{
 "claim_taxonomy": {
  "categories": [
   "ARCHITECTURE",
   "SECURITY",
   "CRYPTOGRAPHY",
   "CONSENSUS",
   "BYZANTINE RESILIENCE",
   "AUTHORIZATION",
   "TRUST",
   "TRAJECTORY GOVERNANCE",
   "L5 GOVERNANCE",
   "MCP ENFORCEMENT",
   "EVIDENCE",
   "PERFORMANCE",
   "AVAILABILITY",
   "RECOVERY",
   "CHAOS",
   "SUPPLY CHAIN",
   "DEPLOYMENT",
   "COMPLIANCE"
  ],
  "rules": [
   {
    "category": "L5 GOVERNANCE",
    "pattern": "CAG-L5|L5-IDENTITY|L5-ADAPTIVE"
   },
   {
    "category": "TRAJECTORY GOVERNANCE",
    "pattern": "TRAJECTOR"
   },
   {
    "category": "MCP ENFORCEMENT",
    "pattern": "MCPGATE"
   },
   {
    "category": "PERFORMANCE",
    "pattern": "LATENCY|BENCH|FAIRNESS"
   },
   {
    "category": "CHAOS",
    "pattern": "SOAK"
   },
   {
    "category": "BYZANTINE RESILIENCE",
    "pattern": "PARTITION|BYZANTINE|FAILURE-DOMAINS|DEGRADED"
   },
   {
    "category": "RECOVERY",
    "pattern": "DISASTER|ROLLBACK|RESTORE|RECOVERY|STORAGE"
   },
   {
    "category": "CONSENSUS",
    "pattern": "PBFT|DAG|FAST-PATH|CONSENSUS|MULTI-REGION|CLUSTER"
   },
   {
    "category": "SUPPLY CHAIN",
    "pattern": "SUPPLY|RELEASE|REPRODUCIBLE-BUILD"
   },
   {
    "category": "DEPLOYMENT",
    "pattern": "HARDWARE|ATTEST"
   },
   {
    "category": "AUTHORIZATION",
    "pattern": "AGENTS|AUTHORITY|LEASE|GOVERNED|ZOD|E6|E7|E8"
   },
   {
    "category": "SECURITY",
    "pattern": "FORMAL|INVARIANT"
   },
   {
    "category": "SECURITY",
    "pattern": "PRIVACY|SECCOMP|CONFINE|SECURITY"
   },
   {
    "category": "EVIDENCE",
    "pattern": "DECISION|SIGNING|EVIDENCE|CLAIMS|LEGACY"
   },
   {
    "category": "COMPLIANCE",
    "pattern": "THIRD-PARTY|REVIEW|CERT"
   },
   {
    "category": "AVAILABILITY",
    "pattern": "PROVIDER"
   },
   {
    "category": "EVIDENCE",
    "pattern": "PROOF-FABRIC|TEST-SUITE"
   },
   {
    "category": "ARCHITECTURE",
    "pattern": "."
   }
  ]
 },
 "claims": [
  {
   "artifacts": [
    {
     "bundle": "pbft-evolution2-2026-09-24",
     "cluster_ids": [
      "cain42-pbft-qc-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "f96088a8edf710b38b3cf22a7c25dd04e2758f7ff7ae9583b8eddf4b04cb2dde"
    },
    {
     "bundle": "pbft-evolution2-2026-09-24",
     "cluster_ids": [
      "cain42-pbft-qc-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "verify_pbft_qc_bundle.py.txt",
     "sha256": "ba452ce42528f11f7f5235727a65cae25a34072bc52b4711fd72581615d06009"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-PBFT-QC",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "disposable cluster on one host",
   "public_label": "DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "A 4-node CAIN-42 PBFT cluster produced authentic quorum certificates (>= 3 of 4 pinned Ed25519 members) with an identical decision chain on every node across a primary failover.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json  (or index.html in a browser)"
  },
  {
   "artifacts": [
    {
     "bundle": "pbft-evolution3-2026-09-24",
     "cluster_ids": [
      "cain42-pbft-qc-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "43e1c61004d3d53a1f76d96f72a7241ef59793a2f77d9beda5f6b40559e9c9a4"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-FAST-PATH",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "bounded model (single slot, 3 views); not deployed live",
   "public_label": "DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "The Evolution 3 fast path commits only with all 4 members' votes and its view-change rule was model-checked (the naive rule was shown unsafe); a real run produced FAST_COMMIT_QCs that verify.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json"
  },
  {
   "artifacts": [],
   "category": "PERFORMANCE",
   "claim_id": "C42-FAST-PATH-LATENCY",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "declared: A/B benchmark on the disposable single-host cluster; no artifact published",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "negative result; host CPU-bound",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "The fast path did NOT produce a measurable latency improvement on this host (paired A/B, 95% CI includes 0).",
   "status": "BENCHMARKED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/pbft_ab_bench.py (results in the certification)"
  },
  {
   "artifacts": [
    {
     "bundle": "dag-evolution4-2026-09-24",
     "cluster_ids": [
      "cain42-dag-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "DAG_CLUSTER_EVIDENCE.json",
     "sha256": "10c08dab4e70a7a5782b9aafe92e7c88e63038085cce3a8a143abb660797bc09"
    },
    {
     "bundle": "dag-evolution4-2026-09-24",
     "cluster_ids": [
      "cain42-dag-evidence"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "verify_dag_bundle.py.txt",
     "sha256": "f544555b9275d412bdd2b459cf780d351058b3755792f44dfb7f8377a5d58fd5"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-DAG-ORDER",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "disposable cluster; ordering bias removed in Evolution 5 (measured), fairness beyond position bias not measured",
   "public_label": "DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "DAG data is availability-certified (3 of 4), anchored only through PBFT, and ordered identically on all 4 nodes including a crash-restarted one; the verifier recomputes the order.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_dag_bundle.py DAG_CLUSTER_EVIDENCE.json"
  },
  {
   "artifacts": [
    {
     "bundle": "mcpgate-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "manifest.json",
     "sha256": "8196297a5ae5ac11dc3d44f4a27618a5631699ed5d2dd40056b76eef47f66ca6"
    },
    {
     "bundle": "mcpgate-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "calls.json",
     "sha256": "d841d64bd89933e273487790396ffec5a930bf9c668348248ade276f19443cbf"
    },
    {
     "bundle": "mcpgate-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "gate_proofs.json",
     "sha256": "bbba0255296226ee3bf5d0856e49a20f6977ee5993f3d7cfdde9f45f3cf8d644"
    },
    {
     "bundle": "mcpgate-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "mcp_server_executed.json",
     "sha256": "460a1fb18f541c589126001227ec36760a7ba9db1347aa13b1cbc63125bb6747"
    },
    {
     "bundle": "cain42-proof-package-2026-09-24",
     "cluster_ids": [
      "cain42-dag-evidence",
      "cain42-proof-package"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "manifest.json",
     "sha256": "c50397779c5aed594357a3f295362b2c5c69f074fd7f096a23db2e3d995f0b26"
    }
   ],
   "category": "MCP ENFORCEMENT",
   "claim_id": "C42-MCPGATE-ENFORCES",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE",
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "self-attested run by the operator; the downstream is a sandbox key-value MCP server; cainstudio.online does not route customer tool calls through this gate",
   "public_label": "LIVE + DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "MCPGate lets a tool call run only with a PBFT-committed authorization bound to the exact action, scope, identity, security context, expiry and single use. On the LIVE 4-region cluster cain-mr-02, through the MCPGate HTTP proxy to a separate MCP server process: 5 authorized calls ran (per the server's own execution log) and 12 attacks were blocked, each with a signed denial returned to the caller (replay, action and tool substitution, capability escalation, identity substitution, context drift, forged QC, forged body, post-consensus mutation, another cluster's certificate, no authorization, expiry).",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verifiers/cain_proof_verify.py .   (see mcpgate-live-2026-09-27/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "cain42-agent-proof-package-2026-09-24",
     "cluster_ids": [
      "evo6"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "manifest.json",
     "sha256": "9ccb5e68a06d51df8c5d02e2c0fd520a627ed09333523f750a8c6f5636a9677e"
    },
    {
     "bundle": "cain42-agent-proof-package-2026-09-24",
     "cluster_ids": [
      "evo6"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "agents.json",
     "sha256": "f10ea2027694d51543995f3668b087dd87585b2df2a9f4e92bb04d0b743e0998"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-AGENTS-CANNOT-SELF-AUTHORIZE",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "scripted agents, not LLMs; attestation SIMULATED; in-process",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Agents propose; only PBFT authorizes. Plan mutation, model update or tool swap after consensus forces reauthorization; undeclared actions, impersonation, replay, forged trajectories, delegation escalation and aggregate-policy (salami) attacks are blocked.",
   "status": "SIMULATED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verifiers/cain_proof_verify.py ."
  },
  {
   "artifacts": [
    {
     "bundle": "final-2026-09-24",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_FINAL_INVARIANTS_RUN.json",
     "sha256": "cdf56006ccb193195e9ccdf765620ff78be8b67a52e4894c881368874265d2e9"
    }
   ],
   "category": "SECURITY",
   "claim_id": "C42-INVARIANTS",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "executable tests, not formal verification; see each invariant's coverage/gap",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "28 executable CAIN-42 invariants (I001-I028: no quorum -> no consensus -> no authorization -> no execution; agents, memory, DAG, delegation, trust and AI predictions cannot create authority; replay, expiry, substitution, tampering rejected) pass on the real code; 22 with full coverage, 6 partial with the gap named.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/cain42_invariants.py"
  },
  {
   "artifacts": [
    {
     "bundle": "final-2026-09-24",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E6_TRAJECTORY_LAB.json",
     "sha256": "3ad3cadaf3e820adb78731ccfcefdd336bbc3467f0573f1be74ea9d22765c460"
    }
   ],
   "category": "TRAJECTORY GOVERNANCE",
   "claim_id": "C42-1000-TRAJECTORIES",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "in-process; scripted agents",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "1,000 agent trajectories (9 kinds incl. 380 attacks) all ended as expected; all 620 allowed actions carry complete, re-verified proof chains; a 1,000-step trajectory accepted 0 stale authorizations.",
   "status": "SIMULATED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/agentic_trajectory_lab.py"
  },
  {
   "artifacts": [
    {
     "bundle": "final-2026-09-24",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E5_ORDERING_FAIRNESS.json",
     "sha256": "32204ce929ad2c04451c67be344ced464c71e9372c551a9906692771819766e6"
    }
   ],
   "category": "PERFORMANCE",
   "claim_id": "C42-ORDERING-FAIRNESS",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "position bias only; censorship and economic bias not measured",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "DAG within-round order is seeded by committed PBFT history: validator-position bias measured before (chi-square 542) and after (1.75).",
   "status": "BENCHMARKED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/dag_fairness_lab.py"
  },
  {
   "artifacts": [],
   "category": "CONSENSUS",
   "claim_id": "C42-LIVE-CLUSTER-EVO2",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "declared: about the live cain-vc cluster; its API is private, hence UNVERIFIED",
   "evidence_level": 1,
   "evidence_level_meaning": "implementation evidence",
   "limits": "live cluster API is private; its first two decisions predate certificates",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "The live cain-vc cluster runs the Evolution 2 engine (upgraded node by node, state preserved).",
   "status": "UNVERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "not publicly reachable"
  },
  {
   "artifacts": [],
   "category": "SECURITY",
   "claim_id": "C42-PRIVACY-FIREWALL",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "declared: a pattern scanner run over the published bundles",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "pattern-based; not a guarantee against every leak class",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Every published evidence bundle passes the public-evidence privacy firewall (keys, tokens, credentials, private IPs, internal URLs, server paths, source).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "scripts/cain42_bft/public_evidence_firewall.py"
  },
  {
   "artifacts": [
    {
     "bundle": "four-server-cluster-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "0ed32a92d4c58c3517679c6c0ca7c318a45960c01b5b63e7ce87db677b6a3b71"
    },
    {
     "bundle": "four-server-cluster-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "verify_host_loss_bundle.py.txt",
     "sha256": "0f26f9c82d40d9c3da44d878ee25ecfab59413475765515475a314019a15b6cf"
    }
   ],
   "category": "BYZANTINE RESILIENCE",
   "claim_id": "C42-INDEPENDENT-FAILURE-DOMAINS",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "one provider (Vultr) and one operator: a provider-wide outage or operator compromise is not covered",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Consensus runs on independent geographic failure domains: cain-mr-02 has 4 replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; every server was taken offline in turn and the cluster kept committing, and with two down it refused to commit.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_host_loss_bundle.py PBFT_QC_BUNDLE.json"
  },
  {
   "artifacts": [],
   "category": "AVAILABILITY",
   "claim_id": "C42-MULTI-PROVIDER",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "declared: a statement about the live topology (every server on one provider)",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "every server is on Vultr; needs a second provider account",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Replicas on more than one infrastructure provider.",
   "status": "NOT_IMPLEMENTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "-"
  },
  {
   "artifacts": [
    {
     "bundle": "multi-region-cluster-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "393d88099d4d62686abff3bf0da841808741717a0978626b04d34e678f35fd4b"
    },
    {
     "bundle": "hourly-proof-mr02",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "proof-000000.json",
     "sha256": "cfc616620eae2ddd7371b0393ca269edb07eb6cb704f17deea9be51d4bba9847"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-LIVE-MULTI-REGION",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "region placement is stated by the operator",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-03T03:20:13Z",
   "statement": "Two live multi-region clusters: cain-mr-01 (4 replicas, 3 regions, WireGuard) and cain-mr-02 (4 servers, 4 regions); each publishes a 30-minute signed proof of its live state, and every decision carries signatures from at least 2 regions.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; python3 verify_hourly_proofs.py <base>"
  },
  {
   "artifacts": [
    {
     "bundle": "partition-test-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "1f1d7d4a3af89f9f710aedc574a191048a5c1d7655513c185443f4135ea478c8"
    },
    {
     "bundle": "asymmetric-partition-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "3618882fe6ed8653886a92daed66009ec5d08e64c46476891f245eb70cdf97e6"
    },
    {
     "bundle": "byzantine-test-2026-09-26",
     "cluster_ids": [
      "cain-byz-01"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "940ed6cf99124c78d57d1c49f0813a5b5dc061390303a90d8a8cce646a874994"
    }
   ],
   "category": "BYZANTINE RESILIENCE",
   "claim_id": "C42-PARTITION-BYZANTINE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE",
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "partitions: whole-host link loss and complete one-way loss (deaf replica, one-way link, mute replica) for 60 s; not flapping links, partial loss, delay or duplication; Byzantine tests on a disposable cluster with the same placement; f=1, two behaviours",
   "public_label": "LIVE + DISPOSABLE CLUSTER VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Live network-partition tests (isolated host commits nothing; 2|2 split commits nothing on either side; agreement within ~3 s of heal) one-way (asymmetric) partitions on the 4-server cluster (deaf replica, one-way link, mute replica: commits continued, identical chains after each heal), and Byzantine tests on the production image (forged votes rejected; equivocating primary proven from its own signatures, quarantined and replaced).",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py / verify_byzantine_bundle.py"
  },
  {
   "artifacts": [
    {
     "bundle": "degraded-network-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "405e189d2ab18bbb435f10380174afc2db354d45f062ac4fe663ee2448f2d562"
    },
    {
     "bundle": "degraded-network-948b189-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "401686a4a9ad475a09f786d02760b8871336c3da61cc9bfd340b12d3e270f9f9"
    }
   ],
   "category": "BYZANTINE RESILIENCE",
   "claim_id": "C42-DEGRADED-NETWORK",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "VERIFIED is for safety only; throughput under loss is a measured weakness, not a pass; one impairment profile, one client host",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Safety under a degraded network: with 10% packet loss, 120 +/- 40 ms delay, 5% duplication and reordering on all four replicas' traffic of the live 4-server cluster for 4 minutes, no fork (identical decision chains on all four, 341 certificates each). Liveness degraded sharply: 0.16 commits/s under the impairment versus 1.76/s before (39 of 61 writes committed within the client's 30 s timeout; p95 7173.9 ms), and fully recovered after (2.02/s, p95 644.0 ms). Re-run after engine 948b189 (backoff resets only on progress): 44 of 62 committed, 0.18/s, view changes cut from 14 to at most 6; throughput did not improve beyond noise, so the view-change storm was not the bottleneck. Safety held again.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json"
  },
  {
   "artifacts": [
    {
     "bundle": "storage-loss-drill-2026-09-27",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "987c53f1dc8af84aa8243e08a6d0b1e3661e6d774adf53055ef91651b6bed74d"
    },
    {
     "bundle": "restore-drill-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "PBFT_QC_BUNDLE.json",
     "sha256": "94162b7304d9484402c253dcdb881bc30665150a9cd0845d213eb4f3e3a30969"
    },
    {
     "bundle": "restore-validation",
     "cluster_ids": [
      "cain-mr-01",
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "validation-2026-09-27.json",
     "sha256": "e6f9a8811e14bf880ba09ef6842a271ba89d3340932ee74e1be374bb4ed8bc8c"
    }
   ],
   "category": "RECOVERY",
   "claim_id": "C42-DISASTER-RECOVERY",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "same provider; backups not encrypted at rest (they hold consensus data that is public by design; identity keys are never backed up); loss of 3 of 4 not drilled; the daily validation checks restorability of every off-host backup, it does not restore into a running replica",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-03T03:20:13Z",
   "statement": "Disaster recovery on the live clusters: two replicas lost their storage at once and were rebuilt only from off-host backups in other regions (0 of 4 writes committed while quorum was lost; 0 decisions lost; identical height and state 10.3 s after restart); a single replica restored from a snapshot in 8.3 s under writes. Hourly backups of both clusters are copied to another region; every day each replica's newest off-host backup is proven to be a quorum-signed prefix of the live history.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; daily: python3 verify_restore_validation.py <latest.json> --key <evidence-root.pub.json>"
  },
  {
   "artifacts": [
    {
     "bundle": "rollback-drill-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "ROLLBACK.json",
     "sha256": "cdf5e71eadcdd18ff55eca385990ff7ac1f3f07e2b3f94f85641a960760a76de"
    }
   ],
   "category": "RECOVERY",
   "claim_id": "C42-ROLLBACK",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 3,
   "evidence_level_meaning": "cryptographic verification",
   "limits": "both engines share one storage format",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Live rollback to the previous engine and forward again, one replica at a time with the primary last; every replica caught up in 10-14 s, cluster HEALTHY 4/4 after each direction.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "VERIFIED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "compare the per-step status in ROLLBACK.json"
  },
  {
   "artifacts": [
    {
     "bundle": "release-cain-mr-02-948b189",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "RELEASE_MANIFEST.json",
     "sha256": "bfbfcaf45ea8622f75a459fc516803efa878bf713a5f138255e3635ffcc95f89"
    },
    {
     "bundle": "release-cain-mr-02-948b189",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "verify_release_manifest.py.txt",
     "sha256": "4353e1d0c31b2b50248c3c531ce20825f82eb90ee66223331932745719a7a0ec"
    },
    {
     "bundle": "release-cain-mr-02-521f84c",
     "cluster_ids": [
      "cain-mr-02"
     ],
     "environment": "LIVE",
     "file": "RELEASE_MANIFEST.json",
     "sha256": "284998cc743ded062fd6845933c3beec2ac75716642da3069347e0824e99eb6c"
    }
   ],
   "category": "SUPPLY CHAIN",
   "claim_id": "C42-REPRODUCIBLE-RELEASE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "source not published: the rebuild is reproducible by the operator; outsiders can check the manifest signature and digests",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "The 4-server cluster runs an image that rebuilds bit-for-bit from its commit (two independent from-scratch builds produced the deployed image ID); pinned base and packages, SBOM, Ed25519-signed release manifest.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_release_manifest.py RELEASE_MANIFEST.json"
  },
  {
   "artifacts": [
    {
     "bundle": "hosted-consensus-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "decision.json",
     "sha256": "f9e53b72eeaedfc256eb5b7b0e426321c6aaeb63c2b5ea1e54da1fba93cdf27e"
    },
    {
     "bundle": "hosted-consensus-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qc.json",
     "sha256": "4314a03ae57da8075806951a4a999d170c5215c3cd8680a3e5633f1bc22d85ba"
    },
    {
     "bundle": "hosted-consensus-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_hosted_decision.py.txt",
     "sha256": "e3a4ceff12c81987af5672cf047ab9935e0e0d95a1ec7b61bf14e39091b1f3f1"
    }
   ],
   "category": "CONSENSUS",
   "claim_id": "C42-HOSTED-CONSENSUS",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "enforce mode is the default for every tenant since 2026-09-27 (GET /fabric/status: mode enforce); a tenant may opt down to shadow mode (logged), in which case its verdicts are recorded but not enforced",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "The hosted Fabric orders every recorded decision through the live PBFT cluster; since 2026-09-27 the gateway itself verifies the commit quorum certificate (>= 3 pinned Ed25519 signatures over the digest it computes for that decision) and a replica's unproven 'COMMITTED' counts as a denial. Each decision shows the check (certificate hash, signers), and GET /fabric/decisions/{id}/integrity re-checks a STORED decision against the commitment the quorum signed (consensus_anchor); every stored decision record is also Ed25519-signed by a key kept outside the database (GET /fabric/decision-signing-key).",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_hosted_decision.py --live https://cainstudio.online membership.json  (see REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "decision-signing-2026-09-27",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "record.json",
     "sha256": "36472edfcda70ee1f29276daf3b7f7ed392ddbbce2f9b342b7b57deb4c0f59aa"
    },
    {
     "bundle": "decision-signing-2026-09-27",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "signing-key.json",
     "sha256": "e506f192a4f946518b781458d5fa9315451ec10138333fa37a86779d8c0ac016"
    },
    {
     "bundle": "decision-signing-2026-09-27",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "verify_decision_record.py.txt",
     "sha256": "78051196a7a7a7e288020d037366fad0a3c4f83c176d8b4469687c50547a64c6"
    }
   ],
   "category": "EVIDENCE",
   "claim_id": "C42-DECISION-RECORD-SIGNING",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "does not protect against root on the gateway host, which holds both key and database; records before 2026-09-27 are unsigned; the full row of a live decision is not public (the demo shows the gateway's own check)",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Every hosted Fabric decision record written since 2026-09-27 is signed: the gateway signs the record's SHA-256 digest with an Ed25519 key kept outside its database, so a database writer who alters a record and recomputes its digest is detected. The published record's digest is recomputed from its own fields by a verifier with no CAIN code, the signature verifies against the key served by another site, and two tampered copies (verdict changed; verdict changed with the digest recomputed) both fail.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_decision_record.py record.json --key https://mcpgate.online/fabric/decision-signing-key --self-test  (see REPRODUCE.txt)"
  },
  {
   "artifacts": [],
   "category": "DEPLOYMENT",
   "claim_id": "C42-HARDWARE-ATTESTATION",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "declared: a statement about the live servers (no TPM, SEV or TDX present)",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); attestation fields in security contexts are declared hashes, not hardware quotes; needs servers with that hardware",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Hardware-backed attestation of nodes or agents.",
   "status": "NOT_IMPLEMENTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "-"
  },
  {
   "artifacts": [
    {
     "bundle": "formal-2026-09-27",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAINPBFTCommitSafety.tla.txt",
     "sha256": "4b5dbbeda5bd6db9be9707a6e5f9dda1f0ea89656b9040e4ad018e1b134ce238"
    },
    {
     "bundle": "formal-2026-09-27",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAINPBFTCommitSafety.tlc.json",
     "sha256": "078d1bc438d8ac7bcf3113c4e8c2ed95799e8a6dcc6bece9f7a28a34536e7fcb"
    },
    {
     "bundle": "formal-2026-09-27",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAINMCPGateAuthorization.tla.txt",
     "sha256": "6a53f85d2ce4d0ac749d556cf0932dee99dbf429b27797285c0e69feb7415fbb"
    },
    {
     "bundle": "formal-2026-09-27",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAINMCPGateAuthorization.tlc.json",
     "sha256": "611048f422608b0ce3399d78dd437bc45c8638198e06b71eadc64e9901a8d712"
    }
   ],
   "category": "SECURITY",
   "claim_id": "C42-FORMAL-VERIFICATION",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "bounded models (N=4, f<=1, one sequence, two views; small action/identity/context/time domains), not a proof about the Python code; no machine-checked proof for unbounded parameters",
   "public_label": "OFFLINE VERIFIED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "TLA+ models of the PBFT commit/view-change rules and of the MCPGate authorization gate, checked exhaustively by TLC within stated bounds: no violation of Agreement, CommitOnlyWhenPrepared, no-execution-without-quorum, action/identity/context binding, expiry or single use; every deliberately broken variant (pre-fix execute rule, NEW_VIEW ignoring reports, weakened quorum, each gate check removed) is caught with a counterexample.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "java -cp tla2tools.jar tlc2.TLC -deadlock <spec> (see formal-2026-09-27/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "soak-72h-2026-09-25",
     "cluster_ids": [
      "cain42-soak72-1b28cf3"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "verify_soak.py.txt",
     "sha256": "deed0270d115ba2cf509820cc7ec464fa835c76420971921558d4e14ac1e0cb4"
    },
    {
     "bundle": "soak-72h-2026-09-25",
     "cluster_ids": [
      "cain42-soak72-1b28cf3"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "REPRODUCE.txt",
     "sha256": "afacde250be9afcf3112a6050b2eec0f67e0b77224ea985e57e6f844928c6d1d"
    },
    {
     "bundle": "soak-72h-2026-09-25",
     "cluster_ids": [
      "cain42-soak72-1b28cf3"
     ],
     "environment": "DISPOSABLE_CLUSTER",
     "file": "checkpoint-0024.json",
     "sha256": "07cec42fd5b8456bf6b5b83560dfd4e8c18e18aa84012e7a37216c57adb1ac63"
    }
   ],
   "category": "CHAOS",
   "claim_id": "C42-SOAK-72H",
   "claim_version": 1,
   "evidence_environment": [
    "DISPOSABLE_CLUSTER"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 3,
   "evidence_level_meaning": "cryptographic verification",
   "limits": "liveness failure, not a safety failure; one host; not the production cluster; the soak nodes ran image soak72-1b28cf3, without the fix; a passing 72-hour run on the fixed build is still required",
   "public_label": "FAILED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "72-hour adversarial soak (dedicated 4-node cluster, fast path + DAG, crash/restart every 10 min, started 2026-09-25T00:10Z): FAILED. PBFT stopped committing at sequence 4094 about 11 h in (2 replicas in view 39, 2 in view 40, every node HEALTHY, every later request denied), and the harness itself was killed when the host ran out of memory (last checkpoint 0024 at 24.15 h). Safety held: 0 cross-node divergences in 5,154 checks. Cause: no progress timer (only an unreachable primary triggered a view change) and NEW_VIEW replies were dropped, so a lagging replica never caught up; fixed in the engine with a regression test that reproduces the split. A new soak on the fixed build has not run.",
   "status": "FAILED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": "FAILED",
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_soak.py https://clawx.click/evidence/soak-72h-2026-09-25/  (prints VERDICT: FAIL)"
  },
  {
   "artifacts": [
    {
     "bundle": "soak-multiregion-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "REPRODUCE.txt",
     "sha256": "a981f6a68fd3104bc64f85cdc773f2f77add11d8cae7b0fcfeee35e6bccdbfef"
    },
    {
     "bundle": "soak-multiregion-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_soak.py.txt",
     "sha256": "8d9f0a48faf4fea54c38c3795d8b76103cf3dfb3bc92ffe0709a5c9825c7141d"
    },
    {
     "bundle": "soak-multiregion-2026-09-26",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "checkpoint-0032.json",
     "sha256": "5d347d80796fff7d3c87c4ac47c8652dfa9d287930db2c7b1d5548377c25249d"
    },
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "soak_verification_transcript.txt",
     "sha256": "6620c4d6b382644169d1ffce552e0c6aa3acbc08d27c188cfe9b98b8c9a3d834"
    }
   ],
   "category": "CHAOS",
   "claim_id": "C42-SOAK-72H-MULTIREGION",
   "claim_version": 2,
   "evidence_environment": [
    "LIVE",
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 3,
   "evidence_level_meaning": "cryptographic verification",
   "limits": "one missing hourly enforcement proof, not a safety failure: consensus agreement held throughout; the cause of the hour-32 timeout is not yet diagnosed; a 72-hour run in which every checkpoint carries enforcement evidence is still required",
   "public_label": "FAILED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "72-hour soak on the live multi-region cluster cain-mr-01 on the fixed build (continuous writes, a random replica killed every 20 minutes, hourly signed hash-chained checkpoints each with an MCPGate-enforced authorization and its refused replay): FAILED by its own pre-committed rule. Checkpoint 0032 (hour 32, 2026-09-28T05:42Z) carries no MCPGate enforcement evidence -- its checkpoint authorization did not commit (CONSENSUS_TIMEOUT) -- and the verifier requires it in every checkpoint, so no later hour can turn the verdict into PASS. At 37.7 h: 107 replica kills / 107 restarts, 0 divergences, 0 anomalies, 37 of 38 checkpoints valid (48 quorum certificates each). The soak keeps running to ~2026-09-29 21:40Z for the record.",
   "status": "FAILED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": "FAILED",
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_soak.py https://clawx.click/evidence/soak-multiregion-2026-09-26/  (prints INVALID checkpoint-0032.json and VERDICT: FAIL)"
  },
  {
   "artifacts": [
    {
     "bundle": "cain45-zod-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "ZOD_RUN.json",
     "sha256": "6617e0f77463f836e03689ad44ca4a997e5a2b906484c75c7e387b7b4338ee2a"
    },
    {
     "bundle": "cain45-zod-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "EVIDENCE_CHAIN.json",
     "sha256": "9b8f04be9dad7f9519157e7cfff94f424cb1144f41d4d0bcb403b6789670ce2b"
    },
    {
     "bundle": "cain45-zod-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qcs.json",
     "sha256": "bed43b640eee07e3d7713a2955b7271c15b4661709d3592c7ca86376c93ac1fc"
    },
    {
     "bundle": "cain45-zod-live-2026-09-27",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_cain45_zod.py.txt",
     "sha256": "2695e2faea451abc5d699e436f449958c93de492146caa7632d156a73f0568a4"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C45-ZOD-LIVE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "the hypervisor ran as a library on the gateway host, operator-run, not as a deployed service in front of customer agents; the approval is the operator's; software measurement only (no TPM/TEE); no seccomp filter; egress is deny-all only (no allowlist)",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Agent Hypervisor / ZoD runtime: an agent acts only inside a ZoD whose authorization the live cluster cain-mr-01 committed with a quorum certificate the hypervisor checks itself; code ran under real confinement (bubblewrap namespaces + cgroup v2, no network); 10 attacks were refused, each a signed DENIED entry in a hash-chained log.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_cain45_zod.py .  (see cain45-zod-live-2026-09-27/REPRODUCE.txt; expect 10 PASS and VERIFIED)"
  },
  {
   "artifacts": [
    {
     "bundle": "e6-live-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "LEASE_RUN.json",
     "sha256": "ed1d621e60927d8d8c3507fc35eb90df16467365329f2a6d747cbb9df822b4e2"
    },
    {
     "bundle": "e6-live-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "EVIDENCE_CHAINS.json",
     "sha256": "bc9fc9c697889499d556ebe7287a2de1c54041df3a9ff302963e69f490930786"
    },
    {
     "bundle": "e6-live-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qcs.json",
     "sha256": "a290fb7d1ef584def0c585c4bf8fd175f342777f285255d695aa4823ccdd77b7"
    },
    {
     "bundle": "e6-live-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_e6_lease.py.txt",
     "sha256": "8ddcee34f1b1bbedd4682229079d3d458cc58006a51ab49ad1b8bc576d4e8b70"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E6-AUTHORITY-LEASES",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "the invalidation logic runs in the hypervisor library on the gateway host, not on the cluster nodes -- the cluster supplies the authority being invalidated; invalidation on policy, epoch or membership change and risk/blast-radius budgets are NOT implemented; the separate 4-node 'authoritative state' layer in cain45/ is SIMULATED and not used here",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Evolution #6 authority leases: for each of 9 conditions a ZoD authorized by the live cluster cain-mr-01 made one successful tool call, the condition was tripped, and the next call was refused without the tool running -- TTL expiry, trust below floor, agent identity swapped, tool schema changed, security context changed, trajectory fork, explicit revocation, parent quarantined (child loses authority), required evidence deleted (that row is SELF-REPORTED: hypervisor-signed, since the log proving it is the one deleted).",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e6_lease.py .  (see e6-live-lease-2026-09-28/REPRODUCE.txt; expect 48/48 checks, VERIFIED)"
  },
  {
   "artifacts": [
    {
     "bundle": "e7-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "LEASE_RUN.json",
     "sha256": "f556b47e040ce60164e803b1398bc0037ba03118ae925e11bad4deed38bddd96"
    },
    {
     "bundle": "e7-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "EVIDENCE_CHAINS.json",
     "sha256": "cd180b374770996e27db226de6053a49bb0e238a697b784565d730979665cd03"
    },
    {
     "bundle": "e7-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qcs.json",
     "sha256": "150c876ed848d7ffed71ea5e538a008e0f4529f56e08030e23f8822978dbbd58"
    },
    {
     "bundle": "e7-lease-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_e7_lease.py.txt",
     "sha256": "26bac3bae9673597e41a63fa40f523f2347977c54c00c67d90e400c610168039"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E7-AUTHORITY-LAPSE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "the 3 membership/epoch trips are INJECTED into the hypervisor's view (the live cluster was not re-keyed); the policy and budget trips are real; enforcement is the hypervisor library on the gateway host, not the cluster nodes; only CALL_MCP_TOOL budgets were exercised live (classes C0-C4 unit-tested)",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Evolution #7: authority granted by the live cluster cain-mr-01 lapses -- the next tool call is refused and the tool never runs -- when the policy root changes or cannot be read, when the risk or blast-radius budget is spent, and when a delegate has spent its parent's budget (delegates are charged up the whole chain, so splitting work cannot multiply authority). Every ZoD is bound to the cluster's real membership configuration, recomputed and quorum-agreed, re-read before every action; a changed epoch, a changed membership or an unknown membership refuses.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e7_lease.py .  (see e7-lease-2026-09-28/REPRODUCE.txt; expect 60/60 checks, VERIFIED)"
  },
  {
   "artifacts": [
    {
     "bundle": "e8-governance-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "GOVERNANCE_RUN.json",
     "sha256": "88aab8c5ecba00a23fb587de273fd883e676f2b18bde610d2288334397c12e94"
    },
    {
     "bundle": "e8-governance-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "EVIDENCE_CHAIN.json",
     "sha256": "fb44b81bddbaa2e42a993333f78f851f20c22d63a4efa52d29bbc7271409cbb9"
    },
    {
     "bundle": "e8-governance-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "qcs.json",
     "sha256": "0e1bea55cebc3f67f40ec5dee89cc5b4b1db2b5785fbb0dad1b53c7ae5f91e3f"
    },
    {
     "bundle": "e8-governance-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_e8_governance.py.txt",
     "sha256": "0fd608899c72c9209b797f23be415ee2076e0301c160ce2e32f52939b1210958"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E8-GOVERNED-EVOLUTION",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "scripted identities, not a real LLM agent; CAIN contains no world model, digital twin or learning memory -- the run shows that such OUTPUTS cannot become authority; governor and hypervisor are a library on the gateway host, the cluster orders and certifies",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "Evolutions #8/#9: a policy -- the authority ceiling for a tenant's ZoDs -- becomes active only when the live cluster cain-mr-01 commits its activation; an expansion needs a registered human who is not the proposer (an agent's self-approved expansion was refused and never reached the cluster); a restriction needs no human and revoked a running ZoD's authority; a ZoD above the ceiling was refused. A world-model prediction, a simulated ALLOW citing a real certified sequence, a 10-agent signed vote and a replayed memory were each presented as the basis for authority and each refused because the live cluster had not certified it.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e8_governance.py .  (see e8-governance-2026-09-28/REPRODUCE.txt; expect 19/19 checks, VERIFIED)"
  },
  {
   "artifacts": [
    {
     "bundle": "cag-l5-hosted-governor-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_CAG_L5_HOSTED_LIVE_RUN.json",
     "sha256": "105c50c212700461c76fcb5373872785983add85ec9450ef0fb0383a4b3015ed"
    },
    {
     "bundle": "cag-l5-hosted-governor-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_hosted_governor_run.py.txt",
     "sha256": "e07672365742b6b916c15b711d18ef2a5551a4e4b7d95d48278b91c764930561"
    },
    {
     "bundle": "cag-l5-hosted-governor-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_CAG_L5_VERIFICATION_MATRIX.json",
     "sha256": "ff1d184b1c8c34d562c73eea205eaf887bb568372b9f5c7ae032f9db3b75cf97"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-CAG-L5-HOSTED-GOVERNOR",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "operator self-test tenant and a scripted agent -- no customer and no LLM agent governed end to end; the endpoint returns a signed verdict and commitment, the caller's gate executes; CAG-L5 is CAIN's own governance designation, not SAE Level 5; see the matrix for which capabilities are only PARTIAL",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "The CAG-L5 system governor runs in the production gateway (CAIN_SYSTEM_GOVERNOR=1): /fabric/mcp/enforce refuses every tenant without a registered, governance-signed system manifest and every request not signed by the agent's registered key, and for a registered system applies policy precedence, the agent/delegator/system/lease authority intersection, model identity, tool registry, emergency controls and cluster-certified governance state. On the live gateway, through all three public domains: 13/13 cases as expected (in-scope read allowed on each domain; unregistered tenant, unsigned, key substitution, replay, outside system authority, model swap, subagent WRITE, unlisted tool and emergency freeze refused; one-operator recovery refused, two-operator recovery restored service); governance state certified by cain-mr-01 (3 signers); 8/8 decision signatures valid; 18-event chain verifies.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_hosted_governor_run.py CAIN42_CAG_L5_HOSTED_LIVE_RUN.json --live  (see cag-l5-hosted-governor-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAIN42_CAG_L5_SYSTEM_BUNDLE.json",
     "sha256": "11cb0a33b7e737b5c08b686c7aac8463e86a6d145c05bc014a86819dd2969c42"
    },
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "verify_system_bundle.py.txt",
     "sha256": "bfe8a4b017f9c762444214b42814487c859c24398980c5cee2446bb87377df4f"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-CAG-L5-SYSTEM-GOVERNANCE",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "reference system with ephemeral keys, run in one process; the live counterpart is C42-CAG-L5-HOSTED-GOVERNOR",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "The CAG-L5 system-governance library composes emergency freeze, 2f+1 governance-state quorum, attested state, a signed system manifest, model identity, tool registry, exact-capability resource checks, deterministic policy precedence, authority intersection, trajectory authorization and graph-derived blast radius with two-operator step-up; Part 41 Tests A-N all behave as specified, and a clean-room verifier recomputes policy, authority, blast radius, quorum and step-up for every decision and rejects a CAIN-signed but unjustified ALLOW.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_system_bundle.py CAIN42_CAG_L5_SYSTEM_BUNDLE.json  (expect 148/148 VALID)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAIN42_L5_TRAJECTORY_BUNDLE.json",
     "sha256": "760d5744b6cf861a3a274f2b694aa5503b5018b3950396a2759471d6dfd8e68d"
    },
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "verify_l5_unified.py.txt",
     "sha256": "231435515c65bea6e2285ab658024fef05e788a3f9b7509b06ec51643e833418"
    }
   ],
   "category": "TRAJECTORY GOVERNANCE",
   "claim_id": "C42-L5-TRAJECTORY-GOVERNANCE",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "library; ephemeral keys; the hosted governor uses it for every decision but long live trajectories were not run",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Continuous trajectory governance: a lease authorizes only if signed by a governance key (never the agent's), bound to the agent and trajectory, time-bounded (<= 1 h) and fully scoped; only ACTIVE/LIMITED trajectories act; containment only tightens; plan, intent, action, parameters, resource and context must match the governance-bound plan; subagent risk is charged to every ancestor. A clean-room verifier recomputes the decision and 9 adversarial requests (43/43 VALID).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": [
    "C42-L5-UNIFIED-V1-SUPERSEDED"
   ],
   "verification_method": "python3 verify_l5_unified.py CAIN42_L5_TRAJECTORY_BUNDLE.json  (expect 43/43 VALID)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-trajectory-system-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAIN42_L5_TRAJECTORY_FAIL_OPEN_PROBES.json",
     "sha256": "a4facfb8103b1bfa87e228426b9dc1a9449c2a1abd791b0a29775f73c622cce1"
    },
    {
     "bundle": "l5-governance-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SUPERSEDED.txt",
     "sha256": "80a2a239868c3dffaca1d4a72cedf37b1b3ab72b01fb78b0011c8d38d87eb42e"
    }
   ],
   "category": "TRAJECTORY GOVERNANCE",
   "claim_id": "C42-L5-TRAJECTORY-FAIL-OPEN-FOUND",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE",
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "the 'before' column is the recorded probe output, not re-runnable from git history",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Negative evidence: the first continuous-authorization implementation (uncommitted, published earlier on 2026-09-28) failed 13 of 13 probes -- self-signed, unsigned, foreign or unbounded leases, empty scope, missing policy/context, PAUSED/ESCALATED/REAUTHORIZATION_REQUIRED trajectories and unchecked plan binding were ALLOWed; containment could revive a TERMINATED trajectory. 5 of its 15 invariants were the constant True. All fixed in 040cee2 with regression tests.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "tests/test_cain42_l5_trajectory_prompt3.py::test_R01..R13 (the pre-fix code was never committed; its outputs are the recorded probe run)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-authority-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAIN42_L5_AUTHORITY_BUNDLE.json",
     "sha256": "1d9554a3731801cba457b949487413a4a2cbefc3fc9c7716c334ed7cb7194557"
    },
    {
     "bundle": "l5-authority-2026-09-28",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "verify_authority_bundle.py.txt",
     "sha256": "0996d6ca0ca6b65b17196bb051e09d168b94fa5d0a375ed44c86beee9492479a"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-L5-IDENTITY-AUTHORITY",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "library; the hosted L5 identity router is opt-in (CAIN_L5_GATEWAY) and off",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Agent identity and dynamic authority: signed versioned agent identities with key lifecycle; capability-, resource- and time-bounded grants; non-escalating delegation; explainable authorization decisions. Two separately written clean-room verifiers return VALID on the published bundle and refuse 25 attack classes.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_authority_bundle.py CAIN42_L5_AUTHORITY_BUNDLE.json"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-governance-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SUPERSEDED.txt",
     "sha256": "80a2a239868c3dffaca1d4a72cedf37b1b3ab72b01fb78b0011c8d38d87eb42e"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-L5-UNIFIED-V1-SUPERSEDED",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "kept for history; must not be read as a current claim",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "SUPERSEDED: the l5-governance-2026-09-28 unified bundle's trajectory ALLOW and its 15/15 trajectory invariants. The ALLOW came from the fail-open authorizer and 5 invariants were constant True. The bundle stays byte-identical for history; the replacement is C42-L5-TRAJECTORY-GOVERNANCE.",
   "status": "UNVERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "SUPERSEDED",
    "superseded_by": [
     "C42-L5-TRAJECTORY-GOVERNANCE"
    ]
   },
   "supersedes": null,
   "verification_method": "-"
  },
  {
   "artifacts": [],
   "category": "EVIDENCE",
   "claim_id": "C42-LEGACY-SELF-ASSERTED",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "declared: a statement about files published by earlier releases; nothing was run",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "self-asserted by earlier releases; no certification body, no reproducible verifier; found by the public evidence inventory (CAIN42_PUBLIC_EVIDENCE_INVENTORY.json)",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Seven older files still served on the sites assert strong statuses that no evidence in this registry supports: CAIN42_BYZANTINE_CERTIFICATION.json (CERTIFIED), CAIN42_ENTERPRISE_PERMANENT_MEMORY.json (A_PLUS_ENTERPRISE_CERTIFIED), CAIN42_RELEASE_MANIFEST.json (PRODUCTION_HARDENED) on clawx.click/evidence/; CAIN_13_STATUS.json and v13/CAIN_13_STATUS.json (OPERATIONAL_PROVEN), cain_14_agentic_trust_evidence.json and v2/kernel-self-defense-evidence.json (OPERATIONAL_AND_VERIFIED) on /proof/bundle/. They are kept for history; their statuses are SUPERSEDED by this registry and must not be read as current claims.",
   "status": "UNVERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "-"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-adaptive-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_L5_ADAPTIVE_BUNDLE.json",
     "sha256": "f08123b921803c4c87aaab29e6cadf1f36ea42a9d24860424b0884fa64725cc1"
    },
    {
     "bundle": "l5-adaptive-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_adaptive_bundle.py.txt",
     "sha256": "f8a9c356c140196a660efa43c214e3e3a9c0005e031dbca3f73767799afc66c8"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-L5-ADAPTIVE-EVOLUTION",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "in-process library, NOT wired into the hosted gateway or MCPGate; deterministic reference runner, no LLM; no multi-day run; role keys are generated fresh for each build, so the bundle shows internal consistency and decision correctness, not provenance, and it is not signed by the evidence-root key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Governed adaptive evolution (Prompt 6): a proposed change to an agent's memory, skills, tools or model routing becomes active only through an evolution gate; a clean-room verifier recomputes all 11 recorded evolution decisions (1 ACCEPT, 1 REQUIRE_APPROVAL deployed only with operator approval, 6 REJECT, 3 QUARANTINE), 143 checks VALID, and rejects a CAIN-signed but unjustified ACCEPT plus 10 tamper classes. Negative evidence: the first version was fail-open on 32 of 32 independent probes (and an earlier 33/33 invariant result was measured against it); fixed in 71eecdb, 0 open.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_adaptive_bundle.py CAIN42_L5_ADAPTIVE_BUNDLE.json  (expect VALID, 143 checks, 11 decisions recomputed)"
  },
  {
   "artifacts": [
    {
     "bundle": "l5-hosted-evolution-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN.json",
     "sha256": "1487c342a84d125a14eca9131bf8a30d98e61c7a5e0dc1ed60460e6e548272b7"
    },
    {
     "bundle": "l5-hosted-evolution-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN_EXPORT.json",
     "sha256": "a23711b93139e00ac87dcb0fda5124d63d80a81c30212c4da1d8f4ab924dac77"
    },
    {
     "bundle": "l5-hosted-evolution-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_hosted_evolution_run.py.txt",
     "sha256": "7e1a0271b43f343f52658b32741ebdd5ef5092d1ee8424c447e2061df8d37a6e"
    },
    {
     "bundle": "l5-hosted-evolution-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_adaptive_bundle.py.txt",
     "sha256": "f8a9c356c140196a660efa43c214e3e3a9c0005e031dbca3f73767799afc66c8"
    }
   ],
   "category": "L5 GOVERNANCE",
   "claim_id": "C42-L5-ADAPTIVE-HOSTED-EVOLUTION",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "operator self-test tenant, scripted agent and scripted evaluator -- no customer and no LLM agent; hosted evolution covers MODEL and TOOL_CONFIGURATION only (authority is never evolvable; memory/skill/model-router registries are not hosted); rollback is operator-signed, automatic regression rollback is not wired; the evaluator's raw measurements are not recomputed; PRE-PRODUCTION",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "The Prompt 6 evolution gate is wired into the production gateway and MCPGate: after registration an agent's model and MCP tool configuration change only through it (agent-signed proposal, tenant-evaluator-signed report, operator approval that is never the proposer), and a deployed change gives a new capability commitment, so the old cluster certificate and every lease stop authorizing until cain-mr-01 certifies the new commitment and a lease is re-issued. Live, through all three public domains: 17/17 enforcement cases as expected (model swapped outside the gate, old lease after a capability change, the disabled tool on each domain and the rolled-back model refused; the enabled tool, the upgraded model and the restored version allowed); gate refusals: no evaluator report REJECT, authority-widening tool change QUARANTINE and undeployable, unapproved model REJECT, deploy without approval or with the agent's own approval refused, agent-signed rollback refused; 4 cain-mr-01 certifications (sequences 22515, 22517, 22518, 22517) whose own records carry each certified commitment; 42-event chain verifies; a clean-room verifier recomputes all 5 hosted evolution decisions (VALID). Found and fixed on the way: the certified governance state did not cover the MCP tool map or per-agent tool configuration.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_hosted_evolution_run.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN.json --live ; python3 verify_adaptive_bundle.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN_EXPORT.json  (see l5-hosted-evolution-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "trust-integrity-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "CAIN42_TRUST_INTEGRITY_LIVE_RUN.json",
     "sha256": "cf2b275c0e552e142185d8fc50fafbfe469c323522eb9fe439243c32666b43cc"
    },
    {
     "bundle": "trust-integrity-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_trust_integrity_run.py.txt",
     "sha256": "45b98bc0ac2ef600ae5210059512ebf07b94f24adfa1ce228672289926df6b0c"
    },
    {
     "bundle": "trust-integrity-2026-09-28",
     "cluster_ids": [
      "cain-mr-01"
     ],
     "environment": "LIVE",
     "file": "verify_transcript.txt",
     "sha256": "8d7f21a7ee39eb0197e88ec2c259d3b7fa5690a08ff7ddbb037be393438cfccf"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-TRUST-INTEGRITY-LIVE",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "action risk reads the tool name and arguments the agent declares, so a tool whose name hides what it does is scored on its arguments only; decision latency is unchanged (about 1.2 to 14 s in this run); signup has no email delivery or captcha; operator-run accounts, no customer traffic; no third-party review; PRE-PRODUCTION",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "A caught attacker no longer gains autonomy on the production gateway. Before 2026-09-28 a new account that sent two prompt injections (both BLOCKED) fell from UNKNOWN to DEGRADED trust, which the matrix answered more permissively than UNKNOWN, so its $250,000 transfer, rm -rf / and DROP TABLE came back ALLOWED. Now the trust matrix is monotone with a runtime floor (no state carrying negative evidence beats UNKNOWN), the independent verifier builds its table from a published spec instead of copying production, every action is scored by tool class, destructiveness, amount and target (high and critical go to a human), deny rules match every spelling of a path, trust is per agent and capped by its key, a trust hold is queued for approval, an approval binds the call's arguments, and an account can mint agent keys so the agent asks and the owner approves. Live, with a fresh free account on each of cainstudio.online, mcpgate.online and clawx.click: every case as specified, including the solo-developer path (agent held, cannot approve itself, owner approves, retry runs, its next low-risk call runs with no approval, a critical action is still held), and all 48 decisions match cain-mr-01's own public record (decision id, verdict, commitment, 3-of-4 commit certificate); clean-room verifier VALID.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_trust_integrity_run.py CAIN42_TRUST_INTEGRITY_LIVE_RUN.json --live  (see trust-integrity-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e15-spatial-physical-intelligence-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_EVOLUTION15_MASTER_PROOF.json",
     "sha256": "9957445a94cf14ba3817b77de59414ee14c53b234f1dfcaa4d620f94d1ac75e1"
    },
    {
     "bundle": "e15-spatial-physical-intelligence-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "b1cce09fef6e2d253932ee6505291ce93c280a7e9eeed162430bd57e3031ea37"
    },
    {
     "bundle": "e15-spatial-physical-intelligence-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END_DEMO.json",
     "sha256": "d41592e1ad486eaac4c5962055140931456484f25f4291077fb47c1ea7e34359"
    },
    {
     "bundle": "e15-spatial-physical-intelligence-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e15.py.txt",
     "sha256": "314b76e83aa2b16a333bf18dbdbc1258137fd3275a69bbcabc5d6d176bbec7ae"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E15-SPATIAL-PHYSICAL",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against a REFERENCE robot adapter and a reference kinematic simulator; CAIN-42 is not a vehicle or a robot, drives nothing and does not guarantee physical safety; no real sensor, vehicle, robot or actuator integration (NOT_IMPLEMENTED); sensor keys are software keys (hardware attestation UNKNOWN); world-model accuracy and sim-to-real fidelity UNKNOWN; real-world attack validation NOT_PERFORMED; not hosted; single host; proof signed with an ephemeral build key; no third-party review; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 15 (spatial + physical intelligence governance) is a TESTED library that brings sensor observations, world state, world-model output, simulation, trajectories and physical actions into CAIN-42's governed trust path. Signed sensor observations are admitted through the E12 evidence layer; the world state is versioned, hash-chained and replayable and binds every ingested observation; a world model's output is PREDICTED evidence bound to its model, configuration, world state and scenario, never authority; a trajectory is a proposal until a signed approval binds it; every physical action binds nine digests (world state, trajectory, decision, capability, authority, policy, risk, consequence, authorization), crosses the E8 commit boundary and reaches an actuator adapter only with a single-use, short-lived permit for that exact command; material reality drift invalidates the authorization and forces re-evaluation or a safe state. P1-P36 36/36 hold; the CAIN-42-E15-Spatial-Physical-Bench contains 55/55 attacks; the 19-step end-to-end run and all 7 deliberate mutations behave as specified; digital, physical and hybrid agents converge on one path; clean-room verifier INTACT.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e15.py <bundle dir>  (see e15-spatial-physical-intelligence-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_EVOLUTION17_MASTER_PROOF.json",
     "sha256": "5cdf9171a4ae94eff42b0d881b523fee95c5a99dd5e5a4506a451312ed45b66a"
    },
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "9f8b2347d9abde8f7123ea5485ad8a8e8cd3197a1e3503ef8bb8b16043b6e1fc"
    },
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END_DEMO.json",
     "sha256": "d26833da1cda93a401ab7e74000a2e1bf99c9c6d2077818e996911e8c2b13c83"
    },
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "COMMIT_EXAMPLES.json",
     "sha256": "e1e42cb0813731a78e2cee3c1c710ea5d9b58a08d36a3c56261de376bfa3a671"
    },
    {
     "bundle": "e17-multi-agent-world-action-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e17.py.txt",
     "sha256": "ee97fe461d2653e48890a0e3ce0cdc75007840bd4326963f42c3c89e5c2be401"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E17-MULTI-AGENT",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against a governed REFERENCE collective; CAIN-42 deploys no fleet, robot, drone, vehicle or customer collective and drives nothing; no real sensor/actuator integration and no deployed multi-agent collective (NOT_IMPLEMENTED); no hardware attestation (UNKNOWN); Sybil-detection completeness and the semantic truth of observations, predictions or causal claims are UNKNOWN; world-model accuracy and sim-to-real fidelity UNKNOWN; real-world attack validation and third-party review NOT_PERFORMED; not hosted; single host; proof signed with an ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 17 (governed multi-agent world action fabric) is a TESTED library that governs action by autonomous agent teams as a first-class system object: a collective is not the sum of its members and a collective action is not the sum of member actions. Collective authority is a constrained INTERSECTION of the governing grant, the mission capabilities, policy and live member authority, never a sum; majority, consensus, negotiation, contracts, roles, membership, coalitions, delegation, subagents, emergence and self-improvement cannot create or amplify authority; a material mission/membership/world-state/causal/topology drift forces reauthorization or a safer decision; dissent is preserved; a world-state fork blocks authorization until reconciliation; a collective trajectory is a proposal; and one action that would fan out to many agents is pre-authorized. Every consequential collective action binds fifteen digests and reaches the E8 governance kernel, and the boundary itself enforces the risk, policy, world-state, authority, decision and consequence verdicts it binds (a consistently re-signed refusal is still refused). Q01-Q61 61/61 hold; the CAIN-42-E17-Multi-Agent-Bench contains 91/91 entries (88 distinct attacks); the 18-step end-to-end run and all 12 deliberate mutations behave as specified; the clean-room verifier returns INTACT (92 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e17.py <bundle dir>  (see e17-multi-agent-world-action-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_EVOLUTION18_MASTER_PROOF.json",
     "sha256": "44c91636b6c8ca33c062b82a79c3e0d25efa65ac891991555a4435fe3320e640"
    },
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "67e05c757e714c2a132f0a1082263ae05f38180d28001c2f99ad331d9f3211ef"
    },
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END_DEMO.json",
     "sha256": "618ac511016dfee612b2dbbdb834356a367810f01a7a579d5582def4c0ea8728"
    },
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "COMMIT_EXAMPLES.json",
     "sha256": "46816dcd70c6f5255ffea609dfaa049061e0b9cffb1ac5316d12c32f6dc67cd4"
    },
    {
     "bundle": "e18-4d-spatial-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e18.py.txt",
     "sha256": "9de07433810550c84dc523ee1966d10e7f8dbc458586f71db2024adb05857dcb"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E18-4D-SPATIAL",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against a governed REFERENCE 4D world; CAIN-42 contains no autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack and drives nothing; no real vehicle / drone / robot / sensor / actuator / airspace integration (NOT_IMPLEMENTED); no physical safety guarantee and no certified autonomy (NOT_IMPLEMENTED); hardware attestation (UNKNOWN); world-model and prediction accuracy and sim-to-real fidelity (UNKNOWN); real sensor validation and real-world adversarial validation (NOT_PERFORMED); third-party review (NOT_PERFORMED); not hosted; single host; proof signed with an ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 18 (4D spatial autonomy fabric) is a TESTED library that governs proposals from autonomous systems across a predictive 4D world: entity state at (X,Y,Z,T) with uncollapsed uncertainty; reachable / policy-permitted / authorized sets kept distinct; probabilistic intent; multiple predicted trajectories; an interaction graph and a conflict field that is not distance-only; time-to-consequence with uncertainty; dynamic signed geofences; governed airspace and roadspace; spatial policy that yields ELIGIBILITY not authorization; multimodal sensor fusion; world-model arbitration that never simply picks the highest confidence; counterfactual future trees; actionability states; a conserved uncertainty budget; a micro-authorization loop; and a reality-gap monitor. Every consequential spatial action binds sixteen digests and reaches the E8 governance kernel, and the boundary itself enforces the policy, actionability, authority, risk and uncertainty verdicts it binds (a consistently re-signed refusal is still refused); AUTHORIZATION IS A FUNCTION OF WORLD STATE and if a material input changes it must be revalidated. Q01-Q89 89/89 hold; the CAIN-42-E18-Spatial-Autonomy-Bench contains 123/123 entries (109 distinct attacks plus 14 invariants re-run as scenarios); the 20-step end-to-end run, its unmutated control and all 12 deliberate mutations behave as specified; the clean-room verifier returns INTACT (111 checks, no CAIN imports). ACTIONABILITY IS NOT AUTHORIZATION. REACHABILITY IS NOT PERMISSION. PREDICTION IS NOT REALITY.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e18.py <bundle dir>  (see e18-4d-spatial-autonomy-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E19_EVIDENCE_BUNDLE.json",
     "sha256": "1b1a8c688b635423af17cc344e68be009cba36dd25fcc874961777770073287e"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "0a7f826fcfe5d8239ea2e22a239383a39d5012d8632a9cf69f1217e691a1a4a4"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "3c65e7413b96502cbcb29a17543076893588b84e49c103f9e8da6fb718347a31"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END_RESULTS.json",
     "sha256": "2eda80387a458f82558e00864e369754657335020a69e4c98e9a3c0e8948c88b"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "8594220cd7cdf9d65f923978de2d2d084294e2cc64d7c5fd85f0b88cd9afe89d"
    },
    {
     "bundle": "e19-governed-autonomy-2026-09-28",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e19.py.txt",
     "sha256": "f2cd70a3a51ef8bdb1678a1d375d12de9b1b6169ef71ac06fb8edf2606e5a29c"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E19-GOVERNED-AUTONOMY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against a governed REFERENCE system (a digital agent, a vehicle abstraction, a drone abstraction, a collective and a human in the E18 4D world); execution in the scenario is SIMULATED; CAIN-42 drives, flies and controls nothing and guarantees no physical safety (NOT_IMPLEMENTED); not hosted (NOT_IMPLEMENTED); semantic truth of beliefs and outcomes and hardware attestation UNKNOWN; multi-host behaviour UNVERIFIED; real-world adversarial validation and third-party review NOT_PERFORMED; single host; proof signed with an ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 19 (governed autonomy operating fabric) is a TESTED library that governs the evolving state of an autonomous system: identity, mission, goals, beliefs, memory, models, learning, authority, world, outcomes and recovery are hash-chained governed state; effective authority is the intersection of sixteen factors (a missing factor is UNKNOWN and empties it; confidence, peer agreement, learning, plans, predictions and compute are not factors); autonomy levels are derived from evidence; a subgoal never exceeds its parent or its mission; memory never becomes policy or authority; a learned change to authority needs a constitutional quorum; and every consequential action carries a sixteen-field action contract that any material state change invalidates and whose verdicts the gate enforces itself before the E8 kernel commits it -- a consistently re-signed refusal is still refused. G1-G108 108/108 hold; the CAIN-42-E19-Governed-Autonomy-Bench contains 189/189 entries (177 distinct attacks); a mutation self-test shows that removing any of four defenses is caught; the 19-stage end-to-end run and all 20 stage attacks behave as specified; the clean-room verifier returns INTACT (117 checks, no CAIN imports). AUTONOMY IS NOT AUTHORITY.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e19.py <bundle dir>  (see e19-governed-autonomy-2026-09-28/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e20-agentic-institutions-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E20_EVIDENCE_BUNDLE.json",
     "sha256": "81e2c651a2207936e05cafc0e5ffccf8e229f288bba7d196bdd27a2083f62078"
    },
    {
     "bundle": "e20-agentic-institutions-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "94d2c221562a6b9dd3ce863527a72e5390e3cb08c7b6f0593ebe3fd3e55dfac1"
    },
    {
     "bundle": "e20-agentic-institutions-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "0f0ebc202bbf271abb7430dd9c437ba6308cace5b3b0fe5578325fdb7eeeed7c"
    },
    {
     "bundle": "e20-agentic-institutions-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END_RESULTS.json",
     "sha256": "26f2784438f42fee9fe617590a749d755130bc7f9444a9509785d984663c1045"
    },
    {
     "bundle": "e20-agentic-institutions-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "fb1df1d592634801f8afa7b44763780f7567fdafa5350ffcd658680994f852be"
    },
    {
     "bundle": "e20-agentic-institutions-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SCALE_RESULTS.json",
     "sha256": "fdd3b0fca9bf1e2f1a42895c334078ef4070aaf61c865d00657874cc06c77528"
    },
    {
     "bundle": "e20-agentic-institutions-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e20.py.txt",
     "sha256": "8db5221232a57f3e22c48431b0af4448781be96eae4132af71054110d6e5e624"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E20-AGENTIC-INSTITUTIONS",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against deterministic REFERENCE institutions; every economy, market and settlement is SIMULATED over abstract units and real money is refused (real financial settlement NOT_IMPLEMENTED); control of any real economy, society, agent population, vehicle, drone or robot NOT_IMPLEMENTED; not hosted (NOT_IMPLEMENTED); the 10,000-agent / 1,000-institution runs are single-process simulations; multi-host behaviour UNVERIFIED; collusion-detector recall and semantic truth of evidence UNKNOWN; real-world adversarial validation and third-party review NOT_PERFORMED; proof signed with an ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 20 (governed agentic civilization fabric) is a TESTED library that governs agents, collectives and machine-native institutions -- formation, membership, delegation, negotiation, contracts, resources, spawning, termination, reputation, trust, federation, disputes, evolution and recovery -- without allowing coordination, capability, economic activity or organizational growth to manufacture authority: institutional authority is an intersection (constitution boundary, founding authority, parent, autonomy-state ceiling) and member authority is the grant plus delegations bounded by their delegator, never a sum; membership, votes, consensus, reputation, trust, wealth, market wins, rewards and model capability are not inputs; a contract or negotiated agreement authorizes nothing by itself; a spawned child is bounded in seven independent dimensions; terminated agents and dissolved institutions cannot resurrect; and every institutional action is judged by E20, then by the E19 action-contract gate, and committed only by the E8 kernel -- a re-signed refusal is still refused. I1-I118 118/118 hold; the CAIN-42-E20-Agentic-Institutions-Bench contains 334/334 entries (328 distinct attacks); a mutation self-test shows that removing any of six defenses is caught; the 20-step end-to-end run detects and contains all 7 hostile events and then recovers and re-authorizes; the clean-room verifier returns INTACT (179 checks, no CAIN imports). Every economy in it is SIMULATED. COLLECTIVE INTELLIGENCE IS NOT INSTITUTIONAL AUTHORITY.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e20.py <bundle dir>  (see e20-agentic-institutions-2026-09-29/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e21-open-ended-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E21_EVIDENCE_BUNDLE.json",
     "sha256": "1754e36f2f720d558a9caf73752f6cffd641c8ca98e589e5608c75adc449c358"
    },
    {
     "bundle": "e21-open-ended-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "faaa218602739d25e249455af27b5978a07d191182213fa3bf5d94266047bfb8"
    },
    {
     "bundle": "e21-open-ended-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "ecf68795be5be013b84ad7778ea7aa575229e949c0c245eb446ff03ef1f373d6"
    },
    {
     "bundle": "e21-open-ended-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "DISCOVERY_RESULTS.json",
     "sha256": "9cfc58f9883a1f3164d74b30510efc49f041a6bb179e107d55e7a54ed2c6562d"
    },
    {
     "bundle": "e21-open-ended-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SELF_EVOLUTION_RESULTS.json",
     "sha256": "847a7e96423084f9b5de50c3cd58081127c4799624991ba33d3c7271f449f478"
    },
    {
     "bundle": "e21-open-ended-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "c5fcf3f07713c24a2cc47828394eea67ce6646f5df008329f02531f07058d754"
    },
    {
     "bundle": "e21-open-ended-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "TAMPER_RESULTS.json",
     "sha256": "34bf85758a491846548eb4d64e384477d79c3b6f40fbc6cb06f62d962a441049"
    },
    {
     "bundle": "e21-open-ended-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SCALE_RESULTS.json",
     "sha256": "aefc739d9858cf96bd2162ad753e6025110f8a79742201341e6dceea0b9b8216"
    },
    {
     "bundle": "e21-open-ended-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e21.py.txt",
     "sha256": "a11a4adaf4b6d6bb4d68a62ca69619083ff71139f88411c065dfc651649cc144"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E21-OPEN-ENDED-INTELLIGENCE",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library exercised against a deterministic SYNTHETIC research problem; it contains no scientific model and runs no real laboratory; scientific truth of any hypothesis UNKNOWN (E21 checks how evidence was produced, not whether a hypothesis is true); novelty only against a supplied corpus; collusion by controllers off-system UNKNOWN; not hosted (NOT_IMPLEMENTED); the 100,000-agent / 100,000-hypothesis runs are single-process SIMULATIONS; multi-host behaviour UNVERIFIED; research bounties SIMULATED; real-world adversarial validation and third-party review NOT_PERFORMED; does not create AGI, solve alignment or guarantee safe self-improvement; proof signed with an ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 21 (governed open-ended intelligence fabric) is a TESTED library that governs autonomous research -- questions, competing hypotheses, experiments, simulations, observations, replication, peer review, adversarial challenge, knowledge, causal claims, benchmarks, model and strategy evolution, research-agent creation and discovery-to-capability promotion -- so that discovery never silently becomes truth, authority or execution: epistemic state is computed from signed evidence whose method class (simulation, synthetic, controlled, real-world, independent replication, third-party) is bound into its signature and grouped by independence key (one controller, environment, dataset and model count once); research authority (charter actions within role) is disjoint from execution authority and no authority function takes a discovery, confidence, vote, benchmark score, knowledge, curiosity or information value as input; a capability leaves quarantine only after validation, an independent adversary, a security review and a governance quorum that excludes the researchers, and a promotion is necessary but never sufficient -- every action is still judged by E20, the E19 action contract and the E8 kernel; revoked evidence invalidates dependent knowledge, policies and capabilities; failed experiments are retained; a discovered governance weakness can only be disclosed. D1-D155 155/155 hold; the CAIN-42-E21-Open-Ended-Intelligence-Bench contains 298/298 entries (290 distinct attacks) and answers NO to 'can a discovered loophole be used to acquire permission to exploit it'; a 17-stage research demonstration refuses all 16 self-authorization attempts; removing any of seven defenses is caught; the clean-room verifier returns INTACT (218 checks, no CAIN imports) and catches all 16 re-signed tamperings. DISCOVERY IS NOT TRUTH IS NOT AUTHORITY IS NOT EXECUTION.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e21.py <bundle dir>  (see e21-open-ended-intelligence-2026-09-29/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e23-governed-meta-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E23_EVIDENCE_BUNDLE.json",
     "sha256": "776ff4c726db9128593c45b0356de5649e186d4519dc9574c18866caffce3615"
    },
    {
     "bundle": "e23-governed-meta-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "c0ae55e83f8f543d96b4d30e1d8029f75bbc7573fa5919076d23b64e73d3eafb"
    },
    {
     "bundle": "e23-governed-meta-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "51de6b22eba57cb54c1e35249bba4e554e09b71c3a6b4c2baf554847ff59cbf2"
    },
    {
     "bundle": "e23-governed-meta-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "db3ef22d776efdc8e0b8352852f1dad07be5eca1b78e07f3ad18b4d685fc2684"
    },
    {
     "bundle": "e23-governed-meta-intelligence-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e23.py.txt",
     "sha256": "354965b0afd3a9961e5aaa8d33a711348b849c2ce70c6977468e9c58c1856b11"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E23-META-INTELLIGENCE",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library; the performance model is synthetic; not hosted; bundle status INCOMPLETE pending the full regression gate; ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 23 (governed meta-intelligence fabric) is a TESTED library in which the system models its own architecture, searches and proposes changes, sandboxes and red-teams them, and can never authorize them: promotion needs a proof by an evaluator key, a canary, a board quorum that excludes the proposer and a human approval, and execution still goes through the E19 action contract and E8. 253/253 invariants hold; 545/545 adversarial scenarios across 80 families are contained; removing any of 7 defenses is caught; 609 tests pass; the clean-room verifier returns INTACT (733 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e23.py <bundle dir>  (see e23-governed-meta-intelligence-2026-09-29/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e24-governed-agentic-internet-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E24_EVIDENCE_BUNDLE.json",
     "sha256": "d01bc735daf75949d03cd3b6a9dc4311ab9fde560db2ccf6feacc0b4e5ac2584"
    },
    {
     "bundle": "e24-governed-agentic-internet-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "7ee04607c06129b9a11c63bc9356123c901b45c34264c1bc216c3c2abb4d6560"
    },
    {
     "bundle": "e24-governed-agentic-internet-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "1354118f51475ae4faf62b38028307a7841d34632f2172087935c98416bcac69"
    },
    {
     "bundle": "e24-governed-agentic-internet-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "57890d38686924d04b1da6cc0cb9f32be238a9967d0bada594a9a2cee88e0275"
    },
    {
     "bundle": "e24-governed-agentic-internet-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e24.py.txt",
     "sha256": "d132fa66c23211d687fda4ea12d2295b8909633967131c4d448b9d27184d6775"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E24-AGENTIC-INTERNET",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library; protocol adapters normalise reference messages and are not network servers; no third-party agent governed; economics SIMULATED; the 10,000-agent run is a single-process model; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 24 (governed agentic internet fabric) is a TESTED library for agents of different organizations and trust domains across thirteen protocol classes: a fourteen-dimension trust vector that is never collapsed, capability claims that stay CLAIMED until attested, signed negotiation and contracts that are never authority, child-subset delegation, cross-domain authority as the intersection of ten factors, quarantine, revocation and a firebreak; one consequential path E24 -> E19 -> E8. 305/305 invariants hold; 756/756 adversarial scenarios across 68 families are contained; removing any of 8 defenses is caught; 806 tests pass; the clean-room verifier returns INTACT (1,952 checks).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e24.py <bundle dir>  (see e24-governed-agentic-internet-2026-09-29/REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "e25-universal-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E25_EVIDENCE_BUNDLE.json",
     "sha256": "45b08b1bedaa987317d3571f023d2175bb5b6a5476a8a7497d35b6de95778f3f"
    },
    {
     "bundle": "e25-universal-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "db12b871bbc4aff35ca201258c0914e5c7ba212ea8b371a98e868ea976730d2d"
    },
    {
     "bundle": "e25-universal-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "756b8aac088fb17a684cd1d98eb38f61fd09fa3086617e58f26e80f0424e7219"
    },
    {
     "bundle": "e25-universal-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CONFORMANCE_RESULTS.json",
     "sha256": "141963ade61a8f9df855f18398ac242ce3e30b8569a211215c33c38d27b185b2"
    },
    {
     "bundle": "e25-universal-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e25.py.txt",
     "sha256": "28179c9eb9cb8f3439985fe4a66c74a6cf01c5efe322825cb354f1bc9e1c03cd"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E25-MACHINE-AGENCY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library plus a reference HTTP service; cross-organization, third-party and hardware-attestation gates NOT VERIFIED; OAuth/OIDC mapped, not implemented; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 25 (universal machine agency fabric) is a TESTED library that turns any consequential machine action into one protocol-neutral envelope signed by the agent instance, authorized by a compiled policy and delegation chain and committed only through the E8 Action Commit boundary, across eighteen protocol adapters that each pass a sixteen-check conformance contract; the agent never holds a raw secret. 517/517 invariants hold; 1,055/1,055 adversarial scenarios across 35 families are contained; every mutant is caught; 60 tests pass; the clean-room verifier returns INTACT (2,977 checks).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e25.py <bundle dir>  (see e25-universal-machine-agency-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e26-universal-machine-agency-trust-2026-09-30",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "CAIN42_E26_EVIDENCE_BUNDLE.json",
     "sha256": "06aaa32ca2b113fd654d5eae4be4a9f65a78a34a34d5e5de355ba76af649f4ec"
    },
    {
     "bundle": "e26-universal-machine-agency-trust-2026-09-30",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "INVARIANTS.json",
     "sha256": "3788124878005ec0b28a71e69e3b9ccdc62e567edcab6defd30b2b8bef41c6c2"
    },
    {
     "bundle": "e26-universal-machine-agency-trust-2026-09-30",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "1dacfe2b50d06e656ded3a1adf238bb889a9f0e3c2fa4287078c6ddbd5a2e836"
    },
    {
     "bundle": "e26-universal-machine-agency-trust-2026-09-30",
     "cluster_ids": [],
     "environment": "OFFLINE",
     "file": "verify_e26.py.txt",
     "sha256": "a71f8e8f8178559cbe836f773aeb36ff7128857254df925c5abd36f0b4f9b5be"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E26-AGENCY-TRUST",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library; hardware attestation, zero-knowledge proofs and third-party interoperability NOT VERIFIED; PRE-PRODUCTION",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 26 (universal machine agency trust fabric) is a TESTED library adding portable signed trust objects, a seventeen-dimension trust vector that never collapses into one score, continuous attestation with explicit levels (hardware stays UNKNOWN), transaction-bound authorization that refuses reuse, attenuating delegation with receipts, revocation epochs, transaction finality and SPIFFE/AuthZEN/COAZ adapters. 532/532 invariants hold; 1,192/1,192 adversarial scenarios (137 specific to E26) are contained; 30 tests pass; the clean-room verifier returns INTACT (3,115 checks).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e26.py <bundle dir>  (see e26-universal-machine-agency-trust-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e27-agentic-internet-control-plane-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E27_EVIDENCE_BUNDLE.json",
     "sha256": "c8c4d962ef7efa2d129d530508cc79f13ae848fdeb485eb9a6a1587b90a210d0"
    },
    {
     "bundle": "e27-agentic-internet-control-plane-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "d0fcd3ca767bb97ecd017b72d4785f25fb29c9cb79067dc306fb4eede6857a54"
    },
    {
     "bundle": "e27-agentic-internet-control-plane-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ATTACK_MANIFEST.json",
     "sha256": "40e87bc2252240960df55f64a74772f00d6f9b8ba592fc9dd8a615516ce411ea"
    },
    {
     "bundle": "e27-agentic-internet-control-plane-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e27.py.txt",
     "sha256": "cb6aabde04b3cf6b507c3700fced3b28c13b866ba4d60ce9063f1c6718362598"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E27-CONTROL-PLANE",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library; kernel/eBPF enforcement, OTLP export, real identity federation and research capabilities NOT IMPLEMENTED; its mutation self-test covers only 2 mutants; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 27 (agentic internet control plane) is a TESTED library that coordinates registry, discovery, routing, policy distribution, cross-domain decisions, contracts, negotiation, inference budgets, incident propagation, emergency policy, edge nodes, conformance and certificates over E25/E26 without becoming a source of authority. 765/765 invariants hold and 1,533/1,533 adversarial scenarios are contained (both cumulative with E26; 341 scenarios specific to E27); 28 tests pass; the clean-room verifier returns INTACT (4,001 checks).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e27.py <bundle dir>  (see e27-agentic-internet-control-plane-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e28-portable-execution-identity-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E28_EVIDENCE_BUNDLE.json",
     "sha256": "e0c33513f1fd8f186c30e02c01b900d99fd84b37e31e22f55dba26ef3f44a2c2"
    },
    {
     "bundle": "e28-portable-execution-identity-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E2E_ARTIFACTS.json",
     "sha256": "9b957c8c6bde8235e15882027203c9e0dc5a45ba769dafa1979f4a4cca3e5d16"
    },
    {
     "bundle": "e28-portable-execution-identity-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END.json",
     "sha256": "664bd84c2f79ab3542184450b8d12db8e599193daf0510e8425750a682f2071b"
    },
    {
     "bundle": "e28-portable-execution-identity-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "6fde45a7c5544e623777d53702bfc26ab70fe4a531d8d70271523df52cc9a84a"
    },
    {
     "bundle": "e28-portable-execution-identity-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SECURITY_RESULTS.json",
     "sha256": "160107bc0fd70e76512198315c8c20c7230549999ea35a0ed9c78ed9357469f2"
    },
    {
     "bundle": "e28-portable-execution-identity-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "12aee97d83c54abb2b48573be884e197b04611d66befe90c00c4d75847e9acf9"
    },
    {
     "bundle": "e28-portable-execution-identity-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SCALE_RESULTS.json",
     "sha256": "ab1b05b068078c60a6c8fdfacbb72c9cf967f4200e67957d209ddd0fea144478"
    },
    {
     "bundle": "e28-portable-execution-identity-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e28.py.txt",
     "sha256": "b3fe31385b6e9835c668035a6cfa23256fcc9f7998747ab6b4745e7a11fadc0b"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E28-EXECUTION-IDENTITY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library, not hosted; the envelope is a CAIN experimental reference protocol with no external adoption; zero-knowledge proofs NOT IMPLEMENTED; hardware attestation UNKNOWN; cross-domain revocation does not propagate; one mutant (the E28 replay cache) survives because E25 stops the same replays; scale runs synthetic and in-process; ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 28 (portable machine agency and execution identity) is a TESTED library: any agent can connect (register with proof of possession, attest, declare capabilities) and receive a signed, versioned, time-bounded execution identity whose envelope travels byte-identically over 23 protocol carriers, while authority never travels -- every receiving domain recomputes it (requested AND federated AND local sponsor AND home ceiling), delegation is a subset of the parent on 16 dimensions, model/runtime/prompt/tool/memory/key changes invalidate authority until re-evaluated, every action is bound to one transaction and reaches the E8 Action Commit boundary, and every decision leaves a signed hash-chained receipt with identity events in an RFC 6962 transparency log. 90/90 invariants hold; 442/442 adversarial scenarios across 8 categories are contained; the mutation self-test kills 9 of 10 mutants (the survivor is explained); conformance 17/17; 11 tests pass; the clean-room verifier returns INTACT (243/243 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e28.py <bundle dir>  (see e28-portable-execution-identity-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e29-machine-transaction-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E29_EVIDENCE_BUNDLE.json",
     "sha256": "069b343bd9b1924b3c76597a79aee0ed4277f4c07e098c23853f06b864f57fbf"
    },
    {
     "bundle": "e29-machine-transaction-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E2E_ARTIFACTS.json",
     "sha256": "83c161bd9f5c67af1b4c585848205bac260b3beedf3961ca9ee7cb7f6c8f9438"
    },
    {
     "bundle": "e29-machine-transaction-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END.json",
     "sha256": "b5d0782d0005c87b67b6653d60055e1a91e4b29015dcd35c9bdaefc8f94f20b3"
    },
    {
     "bundle": "e29-machine-transaction-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "a968d27ac19bf16ffff148e31982ba62b729eb88bf46637ca3ea9c1982c52bcc"
    },
    {
     "bundle": "e29-machine-transaction-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SECURITY_RESULTS.json",
     "sha256": "9759b3a24ca091a48a96e112640ed93ccd8c952ad26f3ab353853b92d28686f0"
    },
    {
     "bundle": "e29-machine-transaction-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "89bf53a04cb987d05716c4f32578584cb9dcf9f1e23d41cbd02f5c2a7f1e0828"
    },
    {
     "bundle": "e29-machine-transaction-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CATASTROPHE_RESULTS.json",
     "sha256": "fd1baf897a2715339bf983895284e474232e4109ccf58fed4f3ae5ac70a3e7e4"
    },
    {
     "bundle": "e29-machine-transaction-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SCALE_RESULTS.json",
     "sha256": "a94494a54323ec04f9f96e1ba4d3fc3c5b2825f21c56eb31fadec621a9ce7b31"
    },
    {
     "bundle": "e29-machine-transaction-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e29.py.txt",
     "sha256": "b3ebc70b4fb2b351367ef5cc5752326d3f948d8b79283614e2199291ad6b4f85"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E29-MACHINE-TRANSACTIONS",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library, not hosted; synthetic TEST units only, real currencies refused, no payment rail; reference agents in one process; competitive radar has no researched competitor data; no novelty claimed; no moat adopted; 10,000/100,000-agent rows synthetic; ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 29 (governed agentic internet transaction fabric) is a TESTED library: a machine transaction runs through twelve separately gated, signed stages and two signed envelopes binding 24 attributes; authority is computed per transaction (delegation, lease, separate economic authority, organization path, contract, counterparty risk with no score, consequence vector, firebreak, partition mode); value moves only through a sealed treasury executor inside the E8 commit boundary and every ledger entry names its committed request; escrow releases only on evidence, never on a claim. 106/106 invariants hold; 258/258 adversarial scenarios contained; mutation 10/10; 0 false allows in ten catastrophe scenarios; 12 tests pass; the clean-room verifier returns INTACT (300/300 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e29.py <bundle dir>  (see e29-machine-transaction-fabric-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E33_EVIDENCE_BUNDLE.json",
     "sha256": "a8cfd1f21243f3f8099227fa951a76574a70400afc2b996462d0ed0544e47ebd"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "OPERATIONS.json",
     "sha256": "6fd22bb4483fe80cb9ac072458934946b9a76ce4afa28a627772a7f9e2890a98"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "EVENTS.json",
     "sha256": "a9f88670bdf8a3aeacd8465c41c47f16fdaa6e92579ae9a789b5d3d68f2acf3a"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SIDECAR_TRANSCRIPT.json",
     "sha256": "cfd7121cc6a643dd131f0510976d24632dff3f73f9e6219c77a1b5246a7bcde0"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END.json",
     "sha256": "bca1b28bfa41d7d4ab7bbe5b64c136e7522d2502c1e611d601b61aae58650d48"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CONFORMANCE.json",
     "sha256": "babe4feb127b022e3f98a718ca4d392539b00a75db4888be17e5b3dd7a64c104"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MALICIOUS.json",
     "sha256": "cddf88ff01c9f37824370340ca237498c7a9fbb441cebffe146bc18157b1e38a"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "a9afc983be48b26b0a4e8ab734c4d23774a51fc2741b8c5247828dad5d723bbe"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SECURITY_RESULTS.json",
     "sha256": "b7e70f2356b9988f803e44b703ef40e8f825511c8e33fdf9b21e6f39d02bc760"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "92e6dd921e44f24e92f22de22b616283ff9865b3320b8b243d9b54e9c196c86c"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SCALE_RESULTS.json",
     "sha256": "b41b148349a5c89166bc1871d4851f53ad92359730228e68aa189b18bdef6007"
    },
    {
     "bundle": "e33-governed-agentic-operating-fabric-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e33.py.txt",
     "sha256": "ca5574308977f7660ce00c8e65f9a5dccc3a8a3b8b37a22478cc237442b1a7d9"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E33-OPERATING-FABRIC",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library, not hosted and not wired into the gateway, MCPGate or the clusters; the sidecar runs locally over stdio against a reference world; adapters are in-process reference adapters; the Governance Cloud is NOT DEPLOYED; Go/REST/gRPC SDKs NOT IMPLEMENTED; code execution is a whitelisted pure-function runner; no content steganalysis; mutation self-test targeted per component; large scale rows routing/hashing only; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 33 (governed agentic operating fabric) is a TESTED library: 22 kinds of agent operation run one explicit 16-state lifecycle; executed operations pass the E32 overlay, E30, E28, E25 and E8 and carry an E31 proof; state-changing operations run inside sealed executors behind E8; governance mutations are routed to their governing engine and never executed; a signed, versioned ABI and a stdio sidecar let an agent that imports nothing from CAIN be governed. 581/581 invariants hold; 2029/2029 scenarios held; mutation 12/12 (targeted); a 27-step loop passes; 11 tests pass; the clean-room verifier returns INTACT (2603/2603 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e33.py <bundle dir>  (see e33-governed-agentic-operating-fabric-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E34_EVIDENCE_BUNDLE.json",
     "sha256": "5af99eca483770511d09ecaebf72f788125f51863bcb519d93bc86a29b354d81"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ENVELOPES.json",
     "sha256": "c83ce59c53ce241eab77378f6b70e16ed96f2a45adadd9f0dc6f492fd9495e55"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "PRIMITIVES.json",
     "sha256": "6ae77551a476ba3fb97b433c01250c51e6b0508e9f157492d4bd3bce6ef32b57"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "DELEGATION.json",
     "sha256": "831d5299332e6c1fdf464967898b18bdfbb06c068a33b620c2b8074be8b4ec3f"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "DISCLOSURE.json",
     "sha256": "d7f4bdef9ecb65d1fa91bcbb474b1d4546449d20a3ec90dd372e08614ca574e9"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END.json",
     "sha256": "d8d6a69abebe70ecf6c5c32f27767daa36d7a3cd8298e1c82897694c993e3d0a"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MALICIOUS.json",
     "sha256": "c2b7d497caa0e48efe02630744e294e32003e19fa22bf853dc095d6525f7ff54"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "75e00f377e385dd8965faf0704fd54fcee52eb0b047fe1d7507364e6c28fd67a"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SECURITY_RESULTS.json",
     "sha256": "2e361b4b5cd38f0198d20f57ac668029d6b44b0d83791ccc0b2938ffcb99cec9"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "36cb6376daa6bda47da043aef36cd4cfbbab278ddb304894ade0fc6a22502689"
    },
    {
     "bundle": "e34-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e34.py.txt",
     "sha256": "2a1fdf67b085f8fafbff1a74b04f7d568d722f469241e73711b1f9d2c4e8092c"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E34-PROOF-CARRYING-AGENCY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library, not hosted; zero-knowledge proofs NOT implemented (salted commitments + Merkle only); interchange protocols are reference adapters; physical/vehicle/robot boundaries refused not governed; Proof Exchange, federation and marketplace are library surfaces only; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 34 (proof-carrying machine agency) is a TESTED library: every governed operation yields one signed, chained GovernanceProofEnvelope binding identity, capability, delegation, authority, policy, evidence, risk, decision, the E8 commit, the enforcement boundary, execution and outcome, and stating what remains UNKNOWN or outside the boundary; fourteen statuses, per-layer proof primitives, an enforcement proof that separates decision from authorization, commit, enforcement, execution and outcome, attenuation-checked delegation proofs, RFC 6962 selective disclosure, denials and incident proofs; a proof is never permission. 629/629 invariants hold; 2664/2664 scenarios held; mutation 12/12; 22 forged objects rejected; 13 tests pass; the clean-room verifier returns INTACT (3286/3286 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e34.py <bundle dir>  (see e34-proof-carrying-machine-agency-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E39_EVIDENCE_BUNDLE.json",
     "sha256": "631877e7bdf41eb900305e721c63184e6d5dd01b2b39fbd3ce64d27917c185ad"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_MISSION_COMPILER.json",
     "sha256": "380258972a06b555788595c9b4ca7b74f9c23abe9de0f2129c0610dead8da0f5"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_FACTORY_PROOFS/DEPLOYMENT_MANIFEST.json",
     "sha256": "4d725b4f989d50b8b5be15db41e3ae0e92380d7d883ba6d7f0e25330c69817f1"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_FACTORY_PROOFS/EVALUATIONS.json",
     "sha256": "87b38c7a0e7fece3e9225c312974549c6c1f86fa065e9ded7a364284ef12b696"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_AGENT_PROOFS/ACTION_PROOFS.json",
     "sha256": "9c1657d357b607e489070ab4aa899572f774d9f47295240cc8a663089799f3a5"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_CONFORMANCE/CONFORMANCE.json",
     "sha256": "b5f8af83dbb8ebddd8f8baea1a727b47d4c059f04d6df6449b9918b17f8276d2"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_INVARIANTS.json",
     "sha256": "c54747a035c81c3264e70fa39d14515f9a8ea84543d7c72b6f45760b68c0b8c4"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_ATTACKS.json",
     "sha256": "d9eb9d03040a7e2adf26c43f347c5996bc36657e3817fcb85e43951380501bf2"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_MUTATION.json",
     "sha256": "84060bfab995cd64a9667b2f0113cb4652018d2802980d6d9f5e564c4abbbd16"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MALICIOUS.json",
     "sha256": "2a7d9f48b5a2956dfa322a5b084ae568e256c1608ce5c539a8d6ae10497f0e1b"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_CLEANROOM/verify_e39.py.txt",
     "sha256": "09332a417887b44549e0ebbfec70542abd0306e28471cc4352a89c4d2b6ff899"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E39-AGENT-FACTORY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library on one host; the world run provisions a handful of real governed agents, scale runs create records only; the mission compiler is deterministic (not an LLM); model routing is over registry entries; twins and 1M/10M action runs are SIMULATED; the factory API is not hosted; conformance counterparts are mocks; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 39 (governed agent factory) is a TESTED library: a mission compiles into a bounded specification whose authority envelope never exceeds the sponsoring principal, a minimal machine organization in which every agent's authority is a subset of the mission envelope and every child's a subset of its parent's, and a workflow whose consequential tasks are gated; agents are red-teamed and evaluated independently (self-certification refused), promoted only by CAIN, provisioned as real governed identities, and their consequential tasks run through the kernel and E8 with E38 action proofs; a retired agent cannot act. 4 real agents provisioned and 3 tasks executed in the 16-step loop; 1041/1041 invariants hold; 3441/3441 adversarial scenarios held; mutation 16/16; conformance 13/13; 19 tests pass; the clean-room verifier returns INTACT (3307/3307 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e39.py <bundle dir>  (see e39-governed-agent-factory-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E38_EVIDENCE_BUNDLE.json",
     "sha256": "bbad2b1a28347dac7e6e4605490d5d0fe5d7e14c5122018285ddb7f1e97f2cce"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E38_PROOF_EXAMPLES/PROOF_CASES.json",
     "sha256": "362238d63e31aa2f61b32e3aec17795d0d79462fcfb776bb69f84f073bf0dfbd"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E38_REVOCATION/MEASUREMENT.json",
     "sha256": "fbdefc48dd52db38f3a399cdb062708d15bed9cceb7b54eed910b89b6e10425a"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E38_TRANSLATION/TRANSLATIONS.json",
     "sha256": "7c74fb5e8bde7fbb3365ab895d8d389cb1f8fc2fa306ceddf1e69a4e37026469"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E38_FEDERATION/FEDERATION.json",
     "sha256": "2b19fda01b379240153c41f3a3f667ab12b701b1f0916d83384af69214d32d88"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E38_CONFORMANCE.json",
     "sha256": "91bcfb901d5524fe9a4c65af05301ef1560710a5f0e5009b50e1e07d7de2d557"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E38_INVARIANTS.json",
     "sha256": "ed45a6a816f36f685bd7988e645232104b40edfb7b83e55a40633f917ae567d5"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E38_ATTACKS.json",
     "sha256": "ed8b158542779f42e63f3c37bf735c714e00ef5c82b3981f05e87f19933cbbc5"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E38_MUTATION.json",
     "sha256": "0f1cf2743638cdbe6e99a59df79c1b014df98ad3097ab1c2e1d06af73c712c56"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MALICIOUS.json",
     "sha256": "e5795ca48519af771197d2e1da2891546a1300dd18aa5efaf1ad332313068933"
    },
    {
     "bundle": "e38-proof-carrying-machine-agency-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E38_VERIFIER/verify_e38.py.txt",
     "sha256": "9730535dd196959faa41114d66ff44296b0232dc4754cea50cbfacdfe0dadcf4"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E38-PROOF-CARRYING-AGENCY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library on one host; the second trust domain and the conformance counterparts are reference/mock implementations; CAIN-GIP is a reference layer, not an Internet, MCP or A2A standard; zero-knowledge proofs NOT implemented; hardware attestation UNKNOWN; third-party verification NOT AVAILABLE; network revocation latency NOT TESTED; a proof shows governance conditions and provenance, not safety; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 38 (portable proof-carrying machine agency) is a TESTED library: every real governed action (kernel + E8 commit + E34 envelope + E37 receipt) yields twelve signed layer proofs and one action proof binding identity, delegation, authority, policy, risk, evidence, authorization, the E8 commit, the enforcement boundary, execution, outcome and environment, with no secrets. A verifier with no CAIN code recomputes VALID / INVALID / INCOMPLETE / STALE / REVOKED / UNKNOWN for every published proof case. A proof is never authority: partial, stale, revoked, simulated, confused or unbound proofs are never VALID; revocation propagation is measured and its exposure window counted; translation declares every lost field; handshakes and federation never create or merge authority. 5 real action proofs and 41 proof cases; 1030/1030 invariants hold; 2141/2141 adversarial scenarios held; mutation 15/15; 0 of 19 injected faults made proof state more permissive; 20 tests pass; the clean-room verifier returns INTACT (509/509 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e38.py <bundle dir>  (see e38-proof-carrying-machine-agency-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E37_EVIDENCE_BUNDLE.json",
     "sha256": "886b37740e3a1e34e74c10d8dca23316bfbe217e680b7abbc26f17f2b4a86a73"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E37_EXECUTION_RECEIPTS.json",
     "sha256": "7805e708e1fda6989b082581ff499654e8d22e2401c07a617f1276508be2a9ae"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E37_MIGRATION_TESTS.json",
     "sha256": "7ad1511400ea9ebb2397cc382b3c61f62c05a734266873fb8c420c222e82aebb"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E37_COVERAGE.json",
     "sha256": "c71101b15a0fb56526d058b72b34357469224e13281a51eb99b134563d1dea10"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E37_RUNTIME_PASSPORTS.json",
     "sha256": "c8c71d306161f46a03ccde35875d4eaf53dd448acafdeac548cc83ce86cfc59c"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E37_CHAOS.json",
     "sha256": "667657576d08ce3b25ec4e208cd211f1973f7e7be50a8121094f5606b135dc12"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E37_INVARIANTS.json",
     "sha256": "347bdbf3168777c7818622f4c5fb5f541cad59ba0111be6eef27439f4bec0fb5"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E37_ATTACKS.json",
     "sha256": "0c9011a8733add7452b27178868ee4dd8ae86b57c4abf4f725b59a17486a25a5"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E37_MUTATION.json",
     "sha256": "e92f2dbcde8e999bcda2777de7801980efbcde59f9f5d6b84fd0ce937add572a"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MALICIOUS.json",
     "sha256": "1e8082f3e67df2ccafdf670979613d60414d34caa2afc046b2362d22df7b915d"
    },
    {
     "bundle": "e37-autonomous-execution-mesh-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e37.py.txt",
     "sha256": "75f4d7f14a62c20c56b98828ff87547acba360245acf3283e4e3d8b47292c661"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E37-AUTONOMOUS-EXECUTION-MESH",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library on one host; declared destinations, regions and clouds are governance records, not deployed nodes; hardware attestation UNKNOWN (no TEE); adapters tested against a reference harness only; cloud targets ARCHITECTURE; the governance quorum is in-process, not the networked PBFT cluster; scale runs are single-host; no customers; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 37 (autonomous execution mesh) is a TESTED library: every governed execution runs IDENTITY -> CAPABILITY -> AUTHORITY -> POLICY -> CONTEXT -> EXECUTION ENVIRONMENT -> ACTION -> E8 -> ENFORCEMENT -> OUTCOME -> PROOF -> REASSESSMENT over the real kernel, sealed executor, E8 commit boundary and E34 proof envelope, and leaves a signed receipt whose E8 commit matches the envelope. Moving an execution (node, runtime, model, region, container, credential) is a governed state transition: authority can only shrink, a material change needs a new epoch, continuity tokens cannot exceed existing authority, and risk, spent budget, revocations, transaction limits, evidence, reputation and incident state cannot be reset. UNKNOWN, OBSERVED and MONITORED never become ENFORCED; claims take the weakest boundary. 71 signed execution receipts; 1132/1132 invariants hold; 2720/2720 adversarial scenarios held; mutation 17/17; chaos 16/16 faults contained with 0 false allows; 16 forged objects rejected; 21 tests pass; the clean-room verifier returns INTACT (2627/2627 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e37.py <bundle dir>  (see e37-autonomous-execution-mesh-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E39_EVIDENCE_BUNDLE.json",
     "sha256": "631877e7bdf41eb900305e721c63184e6d5dd01b2b39fbd3ce64d27917c185ad"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_INVARIANTS.json",
     "sha256": "c54747a035c81c3264e70fa39d14515f9a8ea84543d7c72b6f45760b68c0b8c4"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_ATTACKS.json",
     "sha256": "d9eb9d03040a7e2adf26c43f347c5996bc36657e3817fcb85e43951380501bf2"
    },
    {
     "bundle": "e39-governed-agent-factory-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E39_CLAIMS.json",
     "sha256": "d8f0153a46c38999be65afbbab3e59d34c1cc7ecf7179711cf1d8a49385d83f1"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E39-GOVERNED-AGENT-FACTORY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library, not hosted; deterministic, no LLM; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 39 (governed agent factory) is a TESTED library: a mission compiles into a bounded specification whose authority envelope never exceeds the sponsoring principal, a minimal machine organization in which every agent's authority is a subset of the mission envelope and every child's a subset of its parent's, and a workflow whose consequential tasks are gated; agents are red-teamed and evaluated independently (self-certification refused), promoted only by CAIN, provisioned as real governed identities, and their consequential tasks run through the kernel and E8 with E38 action proofs; a retired agent cannot act. 4 real agents provisioned and 3 tasks executed in the 16-step loop; 1041/1041 invariants hold; 3441/3441 adversarial scenarios held; mutation 16/16; conformance 13/13; 19 tests pass; the clean-room verifier returns INTACT (3307/3307 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e39.py <bundle dir>  (see e39-governed-agent-factory-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E36_EVIDENCE_BUNDLE.json",
     "sha256": "ec21b49b6c0856fae5f54082f59cc9fc8fe40a11ab4be9dac2ea3cc6c87e24b5"
    },
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "EXCHANGE.json",
     "sha256": "c1f33919c76ed9aa6596e1d5bd18ae630be632c5005da9b9a7e967795a968f7d"
    },
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END.json",
     "sha256": "0c1ea07212057364ae56d2bd7ee33e6c443eb841f1d3e89c467e2c02a951e2be"
    },
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E36_MARKET_MODEL.json",
     "sha256": "471ade0a9b8d3be8d76db51152e6da675d6f415d4aff671476dd6e1625327e08"
    },
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E36_PUBLIC_EXAMPLES.json",
     "sha256": "e08b5a8a70abc3ef82f4db23e2d416beb50bf959e02e35c7b4297ab167167cc2"
    },
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MALICIOUS.json",
     "sha256": "fcd782ee95854025320c52fd9294b281b730356e80ada19f78a8c6153e787371"
    },
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "837b31084233cf8e3449c5a765153d92854dc0679e49070c8e9cd43d2f4d13c9"
    },
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SECURITY_RESULTS.json",
     "sha256": "67eca83f959b57ad75df56d844ba37d1d185b029a1fb0e9b112b171cf8c7f51b"
    },
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "e3136897d1946aed74d08988400b933af88c0a7df91b28b5ecc3a1e82d80abb6"
    },
    {
     "bundle": "e36-machine-agency-exchange-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e36.py.txt",
     "sha256": "37ed74e7ef0716159a6cc0199f2b1c5750ffd2f2d80da8e60e2504a9b2dc7b13"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E36-MACHINE-AGENCY-EXCHANGE",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library, not a deployed network; the directory and marketplace are local registries; NOT a bank, custodian or regulator; settlement units SYNTHETIC, no payment rail; CAIN-MSDP experimental; A2A/MCP via reference adapters only; dispute/arbitration not legal advice; no insurance or underwriting; no customers or market data; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 36 (machine agency exchange) is a TESTED library: a governed exchange where machine services are discovered, verified, negotiated with, contracted, hired and transacted with along the lifecycle DISCOVER -> IDENTIFY -> VERIFY -> EVALUATE -> NEGOTIATE -> CONTRACT -> AUTHORIZE -> EXECUTE -> PROVE -> SETTLE -> RATE -> REASSESS -> RENEW_OR_REVOKE. Governability-aware discovery never upgrades UNKNOWN to MATCH; a service chain produces identity/authority/contract/capability/execution/proof/settlement proof chains; a subcontractor's authority cannot exceed its parent's. No economic object is authority: CONTRACT != AUTHORITY, REPUTATION != AUTHORITY, PAYMENT != AUTHORITY. CAIN is not a bank, custodian or regulator; settlement units are SYNTHETIC. 842/842 invariants hold; 3340/3340 economic/governance scenarios held; mutation 15/15; a 13-step exchange lifecycle passes; 15 forged objects rejected; 14 tests pass; the clean-room verifier returns INTACT (3601/3601 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e36.py <bundle dir>  (see e36-machine-agency-exchange-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E35_EVIDENCE_BUNDLE.json",
     "sha256": "fbc0f2a94e5ab7ad6a7a0c59a671300bbfb7a1010e56121c1ffd7d666ca03d9d"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INTELLIGENCE.json",
     "sha256": "8febd56917bc7b0dc5460dc86e89250d2135d68e14156811b8b3253d6004cbb6"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "COUNTERFACTUALS.json",
     "sha256": "e5567aaeab877c5762ba4c3cc829c635d60813e4bbe27379490e018a50387eb0"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "OBLIGATIONS.json",
     "sha256": "da39592a1e0e56a1ad5d9dd6a195bc1b429d1f15be0e71a825bb49d1a4d6784d"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "KNOWLEDGE_GRAPH.json",
     "sha256": "598784fc8a9b292b6dc3cf6392f673aa66944352a66b0b55fa3e06f575f5317e"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END.json",
     "sha256": "95a9d400fdfb03d0fa326b4d034bbdecb5c9c65efdd79cf6c53da3060af64592"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MALICIOUS.json",
     "sha256": "45da77bd1af09a243123fd057754e5f7efa55f7e5667e06108f72be4f0aa1492"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "d9a78c8d76ab5d13c8017f87ecd70f269befe7a9d0c4f08067e18f964a7e4c38"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SECURITY_RESULTS.json",
     "sha256": "50ae0bd7f44946dbd81ea3ba21d3c22617516de25677ed3b1ac55d495fe7fdab"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "098de18c9b293bdbc9bde9f0ed6b9bda8dd1729be59846524bb89de0c9bca03c"
    },
    {
     "bundle": "e35-governance-intelligence-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e35.py.txt",
     "sha256": "bc5ccdeef5752667d2e89bdb54dbcfc72a6cd96a066d9b6461ad6231a35961f1"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E35-GOVERNANCE-INTELLIGENCE",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library, not hosted and NOT in the trusted root; predictions modelled over synthetic features, not calibrated against real incidents; red/blue team, lab, tournament and marketplace run in-process with no external ecosystem; internal multi-dimensional views, not certifications; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 35 (continuous governance intelligence) is a TESTED library placed deliberately outside the trusted authorization root: it observes with provenance, scores risk across dimensions without ever collapsing into one number, predicts with explicit confidence, assumptions, horizon and unknowns, calibrates by dimension, explores counterfactuals that are never facts, and recommends; a learned control is deployed only after a deterministic review and a canary, and the reviewed action still passes the kernel and E8. Learning never creates authority. 799/799 invariants hold; 3544/3544 scenarios held; mutation 15/15; a 23-step loop passes; 16 forged objects rejected; 12 tests pass; the clean-room verifier returns INTACT (3810/3810 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e35.py <bundle dir>  (see e35-governance-intelligence-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E32_EVIDENCE_BUNDLE.json",
     "sha256": "e173cdbc247dbe027efb0e0d7f7dc107a8127da30c33c18235d2697518a49de1"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "LOOP.json",
     "sha256": "aa319857436b2416e731a0a7c91c76d8cb14ebbf6989cf721a0baa407f792797"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "ARENA.json",
     "sha256": "2010175a8b31382cc9471033b5baca817c9addd8bf3e89706fd429b3bd906c01"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "PROMOTION.json",
     "sha256": "2a13eac3d2b1bbd15d1262768d991d6b32d7cf622e2ec21b8ac94d3a61a70c02"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CONFIG_CHAIN.json",
     "sha256": "49989a7aa99c9c0cdb81d162adc39f7e84d5570b1a325a5300d3556e17b5a4cd"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "DRIFT.json",
     "sha256": "24c3f101620a4a1aee526677bcef72b925551f5ac10f24403b7193f16c655b0a"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "PREDICTIONS.json",
     "sha256": "caf9bc55b30691865bc8fbc95d709b898511bd27a6f8c9a7e6dbe00e9af6e3d2"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SELF_REPAIR.json",
     "sha256": "f2767931d31e13d57ea3bab7053db7464c4b8190767880d3e002884014e04843"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MALICIOUS.json",
     "sha256": "da8d8077c3f6c1386f012d46b8c3c012544e97e2692d754a83c5c5b9e3bb2ad7"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "a7e8582447f1c77485e20c047371f2641ca918be81f093f03215e45a9d1ad322"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SECURITY_RESULTS.json",
     "sha256": "43b323ce51df0ab192fec75e6bf854127172ea4b8d76a3f0863b64bf2fd22d89"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "c34a1a8eceebb3c5c52d7aef4d6ba2c0797b44eb28563aa7eeda15dbe8eb544b"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SCALE_RESULTS.json",
     "sha256": "44bcce28c664f3db0685ed131c059acedbbf772becf5bef7b34d6634e0ca457c"
    },
    {
     "bundle": "e32-governed-autonomy-learning-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e32.py.txt",
     "sha256": "94cd1a94c4056b04ba1cc2b7f3f718858fa4f93773a3358d3bb703cf0a307266"
    }
   ],
   "category": "AUTHORIZATION",
   "claim_id": "C42-E32-GOVERNED-LEARNING",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library, not hosted; learning results are SIMULATED (synthetic workload, labelled harm oracle), not learned from production traffic; learning can only change a restrict-only overlay; world models are small statistical learners; hidden set hidden from code, not from host access; one human reviewer key; no external research sources ingested; large scale rows learn without execution or hash only; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 32 (governed autonomy learning fabric) is a TESTED library: a 17-step learning loop over real governed actions mines failures, compiles restrict-only candidate rules, sandboxes them in fresh worlds, scores them on a 15-dimension vector against a hidden set committed in advance, self-plays, diffs, canaries and promotes only through a signed gate with a registered human approval; no learning path can widen authority, and a deny-everything strawman is rejected. In a SIMULATED run, harm that got through fell from 41 to 3. 303/303 invariants hold; 1013/1013 scenarios held; mutation 12/12; 13 tests pass; the clean-room verifier returns INTACT (1420/1420 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e32.py <bundle dir>  (see e32-governed-autonomy-learning-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E31_EVIDENCE_BUNDLE.json",
     "sha256": "93441adfb102ee7df48d92c0688e55150ad691db9e609bbc0fec45a9cf1eaa29"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "PROOF_EXAMPLES.json",
     "sha256": "60982ee573f895fd95c4d7ee415da2f79854cb73356793b11f9bbb52005899c4"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "TRUST_ANCHORS.json",
     "sha256": "265ff83f94c68da17ca1042d085b993107407ae2bef440f225e2320b1af204eb"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "TRANSPARENCY_LOG.json",
     "sha256": "8c293680bd3c01b119a5620c56ab36ab9dcad7c377ec889d68dc7d3e98273793"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MALICIOUS_PROOFS.json",
     "sha256": "e8b9e02124109c4698029c710d0c47cee6403eef091f0a0fc06b8761e37d1e1f"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "GOVERNANCE_OBJECTS.json",
     "sha256": "a6fd7fd1a29ed4216b542f0df4dfc35dbffb14af664b3220d73f3fd6f1f5fa77"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "2e491f258a4c95ebc823c9952e2ecada3c0799836784422410d2174c18212bdb"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SECURITY_RESULTS.json",
     "sha256": "7e1a4bb47534f334bbee6e032f6c477df33a869a195f6f63ca5e62a19ee70fde"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "e369e92d60ee2357e3d122a7948b80c9ff5d796c79b7b63ea43e93405b90ccc8"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SCALE_RESULTS.json",
     "sha256": "f5d109f534b07bee9a0208a14be1cdfa20fe7d411e7b677c544dc05a73a5fcd3"
    },
    {
     "bundle": "e31-universal-proof-of-governance-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e31.py.txt",
     "sha256": "b3c6994800e686e9564673d0d51546e48c05d68da847f6af51dd45e2a6127ea7"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E31-PROOF-OF-GOVERNANCE",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process library, not hosted and not wired into the gateway, MCPGate or the clusters; witnesses are separate code and keys in the same process, not separate organizations; CAIN-GIP carriers are in-process adapters and CAIN-GIP is not a standard; trust anchors are published with the proofs; no trusted time source; partition not addressed; G0-G8 is CAIN's internal profile; scale rows synthetic; ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 31 (universal proof-of-governance fabric) is a TESTED library: every allowed action run through the proof kernel yields a signed GovernanceProof bound to 16 action fields and to four independently signed or hash-chained artifacts (E30 action receipt, E28 governance receipt, E25 execution receipt, E8 kernel evidence), every refusal yields a signed failure proof, the five enforcement layers are recomputed from the artifacts and never collapsed, proofs sit in an append-only RFC 6962 log, and a proof is evidence, never authority. 252/252 invariants hold; 1269/1269 scenarios held; mutation 12/12; conformance G8 on CAIN's internal profile; 15 tests pass; the TypeScript verifier returns INTACT and detects tampering; the clean-room verifier returns INTACT (1676/1676 checks, no CAIN imports) and rejects all 88 forged proofs.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e31.py <bundle dir>  (see e31-universal-proof-of-governance-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "CAIN42_E30_EVIDENCE_BUNDLE.json",
     "sha256": "593fca95b7a63ebf340714181f27e4a216770fe36d4929baedeb11227507e368"
    },
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "E2E_ARTIFACTS.json",
     "sha256": "1761ee10d0051e61287f07eb6025ccdb5b86c0914ce1498e68b5ddf42f4f574a"
    },
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "END_TO_END.json",
     "sha256": "850d24504f7a1329d1bebef1525fb0a0fd91904545af8707b182ee14104e0d17"
    },
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "INVARIANTS.json",
     "sha256": "5decd699d62b4d43a3d6abb412a6569e1dd179ae15e5df8680939f31b0d081a1"
    },
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SECURITY_RESULTS.json",
     "sha256": "291704d32d93b39f169e93dd5199c4c4a0f8403787db7708f0cf9b880c804692"
    },
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "MUTATION_RESULTS.json",
     "sha256": "12436ab308723800ee3b10c78bb3c977a8a910399ae56d3379d02b95cdec36d6"
    },
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "COVERAGE_MAP.json",
     "sha256": "5e7bad103c51f7c8887f3476723552fbdad77a28b3a1d674ab75356827932e4d"
    },
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "TYPESCRIPT_SDK_RESULTS.json",
     "sha256": "75f5d964fbccc77802c7cfb2a2cd4f4ff158257a8a836d0825fd21c8080acad2"
    },
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "SCALE_RESULTS.json",
     "sha256": "79e01b9b5aea2f6bc9b8f36e0bf247c382900721d59d5e63e16d06df380baecf"
    },
    {
     "bundle": "e30-governed-machine-autonomy-2026-09-30",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "verify_e30.py.txt",
     "sha256": "ae2b0707d29f0aec8dce8065452ef647b8e10d28722a41a48dc0aa1d0b4ef4e3"
    }
   ],
   "category": "ARCHITECTURE",
   "claim_id": "C42-E30-MACHINE-AUTONOMY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 4,
   "evidence_level_meaning": "adversarial verification",
   "limits": "in-process integration library, not hosted and not wired into the gateway, MCPGate or the clusters; paths outside the E25/E8 boundary are UNCONTROLLED or UNKNOWN and physical actuators are refused, not governed; perception agreement is not physical truth; injection detection is a marker list with UNKNOWN recall; the TypeScript SDK verifies only; research engine and frontier lab are registers; 10,000/100,000-agent rows synthetic; ephemeral build key; PRE-PRODUCTION",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Evolution 30 (governed machine autonomy fabric) is a TESTED integration library: every consequential agent action is normalized into a 20-field universal machine action, checked against autonomy state, autonomy level, a signed budget ledger, containment, environment, perception, memory and intent, executed only through E28 -> E25 -> E8, and recorded in a signed, hash-chained universal action receipt whether it was allowed or refused; no agent can promote its own autonomy level, self-improvement passes a staged firewall with a human review and canary, and a coverage map reports UNCONTROLLED and UNKNOWN paths. 166/166 invariants hold; 889/889 scenarios held; mutation 11/11; a 28-step end-to-end run passes; 11 tests pass; the TypeScript verifier returns INTACT and detects tampering; the clean-room verifier returns INTACT (1187/1187 checks, no CAIN imports).",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_e30.py <bundle dir>  (see e30-governed-machine-autonomy-2026-09-30/REPRODUCTION.md)"
  },
  {
   "artifacts": [
    {
     "bundle": "mcpgate-residency-2026-09-29",
     "cluster_ids": [],
     "environment": "SIMULATED",
     "file": "RESIDENCY_RESULTS.json",
     "sha256": "4f3dbb942cfe27ee54eee97117a356601fbb53255ab6c3f371996399d06894a5"
    }
   ],
   "category": "MCP ENFORCEMENT",
   "claim_id": "C42-MCPGATE-SCHEMA-RESIDENCY",
   "claim_version": 1,
   "evidence_environment": [
    "SIMULATED"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "the flag is OFF in production, so no production traffic has used it; A+++ gate 6 passes on the proxy code path, the overall A+++ verdict stays BLOCKED; single-host in-process measurements",
   "public_label": "SIMULATED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "An authorization-aware MCPGate router library keeps tool schemas in PINNED, HOT, WARM, COLD or EVICTED context residency by a deterministic score (frequency, recency, task similarity, dependencies, tenant affinity) and never lets residency decide a call: every call's schema is the canonical, digest-checked one, the CAIN authorizer receives no residency information and its DENY is final even for a flooded HOT tool, an evicted tool is still callable only through full authorization, canonical schemas are never deleted, every decision is hash-chained evidence, and limits produce backpressure. Measured on one host: active context 6-31x smaller than exposing every schema (50-1,000 tools). It is wired into the MCPGate proxy (cain/mcp_proxy.py) behind CAIN_MCP_RESIDENCY: with residency on and off every tools/call decision is identical, and 20 of 20 bypass tests pass.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "in the repository: python3 -m pytest -q tests/test_mcp_residency_router.py; bundle integrity: MANIFEST.json"
  },
  {
   "artifacts": [
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "MANIFEST.json",
     "sha256": "eae407b62ada12d041469ca7bf152d60c920300674f245eeed02d352c8f71894"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "BUILD_MANIFEST.json",
     "sha256": "73c2eef47cfd125f20569f16eb6d67dd7bae8d6e8de327ae9f153024c488a1b5"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "DEPLOYMENT_ATTESTATION.json",
     "sha256": "1f024bd40627590c096262ffa3d604e2b69c7b35f312216835ac478479cf4834"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "SBOM.cdx.json",
     "sha256": "06fd9361f4fae497042e534409f491a9e4f2fe6fc2b6593598a847effb2e5a22"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "TEST_VECTORS.json",
     "sha256": "31dd775521e4694fe22a90289d8df9a6890aec74e12350126dc60b2307b75253"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "verify_proof_fabric.py.txt",
     "sha256": "c5788943a71a73a049a1eb3616a5ad98092c12b03f8f1bc09b7a1188b56dc816"
    }
   ],
   "category": "EVIDENCE",
   "claim_id": "C42-PUBLIC-PROOF-FABRIC",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 5,
   "evidence_level_meaning": "reproducible public verification",
   "limits": "software measurement by the operator, not hardware attestation; the gateway has no build step and its source is not public, so the artifact can be hash-checked but not rebuilt by a stranger; the performance index shows every published benchmark lacks at least one required condition",
   "public_label": "LIVE VERIFIED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "The CAIN-42 public proof fabric is published and verifiable by anyone: a build manifest and per-file artifact list of the running gateway (990 source files, 958 byte-identical to the commit, the other 32 named), a CycloneDX SBOM (177 installed distributions with content hashes) and a dependency-drift record, a deployment attestation (deployment id, configuration hash of non-secret switches, running code == artifact, hardware attestation NOT AVAILABLE), a test manifest from a real run with its JUnit XML, 76 public test vectors, a provenance graph, a failure ledger, and Byzantine and performance indexes, all signed by the evidence-root key; a clean-room verifier recomputes every value.",
   "status": "VERIFIED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "REPRODUCIBLE",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric-2026-09-28/  (see its REPRODUCE.txt)"
  },
  {
   "artifacts": [
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "TEST_MANIFEST.json",
     "sha256": "53e44b5cfcc4343a5a495c2671ce545c55cba6d8bc0a143d60eb3a39209645da"
    },
    {
     "bundle": "proof-fabric-2026-09-28",
     "cluster_ids": [],
     "environment": "LIVE",
     "file": "verify_proof_fabric.py.txt",
     "sha256": "c5788943a71a73a049a1eb3616a5ad98092c12b03f8f1bc09b7a1188b56dc816"
    }
   ],
   "category": "EVIDENCE",
   "claim_id": "C42-TEST-SUITE-RUN",
   "claim_version": 1,
   "evidence_environment": [
    "LIVE"
   ],
   "evidence_environment_source": "derived from the cluster_id recorded in each artifact's bundle",
   "evidence_level": 2,
   "evidence_level_meaning": "automated test evidence",
   "limits": "operator-run on the gateway host, not independent CI; the suites need the repository, which is not public",
   "public_label": "IMPLEMENTED",
   "revalidate_by": "2026-10-31T03:20:13Z",
   "statement": "A real run of the defined CAIN-42 suites (site, l5-governance, hypervisor, mcp-enforcement, byzantine, gateway): 1857 tests, 1842 passed, 0 failed, 0 errors, 7 skipped, 8 expected failures (documented known gaps). Each test is listed with its purpose, category, file hash and JUnit evidence.",
   "status": "TESTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": true,
    "result": null,
    "state": "TESTED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric-2026-09-28/  (checks the totals against the published JUnit XML)"
  },
  {
   "artifacts": [],
   "category": "COMPLIANCE",
   "claim_id": "C42-THIRD-PARTY-REVIEW",
   "claim_version": 1,
   "evidence_environment": [
    "OFFLINE"
   ],
   "evidence_environment_source": "declared: no review exists; nothing to observe",
   "evidence_level": 0,
   "evidence_level_meaning": "claim only",
   "limits": "none exists",
   "public_label": "NOT ESTABLISHED",
   "revalidate_by": "2026-12-30T03:20:13Z",
   "statement": "Independent third-party review or certification (SOC 2, ISO 27001, FedRAMP, ...).",
   "status": "NOT_IMPLEMENTED",
   "status_model": {
    "independently_verified": false,
    "publicly_reproducible": false,
    "result": null,
    "state": "CLAIMED",
    "superseded_by": null
   },
   "supersedes": null,
   "verification_method": "-"
  }
 ],
 "evidence_root_public_key_b64": "t1I4vBpOasgbBSWYTN2g7xL1En7qZ6lhgbt6n2OpeG8=",
 "git_commit": "f871727ce81c01a854e0ac0f07abbea19a4d0b3e",
 "issued_at": "2026-10-01T03:20:30Z",
 "key_epoch": 1,
 "label_rule": "public_label = f(status, evidence_environment): FAILED; UNVERIFIED/NOT_IMPLEMENTED -> NOT ESTABLISHED; SIMULATED; VERIFIED/REPRODUCIBLE -> '<environments> VERIFIED'; otherwise IMPLEMENTED. A claim past revalidate_by is STALE until re-issued from fresh evidence.",
 "live_clusters": [
  "cain-mr-01",
  "cain-mr-02"
 ],
 "live_topology": {
  "cain-mr-01": {
   "key_fingerprint": "2f46fc4814549cfa551ac58182edca4245e47c3c38251ee11dc847d54bab8e28",
   "members": [
    {
     "node_id": "cain-mr-node-1",
     "provider": "vultr",
     "public_key_b64": "vxjpwp7HlNHusE21m1bcLDy8CwNbErxp9FtJCrctbdE=",
     "region": "atl"
    },
    {
     "node_id": "cain-mr-node-2",
     "provider": "vultr",
     "public_key_b64": "riT7vpUegPEUR8orAqgcpEpdY8YI2mGYXHdkIpju3KE=",
     "region": "lax"
    },
    {
     "node_id": "cain-mr-node-3",
     "provider": "vultr",
     "public_key_b64": "05ABjKsgxxCqhgfZJ9DtjnDENO8kSd82WqLfrRUq6Qw=",
     "region": "lax"
    },
    {
     "node_id": "cain-mr-node-4",
     "provider": "vultr",
     "public_key_b64": "QO/JXphJ858ZBu0wpCXTHcskThjkid68PfsfBjHhaZ0=",
     "region": "mia"
    }
   ],
   "membership_url": "https://cainstudio.online/api/v1/live-cluster/membership?cluster=cain-mr-01",
   "providers": [
    "vultr"
   ],
   "regions": [
    "atl",
    "lax",
    "mia"
   ]
  },
  "cain-mr-02": {
   "key_fingerprint": "5676a770d81add674e35e7765dc935519672099cb10c4ed8745e5284cc2c05ab",
   "members": [
    {
     "node_id": "cain-mr2-node-1",
     "provider": "vultr",
     "public_key_b64": "8P4PCtI04O2rvGpeOufwkU1RJnPdjMjth+L/UcerxI4=",
     "region": "atl"
    },
    {
     "node_id": "cain-mr2-node-2",
     "provider": "vultr",
     "public_key_b64": "u3OhqYRLR2Rys0byPlSE1vHcjPWVSLt3j4XzMv2EwGs=",
     "region": "lax"
    },
    {
     "node_id": "cain-mr2-node-3",
     "provider": "vultr",
     "public_key_b64": "+x/1i4xlleDAdLt6vNaNfFaGVn8yo/N35Ax0mYAv2F8=",
     "region": "mia"
    },
    {
     "node_id": "cain-mr2-node-4",
     "provider": "vultr",
     "public_key_b64": "SqIx0XEixGU8RzpKPmVxA9P6k4udhRFeMx4CPTedc+o=",
     "region": "sjc"
    }
   ],
   "membership_url": "https://cainstudio.online/api/v1/live-cluster/membership?cluster=cain-mr-02",
   "providers": [
    "vultr"
   ],
   "regions": [
    "atl",
    "lax",
    "mia",
    "sjc"
   ]
  }
 },
 "registry": "CAIN42/PUBLIC-CLAIMS/v2",
 "registry_digest": "df4f2fbc3c910dd5e1ebfbe74b03416680b9c99cf8d3c852da7cd7cb4f4f852c",
 "registry_locations": [
  "https://cainstudio.online/proof/bundle/claims/",
  "https://mcpgate.online/proof/bundle/claims/",
  "https://clawx.click/evidence/claims/"
 ],
 "signature_b64": "0jmH9J7JLFfpHsIX66IJBTuv9GrgX2rdDkLGcCESSFSYIxUbHK6CyIUAYn14NmRpdfHXXf91EdaRTTk05O0HBA==",
 "sites": {
  "cainstudio.online": "/proof/bundle/",
  "clawx.click": "/evidence/",
  "mcpgate.online": "/proof/bundle/"
 },
 "status_model": {
  "rule": "CLAIMED: asserted, no evidence; TESTED: automated tests (a FAILED result stays TESTED with result FAILED); VERIFIED: checked; REPRODUCIBLE: VERIFIED and a public verifier anyone can run is published; SUPERSEDED: replaced, kept for history; INDEPENDENTLY_VERIFIED: only by a distinct external process -- none exists",
  "states": [
   "DRAFT",
   "CLAIMED",
   "TESTED",
   "VERIFIED",
   "INDEPENDENTLY_VERIFIED",
   "REPRODUCIBLE",
   "SUPERSEDED",
   "REVOKED"
  ]
 }
}