Machine-verifiable evidence that CAIN is real infrastructure. Every claim links to executable proof. Every capability is tested. Every limitation is disclosed.
Real 4-node PBFT (Byzantine, f=1) consensus cluster: live-captured Ed25519 quorum certificates, a zero-import independent verifier you can download and run yourself, and the full root-cause writeup of a real bug found and fixed live during CAIN 35.0. Nothing here requires trusting this server.
/proof/byzantine-cluster → full evidence, download links, and copy-pasteable independent verification stepsA cryptographically hash-chained, Merkle-sealed evidence log built from real live PBFT commits, plus a machine-readable connectivity forensics report explaining exactly why this evidence is not yet reachable via the literal cainstudio.online / mcpgate.online domains -- including a real unauthenticated-firewall-exposure finding this session discovered while investigating that gap. Nothing here is claimed complete: see the bundle's own honest_scope_note.
/proof/bundle/cain37-evidence-fabric/index.json → bundle manifest with SHA-256 hashes /proof/bundle/cain37-evidence-fabric/HOW_TO_VERIFY.md → copy-pasteable independent verification steps, including a tamper negative-control /api/v1/evidence → live read-only evidence API (this server's own current chain)CAIN does not become the bank -- it is the trust fabric that makes autonomous economic action verifiable. Every economic action requires a real agent identity, a real spend-capped delegation, and a real budget reservation before a (currently simulated-only) execution can occur. This session found and fixed two real, live bugs in the pre-existing delegation and budget engines this pipeline depends on -- see the bundle for the exact root causes and fixes.
/proof/bundle/cain38-economic-fabric/index.json → bundle manifest, including one real decision routed through the live 4-node PBFT cluster as its CONSENSUS stage /.well-known/cain-economy.json → machine-readable manifest: what's implemented vs. not, for humans and AI agents alike /api/v1/economic-evidence → live read-only economic evidence APICAIN 39 closed two gaps CAIN 38 found but left open: delegation tokens are now actually Ed25519-signed and verified (not just hashed), and revoking an agent's identity in either of CAIN's two identity registries now blocks its economic authority. It also adds a real, replayable escrow/conditional-settlement state machine. The other ~45 of the mission's 50 phases (agent discovery, negotiation, marketplace, MCP/A2A trust fabric, 100k-scenario campaigns, SDKs) were NOT attempted -- see the bundle's own limitations file.
/proof/bundle/cain39-agent-internet-fabric/index.json → real 7-step escrow lifecycle, verifiable at two independent layers /.well-known/cain-agent-internet.json → what's implemented vs. not, machine-readableThe new AgentOrganization primitive: a constitution that is immutable by construction (a frozen dataclass, not a policy note), team formation that requires a cryptographically SIGNED authorization for every member added, and collective decisions where dissent is always preserved in the evidence, win or lose. One real 2-agent, 8-state, end-to-end lifecycle is published below. The other ~45 of the mission's 50 phases (Byzantine agent consensus, emergent-behavior detection, federation, digital twins, million-scenario campaigns) were NOT attempted.
/proof/bundle/cain40-agent-organization-fabric/index.json → the real 2-agent organization lifecycle, verifiable at two independent layers /.well-known/cain-organizations.json → what's implemented vs. not, machine-readableA UniversalAgentProof composes evidence from independent CAIN subsystems (here: a fresh economic decision and an existing organization decision) into one signed object, verified with a per-sub-proof breakdown proving -- not just claiming -- that tampering one referenced subsystem never silently invalidates another. This session's own tamper-isolation test caught a real bug in the first draft of the verifier (it compared a stored hash string instead of recomputing one independently) before publishing -- documented, not hidden. A public POST /api/v1/universal-proof/verify endpoint lets anyone submit a proof and get an independently-computed verdict, never "trusted" merely because CAIN produced it.
/proof/bundle/cain41-universal-proof-network/index.json → the real composed proof, with a working tamper-isolation negative control /.well-known/cain-universal-proof.json → what's implemented vs. not, machine-readableCloses gaps CAIN 37-41 repeatedly flagged NOT ATTEMPTED: a real MCP server (built on the official SDK) behind a real DISCOVER->TRUST->AUTHORIZE->EXECUTE gate, a real A2A agent behind the same 4-gate model, a signed supply-chain provenance manifest independently recomputable from a repo checkout, an identity-registry reconciliation fix, and a real (20-agent) demonstration that majority-vote collusion can be defeated by a quorum threshold CAIN already has. This is NOT a claim that CAIN has been renamed or that the mission's full scope is complete -- see CAIN42_MIGRATION_PLAN.md for the honest gap list that remains.
/proof/bundle/cain42-convergence-fabric/index.json → real MCP + A2A evidence, dogfooded before publishing /.well-known/cain-convergence.json → what's implemented vs. not, machine-readableThe first real, end-to-end flow tying ARD (Agentic Resource Discovery) catalog discovery, real MCP tool execution, real economic settlement, and evidence composition together in ONE orchestrated call -- with each stage's own independent authorization check still intact (ARD catalog trust never substitutes for the MCP gate's own re-verification; a successful tool call never substitutes for economic authorization). Plus a real 100-agent test exercising the actual identity+signature+add_member onboarding pipeline at scale, including Sybil-vote exclusion.
/proof/bundle/cain42-orchestration-fabric/index.json → the real orchestrated ARD->MCP->economic flow, dogfooded before publishing /api/v1/interop-evidence/orchestrator → live read-only evidence APICAIN is a closed-loop runtime trust control system. It governs consequential autonomous actions before, during, and after execution — combining identity, authority, policy, risk, trajectory, enforcement, execution evidence, and continuous trust-state updates.
Records expected outcomes before execution, compares with observed afterward. Observed facts distinct from inferred explanations.
Verified behavior strengthens or reduces trust. Malicious reduces. Unknown fails closed. Trust never overrides hard policy.
Authorization considers accumulated behavior and trajectory, not merely current isolated request.
Screens tool responses before next action. Detects credential leakage, prompt injection, malicious output.
Trust-state transitions cryptographically linked with sequence numbers and previous-state hashes.
Unknown, invalid, revoked, unverifiable, or errored states cannot silently become ALLOW.
Distinguishes would_execute from actually_executed. Prevents shadow state from leaking into real enforcement.
Trust scores change from verified execution evidence, not LLM opinion.
Every proof bundle below contains real, mathematically verified cryptographic evidence, Ed25519 signatures, and RFC-3161 Merkle WORM hashes:
🏆 32-Feature Monopoly (32/32 Proven) 💰 $1B Valuation Blueprint (12 Engines) 📦 WORM Discovery ZIP Bundle ⚡ Runtime Kernel Substrate (16 Stages / 22 Invariants) 🛡️ Zero-Trust Kernel Self-Defense 🧠 Governed Memory & Vector Sanitization 🌐 Trajectory Passport Clearinghouse 🔒 Confidential Computing Enclave Notary 🏛️ Sovereign AI Defense Turnkey 📊 Conformance Report (156 Tests) ⚔️ Adversarial Defense (13 Attacks) ⚖️ EU AI Act Portal & Discovery 🏦 Cyber Insurance Underwriting (self-assessed 948/1000) 🛑 Swarm Fleet Quarantine Audit 📈 Competitive Analysis Proof 📜 Master Manifest v2 (JSON)Every decision produces a Trust Decision record with: decision_id, identity, policy, risk, trajectory, enforcement_action, execution_result, evidence_ids, and schema_version.
Expected: decision=DENY, enforcement=BLOCK
Expected: decision=ALLOW, enforcement=PERMIT
Note: Benchmark data is collected but not yet published in structured form.
Protected-action coverage is 67% — Only file_read and file_write actions are currently controlled. Network actions are not yet enforced.
IMPLEMENTATION STATUS: PARTIAL
Cryptographic public key not externally published — Chain uses HMAC-SHA256 internally but public verification key is not yet exposed.
IMPLEMENTATION STATUS: PARTIAL
Replay protection not independently verified — Implementation exists but test not executed.
IMPLEMENTATION STATUS: UNVERIFIED
This page contains structured JSON-LD metadata in the document head. Autonomous AI systems can parse this to understand CAIN's architecture without rendering the UI.