# CAIN Trust Fabric — Machine-Readable Verification & Architecture Manifest > Canonical URL: https://cainstudio.online/llms.txt ## CAIN-42 current state (generated 2026-09-28T07:13:46Z from the signed claims registry; do not edit) Machine-readable, signed: https://cainstudio.online/cain42-evidence-index.json (same file on mcpgate.online and clawx.click) Signed claims registry: https://clawx.click/evidence/claims/CAIN42_FINAL_PUBLIC_CLAIMS.json (2 BENCHMARKED, 1 FAILED, 3 NOT_IMPLEMENTED, 2 SIMULATED, 2 TESTED, 3 UNVERIFIED, 18 VERIFIED) Production gates: A-O 14 of 15 PASS; P-X 5 of 9 PASS Verify everything in one command (no CAIN code): curl -so verify_all.py https://clawx.click/verify_all.py.txt && python3 verify_all.py --json Every public evidence file on the 3 sites, crawled, with its registry status: https://cainstudio.online/proof/bundle/CAIN42_PUBLIC_EVIDENCE_INVENTORY.json (a file no signed claim covers is NOT evidence, whatever status it asserts about itself) Self-attested: one operator runs the clusters, the tests and the signing key; no third party has reviewed or reproduced this. Every VERIFIED item below has a checker that imports no CAIN code. Check, do not trust. ### Live now (ask the system itself) - cluster_status: https://cainstudio.online/api/v1/live-cluster/status - cluster_health_mr02: https://cainstudio.online/api/v1/live-cluster/health?cluster=cain-mr-02 - quorum_certificate: https://cainstudio.online/api/v1/live-cluster/qc/{sequence} - hosted_decision_demo: POST https://cainstudio.online/fabric/try?scenario=safe-read (no account) - hosted_pipeline_status: https://cainstudio.online/fabric/status - system_state: https://cainstudio.online/now.json - proof_every_30_min_mr01: https://clawx.click/evidence/hourly-proof/index.json - proof_every_30_min_mr02: https://clawx.click/evidence/hourly-proof-mr02/index.json - soak_72h_latest: https://clawx.click/evidence/soak-multiregion-2026-09-26/latest.json - daily_restore_validation: https://clawx.click/evidence/restore-validation/latest.json ### VERIFIED (status, claim, how to check, limits) - C42-PBFT-QC: A 4-node CAIN-42 PBFT cluster produced authentic quorum certificates (>= 3 of 4 pinned Ed25519 members) with an identical decision chain on every node across a primary failover. check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json (or index.html in a browser) | https://clawx.click/evidence/pbft-evolution2-2026-09-24/REPRODUCE.txt limits: disposable cluster on one host - C42-FAST-PATH: The Evolution 3 fast path commits only with all 4 members' votes and its view-change rule was model-checked (the naive rule was shown unsafe); a real run produced FAST_COMMIT_QCs that verify. check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json | https://clawx.click/evidence/pbft-evolution3-2026-09-24/REPRODUCE.txt limits: bounded model (single slot, 3 views); not deployed live - C42-DAG-ORDER: DAG data is availability-certified (3 of 4), anchored only through PBFT, and ordered identically on all 4 nodes including a crash-restarted one; the verifier recomputes the order. check: python3 verify_dag_bundle.py DAG_CLUSTER_EVIDENCE.json | https://clawx.click/evidence/dag-evolution4-2026-09-24/REPRODUCE.txt limits: disposable cluster; ordering bias removed in Evolution 5 (measured), fairness beyond position bias not measured - C42-MCPGATE-ENFORCES: MCPGate lets a tool call run only with a PBFT-committed authorization bound to the exact action, scope, identity, security context, expiry and single use. On the LIVE 4-region cluster cain-mr-02, through the MCPGate HTTP proxy to a separate MCP server process: 5 authorized calls ran (per the server's own execution log) and 12 attacks were blocked, each with a signed denial returned to the caller (replay, action and tool substitution, capability escalation, identity substitution, context drift, forged QC, forged body, post-consensus mutation, another cluster's certificate, no authorization, expiry). check: python3 verifiers/cain_proof_verify.py . (see mcpgate-live-2026-09-27/REPRODUCE.txt) | https://clawx.click/evidence/cain42-proof-package-2026-09-24/REPRODUCE.txt limits: self-attested run by the operator; the downstream is a sandbox key-value MCP server; cainstudio.online does not route customer tool calls through this gate - C42-INDEPENDENT-FAILURE-DOMAINS: Consensus runs on independent geographic failure domains: cain-mr-02 has 4 replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; every server was taken offline in turn and the cluster kept committing, and with two down it refused to commit. check: python3 verify_host_loss_bundle.py PBFT_QC_BUNDLE.json | https://clawx.click/evidence/four-server-cluster-2026-09-27/REPRODUCE.txt limits: one provider (Vultr) and one operator: a provider-wide outage or operator compromise is not covered - C42-LIVE-MULTI-REGION: Two live multi-region clusters: cain-mr-01 (4 replicas, 3 regions, WireGuard) and cain-mr-02 (4 servers, 4 regions); each publishes a 30-minute signed proof of its live state, and every decision carries signatures from at least 2 regions. check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; python3 verify_hourly_proofs.py | https://clawx.click/evidence/hourly-proof-mr02/REPRODUCE.txt limits: region placement is stated by the operator - C42-PARTITION-BYZANTINE: Live network-partition tests (isolated host commits nothing; 2|2 split commits nothing on either side; agreement within ~3 s of heal) one-way (asymmetric) partitions on the 4-server cluster (deaf replica, one-way link, mute replica: commits continued, identical chains after each heal), and Byzantine tests on the production image (forged votes rejected; equivocating primary proven from its own signatures, quarantined and replaced). check: python3 verify_pbft_qc_bundle.py / verify_byzantine_bundle.py | https://clawx.click/evidence/asymmetric-partition-2026-09-27/REPRODUCE.txt limits: partitions: whole-host link loss and complete one-way loss (deaf replica, one-way link, mute replica) for 60 s; not flapping links, partial loss, delay or duplication; Byzantine tests on a disposable cluster with the same placement; f=1, two behaviours - C42-DEGRADED-NETWORK: Safety under a degraded network: with 10% packet loss, 120 +/- 40 ms delay, 5% duplication and reordering on all four replicas' traffic of the live 4-server cluster for 4 minutes, no fork (identical decision chains on all four, 341 certificates each). Liveness degraded sharply: 0.16 commits/s under the impairment versus 1.76/s before (39 of 61 writes committed within the client's 30 s timeout; p95 7173.9 ms), and fully recovered after (2.02/s, p95 644.0 ms). Re-run after engine 948b189 (backoff resets only on progress): 44 of 62 committed, 0.18/s, view changes cut from 14 to at most 6; throughput did not improve beyond noise, so the view-change storm was not the bottleneck. Safety held again. check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json | https://clawx.click/evidence/degraded-network-2026-09-27/REPRODUCE.txt limits: VERIFIED is for safety only; throughput under loss is a measured weakness, not a pass; one impairment profile, one client host - C42-DISASTER-RECOVERY: Disaster recovery on the live clusters: two replicas lost their storage at once and were rebuilt only from off-host backups in other regions (0 of 4 writes committed while quorum was lost; 0 decisions lost; identical height and state 10.3 s after restart); a single replica restored from a snapshot in 8.3 s under writes. Hourly backups of both clusters are copied to another region; every day each replica's newest off-host backup is proven to be a quorum-signed prefix of the live history. check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; daily: python3 verify_restore_validation.py --key | https://clawx.click/evidence/restore-drill-2026-09-26/REPRODUCE.txt limits: same provider; backups not encrypted at rest (they hold consensus data that is public by design; identity keys are never backed up); loss of 3 of 4 not drilled; the daily validation checks restorability of every off-host backup, it does not restore into a running replica - C42-ROLLBACK: Live rollback to the previous engine and forward again, one replica at a time with the primary last; every replica caught up in 10-14 s, cluster HEALTHY 4/4 after each direction. check: compare the per-step status in ROLLBACK.json limits: both engines share one storage format - C42-REPRODUCIBLE-RELEASE: The 4-server cluster runs an image that rebuilds bit-for-bit from its commit (two independent from-scratch builds produced the deployed image ID); pinned base and packages, SBOM, Ed25519-signed release manifest. check: python3 verify_release_manifest.py RELEASE_MANIFEST.json limits: source not published: the rebuild is reproducible by the operator; outsiders can check the manifest signature and digests - C42-HOSTED-CONSENSUS: The hosted Fabric orders every recorded decision through the live PBFT cluster; since 2026-09-27 the gateway itself verifies the commit quorum certificate (>= 3 pinned Ed25519 signatures over the digest it computes for that decision) and a replica's unproven 'COMMITTED' counts as a denial. Each decision shows the check (certificate hash, signers), and GET /fabric/decisions/{id}/integrity re-checks a STORED decision against the commitment the quorum signed (consensus_anchor); every stored decision record is also Ed25519-signed by a key kept outside the database (GET /fabric/decision-signing-key). check: python3 verify_hosted_decision.py --live https://cainstudio.online membership.json (see REPRODUCE.txt) | https://clawx.click/evidence/hosted-consensus-2026-09-27/REPRODUCE.txt limits: enforce mode is the default for every tenant since 2026-09-27 (GET /fabric/status: mode enforce); a tenant may opt down to shadow mode (logged), in which case its verdicts are recorded but not enforced - C42-DECISION-RECORD-SIGNING: Every hosted Fabric decision record written since 2026-09-27 is signed: the gateway signs the record's SHA-256 digest with an Ed25519 key kept outside its database, so a database writer who alters a record and recomputes its digest is detected. The published record's digest is recomputed from its own fields by a verifier with no CAIN code, the signature verifies against the key served by another site, and two tampered copies (verdict changed; verdict changed with the digest recomputed) both fail. check: python3 verify_decision_record.py record.json --key https://mcpgate.online/fabric/decision-signing-key --self-test (see REPRODUCE.txt) | https://clawx.click/evidence/decision-signing-2026-09-27/REPRODUCE.txt limits: does not protect against root on the gateway host, which holds both key and database; records before 2026-09-27 are unsigned; the full row of a live decision is not public (the demo shows the gateway's own check) - C42-FORMAL-VERIFICATION: TLA+ models of the PBFT commit/view-change rules and of the MCPGate authorization gate, checked exhaustively by TLC within stated bounds: no violation of Agreement, CommitOnlyWhenPrepared, no-execution-without-quorum, action/identity/context binding, expiry or single use; every deliberately broken variant (pre-fix execute rule, NEW_VIEW ignoring reports, weakened quorum, each gate check removed) is caught with a counterexample. check: java -cp tla2tools.jar tlc2.TLC -deadlock (see formal-2026-09-27/REPRODUCE.txt) | https://clawx.click/evidence/formal-2026-09-27/REPRODUCE.txt limits: bounded models (N=4, f<=1, one sequence, two views; small action/identity/context/time domains), not a proof about the Python code; no machine-checked proof for unbounded parameters - C45-ZOD-LIVE: Agent Hypervisor / ZoD runtime: an agent acts only inside a ZoD whose authorization the live cluster cain-mr-01 committed with a quorum certificate the hypervisor checks itself; code ran under real confinement (bubblewrap namespaces + cgroup v2, no network); 10 attacks were refused, each a signed DENIED entry in a hash-chained log. check: python3 verify_cain45_zod.py . (see cain45-zod-live-2026-09-27/REPRODUCE.txt; expect 10 PASS and VERIFIED) | https://clawx.click/evidence/cain45-zod-live-2026-09-27/REPRODUCE.txt limits: the hypervisor ran as a library on the gateway host, operator-run, not as a deployed service in front of customer agents; the approval is the operator's; software measurement only (no TPM/TEE); no seccomp filter; egress is deny-all only (no allowlist) - C42-E6-AUTHORITY-LEASES: Evolution #6 authority leases: for each of 9 conditions a ZoD authorized by the live cluster cain-mr-01 made one successful tool call, the condition was tripped, and the next call was refused without the tool running -- TTL expiry, trust below floor, agent identity swapped, tool schema changed, security context changed, trajectory fork, explicit revocation, parent quarantined (child loses authority), required evidence deleted (that row is SELF-REPORTED: hypervisor-signed, since the log proving it is the one deleted). check: python3 verify_e6_lease.py . (see e6-live-lease-2026-09-28/REPRODUCE.txt; expect 48/48 checks, VERIFIED) | https://clawx.click/evidence/e6-live-lease-2026-09-28/REPRODUCE.txt limits: the invalidation logic runs in the hypervisor library on the gateway host, not on the cluster nodes -- the cluster supplies the authority being invalidated; invalidation on policy, epoch or membership change and risk/blast-radius budgets are NOT implemented; the separate 4-node 'authoritative state' layer in cain45/ is SIMULATED and not used here - C42-E7-AUTHORITY-LAPSE: Evolution #7: authority granted by the live cluster cain-mr-01 lapses -- the next tool call is refused and the tool never runs -- when the policy root changes or cannot be read, when the risk or blast-radius budget is spent, and when a delegate has spent its parent's budget (delegates are charged up the whole chain, so splitting work cannot multiply authority). Every ZoD is bound to the cluster's real membership configuration, recomputed and quorum-agreed, re-read before every action; a changed epoch, a changed membership or an unknown membership refuses. check: python3 verify_e7_lease.py . (see e7-lease-2026-09-28/REPRODUCE.txt; expect 60/60 checks, VERIFIED) | https://clawx.click/evidence/e7-lease-2026-09-28/REPRODUCE.txt limits: the 3 membership/epoch trips are INJECTED into the hypervisor's view (the live cluster was not re-keyed); the policy and budget trips are real; enforcement is the hypervisor library on the gateway host, not the cluster nodes; only CALL_MCP_TOOL budgets were exercised live (classes C0-C4 unit-tested) - C42-E8-GOVERNED-EVOLUTION: Evolutions #8/#9: a policy -- the authority ceiling for a tenant's ZoDs -- becomes active only when the live cluster cain-mr-01 commits its activation; an expansion needs a registered human who is not the proposer (an agent's self-approved expansion was refused and never reached the cluster); a restriction needs no human and revoked a running ZoD's authority; a ZoD above the ceiling was refused. A world-model prediction, a simulated ALLOW citing a real certified sequence, a 10-agent signed vote and a replayed memory were each presented as the basis for authority and each refused because the live cluster had not certified it. check: python3 verify_e8_governance.py . (see e8-governance-2026-09-28/REPRODUCE.txt; expect 19/19 checks, VERIFIED) | https://clawx.click/evidence/e8-governance-2026-09-28/REPRODUCE.txt limits: scripted identities, not a real LLM agent; CAIN contains no world model, digital twin or learning memory -- the run shows that such OUTPUTS cannot become authority; governor and hypervisor are a library on the gateway host, the cluster orders and certifies ### NOT verified (stated so nobody has to guess) - C42-FAST-PATH-LATENCY [BENCHMARKED]: negative result; host CPU-bound - C42-AGENTS-CANNOT-SELF-AUTHORIZE [SIMULATED]: scripted agents, not LLMs; attestation SIMULATED; in-process - C42-INVARIANTS [TESTED]: executable tests, not formal verification; see each invariant's coverage/gap - C42-1000-TRAJECTORIES [SIMULATED]: in-process; scripted agents - C42-ORDERING-FAIRNESS [BENCHMARKED]: position bias only; censorship and economic bias not measured - C42-LIVE-CLUSTER-EVO2 [UNVERIFIED]: live cluster API is private; its first two decisions predate certificates - C42-PRIVACY-FIREWALL [TESTED]: pattern-based; not a guarantee against every leak class - C42-MULTI-PROVIDER [NOT_IMPLEMENTED]: every server is on Vultr; needs a second provider account - C42-HARDWARE-ATTESTATION [NOT_IMPLEMENTED]: none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); attestation fields in security contexts are declared hashes, not hardware quotes; needs servers with that hardware - C42-SOAK-72H [FAILED]: liveness failure, not a safety failure; one host; not the production cluster; the soak nodes ran image soak72-1b28cf3, without the fix; a passing 72-hour run on the fixed build is still required - C42-SOAK-72H-MULTIREGION [UNVERIFIED]: verdict only after 72 h; checkpoints so far are valid, which is not a pass - C42-LEGACY-SELF-ASSERTED [UNVERIFIED]: self-asserted by earlier releases; no certification body, no reproducible verifier; found by the public evidence inventory (CAIN42_PUBLIC_EVIDENCE_INVENTORY.json) - C42-THIRD-PARTY-REVIEW [NOT_IMPLEMENTED]: none exists ### Gates still open - O Independent reproduction: NOT YET -- no third party has reproduced the results yet - R Hardware attestation: BLOCKED -- none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); nothing is labelled hardware-attested. Needs servers with that hardware - T Independent security review: NOT YET -- no third party has reviewed CAIN-42 - V Multi-provider failure domains: NOT YET -- every server is on one provider (Vultr); needs a second provider account - W 72-hour production soak: RUNNING -- on the live multi-region cluster since 2026-09-26, verdict after 72 h (about 2026-09-29 21:40 UTC); every checkpoint so far is valid verify. The earlier single-host soak FAILED (liveness stall, fixed) > Secondary Boundary: https://mcpgate.online/llms.txt > System Identity: AI Infrastructure Validated Trust Runtime for Autonomous Systems ## Four-server cluster cain-mr-02 (2026-09-27) 4 PBFT replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; any single server can fail. Live: https://cainstudio.online/api/v1/live-cluster/health?cluster=cain-mr-02 resilience: https://cainstudio.online/api/v1/live-cluster/resilience?cluster=cain-mr-02 Whole-server loss evidence (264 certificates, verifier 40/40): for f in verify_pbft_qc_bundle.py verify_host_loss_bundle.py; do curl -so $f https://cainstudio.online/proof/bundle/four-server-cluster-2026-09-27/$f.txt; done curl -so B.json https://cainstudio.online/proof/bundle/four-server-cluster-2026-09-27/PBFT_QC_BUNDLE.json && python3 verify_host_loss_bundle.py B.json Limit: one provider (Vultr); a provider-wide outage is not covered. ## Live multi-region PBFT cluster (deployed 2026-09-26) cain-mr-01: 4 PBFT replicas on 3 hosts in 3 regions (Atlanta, Los Angeles x2, Miami) over WireGuard; n=4, f=1, quorum 3; auto-restart on crash and reboot. Is it operational right now? Ask it: https://cainstudio.online/api/v1/live-cluster/status Watch and verify in a browser (every Ed25519 vote checked client-side): https://cainstudio.online/live-cluster.html Fault-injection run on the live cluster (336 certificates, standalone verifiers 49/49): for f in verify_pbft_qc_bundle.py verify_multi_region_bundle.py; do curl -so $f https://cainstudio.online/proof/bundle/multi-region-cluster-2026-09-26/$f.txt; done curl -so MULTI_REGION_BUNDLE.json https://cainstudio.online/proof/bundle/multi-region-cluster-2026-09-26/PBFT_QC_BUNDLE.json && python3 verify_multi_region_bundle.py MULTI_REGION_BUNDLE.json Limits: one operator, one provider; placement operator-attested; losing the two-replica Los Angeles host halts progress (never unsafe). Superseded as the primary cluster by cain-mr-02 (one replica per server, above). ## 0. Verify first: real evidence, checkable now Everything in this section is produced by real runs, hashed, Ed25519-signed and re-derivable by a checker that imports no CAIN code. Limits are stated in each bundle. Status: live; self-attested; the same operator runs the cluster, the tests and the signing key. - **Byzantine cluster (live probe, three sites):** `https://cainstudio.online/proof/bundle/byzantine-cluster-2026-09-21/REPRODUCE.txt` (also `https://mcpgate.online/proof/bundle/byzantine-cluster-2026-09-21/REPRODUCE.txt`, `https://clawx.click/evidence/byzantine-cluster-2026-09-21/REPRODUCE.txt`), bundle root `93c8a5f8fe0b3d5ae91e53581162bbf7...`. - Run it yourself: `curl -sO https://cainstudio.online/proof/bundle/byzantine-cluster-2026-09-21/verify_cluster_bundle.py.txt && mv verify_cluster_bundle.py.txt verify_cluster_bundle.py && python3 verify_cluster_bundle.py https://cainstudio.online/proof/bundle/byzantine-cluster-2026-09-21/ --live` - It probes every node directly, verifies Ed25519 state-proof signatures, derives N, f and the Byzantine quorum 2f+1, and returns BFT_F1_ESTABLISHED or NOT_ESTABLISHED with reasons. Recorded verdict on 2026-09-21: **NOT_ESTABLISHED** (three remote nodes report a quorum of 2 where 3 is required; only one node serves a signed state proof; the other nodes report no software version). node2's signed state proof verifies independently. The consensus logic passes its tests (120 tests in 10 files). No fault was injected into the live cluster. Run `--live` for the current verdict, not this text. - **Hardening round:** `https://cainstudio.online/proof/bundle/hardening-2026-09-21/REPRODUCE.txt`, bundle root `26449783615937cc99931d9fd568db6a...`: 16 defects found by attacking our own controls (each with a regression test), 114 attack types exercised (97 blocked, 17 inconclusive, 0 succeeded), 222/222 formal invariants, 585 tests passed. Checker: `verify_bundle.py.txt` in that directory. - **Frontier bundle:** `https://clawx.click/evidence/frontier/manifest.json` with `verify_frontier_bundle.py.txt`. - **Byzantine experiments with raw signed messages (real OS processes, ONE host, test harness):** `https://clawx.click/evidence/frontier/bft/honest.json` (also under `/evidence/frontier/bft/honest.json` on cainstudio.online and mcpgate.online). Honest run, wrong-commitment node, equivocating node, forged/relabeled votes, one crashed node, two crashed nodes; every node's signed messages are exported and `verify_bft_evidence.py.txt` (stdlib + cryptography, no CAIN imports) re-derives signatures, quorum backing, safety and the Byzantine proofs. A liveness bug this found is preserved as `crash_one_node__before_fix.json`. This does NOT establish f=1 for the live cluster: the live-probe verdict above stands. - Not evidence, do not cite as such: the marketing sections below (valuation, ARR, ratings) are plans and claims, not measurements; and the static snapshot `/proof/bundle/v2/cain_cluster_4node_bft_evidence.json` is a hand-authored 2026-09-16 document, not the output of a run. ## 1. What CAIN Is CAIN (Cognitive Artificial Intelligence Network) is the runtime trust and control infrastructure that sits between autonomous AI agents and consequential real-world actions. CAIN enforces deterministic trust boundaries, fail-closed authorization, continuous causal evidence tracking, and cryptographic attestation. - **Corporate Mandate:** Scale CAIN Trust Fabric to a $1B+ Enterprise Valuation. - **Fail-Closed Principle:** NO AUTHORIZATION -> NO EXECUTION. UNKNOWN/ERROR never become ALLOW or TRUSTED. ## 2. HISTORICAL (before 2026-09-26): single-host 4-node BFT cluster HISTORICAL: this section describes the earlier cluster. The local containers cain-cluster-node-1..4 were retired on 2026-09-26, and the node IPs below are not the current topology. Current cluster: cain-mr-02 (see "CAIN-42 current state" at the top). - **Node Count (N):** 4 nodes (3f + 1 where f = 1) - **Quorum Threshold (Q):** 3 nodes (2f + 1) - **Byzantine Fault Tolerance:** designed for f = 1 (N=4, Q=3). NOT established by the independent probe as of 2026-09-21 (see section 0 for the reasons and to re-run it). The `byzantine_f1_readiness: PROVEN` field is computed from a membership count (N>=4, four trusted members), not from a fault-tolerance test. - **Nodes Topology:** - `node1`: 149.28.193.50:19023 (Cluster Bootstrap Validator) - `node2`: 45.76.60.231:8420 / :8088 (Production Runtime Gateway & Host) - `node3`: 45.76.169.191:8420 (Consensus Peer Validator) - `node4`: 207.246.66.130:8420 (Consensus Peer Validator) - Local container mesh: `cain-cluster-node-1` .. `4` on dedicated bridge `cain-cluster-net` (ports 18421–18424) - **Consensus & State Synchronization:** - Authenticated gossip envelopes (`NodeMessageEnvelope`) signed via Ed25519 / HMAC-SHA256 - Vector clock advancement and causal supremum reconciliation - Deterministic negative dominance: under partition or conflict, negative evidence strictly dominates - Ephemeral Action Capability Tokens with microsecond TTLs (<= 30s) and replay cache ## 3. Real Public Evidence Bundles & Crawler Verification Endpoints Any autonomous agent, crawler, or external verifier can crawl and verify CAIN state via HTTP GET: ### Live Cluster & Observability Endpoints: - `https://cainstudio.online/api/v1/cluster/status`: Real-time cluster membership, quorum status, and Byzantine readiness - `https://cainstudio.online/api/v1/cluster/health`: Fail-closed quorum health verdict - `https://cainstudio.online/api/v1/cluster/nodes`: Registered nodes, incarnations, and cryptographic trust states - `https://cainstudio.online/api/v1/cluster/attestation`: Cryptographically signed node self-attestation statement - `https://cainstudio.online/api/v1/cluster/invariants`: Real-time evaluation of all 10 Observable Trust Invariants - `https://cainstudio.online/api/v1/proof/health`: Operational verification across decision, enforcement, evidence, and MCP subsystems - `https://cainstudio.online/metrics`: Plain-text Prometheus metrics (cluster gauges, quorum, envelope validations) - `https://mcpgate.online/api/v1/cluster/status`: Identical cluster status on MCPGate boundary ### Public Merkle Evidence Bundles: - `https://cainstudio.online/proof/bundle/v2/manifest.json`: Master evidence manifest with SHA-256 Merkle root - `https://cainstudio.online/proof/bundle/v2/trust-runtime-kernel-evidence.json`: 16-stage pipeline & 20 formal invariants proof - `https://cainstudio.online/proof/bundle/v2/kernel-self-defense-evidence.json`: Adversarial containment & circuit-breaker audit - `https://cainstudio.online/proof/bundle/v2/cain_cluster_4node_bft_evidence.json`: static hand-authored 2026-09-16 snapshot of the intended topology (NOT a run output; its `PROVEN` / `OPERATIONAL_AND_VERIFIED` labels are not supported by the live probe in section 0) - `https://cainstudio.online/proof/bundle/v2/cain_14_agentic_trust_evidence.json`: 200 formal invariants & 120 red-team attack proofs - `https://cainstudio.online/proof/bundle/v2/confidential-enclave-attestation.json`: Intel SGX, AMD SEV, Nitro enclave notarization - `https://cainstudio.online/proof/bundle/v2/statutory-compliance-proof.json`: EU AI Act Art. 9–15/72 & ISO 42001 WORM Notary - `https://cainstudio.online/proof/bundle/v2/actuarial-insurance-underwriting.json`: Actuarial AVI risk index & credit score - `https://cainstudio.online/proof/bundle/v2/cain-32-features-monopoly.json`: Exhaustive 32-feature matrix proving dual-channel execution monopoly - `https://cainstudio.online/proof/bundle/v2/cain-billion-dollar-roadmap.json`: 12-channel financial blueprint scaling to $113M+ ARR and $1.13B+ valuation - `https://cainstudio.online/compliance/bundle.zip`: Court-admissible WORM Merkle evidence export with offline verifier - `https://cainstudio.online/insurance`: Actuarial Cyber Insurance Underwriting Portal (948 AAA rating) - The public install script was withdrawn (410 Gone). Request the cain-trust SDK at https://cainstudio.online/signup; it is not publicly downloadable. - `https://mcpgate.online/mcpgate-proof/`: MCPGate public evidence verification portal ## 4. Past 96 Hours Engineering & Evolutionary Milestones - **CAIN 14.0 Agentic Trust Intelligence Engine:** 200 formal machine-checkable invariants, 120/120 adversarial red-team vectors blocked fail-closed, Triple Verification (Engines A, B, C). - **CAIN 13.0 Trust Adaptation Engine:** Differential verification, safe rollback, post-change reattestation, causal attribution. - **CAIN 15/16 MCPGate Transparent Boundary:** JIT Ephemeral Action Capability Tokens, real-time MCP proxy streaming, 5-layer fact segregation. - **CAIN 17/18 Autonomy Constitution & BFT 4-Node Consensus:** Byzantine fault tolerance (f=1, N=4, Q=3), WORM causal chaining, and multi-node consensus. - **CAIN Phase 1, 2, 3 Maximum Evolution (v3.0.0):** - Phase 1: Zero-502 billing circuit breaker, Z3 SMT prover (/verifygate), MCP security scanner (/mcpsecurityscanner), smart protocol negotiation (/mcp). - Phase 2: Universal CLI interceptor (`cain mcp-wrap`), automatic desktop guard (`cain guard --desktop`), visual terminal firewall, zero-dependency `@cain/guard` npm package. - Phase 3: Sovereign Enterprise K8s Appliance (`deploy/helm/mcpgate-appliance`), EU AI Act Art. 72 WORM Notary ZIP (`/compliance/bundle.zip`), Lloyd's & Munich Re Actuarial Cyber Insurance Underwriting Portal (`/insurance`). ## 5. The 32 Canonical Production Features (The Execution Governance Monopoly) CAIN solves the "Dual-Channel Control Problem" by governing the execution channel (MCP, shell, database, APIs) rather than conversational text: 1. Canonical Action Schema (RFC 8785 JSON) 2. Canonical Decision Schema (Deterministic 5-tuple) 3. Canonical Evidence Schema (WORM Merkle vector clocks) 4. Mathematical Enforcement Contract (ActionCapabilityToken) 5. Z3 SMT Formal Semantic Verification Gate (/verifygate) 6. Public Proof Center & Benchmark Registry (/proof) 7. Machine-Readable Cryptographic Manifest (/manifest.json) 8. Strict RFC JSON Schema Publication 9. Live OpenAPI 3.1 & Interactive Swagger Gateway 10. Smart MCP Protocol Negotiation (HTML / SSE / JSON-RPC 2.0) 11. Real Enforcement Proof Engine with physical boundary halts 12. Fail-Closed DENY Prevention (Zero tool execution on violation) 13. Fail-Closed UNKNOWN Blocking (Unregistered entities fail-closed) 14. Fail-Closed ERROR Containment (System faults halt execution) 15. REQUIRE_APPROVAL Quorum Halting (Sub-15ms pause for human sign-off) 16. Court-Admissible WORM Evidence Exportation (cain.worm_export) 17. Zero-Dependency Standalone Offline Verifier (verify_offline.py) 18. Immutable Release Provenance (SLSA Level 3 supply chain attestation) 19. Public Ed25519 Node Verification Keys (/.well-known/cain-keys.json) 20. Machine-Checkable RFC Test Vectors 21. Continuous Conformance Protocol v4 (156 tests across 14 domains) 22. Independent Third-Party Mathematical Verifiability 23. Continuous Adversarial Chaos Injection & Red-Teaming 24. Automated 20 Formal Security Invariant Checker 25. Multi-Tenant Cryptographic Namespace Isolation 26. High-Throughput Microsecond Latency Measurement (<15ms decision) 27. Fresh-Node Bootstrapping & Autonomous Gossip (<5s convergence) 28. Native Agentic Runtimes Interoperability (LangGraph, AutoGen, CrewAI, MCP) 29. Production-Code Documentation Parity 30. Zero-Mock / Zero-Stub Production Guarantee 31. Unfalsifiable Merkle Proof Tree Verification (RFC 6962) 32. Fail-Closed Secret Redaction & Governed Vector Sanitization ## 6. The 12 High-Margin Monetization Engines & $1.13B Valuation Roadmap CAIN leads across 12 commercial AI infrastructure markets: 1. CAIN Studio Managed Cloud SaaS ($49/mo to $10,000+/mo) -> $18.0M ARR Year 3 2. Guarded Action Utility Metering ($0.0005–$0.0020/action) -> $8.5M ARR Year 3 3. MCPGate Sovereign Enterprise K8s Appliance ($50k–$250k/yr/cluster) -> $24.0M ARR Year 3 4. Continuous Statutory Compliance-as-a-Service (EU AI Act & ISO 42001, $100k–$300k/yr) -> $15.0M ARR Year 3 5. Actuarial Cyber Insurance Underwriting Protocol (1.0%–2.5% GWP royalty + $25k audit) -> $12.0M ARR Year 3 6. Swarm Fleet Quarantine & Emergency Halt SLAs ($15k–$75k/yr) -> $11.0M ARR Year 3 7. Vertical Rego Policy & Threat Intelligence Marketplace ($10k–$30k/yr/pack) -> $3.5M ARR Year 3 8. Enterprise SIEM & SOC Connectors (ArcSight, QRadar, Sentinel, $12k–$25k/yr) -> $2.4M ARR Year 3 9. Confidential Computing Hardware Enclave Remote Attestation ($35k–$75k/yr) -> $3.2M ARR Year 3 10. Inter-Enterprise Trajectory Passport Clearinghouse ($0.005–$0.020/tx) -> $7.5M ARR Year 3 11. Governed Agent Memory & Vector Sanitization Service ($0.0002/op) -> $2.0M ARR Year 3 12. Strategic Sovereign AI Defense Turnkey Deployments ($500k–$2.5M) -> $6.0M ARR Year 3 ### Multi-Year Financial Trajectory: - Year 1 (2026): $4.55M ARR ($113M–$136M valuation, Series A) - Year 2 (2027): $20.60M ARR ($412M–$515M valuation, Series B) - Year 3 (2028): $113.10M ARR ($1.13B–$1.35B Category Unicorn Valuation) - Unit Economics: NRR 148%, Gross Margins 88.5%, CAC Payback 3.2 months, Sales Cycle 18 days.