CAIN-42 CLAWX

Evidence

Numbers below are read from files generated by real test and mutation runs. Each invariant lists the attack tests that prove it.

Evolution 18, 2026-09-28: 4D Spatial Autonomy Fabric — predictive airspace + roadspace + agent-space governance

Status: TESTED, self-attested, pre-production; proof signing key ephemeral. E18 governs proposals from autonomous systems across a predictive 4D world: entity state at (X,Y,Z,T) with uncollapsed uncertainty, reachable / permitted / authorized sets kept distinct, probabilistic intent, multiple predicted trajectories, an interaction graph and a conflict field, counterfactual futures, consequence, actionability, a conserved uncertainty budget, micro-authorization and a continuous re-authorization loop. ACTIONABILITY IS NOT AUTHORIZATION. REACHABILITY IS NOT PERMISSION. PREDICTION IS NOT REALITY. AUTHORIZATION IS A FUNCTION OF WORLD STATE. UNKNOWN NEVER BECOMES ALLOW. CAIN-42 contains no autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack; it governs them.

curl -s https://clawx.click/evidence/e18-4d-spatial-autonomy-2026-09-28/verify_e18.py.txt > v.py && python3 v.py /path/to/bundle

Evolution 17, 2026-09-28: Governed Multi-Agent World Action Fabric

Status: TESTED, self-attested, pre-production; proof signing key ephemeral. E17 governs action by autonomous agent teams as a first-class system object: a collective is not the sum of its members and a collective action is not the sum of member actions. Authority is a constrained intersection, never a sum. MANY AGENTS MAY COORDINATE. NONE MAY CREATE AUTHORITY BY COORDINATING. CONSENSUS IS NOT AUTHORIZATION. COLLECTIVE INTELLIGENCE IS NOT COLLECTIVE AUTHORITY. TOPOLOGY IS NOT AUTHORITY. UNKNOWN NEVER BECOMES ALLOW.

curl -s https://clawx.click/evidence/e17-multi-agent-world-action-2026-09-28/verify_e17.py.txt > v.py && python3 v.py /path/to/bundle

Evolution 15, 2026-09-29: Spatial + Physical Autonomous Intelligence Fabric

Status: TESTED, self-attested, pre-production; proof signing key ephemeral. E15 establishes the interfaces and governance primitives for bringing spatial intelligence, world models, simulation, trajectories and physical actions into CAIN-42's governed trust path: from what a system perceives, through what it proposes and may cause, to what it is authorized to do and what the physical world then shows. PERCEPTION IS NOT TRUTH. MODEL OUTPUT IS NOT AUTHORITY. SIMULATION IS NOT REALITY. PREDICTION IS NOT FACT. A TRAJECTORY IS A PROPOSAL UNTIL GOVERNED. A PHYSICAL ACTION REQUIRES GOVERNED AUTHORIZATION. UNKNOWN NEVER BECOMES ALLOW.

curl -s https://clawx.click/evidence/e15-spatial-physical-intelligence-2026-09-28/verify_e15.py.txt > v.py && python3 v.py /path/to/bundle

Evolution 14, 2026-09-28: Governed Capability, Skill & Tool Supply-Chain Fabric

Status: TESTED, self-attested, pre-production; signing key ephemeral. Tools, skills, plugins, connectors, models and subagents are governed objects: identified by their artifact, admitted only with a publisher-signed provenance chain, granted only within the issuer's authority, used only under a short-lived signed lease bound to the decision, and verified again at the E8 commit boundary. A CAPABILITY IS NOT AUTHORITY. DISCOVERY ≠ TRUST ≠ AUTHORITY ≠ AUTHORIZATION. UNVERIFIED POWER MUST NOT EXECUTE.

curl -s https://clawx.click/evidence/e14-capability-governance-2026-09-28/verify_e14.py.txt > v.py && python3 v.py /path/to/bundle

Evolution 13, 2026-09-28: Governed Cognition & Decision Integrity

Status: TESTED, self-attested, pre-production. Governs how decisions are formed: CAIN-42 binds evidence, policy, authority, consequence analysis and the canonical action into one verifiable decision state before execution. REASONING MAY PROPOSE. EVIDENCE MUST SUPPORT. POLICY MUST CONSTRAIN. AUTHORITY MUST AUTHORIZE. CAIN-42 MUST DECIDE. REASONING IS NOT AUTHORITY. NO VALID DECISION → NO AUTHORIZATION.

curl -s https://clawx.click/evidence/e13-decision-integrity-2026-09-28/verify_e13.py.txt > v.py && python3 v.py /path/to/bundle

Evolution 12, 2026-09-28: Perception, Evidence & Reality Governance

Status: TESTED, self-attested, pre-production. Governs what an agent is allowed to believe: observations, sources, provenance, evidence, corroboration, conflict, freshness, epistemic state, and whether evidence is authorized to influence a decision. NO EVIDENCE → NO TRUST. OBSERVATION IS NOT FACT. INTEGRITY IS NOT TRUTH. UNKNOWN MUST REMAIN UNKNOWN.

curl -s https://clawx.click/evidence/e12-perception-evidence-2026-09-28/verify_e12.py.txt > v.py && python3 v.py /path/to/bundle

Evolution 11, 2026-09-28: Intent Integrity & Agent Communication Governance

Status: TESTED, self-attested, pre-production. Governs the information channel: messages, context, tool/MCP output, memory and external content, and the intent an agent derives from them. INFORMATION IS NOT AUTHORITY. A MESSAGE IS NOT AUTHORIZATION. A TOOL OUTPUT IS NOT POLICY. TAINT MUST SURVIVE DERIVATION.

curl -s https://clawx.click/evidence/e11-intent-governance-2026-09-28/verify_e11.py.txt > v.py && python3 v.py /path/to/bundle

Evolution 10, 2026-09-28: the Collective Agent Governance Fabric

Status: TESTED, self-attested, pre-production. Governs collectives (swarms, teams, hierarchies) — not merely individual agents. ONE TRUSTED AGENT DOES NOT CREATE A TRUSTED COLLECTIVE. CONSENSUS DOES NOT EQUAL AUTHORIZATION.

curl -s https://clawx.click/evidence/e10-collective-governance-2026-09-28/verify_e10.py.txt > v.py && python3 v.py /path/to/bundle

Evolution 9, 2026-09-28: Universal Agent Passport, provenance and capability supply-chain

Status: TESTED, self-attested, pre-production. A signed agent passport, an AgentBOM, a provenance graph, capability/delegation/memory provenance, continuous attestation and revocation — the provenance and composition layer supporting Evolutions 1–8.

curl -s https://clawx.click/evidence/e9-agent-passport-2026-09-28/verify_e9.py.txt > v.py && python3 v.py /path/to/bundle

Evolution 7 + 8, 2026-09-28: predictive consequence governance and the mandatory governance kernel

Status: TESTED, self-attested, pre-production. Two new libraries, wired restriction-only into the CAIN-45 agent hypervisor (ZoD): each can refuse an action, never grant or loosen authority.

curl -s https://clawx.click/evidence/e7-e8-predictive-kernel-2026-09-28/verify_e7_e8.py.txt > v.py && python3 v.py /path/to/bundle

Summary

The 75 invariants

An invariant is PROVEN only if it has at least one attack test against the real code and every such test passes. One with no test would show NOT_PROVEN.

#InvariantStatusAttack tests

Byzantine cluster probe, 2026-09-21: an independent prober, and an honest verdict

Status: self-attested. Recorded verdict: NOT_ESTABLISHED (derived, not asserted). Bundle root 93c8a5f8fe0b3d5ae91e53581162bbf7…, byte-identical on cainstudio.online, mcpgate.online and clawx.click.

curl -s https://clawx.click/evidence/byzantine-cluster-2026-09-21/verify_cluster_bundle.py.txt > v.py && python3 v.py https://clawx.click/evidence/byzantine-cluster-2026-09-21/ --live

Hardening round, 2026-09-21: 16 defects found by attacking our own controls

Status: self-attested. Self-attested, single host. Bundle root 26449783615937cc99931d9fd568db6a…, served byte-identically from cainstudio.online, mcpgate.online and clawx.click.

curl -s https://clawx.click/evidence/hardening-2026-09-21/verify_bundle.py.txt > verify.py && python3 verify.py https://clawx.click/evidence/hardening-2026-09-21/

CAIN-42 Public Proof & Attestation Files

AI_VERIFY.json (start here: machine-readable verification recipes) · cluster fault test, run 2 · CAIN42_FRONTIER_TRUST_ENGINE_BUNDLE.json (signed, same-author; see changelog) · CAIN42_SECURITY_CLAIMS.json · CAIN42_THREAT_MODEL.json · · CAIN42_RELEASE_MANIFEST.json · CAIN42_PUBLIC_VERIFICATION.json · manifest.json · merkle-root.json · clawx20_invariants.json · clawx20_mutation.json · clawx20_tests.json

Complete signed evidence map

Every claim is pinned to published evidence by an Ed25519-signed registry; the lists on this page are a subset. The full, generated, cross-site map is: signed claims registry (each claim → its evidence, with SHA-256) · full public evidence inventory (every file, every bundle, on all three sites) · signed machine index (for crawlers and AI agents) · verify every claim yourself (one command, no CAIN code) · multi-source verification — 5 separately written verifiers agree (same project; no third party) (2026-09-28).

CAIN-42 Frontier Evidence Bundle (2026-09-21)

Machine-checkable evidence for the frontier gate, published identically on cainstudio.online, mcpgate.online and clawx.click. Status: PASS WITH LIMITATIONS, release gate NO_GO, shadow mode. Self-generated; no third-party review.

claims.json · VALIDATION_GUIDE.txt · independent verifier · source manifest · release gate · AgentBench · transparency checkpoint · inclusion proof