{
 "claims": [
  {
   "claim": "at a PROTECTED boundary there is no contract, decision or E8 commit without an ACTIVE, quorum-certified package whose compiled terms the contract matches exactly"
  },
  {
   "claim": "a package revoked between decision and commit is refused by E8 and nothing executes"
  },
  {
   "claim": "revocation is permanent across republish, rollback, restart and stale replicas; older packages can never be re-activated, including via suspend"
  },
  {
   "claim": "policy tightening: 17 z3 lemmas UNSAT (per-operator semantics and optimizer rules, all values); compiler order matches semantics on 96,831 bounded pairs",
   "holds": true
  },
  {
   "claim": "the clean-room registry verifier re-derives certificates, chain, lifecycle and state from the log alone and refuses illegal transitions even with valid certificates",
   "example": "VERIFIED"
  }
 ],
 "date": "2026-10-04",
 "not_claimed": [
  "multi-host / multi-region registry",
  "MCPGate enforcement (not integrated)",
  "production deployment",
  "independent third-party verification",
  "SMT proof of ir_leq code"
 ],
 "overwrites": "nothing",
 "schema": "cain.claims.evolution9.v1",
 "scope": "mandatory verified governance packages on the contract fabric (RIG, OpenShell, MemVault, SCITT)",
 "status": "TESTED, COMMITTED, NOT DEPLOYED",
 "tests": "90/90 passed"
}
