proof 63 at 2026-09-28T07:38:05Z: OPERATIONAL · 4/4 replicas, agreement yes · write committed at sequence 611 with a quorum certificate signed by 3 members (atl, mia, sjc), verified: True
signed proof · verify the whole chainproof 69 at 2026-09-28T07:23:09Z: OPERATIONAL · 4/4 replicas, agreement yes · write committed at sequence 17773 with a quorum certificate signed by 3 members (atl, lax), verified: True
signed proof · verify the whole chaincheckpoint 34 at 2026-09-28T07:42:07Z · 34.044 of 72.0 h · height 17926 · 16828 committed, 105 refused · 96 replica kills / 96 restarts · divergences 0 · anomalies 0 · MCPGate authorization enforced (ALLOW + refused replay)
signed checkpoint · verify all checkpointsWhat was verified. Three verifier implementations that share no code and import nothing from CAIN independently re-derive canonical JSON, Ed25519 signatures, the trajectory hash chain and its RFC-6962-style Merkle root, delegation non-escalation, authority intersection, policy/action binding and the invariant matrices. All three return VALID against the published bundles: verify_l5_unified.py (22/22), verify_authority_bundle.py (22/22) and verify_l5_bundle.py (10/10). The signed artifacts and the verifiers are published on both evidence roots so either site can be checked by hand. reproduce it with one command · manifest with per-file SHA-256 · the unified verifier (no CAIN imports) · the signed bundle
What this proves, and what it does not. It proves the artifacts are internally consistent and cryptographically sound under a verification implementation that shares no code with the runtime. It does not prove independent third-party review: the verifiers, the runtime and the operator are the same, on one host, with one provider, and no external party has reproduced it. So we do not claim CAIN-42 is "fully independently verified from more than one source" — that would be false today. What is true is narrower and checkable: multiple independent verifier implementations agree, on published signed artifacts. No L5 claim is made.
New governed libraries, none of which can authorize anything. A Trajectory Firewall hash-chains a long-horizon run and flags plan/authority drift, scope creep, privilege accumulation, tool/model/identity/memory substitution, stale authorization, delegated escalation and suspicious retries. Stopping Intelligence reaches STOP/WAIT/REQUEST_APPROVAL/REPLAN/ROLLBACK/QUARANTINE/ESCALATE and can only ever make an action less permissive. A Swarm Authority Fabric keeps CHILD ≤ PARENT and SWARM ≤ POLICY, and treats unanimous agent votes as informational. A Governed Tool lifecycle makes discovery and creation grant NO AUTHORITY. A Governed Memory Fabric classifies every item, calibrates it, and cannot become policy. Resource Authority is time/scope/resource/policy/trajectory-bound, revocable and non-escalating. They encode one rule: LEARNING, PREDICTION, MEMORY, SIMULATION, DISCOVERY and AGENT CONSENSUS may change capability but never create execution authority. 419 new unit tests plus one executable Part XXVIII invariant matrix.
Limits. These six fabrics are TESTED unit libraries, not VERIFIED: no published independent evidence bundle exercises them, and they are not wired into the hosted enforcement path. The world model is tabular, not neural; the memory is not a vector store. The hosted runtime remains PRE_PRODUCTION. see every claim's evidence and limits
Policy changes are governed. A tenant's policy (which capabilities a ZoD may hold, the largest budgets it may get) now becomes active only when the live cluster cain-mr-01 commits its activation. Widening it needs a registered human who is not the proposer; narrowing it needs no one, because authority may always go down. On the live cluster: an agent's first policy was approved by a human and activated (QC 16148); the agent then proposed an expansion and approved it itself — refused, and the cluster was never asked; a failure lab's restriction was activated (QC 16151) and a running ZoD lost its authority on its next call; a ZoD above the ceiling was refused. verify: python3 verify_e8_governance.py . -> 19/19 checks, VERIFIED
Predictions, simulations, agent votes and memories are not authority. Four things an intelligent system produces were presented to the hypervisor as the basis for a ZoD: a world-model prediction with 0.99 confidence, a simulated ALLOW citing a real certified sequence, ten agents' unanimous signed vote, and a memory replaying a real decision with the verdict changed. Each was refused because the live cluster had not certified it; across the run exactly one ZoD was ever authorized.
Limits. Scripted identities, not a real LLM agent. CAIN does not contain a world model, digital twin or learning memory: the run shows their outputs cannot become authority. The governor runs as a library on the gateway host. The registry now also names seven older files on the sites whose self-asserted statuses (CERTIFIED, PRODUCTION_HARDENED, OPERATIONAL_PROVEN...) no evidence supports; they stay for history, marked superseded.
Four ways authority could survive what should end it, found by an independent probe, all fixed. Moving the clock back revived an expired grant (now: a stored time high-water mark refuses a clock that goes backwards). A tool could run while the evidence log was unwritable (now: the intent is recorded before the effect, so no log means no execution). A failing trust service, and a cluster that errored during authorization, raised instead of refusing (now: recorded refusals). Tests: 4 former gaps now pass, and fail on the previous code.
Faster. Every action re-verified every signature since the ZoD began. Now each entry is re-hashed but its signature verified once: gate p50 with 100 ZoDs in the store went from 113 ms to 18.7 ms (1,000 ZoDs: 36 ms; p99 about 0.3 s). Measured on the gateway host.
Limits. Library-level fixes in the hypervisor on the gateway host; the p99 tail is not yet explained.
Evolution #7: the five conditions Evolution #6 left open, on live authority. Every ZoD was authorized by the live cluster cain-mr-01 (decision QC 15876, ZoD QCs 15880-15892), made one successful tool call, and was refused on the next call with the tool never running once: the policy root changed; the policy source became unreadable (unknown is refused, never read as unchanged); the risk budget was spent; the blast-radius budget was spent (actions now carry consequence classes C0 read to C4 security/infrastructure); and a delegate spent its parent's budget — delegates are charged up the whole chain, so splitting work across children cannot multiply authority. Each ZoD is bound to the cluster's real membership configuration (hash recomputed, a quorum of replicas agreeing), re-read before every action (36 live reads in this run); a changed epoch, a changed membership and an unreachable cluster were each refused. Also fixed: a retry after a replica committed but timed out used to be refused as 'not committed'; the client now takes the committed sequence from the replica's cached reply and accepts it only if that certificate verifies over the exact request. verify: python3 verify_e7_lease.py . -> 60/60 checks, VERIFIED
Limits. Stated, not hidden: the three membership/epoch changes were INJECTED into the hypervisor's view (the live cluster was not re-keyed); the policy and budget trips are real. Enforcement is the hypervisor library on the gateway host. Only tool-call budgets were exercised live.
Agent Hypervisor / ZoD runtime, authority from the live cluster. An agent never holds execution authority; it acts only inside a ZoD (Zone of Decision), and only after the live 4-server cluster cain-mr-01 has committed that ZoD's authorization with a quorum certificate (3 of 4 Ed25519 signatures) that the hypervisor checks itself. Code runs under real confinement (bubblewrap namespaces + cgroup v2, no network, host tree invisible). Two ZoDs were authorized at cluster sequences 13379 and 13380; 10 attacks were refused, each as a signed DENIED entry; 45 evidence entries, hash-chained. verify: python3 verify_cain45_zod.py . -> 10 PASS, VERIFIED (about 0.3 s)
Authority leases, tripped live (Evolution #6). A ZoD is a temporal authority lease. For each of 9 conditions a fresh ZoD was authorized by cain-mr-01 (decision QC 15746, lease QCs 15748-15759), one tool call succeeded under that live authority, the condition was tripped, and the next call was refused with the tool never running: TTL expiry, trust below floor, agent identity swapped, tool schema changed (rug-pull), security context changed, trajectory fork, explicit revocation, parent quarantined (child loses authority with it), required evidence deleted. Four of these were holes found and closed this release: before the fix a child ZoD kept acting after its parent was quarantined, a tool whose schema changed after authorization was still called, a re-registered (swapped) agent identity kept acting, and deleting the evidence log did not stop execution. verify: python3 verify_e6_lease.py . -> 48/48 checks, VERIFIED
Limits. Stated, not hidden: the invalidation logic runs in the hypervisor library on the gateway host, not on the cluster nodes; what comes from the cluster is the authority being invalidated. The evidence-deletion row is SELF-REPORTED: its result is signed by the run's hypervisor, but the log that would prove it is the one deleted. Not implemented yet: invalidation on policy, epoch or membership change, risk and blast-radius budgets. A separate 4-node 'authoritative state' layer in the code is SIMULATED (one process holds all 4 keys) and is not used for any of this evidence. seccomp, egress allowlists and hardware attestation are not established.
Customers can now export any of their decisions exactly as stored and signed (GET /fabric/decisions/{id}/signed-record) and verify it offline with the published verifier, which contains no CAIN code. New disk and memory watcher on all four servers, after /tmp filled up on the Atlanta server; every server is currently below 80% disk use.
Verifier and worked exampleEvery hosted decision record is now Ed25519-signed by a key kept outside the database, so an edit is detectable even if its digest is recomputed; that covers the stages after consensus and the final verdict. Public key at /fabric/decision-signing-key. Verified live. Not covered: root on the gateway server. Gate X PASS (5 of 9).
Decision signing keyThe previous full run's 13 test failures traced and fixed without weakening a check (latest run: 5453 passed; its remaining failures belong to a change still in progress). The Verification Center correctly flagged one claim as TAMPERED: a soak verifier had been overwritten after signing. The signed bytes are restored and the fix is published as v2. That soak's real outcome is recorded: it stopped at 24 of 72 hours and its verifier returns FAIL. The daily signed sync now measures the live 4-region cluster.
Soak verifier update and outcome · llms.txtTwo-replica storage loss, rebuilt from off-host backups. On the live 4-server cluster, the Miami and Silicon Valley replicas lost their storage at the same time and were rebuilt only from backups held in other regions. While both were down the cluster committed 0 of 4 writes; afterwards 0 decisions were lost and all four were identical 10.3 s after restart. verify 416 certificates
MCPGate enforcing live consensus. Authorizations committed by the live 4-server cluster; every tool call went over HTTP through the MCPGate proxy to a separate MCP server process. 5 authorized calls ran (per the server's own log); 12 attacks were blocked, and each caller received the gate's signed denial. verify with one command
Hosted decisions: the gateway now checks the quorum certificate itself. Security fix: the hosted consensus stage used to accept a replica's word that a decision was committed, so one lying replica could have authorized a decision with no quorum. The gateway now verifies 3 pinned Ed25519 signatures over the digest it computes for that decision, and shows the check on every decision. verify a decision yourself
Formal models checked. TLA+ models of the PBFT commit/view-change rules and of the MCPGate gate, checked exhaustively by TLC: 0 violations in 7.3 million distinct states, and all 8 deliberately broken variants caught. An earlier run had been recorded as incomplete because the checker stopped at the model's normal end state; fixed. models and results
Claims registry rebuilt from current evidence. 24 signed claims. It had still said one host and no formal verification, and still called the failed single-host 72-hour soak 'in progress'; it now records that soak as FAILED and the multi-region soak as running. Gates: 14 of 15 (A-O) and 3 of 9 (P-X); hardware attestation is blocked (no TPM, SEV or TDX on any server). verify the registry
One-way network partitions. On the live 4-server cluster: a replica that can talk but not listen, a one-way link between two backups, and a replica that can listen but not talk. The cluster kept committing in each case, went through view changes, and all four replicas held identical decision chains after each heal. verify 968 certificates
Daily restore validation. Every day each replica's newest off-host backup (8 replicas, 2 clusters) is fetched from the server in another region that holds it and proven to be a quorum-signed prefix of the live history; tampered backups fail even with a re-hashed manifest. verify
Signed evidence index for crawlers and AI agents. /cain42-evidence-index.json on all three sites: every claim with its status, limits, artifact hashes and verification command, every gate, and the live endpoints, generated from the signed registry and signed with the evidence-root key; llms.txt carries the same, generated. claims registry
Degraded network: safe, but slow. 10% packet loss, 120±40 ms jitter, 5% duplication and reordering on all four replicas of the live 4-server cluster for 4 minutes: no fork, but throughput fell from 1.76 to 0.16 commits/s and 22 of 61 writes timed out; it recovered fully afterwards. The evidence publisher now runs the privacy firewall before anything reaches the sites (a bundle was briefly public with an internal subnet in its description). verify 2,728 certificates
Engine 948b189 on the 4-server cluster: fewer view changes, same throughput under loss. View-change backoff now resets only when a view commits, and a fresh view is not accused. Released reproducibly (two independent builds, identical image ID; signed release manifest 17/17), upgraded replica by replica under live traffic (each caught up in 11-31 s, no quarantines). Re-running the same degraded-network test: view changes fell from 14 to at most 6, but throughput under 10% loss stayed about the same (0.16 -> 0.18 commits/s). The storm was not the bottleneck; message delivery under loss is. Safety held (4,448 certificates, no fork). before/after, verify 4,448 certificates
The self-hosted SDK and MCP proxy now hold any undeclared action for approval instead of allowing it. Authorized tools are declared with guard(allow=[...]), allowed_tools=[...] or CAIN_ALLOWED_ACTIONS. Opting out (CAIN_UNKNOWN_ACTION_POLICY=allow) is explicit and recorded on every decision. 1516 dependent tests pass.
Free shadow mode for every customer; paid plans can switch themselves to enforce mode (POST /fabric/settings). The 4-server cluster's image was reproduced exactly by two independent builds (signed manifest 17/17). SDK allowlists and opt-in default-deny. Audit fixes applied. 13 of 15 gates pass.
Release manifestcain-mr-02 runs one replica on each of Atlanta, Los Angeles, Miami and Silicon Valley. Every server was taken offline in turn, and it kept committing each time (6/6, with a leader change each time). With two down it refused. 264 certificates, 40/40. Only the provider (Vultr) remains a single point of failure. 12 of 15 gates pass.
Verify the four-server cluster · Computed resilienceTwo independent from-scratch builds of one commit gave the same image ID, with every layer identical. Backups are also stored on another region's host. The live cluster moves to the reproducible image after the soak.
Reproducibility evidenceA forging replica's votes were rejected everywhere (6/6 committed). An equivocating primary was proven from its own signatures, quarantined by all 3 honest replicas and replaced (6/6 committed). 29/29 checks. This ran on a disposable cluster with the same placement. A signed operational proof is published every 30 minutes. The test suite is fully green (870/0), including a fixed approval-workflow bug. 11 of 15 gates pass.
Verify the Byzantine tests · Verify the operational proofsSame image on every host; 1,461 image files byte-identical to the commit; 47-package SBOM; Ed25519-signed (verifier 16/16). Tests: 865 passed, 4 failed; the failures predate this work and are listed by name.
Release manifest · Test reportWith Miami cut off, the other three committed 6/6 and the isolated replica committed nothing. In a 2|2 split neither side committed, so there was no split brain. All four agreed within about 3 s of each heal (2,960 certificates, 32/32). The anti-entropy fix (81bdf84) is rolled out live. Drill: rolling restart under writes 83/83 with 0 failures; disk-loss rebuild in 13.6 s. 7 of 15 production gates pass.
Every homepage lists the fifteen production gates with evidence links (5 of 15 pass today) and a live cluster-state line. A load test on the live cluster exposed a real defect: a replica signed after losing primacy and accused honest peers with a mismatched-signer proof. Safety held. Fixed in 9fedb49 with tests and rolled out live the same day as a rolling upgrade; all four replicas agree. Also: health endpoint, rolling upgrades, online backups.
4 PBFT replicas on 3 hosts in Atlanta, Los Angeles and Miami over WireGuard (n=4, f=1, quorum 3). Fault injection on the live cluster: Miami down, 6/6 committed; one Los Angeles replica down, 6/6; whole Los Angeles host down, 0/3 (refused, as required); Atlanta and the primary down, view change, then 6/6. 336 certificates, 49/49 standalone checks. The signatures confirm that no decision taken during an outage was signed by a stopped replica. Scope: one operator, one provider; not yet in the hosted decision path.
Live cluster: watch, verify, audit, tamper · Verify the fault-injection run · REPRODUCE.txtEvolution 2 of the PBFT engine is committed (364f1bf). It adds up to 4 proposals in flight, a pacemaker that only sets timeouts and cannot authorize anything, and an AuthorizationCertificate that is valid only with a valid COMMIT quorum certificate and a request whose intent, proposal and action hashes match. It also fixes a real defect: the post-commit authorization proof hardcoded trust_state=HIGH and risk_state=LOW, which it never evaluated. It now says NOT_EVALUATED. Tests: 135/135 PBFT Evolution 1+2 and 167/167 wider Byzantine/cluster suites. Public evidence: a disposable 4-node cluster built from c188442 committed 20 decisions across a primary failover. All 160 quorum certificates are published with the signed votes, a standalone verifier that uses no CAIN code, and a page that checks them in your browser (29/29, including 7 tamper controls that must fail). MCPGate is not yet wired to consume the AuthorizationCertificate. The run used one host. Later the same day the live cain-vc cluster was upgraded to this build, node by node: state was preserved on all 4 nodes, a smoke write committed, and rollback copies were kept. Its first new decision's COMMIT and PREPARE certificates and AuthorizationCertificate verify on all 4 nodes. Its first two decisions predate certificates, so its history cannot be verified from genesis, and its API is not publicly reachable.
Not production in the business sense: no customer traffic, same-operator infrastructure, no third-party review. What changed: cain_agi_control_boundary.ControlBoundary.submit_proposal() — the one pipeline here that calls MCPGateLastMileEnforcer (in-flight parameter-mutation defense) after issuing a signed Proof-Carrying Decision — was fully built and tested but reachable only from pytest before today; grepped every live route file for a reference and found none. Now live at /fabric/agi/propose (auth-gated, execution scoped to a small registered sandbox tool set).
cain_agent_trust_passport.py, composing existing identity attestation, evidence-backed trust state, and capability-delegation-chain verification into one signed artifact; fails closed rather than fabricating a trust score."state_transfer_implemented": false in every rejoin-stage result regardless of actual outcome. The protocol is real; the field now reflects a live probe instead of a constant.Restart=always. Still open: multi-node BFT rejoin certification has not passed the full pipeline, and most of the larger "autonomous agency" roadmap this codebase is periodically asked to build remains intentionally unbuilt.
Doctrine: COMPROMISED COGNITION ≠ COMPROMISED AUTHORITY ≠ COMPROMISED WORLD STATE — Consequential autonomy is continuously bound, observable, cryptographically evidenced, independently verifiable, and recoverable from cognition through real-world effect.