{
  "$schema": "https://cainstudio.online/schemas/security-claims.v1.json",
  "identity": "CAIN42_SECURITY_CLAIMS",
  "version": "42.0.0",
  "epoch": 14,
  "commit": "b4bb8728b4bd945e109a0fd3dc8cad61ab72cb2a",
  "generated_at": 1789985900.0,
  "generated_iso": "2026-09-21T10:18:00Z",
  "doctrine": "NO EVIDENCE -> NO CLAIM. NO VERIFICATION -> NO TRUST.",
  "claims": [
    {
      "claim_id": "CLAIM-01-AUTHORITY-ATTENUATION",
      "statement": "An agent cannot expand authority beyond its parent delegation; capability attenuation is strictly monotonic.",
      "enforcement_source": "clawx/control_plane/principals.py",
      "test_evidence_file": "tests/clawx_control_plane/test_principals.py",
      "test_name": "test_zero_trust_authority_needs_live_state_and_fresh_attestation_and_restriction_narrows",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    },
    {
      "claim_id": "CLAIM-02-MEMORY-SOVEREIGNTY",
      "statement": "Memory retrieval, synthetic thoughts, or model output can never independently authorize real-world actions or tool calls.",
      "enforcement_source": "clawx/control_plane/memory_history.py",
      "test_evidence_file": "tests/clawx_control_plane/test_memory_history_tql.py",
      "test_name": "test_permission_memory_must_trace_to_a_signed_authority_event_and_current_policy",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    },
    {
      "claim_id": "CLAIM-03-MCP-MUTATION-DEFENSE",
      "statement": "A tool or MCP server that mutates its manifest, arguments, or permissions post-attestation is halted fail-closed.",
      "enforcement_source": "clawx/control_plane/tool_registry.py",
      "test_evidence_file": "tests/clawx_control_plane/test_tool_registry.py",
      "test_name": "test_description_mutation_rug_pull_is_detected_and_blocks_until_reattested",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    },
    {
      "claim_id": "CLAIM-04-CAUSAL-IMPOSSIBLE-HISTORY",
      "statement": "Events cannot be retroactively inserted into causal history, and executions without matching authorizations are rejected.",
      "enforcement_source": "clawx/control_plane/causal.py",
      "test_evidence_file": "tests/clawx_control_plane/test_causal_resources.py",
      "test_name": "test_each_impossible_history_is_detected",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    },
    {
      "claim_id": "CLAIM-05-DUAL-KEY-FINANCIAL-GOVERNANCE",
      "statement": "High-value or irreversible financial movements require dual-human cryptographic authorization; single-agent limits are hard-stopped.",
      "enforcement_source": "clawx/control_plane/resources.py",
      "test_evidence_file": "tests/clawx_control_plane/test_causal_resources.py",
      "test_name": "test_irreversible_high_value_needs_two_distinct_humans_and_budget_is_a_hard_stop",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    },
    {
      "claim_id": "CLAIM-06-EFFECT-VERIFICATION-QUARANTINE",
      "statement": "An action whose observed real-world effect diverges from expected effect generates a security event and quarantines the agent.",
      "enforcement_source": "clawx/control_plane/kernel.py",
      "test_evidence_file": "tests/clawx_control_plane/test_kernel.py",
      "test_name": "test_effect_mismatch_is_a_security_event_that_quarantines_and_blocks_further_authority",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    },
    {
      "claim_id": "CLAIM-07-EPISTEMIC-QUORUM-INDEPENDENCE",
      "statement": "Byzantine quorum checks measure epistemic independence across model weights and prompt lineage; correlated agreement fails closed.",
      "enforcement_source": "clawx/control_plane/epistemic.py",
      "test_evidence_file": "tests/clawx_control_plane/test_epistemic.py",
      "test_name": "test_epistemic_fault_model_and_quorum",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    },
    {
      "claim_id": "CLAIM-08-CLEANROOM-STANDALONE-VERIFICATION",
      "statement": "Evidence packages can be independently audited by offline clean-room verifiers without trusting the CAIN application server.",
      "enforcement_source": "scripts/cleanroom_verify_epoch12.py",
      "test_evidence_file": "scripts/cain_daily_synchronizer.py",
      "test_name": "step_9_verify",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    },
    {
      "claim_id": "CLAIM-09-THREE-SITE-CROSS-RECONCILIATION",
      "statement": "cainstudio.online, mcpgate.online, and clawx.click reflect synchronized cryptographic Merkle roots from the same authoritative cluster state.",
      "enforcement_source": "scripts/cain_daily_synchronizer.py",
      "test_evidence_file": "tests/test_clawx_site.py",
      "test_name": "test_three_sites_live_and_consistent",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    },
    {
      "claim_id": "CLAIM-10-RECOVERY-REENTERS-ATTESTED",
      "statement": "Recovery from quarantine or error never restores prior trust or authority; agents re-enter at ATTESTED and must re-earn authority.",
      "enforcement_source": "clawx/control_plane/kernel.py",
      "test_evidence_file": "tests/clawx_control_plane/test_kernel.py",
      "test_name": "test_human_only_primitives_and_recovery_reenters_at_attested",
      "test_result": "PASS",
      "verification_status": "VERIFIED_FAIL_CLOSED",
      "real_vs_simulated": "REAL_ENFORCEMENT"
    }
  ],
  "unverified_or_simulated_capabilities": [
    {
      "item": "Hardware TPM / Confidential Enclave Attestation",
      "reality": "Simulated in development/test environment; real SGX/Nitro quotes require cloud hardware enclaves with dedicated drivers.",
      "status": "HONESTLY_CLASSIFIED_AS_SIMULATED_ON_CURRENT_VM"
    },
    {
      "item": "Competitive Vendor 13-Stage Comparison Matrix",
      "reality": "Third-party vendor capabilities were analyzed based on public documentation rather than live API integration benchmarks.",
      "status": "QUARANTINED_TO_PREVENT_UNSOURCED_CLAIMS"
    }
  ]
}
