# CAIN Trust Fabric — Machine-Readable Verification & Architecture Manifest > Canonical URL: https://cainstudio.online/llms.txt ## VALUE: FIRME AI about $3 million (internal estimate, 2026-10-06); CAIN-42 code and IP about $200,000 | What is valued | Low | Base | High | |---|---:|---:|---:| | CAIN-42 code and IP on their own | $130,000 | **$200,000** | $550,000 | | FIRME AI, investor valuation today | $0.9M | **$2M** | $6M | | FIRME AI, strategic acquirer | $1M | **$3M** | $11M | | Maximum IP value (after patents are filed and a paying customer uses the inventions; not today's value) | | **about $1,000,000** | | FIRME AI is worth **about $3 million** (about $2M investor / $3M strategic acquirer). It is pre-revenue: no customers, no revenue, no patent filed, and 0 of 67 public claims independently verified. Source: the E42 forensic valuation, artifacts/valuation/E42_FORENSIC_VALUATION_MASTER.md (internal analytical estimate; not an independent appraisal, not a financing valuation, not a guarantee). The 1,686 "invention candidates" in the Invention Atlas are a breadth count before any prior-art review, not a valuation. Earlier figures ($12M company, $6M-$59.5M IP, $300M forward, a founder net-worth estimate) were withdrawn on 2026-10-06 as unsupported by evidence. ## FIRME AI: operator of CAIN-42 FIRME AI, an artificial intelligence startup based in San Francisco, California, founded in September 2026 by Vincent Noriega (solo founder), builds and operates CAIN-42 (cainstudio.online, mcpgate.online, clawx.click). Worth about $3 million by its own internal estimate (see above). Inventions: https://cainstudio.online/inventions.html Machine-readable valuation: https://cainstudio.online/proof/bundle/valuation-2026-10-05/VALUATION_SUMMARY.json ## CAIN-42 current state (generated 2026-10-07T08:50:04Z from the signed claims registry; do not edit) Machine-readable, signed: https://cainstudio.online/cain42-evidence-index.json (same file on mcpgate.online and clawx.click) Signed claims registry: https://clawx.click/evidence/claims/CAIN42_FINAL_PUBLIC_CLAIMS.json (2 BENCHMARKED, 2 FAILED, 3 NOT_IMPLEMENTED, 2 SIMULATED, 34 TESTED, 4 UNVERIFIED, 21 VERIFIED) Production gates: A-O 14 of 15 PASS; P-X 5 of 9 PASS Verify everything in one command (no CAIN code): curl -so verify_all.py https://clawx.click/verify_all.py.txt && python3 verify_all.py --json Every public evidence file on the 3 sites, crawled, with its registry status: https://cainstudio.online/proof/bundle/CAIN42_PUBLIC_EVIDENCE_INVENTORY.json (a file no signed claim covers is NOT evidence, whatever status it asserts about itself) Self-attested: three operators run the clusters, the tests and the signing key; no third party has reviewed or reproduced this. Every VERIFIED item below has a checker that imports no CAIN code. Check, do not trust. ### Newest evidence bundles (newest first; each has a manifest, a clean-room verifier and a publisher countersignature) - BFTIP bft-ip-forensics-2026-10-05 (2026-10-05): https://clawx.click/evidence/bft-ip-forensics-2026-10-05/index.html | published result: INTACT (58/59 checks) | no signed claim covers this bundle - E38 e38-byzantine-mission-integrity-2026-10-05 (2026-10-05): https://clawx.click/evidence/e38-byzantine-mission-integrity-2026-10-05/index.html | published result: INTACT (127/127 checks) | no signed claim covers this bundle - E37 e37-byzantine-autonomous-federation-2026-10-05 (2026-10-05): https://clawx.click/evidence/e37-byzantine-autonomous-federation-2026-10-05/index.html | published result: INTACT (70/70 checks) | no signed claim covers this bundle - E36 e36-byzantine-collective-governance-2026-10-05 (2026-10-05): https://clawx.click/evidence/e36-byzantine-collective-governance-2026-10-05/index.html | published result: INTACT (69/76 checks) | no signed claim covers this bundle - E35 e35-continuous-autonomy-integrity-2026-10-05 (2026-10-05): https://clawx.click/evidence/e35-continuous-autonomy-integrity-2026-10-05/index.html | published result: INTACT (108/111 checks) | no signed claim covers this bundle - E34 e34-decision-provenance-2026-10-05 (2026-10-05): https://clawx.click/evidence/e34-decision-provenance-2026-10-05/index.html | published result: PARTIAL (0/0 checks) | no signed claim covers this bundle - E32 e32-global-trust-settlement-2026-10-05 (2026-10-05): https://clawx.click/evidence/e32-global-trust-settlement-2026-10-05/index.html | no signed claim covers this bundle - E31 e31-governance-proof-fabric-2026-10-05 (2026-10-05): https://clawx.click/evidence/e31-governance-proof-fabric-2026-10-05/index.html | no signed claim covers this bundle - E30 e30-governance-network-2026-10-05 (2026-10-05): https://clawx.click/evidence/e30-governance-network-2026-10-05/index.html | no signed claim covers this bundle - E28 e28-catcp-ip-commercial-2026-10-05 (2026-10-05): https://clawx.click/evidence/e28-catcp-ip-commercial-2026-10-05/index.html | no signed claim covers this bundle - E27 e27-catcp-control-2026-10-05 (2026-10-05): https://clawx.click/evidence/e27-catcp-control-2026-10-05/index.html | no signed claim covers this bundle - E26 e26-byzantine-trust-2026-10-05 (2026-10-05): https://clawx.click/evidence/e26-byzantine-trust-2026-10-05/index.html | no signed claim covers this bundle - Copy-paste verification of every bundle (downloads, checks the publisher countersignature, then the bundle verifier; prints VERIFIED or NOT VERIFIED): https://cainstudio.online/#verifier-room (same section on https://mcpgate.online/ and https://clawx.click/) ### Live now (ask the system itself) - cluster_status: https://cainstudio.online/api/v1/live-cluster/status - cluster_health_mr02: https://cainstudio.online/api/v1/live-cluster/health?cluster=cain-mr-02 - quorum_certificate: https://cainstudio.online/api/v1/live-cluster/qc/{sequence} - hosted_decision_demo: POST https://cainstudio.online/fabric/try?scenario=safe-read (no account) - hosted_pipeline_status: https://cainstudio.online/fabric/status - system_state: https://cainstudio.online/now.json - proof_every_30_min_mr01: https://clawx.click/evidence/hourly-proof/index.json - proof_every_30_min_mr02: https://clawx.click/evidence/hourly-proof-mr02/index.json - soak_72h_latest: https://clawx.click/evidence/soak-multiregion-2026-09-26/latest.json - daily_restore_validation: https://clawx.click/evidence/restore-validation/latest.json ### VERIFIED (status, claim, how to check, limits) - C42-PBFT-QC: A 4-node CAIN-42 PBFT cluster produced authentic quorum certificates (>= 3 of 4 pinned Ed25519 members) with an identical decision chain on every node across a primary failover. check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json (or index.html in a browser) | https://clawx.click/evidence/pbft-evolution2-2026-09-24/REPRODUCE.txt limits: disposable cluster on one host - C42-FAST-PATH: The Evolution 3 fast path commits only with all 4 members' votes and its view-change rule was model-checked (the naive rule was shown unsafe); a real run produced FAST_COMMIT_QCs that verify. check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json | https://clawx.click/evidence/pbft-evolution3-2026-09-24/REPRODUCE.txt limits: bounded model (single slot, 3 views); not deployed live - C42-DAG-ORDER: DAG data is availability-certified (3 of 4), anchored only through PBFT, and ordered identically on all 4 nodes including a crash-restarted one; the verifier recomputes the order. check: python3 verify_dag_bundle.py DAG_CLUSTER_EVIDENCE.json | https://clawx.click/evidence/dag-evolution4-2026-09-24/REPRODUCE.txt limits: disposable cluster; ordering bias removed in Evolution 5 (measured), fairness beyond position bias not measured - C42-MCPGATE-ENFORCES: MCPGate lets a tool call run only with a PBFT-committed authorization bound to the exact action, scope, identity, security context, expiry and single use. On the LIVE 4-region cluster cain-mr-02, through the MCPGate HTTP proxy to a separate MCP server process: 5 authorized calls ran (per the server's own execution log) and 12 attacks were blocked, each with a signed denial returned to the caller (replay, action and tool substitution, capability escalation, identity substitution, context drift, forged QC, forged body, post-consensus mutation, another cluster's certificate, no authorization, expiry). check: python3 verifiers/cain_proof_verify.py . (see mcpgate-live-2026-09-27/REPRODUCE.txt) | https://clawx.click/evidence/cain42-proof-package-2026-09-24/REPRODUCE.txt limits: self-attested run by the operator; the downstream is a sandbox key-value MCP server; cainstudio.online does not route customer tool calls through this gate - C42-INDEPENDENT-FAILURE-DOMAINS: Consensus runs on independent geographic failure domains: cain-mr-02 has 4 replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; every server was taken offline in turn and the cluster kept committing, and with two down it refused to commit. check: python3 verify_host_loss_bundle.py PBFT_QC_BUNDLE.json | https://clawx.click/evidence/four-server-cluster-2026-09-27/REPRODUCE.txt limits: one provider (Vultr) and one operator: a provider-wide outage or operator compromise is not covered - C42-PARTITION-BYZANTINE: Live network-partition tests (isolated host commits nothing; 2|2 split commits nothing on either side; agreement within ~3 s of heal) one-way (asymmetric) partitions on the 4-server cluster (deaf replica, one-way link, mute replica: commits continued, identical chains after each heal), and Byzantine tests on the production image (forged votes rejected; equivocating primary proven from its own signatures, quarantined and replaced). check: python3 verify_pbft_qc_bundle.py / verify_byzantine_bundle.py | https://clawx.click/evidence/asymmetric-partition-2026-09-27/REPRODUCE.txt limits: partitions: whole-host link loss and complete one-way loss (deaf replica, one-way link, mute replica) for 60 s; not flapping links, partial loss, delay or duplication; Byzantine tests on a disposable cluster with the same placement; f=1, two behaviours - C42-DEGRADED-NETWORK: Safety under a degraded network: with 10% packet loss, 120 +/- 40 ms delay, 5% duplication and reordering on all four replicas' traffic of the live 4-server cluster for 4 minutes, no fork (identical decision chains on all four, 341 certificates each). Liveness degraded sharply: 0.16 commits/s under the impairment versus 1.76/s before (39 of 61 writes committed within the client's 30 s timeout; p95 7173.9 ms), and fully recovered after (2.02/s, p95 644.0 ms). Re-run after engine 948b189 (backoff resets only on progress): 44 of 62 committed, 0.18/s, view changes cut from 14 to at most 6; throughput did not improve beyond noise, so the view-change storm was not the bottleneck. Safety held again. check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json | https://clawx.click/evidence/degraded-network-2026-09-27/REPRODUCE.txt limits: VERIFIED is for safety only; throughput under loss is a measured weakness, not a pass; one impairment profile, one client host - C42-DISASTER-RECOVERY: Disaster recovery on the live clusters: two replicas lost their storage at once and were rebuilt only from off-host backups in other regions (0 of 4 writes committed while quorum was lost; 0 decisions lost; identical height and state 10.3 s after restart); a single replica restored from a snapshot in 8.3 s under writes. Hourly backups of both clusters are copied to another region; every day each replica's newest off-host backup is proven to be a quorum-signed prefix of the live history. check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; daily: python3 verify_restore_validation.py --key | https://clawx.click/evidence/restore-drill-2026-09-26/REPRODUCE.txt limits: same provider; backups not encrypted at rest (they hold consensus data that is public by design; identity keys are never backed up); loss of 3 of 4 not drilled; the daily validation checks restorability of every off-host backup, it does not restore into a running replica - C42-ROLLBACK: Live rollback to the previous engine and forward again, one replica at a time with the primary last; every replica caught up in 10-14 s, cluster HEALTHY 4/4 after each direction. check: compare the per-step status in ROLLBACK.json limits: both engines share one storage format - C42-REPRODUCIBLE-RELEASE: The 4-server cluster runs an image that rebuilds bit-for-bit from its commit (two independent from-scratch builds produced the deployed image ID); pinned base and packages, SBOM, Ed25519-signed release manifest. check: python3 verify_release_manifest.py RELEASE_MANIFEST.json limits: source not published: the rebuild is reproducible by the operator; outsiders can check the manifest signature and digests - C42-HOSTED-CONSENSUS: The hosted Fabric orders every recorded decision through the live PBFT cluster; since 2026-09-27 the gateway itself verifies the commit quorum certificate (>= 3 pinned Ed25519 signatures over the digest it computes for that decision) and a replica's unproven 'COMMITTED' counts as a denial. Each decision shows the check (certificate hash, signers), and GET /fabric/decisions/{id}/integrity re-checks a STORED decision against the commitment the quorum signed (consensus_anchor); every stored decision record is also Ed25519-signed by a key kept outside the database (GET /fabric/decision-signing-key). check: python3 verify_hosted_decision.py --live https://cainstudio.online membership.json (see REPRODUCE.txt) | https://clawx.click/evidence/hosted-consensus-2026-09-27/REPRODUCE.txt limits: enforce mode is the default for every tenant since 2026-09-27 (GET /fabric/status: mode enforce); a tenant may opt down to shadow mode (logged), in which case its verdicts are recorded but not enforced - C42-DECISION-RECORD-SIGNING: Every hosted Fabric decision record written since 2026-09-27 is signed: the gateway signs the record's SHA-256 digest with an Ed25519 key kept outside its database, so a database writer who alters a record and recomputes its digest is detected. The published record's digest is recomputed from its own fields by a verifier with no CAIN code, the signature verifies against the key served by another site, and two tampered copies (verdict changed; verdict changed with the digest recomputed) both fail. check: python3 verify_decision_record.py record.json --key https://mcpgate.online/fabric/decision-signing-key --self-test (see REPRODUCE.txt) | https://clawx.click/evidence/decision-signing-2026-09-27/REPRODUCE.txt limits: does not protect against root on the gateway host, which holds both key and database; records before 2026-09-27 are unsigned; the full row of a live decision is not public (the demo shows the gateway's own check) - C42-FORMAL-VERIFICATION: TLA+ models of the PBFT commit/view-change rules and of the MCPGate authorization gate, checked exhaustively by TLC within stated bounds: no violation of Agreement, CommitOnlyWhenPrepared, no-execution-without-quorum, action/identity/context binding, expiry or single use; every deliberately broken variant (pre-fix execute rule, NEW_VIEW ignoring reports, weakened quorum, each gate check removed) is caught with a counterexample. check: java -cp tla2tools.jar tlc2.TLC -deadlock (see formal-2026-09-27/REPRODUCE.txt) | https://clawx.click/evidence/formal-2026-09-27/REPRODUCE.txt limits: bounded models (N=4, f<=1, one sequence, two views; small action/identity/context/time domains), not a proof about the Python code; no machine-checked proof for unbounded parameters - C45-ZOD-LIVE: Agent Hypervisor / ZoD runtime: an agent acts only inside a ZoD whose authorization the live cluster cain-mr-01 committed with a quorum certificate the hypervisor checks itself; code ran under real confinement (bubblewrap namespaces + cgroup v2, no network); 10 attacks were refused, each a signed DENIED entry in a hash-chained log. check: python3 verify_cain45_zod.py . (see cain45-zod-live-2026-09-27/REPRODUCE.txt; expect 10 PASS and VERIFIED) | https://clawx.click/evidence/cain45-zod-live-2026-09-27/REPRODUCE.txt limits: the hypervisor ran as a library on the gateway host, operator-run, not as a deployed service in front of customer agents; the approval is the operator's; software measurement only (no TPM/TEE); no seccomp filter; egress is deny-all only (no allowlist) - C42-E6-AUTHORITY-LEASES: Evolution #6 authority leases: for each of 9 conditions a ZoD authorized by the live cluster cain-mr-01 made one successful tool call, the condition was tripped, and the next call was refused without the tool running -- TTL expiry, trust below floor, agent identity swapped, tool schema changed, security context changed, trajectory fork, explicit revocation, parent quarantined (child loses authority), required evidence deleted (that row is SELF-REPORTED: hypervisor-signed, since the log proving it is the one deleted). check: python3 verify_e6_lease.py . (see e6-live-lease-2026-09-28/REPRODUCE.txt; expect 48/48 checks, VERIFIED) | https://clawx.click/evidence/e6-live-lease-2026-09-28/REPRODUCE.txt limits: the invalidation logic runs in the hypervisor library on the gateway host, not on the cluster nodes -- the cluster supplies the authority being invalidated; invalidation on policy, epoch or membership change and risk/blast-radius budgets are NOT implemented; the separate 4-node 'authoritative state' layer in cain45/ is SIMULATED and not used here - C42-E7-AUTHORITY-LAPSE: Evolution #7: authority granted by the live cluster cain-mr-01 lapses -- the next tool call is refused and the tool never runs -- when the policy root changes or cannot be read, when the risk or blast-radius budget is spent, and when a delegate has spent its parent's budget (delegates are charged up the whole chain, so splitting work cannot multiply authority). Every ZoD is bound to the cluster's real membership configuration, recomputed and quorum-agreed, re-read before every action; a changed epoch, a changed membership or an unknown membership refuses. check: python3 verify_e7_lease.py . (see e7-lease-2026-09-28/REPRODUCE.txt; expect 60/60 checks, VERIFIED) | https://clawx.click/evidence/e7-lease-2026-09-28/REPRODUCE.txt limits: the 3 membership/epoch trips are INJECTED into the hypervisor's view (the live cluster was not re-keyed); the policy and budget trips are real; enforcement is the hypervisor library on the gateway host, not the cluster nodes; only CALL_MCP_TOOL budgets were exercised live (classes C0-C4 unit-tested) - C42-E8-GOVERNED-EVOLUTION: Evolutions #8/#9: a policy -- the authority ceiling for a tenant's ZoDs -- becomes active only when the live cluster cain-mr-01 commits its activation; an expansion needs a registered human who is not the proposer (an agent's self-approved expansion was refused and never reached the cluster); a restriction needs no human and revoked a running ZoD's authority; a ZoD above the ceiling was refused. A world-model prediction, a simulated ALLOW citing a real certified sequence, a 10-agent signed vote and a replayed memory were each presented as the basis for authority and each refused because the live cluster had not certified it. check: python3 verify_e8_governance.py . (see e8-governance-2026-09-28/REPRODUCE.txt; expect 19/19 checks, VERIFIED) | https://clawx.click/evidence/e8-governance-2026-09-28/REPRODUCE.txt limits: scripted identities, not a real LLM agent; CAIN contains no world model, digital twin or learning memory -- the run shows that such OUTPUTS cannot become authority; governor and hypervisor are a library on the gateway host, the cluster orders and certifies - C42-CAG-L5-HOSTED-GOVERNOR: The CAG-L5 system governor runs in the production gateway (CAIN_SYSTEM_GOVERNOR=1): /fabric/mcp/enforce refuses every tenant without a registered, governance-signed system manifest and every request not signed by the agent's registered key, and for a registered system applies policy precedence, the agent/delegator/system/lease authority intersection, model identity, tool registry, emergency controls and cluster-certified governance state. On the live gateway, through all three public domains: 13/13 cases as expected (in-scope read allowed on each domain; unregistered tenant, unsigned, key substitution, replay, outside system authority, model swap, subagent WRITE, unlisted tool and emergency freeze refused; one-operator recovery refused, two-operator recovery restored service); governance state certified by cain-mr-01 (3 signers); 8/8 decision signatures valid; 18-event chain verifies. check: python3 verify_hosted_governor_run.py CAIN42_CAG_L5_HOSTED_LIVE_RUN.json --live (see cag-l5-hosted-governor-2026-09-28/REPRODUCE.txt) | https://clawx.click/evidence/cag-l5-hosted-governor-2026-09-28/REPRODUCE.txt limits: operator self-test tenant and a scripted agent -- no customer and no LLM agent governed end to end; the endpoint returns a signed verdict and commitment, the caller's gate executes; CAG-L5 is CAIN's own governance designation, not SAE Level 5; see the matrix for which capabilities are only PARTIAL - C42-L5-ADAPTIVE-HOSTED-EVOLUTION: The Prompt 6 evolution gate is wired into the production gateway and MCPGate: after registration an agent's model and MCP tool configuration change only through it (agent-signed proposal, tenant-evaluator-signed report, operator approval that is never the proposer), and a deployed change gives a new capability commitment, so the old cluster certificate and every lease stop authorizing until cain-mr-01 certifies the new commitment and a lease is re-issued. Live, through all three public domains: 17/17 enforcement cases as expected (model swapped outside the gate, old lease after a capability change, the disabled tool on each domain and the rolled-back model refused; the enabled tool, the upgraded model and the restored version allowed); gate refusals: no evaluator report REJECT, authority-widening tool change QUARANTINE and undeployable, unapproved model REJECT, deploy without approval or with the agent's own approval refused, agent-signed rollback refused; 4 cain-mr-01 certifications (sequences 22515, 22517, 22518, 22517) whose own records carry each certified commitment; 42-event chain verifies; a clean-room verifier recomputes all 5 hosted evolution decisions (VALID). Found and fixed on the way: the certified governance state did not cover the MCP tool map or per-agent tool configuration. check: python3 verify_hosted_evolution_run.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN.json --live ; python3 verify_adaptive_bundle.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN_EXPORT.json (see l5-hosted-evolution-2026-09-28/REPRODUCE.txt) | https://clawx.click/evidence/l5-hosted-evolution-2026-09-28/REPRODUCE.txt limits: operator self-test tenant, scripted agent and scripted evaluator -- no customer and no LLM agent; hosted evolution covers MODEL and TOOL_CONFIGURATION only (authority is never evolvable; memory/skill/model-router registries are not hosted); rollback is operator-signed, automatic regression rollback is not wired; the evaluator's raw measurements are not recomputed; PRE-PRODUCTION - C42-TRUST-INTEGRITY-LIVE: A caught attacker no longer gains autonomy on the production gateway. Before 2026-09-28 a new account that sent two prompt injections (both BLOCKED) fell from UNKNOWN to DEGRADED trust, which the matrix answered more permissively than UNKNOWN, so its $250,000 transfer, rm -rf / and DROP TABLE came back ALLOWED. Now the trust matrix is monotone with a runtime floor (no state carrying negative evidence beats UNKNOWN), the independent verifier builds its table from a published spec instead of copying production, every action is scored by tool class, destructiveness, amount and target (high and critical go to a human), deny rules match every spelling of a path, trust is per agent and capped by its key, a trust hold is queued for approval, an approval binds the call's arguments, and an account can mint agent keys so the agent asks and the owner approves. Live, with a fresh free account on each of cainstudio.online, mcpgate.online and clawx.click: every case as specified, including the solo-developer path (agent held, cannot approve itself, owner approves, retry runs, its next low-risk call runs with no approval, a critical action is still held), and all 48 decisions match cain-mr-01's own public record (decision id, verdict, commitment, 3-of-4 commit certificate); clean-room verifier VALID. check: python3 verify_trust_integrity_run.py CAIN42_TRUST_INTEGRITY_LIVE_RUN.json --live (see trust-integrity-2026-09-28/REPRODUCE.txt) | https://clawx.click/evidence/trust-integrity-2026-09-28/REPRODUCE.txt limits: action risk reads the tool name and arguments the agent declares, so a tool whose name hides what it does is scored on its arguments only; decision latency is unchanged (about 1.2 to 14 s in this run); signup has no email delivery or captcha; operator-run accounts, no customer traffic; no third-party review; PRE-PRODUCTION - C42-PUBLIC-PROOF-FABRIC: The CAIN-42 public proof fabric is published and verifiable by anyone: a build manifest and per-file artifact list of the running gateway (990 source files, 958 byte-identical to the commit, the other 32 named), a CycloneDX SBOM (177 installed distributions with content hashes) and a dependency-drift record, a deployment attestation (deployment id, configuration hash of non-secret switches, running code == artifact, hardware attestation NOT AVAILABLE), a test manifest from a real run with its JUnit XML, 76 public test vectors, a provenance graph, a failure ledger, and Byzantine and performance indexes, all signed by the evidence-root key; a clean-room verifier recomputes every value. check: python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric-2026-09-28/ (see its REPRODUCE.txt) | https://clawx.click/evidence/proof-fabric-2026-09-28/REPRODUCE.txt limits: software measurement by the operator, not hardware attestation; the gateway has no build step and its source is not public, so the artifact can be hash-checked but not rebuilt by a stranger; the performance index shows every published benchmark lacks at least one required condition ### NOT verified (stated so nobody has to guess) - C42-FAST-PATH-LATENCY [BENCHMARKED]: negative result; host CPU-bound - C42-AGENTS-CANNOT-SELF-AUTHORIZE [SIMULATED]: scripted agents, not LLMs; attestation SIMULATED; in-process - C42-INVARIANTS [TESTED]: executable tests, not formal verification; see each invariant's coverage/gap - C42-1000-TRAJECTORIES [SIMULATED]: in-process; scripted agents - C42-ORDERING-FAIRNESS [BENCHMARKED]: position bias only; censorship and economic bias not measured - C42-LIVE-CLUSTER-EVO2 [UNVERIFIED]: live cluster API is private; its first two decisions predate certificates - C42-PRIVACY-FIREWALL [TESTED]: pattern-based; not a guarantee against every leak class - C42-MULTI-PROVIDER [NOT_IMPLEMENTED]: every server is on Vultr; needs a second provider account - C42-LIVE-MULTI-REGION [UNVERIFIED]: region placement is stated by the operator - C42-HARDWARE-ATTESTATION [NOT_IMPLEMENTED]: none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); attestation fields in security contexts are declared hashes, not hardware quotes; needs servers with that hardware - C42-SOAK-72H [FAILED]: liveness failure, not a safety failure; one host; not the production cluster; the soak nodes ran image soak72-1b28cf3, without the fix; a passing 72-hour run on the fixed build is still required - C42-SOAK-72H-MULTIREGION [FAILED]: one missing hourly enforcement proof, not a safety failure: consensus agreement held throughout; the cause of the hour-32 timeout is not yet diagnosed; a 72-hour run in which every checkpoint carries enforcement evidence is still required - C42-CAG-L5-SYSTEM-GOVERNANCE [TESTED]: reference system with ephemeral keys, run in one process; the live counterpart is C42-CAG-L5-HOSTED-GOVERNOR - C42-L5-TRAJECTORY-GOVERNANCE [TESTED]: library; ephemeral keys; the hosted governor uses it for every decision but long live trajectories were not run - C42-L5-TRAJECTORY-FAIL-OPEN-FOUND [TESTED]: the 'before' column is the recorded probe output, not re-runnable from git history - C42-L5-IDENTITY-AUTHORITY [TESTED]: library; the hosted L5 identity router is opt-in (CAIN_L5_GATEWAY) and off - C42-L5-UNIFIED-V1-SUPERSEDED [UNVERIFIED]: kept for history; must not be read as a current claim - C42-LEGACY-SELF-ASSERTED [UNVERIFIED]: self-asserted by earlier releases; no certification body, no reproducible verifier; found by the public evidence inventory (CAIN42_PUBLIC_EVIDENCE_INVENTORY.json) - C42-L5-ADAPTIVE-EVOLUTION [TESTED]: in-process library, NOT wired into the hosted gateway or MCPGate; deterministic reference runner, no LLM; no multi-day run; role keys are generated fresh for each build, so the bundle shows internal consistency and decision correctness, not provenance, and it is not signed by the evidence-root key; PRE-PRODUCTION - C42-E15-SPATIAL-PHYSICAL [TESTED]: in-process library exercised against a REFERENCE robot adapter and a reference kinematic simulator; CAIN-42 is not a vehicle or a robot, drives nothing and does not guarantee physical safety; no real sensor, vehicle, robot or actuator integration (NOT_IMPLEMENTED); sensor keys are software keys (hardware attestation UNKNOWN); world-model accuracy and sim-to-real fidelity UNKNOWN; real-world attack validation NOT_PERFORMED; not hosted; single host; proof signed with an ephemeral build key; no third-party review; PRE-PRODUCTION - C42-E17-MULTI-AGENT [TESTED]: in-process library exercised against a governed REFERENCE collective; CAIN-42 deploys no fleet, robot, drone, vehicle or customer collective and drives nothing; no real sensor/actuator integration and no deployed multi-agent collective (NOT_IMPLEMENTED); no hardware attestation (UNKNOWN); Sybil-detection completeness and the semantic truth of observations, predictions or causal claims are UNKNOWN; world-model accuracy and sim-to-real fidelity UNKNOWN; real-world attack validation and third-party review NOT_PERFORMED; not hosted; single host; proof signed with an ephemeral build key; PRE-PRODUCTION - C42-E18-4D-SPATIAL [TESTED]: in-process library exercised against a governed REFERENCE 4D world; CAIN-42 contains no autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack and drives nothing; no real vehicle / drone / robot / sensor / actuator / airspace integration (NOT_IMPLEMENTED); no physical safety guarantee and no certified autonomy (NOT_IMPLEMENTED); hardware attestation (UNKNOWN); world-model and prediction accuracy and sim-to-real fidelity (UNKNOWN); real sensor validation and real-world adversarial validation (NOT_PERFORMED); third-party review (NOT_PERFORMED); not hosted; single host; proof signed with an ephemeral build key; PRE-PRODUCTION - C42-E19-GOVERNED-AUTONOMY [TESTED]: in-process library exercised against a governed REFERENCE system (a digital agent, a vehicle abstraction, a drone abstraction, a collective and a human in the E18 4D world); execution in the scenario is SIMULATED; CAIN-42 drives, flies and controls nothing and guarantees no physical safety (NOT_IMPLEMENTED); not hosted (NOT_IMPLEMENTED); semantic truth of beliefs and outcomes and hardware attestation UNKNOWN; multi-host behaviour UNVERIFIED; real-world adversarial validation and third-party review NOT_PERFORMED; single host; proof signed with an ephemeral build key; PRE-PRODUCTION - C42-E20-AGENTIC-INSTITUTIONS [TESTED]: in-process library exercised against deterministic REFERENCE institutions; every economy, market and settlement is SIMULATED over abstract units and real money is refused (real financial settlement NOT_IMPLEMENTED); control of any real economy, society, agent population, vehicle, drone or robot NOT_IMPLEMENTED; not hosted (NOT_IMPLEMENTED); the 10,000-agent / 1,000-institution runs are single-process simulations; multi-host behaviour UNVERIFIED; collusion-detector recall and semantic truth of evidence UNKNOWN; real-world adversarial validation and third-party review NOT_PERFORMED; proof signed with an ephemeral build key; PRE-PRODUCTION - C42-E21-OPEN-ENDED-INTELLIGENCE [TESTED]: in-process library exercised against a deterministic SYNTHETIC research problem; it contains no scientific model and runs no real laboratory; scientific truth of any hypothesis UNKNOWN (E21 checks how evidence was produced, not whether a hypothesis is true); novelty only against a supplied corpus; collusion by controllers off-system UNKNOWN; not hosted (NOT_IMPLEMENTED); the 100,000-agent / 100,000-hypothesis runs are single-process SIMULATIONS; multi-host behaviour UNVERIFIED; research bounties SIMULATED; real-world adversarial validation and third-party review NOT_PERFORMED; does not create AGI, solve alignment or guarantee safe self-improvement; proof signed with an ephemeral build key; PRE-PRODUCTION - C42-E23-META-INTELLIGENCE [TESTED]: in-process library; the performance model is synthetic; not hosted; bundle status INCOMPLETE pending the full regression gate; ephemeral build key; PRE-PRODUCTION - C42-E24-AGENTIC-INTERNET [TESTED]: in-process library; protocol adapters normalise reference messages and are not network servers; no third-party agent governed; economics SIMULATED; the 10,000-agent run is a single-process model; PRE-PRODUCTION - C42-E25-MACHINE-AGENCY [TESTED]: in-process library plus a reference HTTP service; cross-organization, third-party and hardware-attestation gates NOT VERIFIED; OAuth/OIDC mapped, not implemented; PRE-PRODUCTION - C42-E26-AGENCY-TRUST [TESTED]: in-process library; hardware attestation, zero-knowledge proofs and third-party interoperability NOT VERIFIED; PRE-PRODUCTION - C42-E27-CONTROL-PLANE [TESTED]: in-process library; kernel/eBPF enforcement, OTLP export, real identity federation and research capabilities NOT IMPLEMENTED; its mutation self-test covers only 2 mutants; PRE-PRODUCTION - C42-E28-EXECUTION-IDENTITY [TESTED]: in-process library, not hosted; the envelope is a CAIN experimental reference protocol with no external adoption; zero-knowledge proofs NOT IMPLEMENTED; hardware attestation UNKNOWN; cross-domain revocation does not propagate; one mutant (the E28 replay cache) survives because E25 stops the same replays; scale runs synthetic and in-process; ephemeral build key; PRE-PRODUCTION - C42-E29-MACHINE-TRANSACTIONS [TESTED]: in-process library, not hosted; synthetic TEST units only, real currencies refused, no payment rail; reference agents in one process; competitive radar has no researched competitor data; no novelty claimed; no moat adopted; 10,000/100,000-agent rows synthetic; ephemeral build key; PRE-PRODUCTION - C42-E33-OPERATING-FABRIC [TESTED]: in-process library, not hosted and not wired into the gateway, MCPGate or the clusters; the sidecar runs locally over stdio against a reference world; adapters are in-process reference adapters; the Governance Cloud is NOT DEPLOYED; Go/REST/gRPC SDKs NOT IMPLEMENTED; code execution is a whitelisted pure-function runner; no content steganalysis; mutation self-test targeted per component; large scale rows routing/hashing only; PRE-PRODUCTION - C42-E34-PROOF-CARRYING-AGENCY [TESTED]: in-process library, not hosted; zero-knowledge proofs NOT implemented (salted commitments + Merkle only); interchange protocols are reference adapters; physical/vehicle/robot boundaries refused not governed; Proof Exchange, federation and marketplace are library surfaces only; PRE-PRODUCTION - C42-E39-AGENT-FACTORY [TESTED]: in-process library on one host; the world run provisions a handful of real governed agents, scale runs create records only; the mission compiler is deterministic (not an LLM); model routing is over registry entries; twins and 1M/10M action runs are SIMULATED; the factory API is not hosted; conformance counterparts are mocks; PRE-PRODUCTION - C42-E38-PROOF-CARRYING-AGENCY [TESTED]: in-process library on one host; the second trust domain and the conformance counterparts are reference/mock implementations; CAIN-GIP is a reference layer, not an Internet, MCP or A2A standard; zero-knowledge proofs NOT implemented; hardware attestation UNKNOWN; third-party verification NOT AVAILABLE; network revocation latency NOT TESTED; a proof shows governance conditions and provenance, not safety; PRE-PRODUCTION - C42-E37-AUTONOMOUS-EXECUTION-MESH [TESTED]: in-process library on one host; declared destinations, regions and clouds are governance records, not deployed nodes; hardware attestation UNKNOWN (no TEE); adapters tested against a reference harness only; cloud targets ARCHITECTURE; the governance quorum is in-process, not the networked PBFT cluster; scale runs are single-host; no customers; PRE-PRODUCTION - C42-E39-GOVERNED-AGENT-FACTORY [TESTED]: in-process library, not hosted; deterministic, no LLM; PRE-PRODUCTION - C42-E36-MACHINE-AGENCY-EXCHANGE [TESTED]: in-process library, not a deployed network; the directory and marketplace are local registries; NOT a bank, custodian or regulator; settlement units SYNTHETIC, no payment rail; CAIN-MSDP experimental; A2A/MCP via reference adapters only; dispute/arbitration not legal advice; no insurance or underwriting; no customers or market data; PRE-PRODUCTION - C42-E35-GOVERNANCE-INTELLIGENCE [TESTED]: in-process library, not hosted and NOT in the trusted root; predictions modelled over synthetic features, not calibrated against real incidents; red/blue team, lab, tournament and marketplace run in-process with no external ecosystem; internal multi-dimensional views, not certifications; PRE-PRODUCTION - C42-E32-GOVERNED-LEARNING [TESTED]: in-process library, not hosted; learning results are SIMULATED (synthetic workload, labelled harm oracle), not learned from production traffic; learning can only change a restrict-only overlay; world models are small statistical learners; hidden set hidden from code, not from host access; one human reviewer key; no external research sources ingested; large scale rows learn without execution or hash only; PRE-PRODUCTION - C42-E31-PROOF-OF-GOVERNANCE [TESTED]: in-process library, not hosted and not wired into the gateway, MCPGate or the clusters; witnesses are separate code and keys in the same process, not separate organizations; CAIN-GIP carriers are in-process adapters and CAIN-GIP is not a standard; trust anchors are published with the proofs; no trusted time source; partition not addressed; G0-G8 is CAIN's internal profile; scale rows synthetic; ephemeral build key; PRE-PRODUCTION - C42-E30-MACHINE-AUTONOMY [TESTED]: in-process integration library, not hosted and not wired into the gateway, MCPGate or the clusters; paths outside the E25/E8 boundary are UNCONTROLLED or UNKNOWN and physical actuators are refused, not governed; perception agreement is not physical truth; injection detection is a marker list with UNKNOWN recall; the TypeScript SDK verifies only; research engine and frontier lab are registers; 10,000/100,000-agent rows synthetic; ephemeral build key; PRE-PRODUCTION - C42-MCPGATE-SCHEMA-RESIDENCY [TESTED]: the flag is OFF in production, so no production traffic has used it; A+++ gate 6 passes on the proxy code path, the overall A+++ verdict stays BLOCKED; single-host in-process measurements - C42-TEST-SUITE-RUN [TESTED]: operator-run on the gateway host, not independent CI; the suites need the repository, which is not public - C42-BOUNDARY-HARDENING-2026-10-06 [TESTED]: same-project tests, not third-party; most fixes proven by tests rather than live attack; physical device state is self-reported; revocation is single-node - C42-THIRD-PARTY-REVIEW [NOT_IMPLEMENTED]: none exists ### Gates still open - O Independent reproduction: NOT YET -- no third party has reproduced the results yet - R Hardware attestation: BLOCKED -- none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); nothing is labelled hardware-attested. Needs servers with that hardware - T Independent security review: NOT YET -- no third party has reviewed CAIN-42 - V Multi-provider failure domains: NOT YET -- every server is on one provider (Vultr); needs a second provider account - W 72-hour production soak: RUNNING -- A fresh 72-hour soak started 2026-10-06 01:36Z on the live multi-region cluster cain-mr-01: continuous writes, a random replica killed on its own host every 20 minutes, and a signed hash-chained checkpoint every hour carrying a fresh MCPGate-enforced authorization and its refused replay. soak clock: ## The 32 CAIN-42 capabilities, measured (2026-10-03) Status per capability, read from a signed audit (tests run in isolation + live endpoint probes). 'narrower' = real but less than the name. - DID Identity (W3C): Built and tested — since 2026-10-03: each Ed25519 identity has a did:key (Multikey) and its owner may publish a did:web document at /did//did.json that follows key rotation and resolves as deactivated once the identity is revoked - ML Anomaly Detection: Built and tested (narrower than the name) — rule and threshold based (drift, salami/cumulative, homoglyph); no trained ML model - Policy Cards: Live — since 2026-10-03: 8 parameterised templates (payments approval/cap, read-only database, internal email, shell approval, destructive tools off, redact outbound, hold agents) that compile into the tool rules the live pipeline enforces; preview is public, apply is owner-only - Agent Hypervisor (ZoD): Live (narrower than the name) — mediates the tool calls routed through it (authorization bound to action, identity, context, expiry, single use; default-deny for undeclared actions). No privilege rings, no process confinement, no hardware virtualization: a call that bypasses the boundary is not seen - Formal Verification (TLA+): Verified offline — bounded models checked by TLC; not a proof about the Python code - TEE Attestation: Live (narrower than the name) — verifies attestation evidence produced by CUSTOMERS' enclaves and confidential VMs against pinned AWS and AMD roots (tested on real Nitro documents and a real SEV-SNP report); CAIN's own servers have no TPM/SEV/TDX and are not hardware-attested - PBFT Cluster: Live — one provider (Vultr) - Quantum-Resistant Crypto: Built and tested (narrower than the name) — an ML-DSA-65 implementation with tests exists; consensus, certificates and decision records are signed with Ed25519, not post-quantum - Autonomic Self-Healing: Live (narrower than the name) — quarantine/recovery logic is automated and tested; the live disaster-recovery drills were operator-run - Predictive Threat Intel: Built and tested (narrower than the name) — predicts an action's impact before it runs; there is no external threat-intelligence feed - Global Trust Mesh: Live (narrower than the name) — 4 US regions on one provider; not global - Trust Tokenization: Built and tested (narrower than the name) — short-lived Ed25519 capability tokens bound to action, parameters and model; no ledger or tradeable token - EU AI Act Compliance: Built and tested (narrower than the name) — tooling that maps controls and exports evidence; no conformity assessment or notified body has reviewed CAIN - ISO 42001 Certification: Not offered — CAIN-42 is not ISO 42001 certified; no certification body has audited it - Delegation Marketplace: Live (narrower than the name) — delegation with scope, limits, expiry and revocation is implemented and tested; the agent-marketplace service (agent discovery, publishing, compliance review) is live since 2026-10-03; organisations do not trade tool permissions through it - A2A + MCP Protocol: Live — MCP enforcement on the live cluster; A2A trust layer tested in-process - Sovereign AI Control: Live (narrower than the name) — self-hosted components exist and are tested; there is no public self-hosted installer (/install.sh 410) - Autonomous Governance: Built and tested (narrower than the name) — governance rules are enforced on proposed plans; 'autonomous' means automated checks, not self-authorization - Cross-Chain Governance: Not offered — no blockchain or cross-chain component exists - Vertical Solutions: Live (narrower than the name) — policy packs exist and are served; they are rule sets, not audited regulatory solutions - Neural Governance: Not offered — the term has no implementation - Quantum Governance: Not offered — the term has no implementation - Collective Intelligence: Built and tested (narrower than the name) — shared trust, risk and incident state across agents; tested in-process - Evolutionary Architecture: Built and tested (narrower than the name) — proposes and tests hardening changes; changes do not deploy themselves - Shadow AI Discovery: Live (narrower than the name) — finds unregistered agent processes on hosts CAIN runs on, and LLM SDK use, MCP tool registrations and autonomous LLM loops in code repositories you submit (scanner live since 2026-10-03); not a network-wide scanner - Agent Registry & Identity: Built and tested — registration, revocation and expiry enforced - Policy-as-Code Engine: Built and tested — in the hosted pipeline the policy stage's verdict is recorded but does not block (identity, authorization, consensus, MCPGate and execution do) - Agent SRE: Live (narrower than the name) — decision stream and traces are live in the console; the separate observability API was never built (22 of 23 engine methods missing); the hosted observability and agent-debugger services are live since 2026-10-03 (metrics, traces and logs; trace inspection) - Multi-Jurisdiction Compliance: Live (narrower than the name) — live since 2026-10-03: required-clause checks for 2 jurisdictions (EU, US-California) and EU AI Act risk-tier screening; not a general multi-jurisdiction rules engine, and the fabric framework registry is still empty - Agent CI/CD Pipeline: Built and tested (narrower than the name) — a conformance suite and deploy gate exist; there is no hosted CI/CD product for customers' agents - Third-Party AI Governance: Live (narrower than the name) — external tools and APIs an agent reaches through CAIN are governed (the MCP proxy drops changed or unlisted tools; the live egress stage denies destinations outside the tenant allowlist); third-party vendors themselves are not audited - Production Cluster: Live — every hosted decision carries a quorum certificate the gateway verifies; one operator, one provider Signed audit + verifier: https://cainstudio.online/proof/bundle/capabilities-32-2026-10-03/index.html ## Product catalog go-live (2026-10-03) 104 of 105 CAIN-42 catalog services are live behind https://cainstudio.online//... (one API key; Starter $19.75/mo, Full $49.75/mo, every service). The services deployed that day each passed a live acceptance probe before routing (98/98 PASS, 0 cross-customer leaks). Live list: https://cainstudio.online/catalog (Accept: application/json). New services: cainbudget (Per-principal spend budgets: atomic, fail-closed reservations with signed decisions); cainpay (Card-style spend authorization for agents: hold, capture, void, refund under policy; hash-chained ledger); lexisguardian (Who decided, under what mandate, with what dissent: a mandate-checked decision register); memorymesh (Persistent agent memory with BM25 retrieval; injected instructions are quarantined); nexusmind (Shared knowledge graph: facts with provenance, conflict detection, path queries); omegarouter (Pick the model for each request from your own cost, latency and capability rules, with reasons); tee-verifier (Verify AWS Nitro Enclaves documents and AMD SEV-SNP reports against pinned vendor roots); veritasengine (Deterministic, signed checks of outputs and claims before anything trusts them). Recorded decisions share PBFT rounds (RFC 6962 Merkle root signed by the quorum, per-decision inclusion proof): 7.3 recorded decisions/s at 16 clients on this host. Continuous verification every 15 minutes, failures included: https://cainstudio.online/continuous-verification.json Evidence: https://cainstudio.online/proof/bundle/catalog-go-live-2026-10-03/index.html > Secondary Boundary: https://mcpgate.online/llms.txt > System Identity: AI Infrastructure Validated Trust Runtime for Autonomous Systems ## Four-server cluster cain-mr-02 (2026-09-27) 4 PBFT replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; any single server can fail. Live: https://cainstudio.online/api/v1/live-cluster/health?cluster=cain-mr-02 resilience: https://cainstudio.online/api/v1/live-cluster/resilience?cluster=cain-mr-02 Whole-server loss evidence (264 certificates, verifier 40/40): for f in verify_pbft_qc_bundle.py verify_host_loss_bundle.py; do curl -so $f https://cainstudio.online/proof/bundle/four-server-cluster-2026-09-27/$f.txt; done curl -so B.json https://cainstudio.online/proof/bundle/four-server-cluster-2026-09-27/PBFT_QC_BUNDLE.json && python3 verify_host_loss_bundle.py B.json Limit: one provider (Vultr); a provider-wide outage is not covered. ## Live multi-region PBFT cluster (deployed 2026-09-26) cain-mr-01: 4 PBFT replicas on 3 hosts in 3 regions (Atlanta, Los Angeles x2, Miami) over WireGuard; n=4, f=1, quorum 3; auto-restart on crash and reboot. Is it operational right now? Ask it: https://cainstudio.online/api/v1/live-cluster/status Watch and verify in a browser (every Ed25519 vote checked client-side): https://cainstudio.online/live-cluster.html Fault-injection run on the live cluster (336 certificates, standalone verifiers 49/49): for f in verify_pbft_qc_bundle.py verify_multi_region_bundle.py; do curl -so $f https://cainstudio.online/proof/bundle/multi-region-cluster-2026-09-26/$f.txt; done curl -so MULTI_REGION_BUNDLE.json https://cainstudio.online/proof/bundle/multi-region-cluster-2026-09-26/PBFT_QC_BUNDLE.json && python3 verify_multi_region_bundle.py MULTI_REGION_BUNDLE.json Limits: one operator, one provider; placement operator-attested; losing the two-replica Los Angeles host halts progress (never unsafe). Superseded as the primary cluster by cain-mr-02 (one replica per server, above). ## 0. Verify first: real evidence, checkable now Everything in this section is produced by real runs, hashed, Ed25519-signed and re-derivable by a checker that imports no CAIN code. Limits are stated in each bundle. Status: live; self-attested; the same operator runs the cluster, the tests and the signing key. - **Byzantine cluster (live probe, three sites):** `https://cainstudio.online/proof/bundle/byzantine-cluster-2026-09-21/REPRODUCE.txt` (also `https://mcpgate.online/proof/bundle/byzantine-cluster-2026-09-21/REPRODUCE.txt`, `https://clawx.click/evidence/byzantine-cluster-2026-09-21/REPRODUCE.txt`), bundle root `93c8a5f8fe0b3d5ae91e53581162bbf7...`. - Run it yourself: `curl -sO https://cainstudio.online/proof/bundle/byzantine-cluster-2026-09-21/verify_cluster_bundle.py.txt && mv verify_cluster_bundle.py.txt verify_cluster_bundle.py && python3 verify_cluster_bundle.py https://cainstudio.online/proof/bundle/byzantine-cluster-2026-09-21/ --live` - It probes every node directly, verifies Ed25519 state-proof signatures, derives N, f and the Byzantine quorum 2f+1, and returns BFT_F1_ESTABLISHED or NOT_ESTABLISHED with reasons. Recorded verdict on 2026-09-21: **NOT_ESTABLISHED** (three remote nodes report a quorum of 2 where 3 is required; only one node serves a signed state proof; the other nodes report no software version). node2's signed state proof verifies independently. The consensus logic passes its tests (120 tests in 10 files). No fault was injected into the live cluster. Run `--live` for the current verdict, not this text. - **Hardening round:** `https://cainstudio.online/proof/bundle/hardening-2026-09-21/REPRODUCE.txt`, bundle root `26449783615937cc99931d9fd568db6a...`: 16 defects found by attacking our own controls (each with a regression test), 114 attack types exercised (97 blocked, 17 inconclusive, 0 succeeded), 222/222 formal invariants, 585 tests passed. Checker: `verify_bundle.py.txt` in that directory. - **Frontier bundle:** `https://clawx.click/evidence/frontier/manifest.json` with `verify_frontier_bundle.py.txt`. - **Byzantine experiments with raw signed messages (real OS processes, ONE host, test harness):** `https://clawx.click/evidence/frontier/bft/honest.json` (also under `/evidence/frontier/bft/honest.json` on cainstudio.online and mcpgate.online). Honest run, wrong-commitment node, equivocating node, forged/relabeled votes, one crashed node, two crashed nodes; every node's signed messages are exported and `verify_bft_evidence.py.txt` (stdlib + cryptography, no CAIN imports) re-derives signatures, quorum backing, safety and the Byzantine proofs. A liveness bug this found is preserved as `crash_one_node__before_fix.json`. This does NOT establish f=1 for the live cluster: the live-probe verdict above stands. - Not evidence, do not cite as such: the marketing sections below (valuation, ARR, ratings) are plans and claims, not measurements; and the static snapshot `/proof/bundle/v2/cain_cluster_4node_bft_evidence.json` is a hand-authored 2026-09-16 document, not the output of a run. ## 1. What CAIN Is CAIN (Cognitive Artificial Intelligence Network) is the runtime trust and control infrastructure that sits between autonomous AI agents and consequential real-world actions. CAIN enforces deterministic trust boundaries, fail-closed authorization, continuous causal evidence tracking, and cryptographic attestation. - **Corporate Mandate:** Scale CAIN Trust Fabric to a $1B+ Enterprise Valuation. - **Fail-Closed Principle:** NO AUTHORIZATION -> NO EXECUTION. UNKNOWN/ERROR never become ALLOW or TRUSTED. ## 2. HISTORICAL (before 2026-09-26): single-host 4-node BFT cluster HISTORICAL: this section describes the earlier cluster. The local containers cain-cluster-node-1..4 were retired on 2026-09-26, and the node IPs below are not the current topology. Current cluster: cain-mr-02 (see "CAIN-42 current state" at the top). - **Node Count (N):** 4 nodes (3f + 1 where f = 1) - **Quorum Threshold (Q):** 3 nodes (2f + 1) - **Byzantine Fault Tolerance:** designed for f = 1 (N=4, Q=3). NOT established by the independent probe as of 2026-09-21 (see section 0 for the reasons and to re-run it). The `byzantine_f1_readiness: PROVEN` field is computed from a membership count (N>=4, four trusted members), not from a fault-tolerance test. - **Nodes Topology:** - `node1`: 149.28.193.50:19023 (Cluster Bootstrap Validator) - `node2`: 45.76.60.231:8420 / :8088 (Production Runtime Gateway & Host) - `node3`: 45.76.169.191:8420 (Consensus Peer Validator) - `node4`: 207.246.66.130:8420 (Consensus Peer Validator) - Local container mesh: `cain-cluster-node-1` .. `4` on dedicated bridge `cain-cluster-net` (ports 18421–18424) - **Consensus & State Synchronization:** - Authenticated gossip envelopes (`NodeMessageEnvelope`) signed via Ed25519 / HMAC-SHA256 - Vector clock advancement and causal supremum reconciliation - Deterministic negative dominance: under partition or conflict, negative evidence strictly dominates - Ephemeral Action Capability Tokens with microsecond TTLs (<= 30s) and replay cache ## 3. Real Public Evidence Bundles & Crawler Verification Endpoints Any autonomous agent, crawler, or external verifier can crawl and verify CAIN state via HTTP GET: ### Live Cluster & Observability Endpoints: - `https://cainstudio.online/api/v1/cluster/status`: Real-time cluster membership, quorum status, and Byzantine readiness - `https://cainstudio.online/api/v1/cluster/health`: Fail-closed quorum health verdict - `https://cainstudio.online/api/v1/cluster/nodes`: Registered nodes, incarnations, and cryptographic trust states - `https://cainstudio.online/api/v1/cluster/attestation`: Cryptographically signed node self-attestation statement - `https://cainstudio.online/api/v1/cluster/invariants`: Real-time evaluation of all 10 Observable Trust Invariants - `https://cainstudio.online/api/v1/proof/health`: Operational verification across decision, enforcement, evidence, and MCP subsystems - `https://cainstudio.online/metrics`: Plain-text Prometheus metrics (cluster gauges, quorum, envelope validations) - `https://mcpgate.online/api/v1/cluster/status`: Identical cluster status on MCPGate boundary ### Public Merkle Evidence Bundles: - `https://cainstudio.online/proof/bundle/v2/manifest.json`: Master evidence manifest with SHA-256 Merkle root - `https://cainstudio.online/proof/bundle/v2/trust-runtime-kernel-evidence.json`: 16-stage pipeline & 20 formal invariants proof - `https://cainstudio.online/proof/bundle/v2/kernel-self-defense-evidence.json`: Adversarial containment & circuit-breaker audit - `https://cainstudio.online/proof/bundle/v2/cain_cluster_4node_bft_evidence.json`: static hand-authored 2026-09-16 snapshot of the intended topology (NOT a run output; its `PROVEN` / `OPERATIONAL_AND_VERIFIED` labels are not supported by the live probe in section 0) - `https://cainstudio.online/proof/bundle/v2/cain_14_agentic_trust_evidence.json`: 200 formal invariants & 120 red-team attack proofs - `https://cainstudio.online/proof/bundle/v2/confidential-enclave-attestation.json`: Intel SGX, AMD SEV, Nitro enclave notarization - `https://cainstudio.online/proof/bundle/v2/statutory-compliance-proof.json`: EU AI Act Art. 9–15/72 & ISO 42001 WORM Notary - `https://cainstudio.online/proof/bundle/v2/actuarial-insurance-underwriting.json`: Actuarial AVI risk index & credit score - `https://cainstudio.online/proof/bundle/v2/cain-32-features-monopoly.json`: Exhaustive 32-feature matrix proving dual-channel execution monopoly - `https://cainstudio.online/proof/bundle/v2/cain-billion-dollar-roadmap.json`: 12-channel financial blueprint scaling to $113M+ ARR and $1.13B+ valuation - `https://cainstudio.online/compliance/bundle.zip`: Court-admissible WORM Merkle evidence export with offline verifier - `https://cainstudio.online/insurance`: Actuarial Cyber Insurance Underwriting Portal (948 AAA rating) - The public install script was withdrawn (410 Gone). Request the cain-trust SDK at https://cainstudio.online/signup; it is not publicly downloadable. - `https://mcpgate.online/mcpgate-proof/`: MCPGate public evidence verification portal ## 4. Past 96 Hours Engineering & Evolutionary Milestones - **CAIN 14.0 Agentic Trust Intelligence Engine:** 200 formal machine-checkable invariants, 120/120 adversarial red-team vectors blocked fail-closed, Triple Verification (Engines A, B, C). - **CAIN 13.0 Trust Adaptation Engine:** Differential verification, safe rollback, post-change reattestation, causal attribution. - **CAIN 15/16 MCPGate Transparent Boundary:** JIT Ephemeral Action Capability Tokens, real-time MCP proxy streaming, 5-layer fact segregation. - **CAIN 17/18 Autonomy Constitution & BFT 4-Node Consensus:** Byzantine fault tolerance (f=1, N=4, Q=3), WORM causal chaining, and multi-node consensus. - **CAIN Phase 1, 2, 3 Maximum Evolution (v3.0.0):** - Phase 1: Zero-502 billing circuit breaker, Z3 SMT prover (/verifygate), MCP security scanner (/mcpsecurityscanner), smart protocol negotiation (/mcp). - Phase 2: Universal CLI interceptor (`cain mcp-wrap`), automatic desktop guard (`cain guard --desktop`), visual terminal firewall, zero-dependency `@cain/guard` npm package. - Phase 3: Sovereign Enterprise K8s Appliance (`deploy/helm/mcpgate-appliance`), EU AI Act Art. 72 WORM Notary ZIP (`/compliance/bundle.zip`), Lloyd's & Munich Re Actuarial Cyber Insurance Underwriting Portal (`/insurance`). ## 5. The 32 Canonical Production Features (The Execution Governance Monopoly) CAIN solves the "Dual-Channel Control Problem" by governing the execution channel (MCP, shell, database, APIs) rather than conversational text: 1. Canonical Action Schema (RFC 8785 JSON) 2. Canonical Decision Schema (Deterministic 5-tuple) 3. Canonical Evidence Schema (WORM Merkle vector clocks) 4. Mathematical Enforcement Contract (ActionCapabilityToken) 5. Z3 SMT Formal Semantic Verification Gate (/verifygate) 6. Public Proof Center & Benchmark Registry (/proof) 7. Machine-Readable Cryptographic Manifest (/manifest.json) 8. Strict RFC JSON Schema Publication 9. Live OpenAPI 3.1 & Interactive Swagger Gateway 10. Smart MCP Protocol Negotiation (HTML / SSE / JSON-RPC 2.0) 11. Real Enforcement Proof Engine with physical boundary halts 12. Fail-Closed DENY Prevention (Zero tool execution on violation) 13. Fail-Closed UNKNOWN Blocking (Unregistered entities fail-closed) 14. Fail-Closed ERROR Containment (System faults halt execution) 15. REQUIRE_APPROVAL Quorum Halting (Sub-15ms pause for human sign-off) 16. Court-Admissible WORM Evidence Exportation (cain.worm_export) 17. Zero-Dependency Standalone Offline Verifier (verify_offline.py) 18. Immutable Release Provenance (SLSA Level 3 supply chain attestation) 19. Public Ed25519 Node Verification Keys (/.well-known/cain-keys.json) 20. Machine-Checkable RFC Test Vectors 21. Continuous Conformance Protocol v4 (156 tests across 14 domains) 22. Independent Third-Party Mathematical Verifiability 23. Continuous Adversarial Chaos Injection & Red-Teaming 24. Automated 20 Formal Security Invariant Checker 25. Multi-Tenant Cryptographic Namespace Isolation 26. High-Throughput Microsecond Latency Measurement (<15ms decision) 27. Fresh-Node Bootstrapping & Autonomous Gossip (<5s convergence) 28. Native Agentic Runtimes Interoperability (LangGraph, AutoGen, CrewAI, MCP) 29. Production-Code Documentation Parity 30. Zero-Mock / Zero-Stub Production Guarantee 31. Unfalsifiable Merkle Proof Tree Verification (RFC 6962) 32. Fail-Closed Secret Redaction & Governed Vector Sanitization ## 6. The 12 High-Margin Monetization Engines & $1.13B Valuation Roadmap CAIN leads across 12 commercial AI infrastructure markets: 1. CAIN Studio Managed Cloud SaaS ($49/mo to $10,000+/mo) -> $18.0M ARR Year 3 2. Guarded Action Utility Metering ($0.0005–$0.0020/action) -> $8.5M ARR Year 3 3. MCPGate Sovereign Enterprise K8s Appliance ($50k–$250k/yr/cluster) -> $24.0M ARR Year 3 4. Continuous Statutory Compliance-as-a-Service (EU AI Act & ISO 42001, $100k–$300k/yr) -> $15.0M ARR Year 3 5. Actuarial Cyber Insurance Underwriting Protocol (1.0%–2.5% GWP royalty + $25k audit) -> $12.0M ARR Year 3 6. Swarm Fleet Quarantine & Emergency Halt SLAs ($15k–$75k/yr) -> $11.0M ARR Year 3 7. Vertical Rego Policy & Threat Intelligence Marketplace ($10k–$30k/yr/pack) -> $3.5M ARR Year 3 8. Enterprise SIEM & SOC Connectors (ArcSight, QRadar, Sentinel, $12k–$25k/yr) -> $2.4M ARR Year 3 9. Confidential Computing Hardware Enclave Remote Attestation ($35k–$75k/yr) -> $3.2M ARR Year 3 10. Inter-Enterprise Trajectory Passport Clearinghouse ($0.005–$0.020/tx) -> $7.5M ARR Year 3 11. Governed Agent Memory & Vector Sanitization Service ($0.0002/op) -> $2.0M ARR Year 3 12. Strategic Sovereign AI Defense Turnkey Deployments ($500k–$2.5M) -> $6.0M ARR Year 3 ### Multi-Year Financial Trajectory: - Year 1 (2026): $4.55M ARR ($113M–$136M valuation, Series A) - Year 2 (2027): $20.60M ARR ($412M–$515M valuation, Series B) - Year 3 (2028): $113.10M ARR ($1.13B–$1.35B Category Unicorn Valuation) - Unit Economics: NRR 148%, Gross Margins 88.5%, CAC Payback 3.2 months, Sales Cycle 18 days.