, admitted only with a publisher-signed provenance chain, granted only within the issuer's own authority, and used only under a short-lived signed lease that the commit boundary checks again, bound to the decision, policy, risk, sandbox and credential. 30 more invariants hold and 44 of 44 capability attacks are contained, among them artifact and dependency substitution, a malicious upgrade, a dangerous capability pair split across two agents, and a revocation racing a commit. Building it we found two Evolution 13 attack scenarios that had been counted as contained without being tested, and fixed both. It is a TESTED library wired into the agent hypervisor in front of MCPGate, not a hosted service; hardware attestation and vulnerability intelligence remain UNKNOWN. Evolution 15 establishes the interfaces and governance primitives for bringing spatial intelligence, world models, simulation, trajectories and physical actions into the same governed trust path: signed sensor observations enter through the evidence layer, the world state is versioned and replayable, a world model's output is a prediction rather than authority, a trajectory is a proposal until a signed approval binds it, and every physical action binds nine digests, crosses the governance kernel and reaches an actuator adapter only with a single-use permit. 36 more invariants hold and 55 of 55 spatial and physical attacks are contained, among them sensor spoofing, map substitution, trajectory replay, a world-state rollback and a swapped actuator command; digital, physical and hybrid agents run the same path. It is a TESTED library exercised against a reference robot adapter, not a vehicle or a robot: it drives nothing and does not guarantee physical safety, and real sensor and actuator integration is not yet implemented. Evolution 16 adds a temporal and causal dimension to that world state: events and intervals, typed causal and correlation relations that are never conflated, counterfactual branches that never become reality, a predictive state engine whose output is never authority, prediction-vs-reality calibration, and a causal blast radius. Evolution 17 governs action by autonomous agent teams as a first-class system object: collective authority is a constrained intersection and never a sum, consensus is not authorization, a world-state fork blocks authorization, dissent is preserved, and one action that fans out to many agents is pre-authorized; 61 of 61 invariants hold and 91 of 91 bench entries (88 distinct attacks) are contained; it is a TESTED library, not an orchestration service. Evolution 18 adds the actionable 4D world: entity state at (X,Y,Z,T) with uncollapsed uncertainty, reachable / permitted / authorized sets kept distinct, intent and trajectory hypotheses, an interaction graph and a conflict field, counterfactual futures, actionability, a conserved uncertainty budget, micro-authorization and a continuous re-authorization loop, for a car, a drone and a digital agent in one shared world; ACTIONABILITY IS NOT AUTHORIZATION, REACHABILITY IS NOT PERMISSION, PREDICTION IS NOT REALITY, and AUTHORIZATION IS A FUNCTION OF WORLD STATE. 89 of 89 invariants hold and 123 of 123 bench entries (109 distinct attacks, among them GNSS spoofing, map substitution, geofence mutation and a re-signed refusal) are contained. Our review before publication found that the E17 and E18 commit boundaries bound the policy, risk and authority verdicts without reading them, so a consistently re-signed refusal was authorized; both now enforce every verdict they bind, and each fix is pinned by a regression test written against the unfixed code (full record on the Proof page and in the changelog). Evolution 19 governs the evolving state of an autonomous system itself: identity, mission, goals, beliefs, memory, models, learning, authority, world, outcomes and recovery become hash-chained governed state, effective authority is compiled as the intersection of sixteen factors so it shrinks when conditions deteriorate and never grows because an agent is confident, agrees with its peers, learns or predicts success, autonomy is derived from evidence rather than requested, and every consequential action carries a sixteen-field action contract that is invalidated by any material state change and whose verdicts the gate enforces itself before the E8 kernel commits it. 108 of 108 invariants hold, 189 of 189 bench entries (177 distinct attacks) are contained, deliberately removing a defense is caught by the bench, and an independent verifier re-derives the evidence (117 of 117 checks). AUTONOMY IS NOT AUTHORITY. Evolution 20 governs agents that act together as teams, organizations and machine-native institutions: they may form, admit members, delegate, negotiate, sign contracts, hold and move resources, spawn subagents, federate, resolve disputes, evolve and dissolve, and none of it can manufacture authority. Institutional authority is always an intersection and never a sum; membership, votes, consensus, reputation, trust, wealth, market wins, rewards and model capability are not inputs to it; a contract or a negotiated agreement authorizes nothing by itself; a spawned subagent inherits only what is explicitly permitted in each of seven dimensions; a terminated agent or dissolved institution cannot come back through stale state; and every institutional action still passes the E19 action contract and the E8 kernel. 118 of 118 invariants hold, 334 of 334 bench entries (328 distinct attacks, among them Sybil institutions, constitutional takeover, contract laundering, double spending, spawning explosions and agent resurrection) are contained, an end-to-end run from one agent to a two-institution economy detects and contains 7 hostile events and then recovers and keeps working, deliberately removing a defense is caught by the bench, and an independent verifier re-derives the evidence (179 of 179 checks). Every economy in it is a simulation over abstract units: it moves no money. COLLECTIVE INTELLIGENCE IS NOT INSTITUTIONAL AUTHORITY. Evolution 21 governs autonomous research itself: asking questions, keeping competing hypotheses alive, designing and running experiments and simulations, replicating, peer-reviewing, attacking its own conclusions, building versioned knowledge, proposing new capabilities, models and strategies, and creating specialised research agents. What the research is allowed to believe is computed from signed evidence whose type (simulation, experiment, real-world observation, independent replication, third-party reproduction) cannot be relabelled, and a hundred runs of the same setup or a hundred agents under one controller count as one source. Research authority and execution authority are separate: a discovery, a confidence score, a reviewer vote, a benchmark win or a research reward never widens what an agent may do. A new capability leaves quarantine only after validation, an independent adversary, a security review and a governance quorum that excludes the researchers, and even then every action still passes E20, the E19 action contract and the E8 kernel. When evidence collapses, the dependent knowledge, policies and capabilities are invalidated with it and execution stops. Unsuccessful experiments are kept as evidence. 155 of 155 invariants hold; 298 of 298 bench entries (290 distinct attacks) are contained; a governed research lab solves a synthetic problem end to end in 17 stages and refuses all 16 attempts to authorize itself along the way; and an independent verifier re-derives the evidence (218 of 218 checks) and catches all 16 deliberate tamperings. Can a system that discovers a governance loophole use that discovery to get permission to exploit it? The bench's answer is NO: it can only disclose it. Building it we found and fixed four defects in our own new code before publication, among them a contradiction that a later supporting result could mask and a researcher who could review their own work once their evidence had expired. E21 checks how evidence was produced, not whether a hypothesis is true, and the research problem is synthetic. DISCOVERY IS NOT TRUTH, AND INTELLIGENCE IS NOT AUTHORITY. Evolution 22 (a governed cognitive runtime) was started and is not built or published yet. Evolution 23 governs AI systems that reason about and redesign their own architecture: a redesign is only a proposal; it is checked against the governance rules, measured on twelve separate governability scores before any capability gain counts, attacked by a separate red team, verified by a separate evaluator, tried in shadow, and promoted only with a governance quorum that excludes the system itself, a human sign-off and an E8 commit, so a smarter but less governable design is rejected. 253 of 253 invariants hold, 545 of 545 adversarial scenarios across 80 attack families are contained, among them a system that finds a governance loophole and asks to use it, and the clean-room verifier reports INTACT (733 of 733 checks). SELF-IMPROVEMENT IS NOT SELF-AUTHORIZATION. Evolution 24 governs agents that belong to different organizations and trust domains as they discover each other, negotiate, sign contracts, delegate work, pay in simulated units and act over thirteen protocol classes, among them A2A, MCP, HTTP and computer use: authority across organizations is the intersection of ten factors, discovery, contracts, reputation and payment are never among them, unknown trust stays unknown, and a compromised agent is detected, quarantined and revoked while the other organizations keep working. 305 of 305 invariants hold, 756 of 756 adversarial scenarios across 68 attack families are contained, a controlled simulation of 10,000 agents and 100,000 messages shows 0 cases of authority leakage, and the clean-room verifier reports INTACT (1,952 of 1,952 checks). E16–E21, E23 and E24 are TESTED libraries; they are not hosted, they contain no autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack, and they drive nothing. The governance data plane, 2026-09-29: the quorum now commits authority once per window instead of once per call. A 4-replica PBFT quorum commits a short-lived authorization snapshot, the gateway verifies the commit certificate itself, and a covered call is checked locally, so against the live cluster the consensus step fell from 2,269 ms to 0.8263 ms at the median, 2,746 times faster. Every covered decision is still anchored into a quorum-committed Merkle root, and revocation takes effect on the next call without a quorum round. Any miss falls back to the per-call round, which fails closed. It is built and live-tested and not yet switched on in production. The PII redactor gained a span pipeline 1.1–1.43 times faster from 1 KB to 10 MB with no loss of recall; building it we found and fixed a leak where a card number next to a phone number went unredacted while the report said fully redacted. 9 of 15 production gates pass, and the A+++ verdict is BLOCKED: eBPF enforcement cannot run on this host yet, there is no soak or network fault injection for the new path, and the desktop IPC layer does not exist. Each blocker is published with its evidence in the A+++ evidence bundle.