CAIN-42 CLAWX
Archived 2026-09-25: this is the previous homepage, kept as history. It is superseded by the current CAIN-42 homepage, and several claims on it (for example the ticker items, "architectural monopoly", "court-admissible", "production features") are not supported by current evidence. For the current state see /now.html and the signed claims registry.

Verify, don't trust (PRE-PRODUCTION, same-operator evidence, implementation not published): Lab · AI_VERIFY.json · Changelog · Evidence

CLAWX

A security fabric for AI agents. The agent proposes an action. CLAWX decides whether it is allowed, records what happened, and leaves evidence anyone can check.

Verify CAIN-42 yourself: Verification Lab (in-browser Ed25519 checks of the 4-node PBFT fault-test bundle, live signed node state, keyless decision sandbox) · AI_VERIFY.json · Gateway infrastructure is live in production (DNS+TLS+auto-restart, verifiable below); overall system status is PRE-PRODUCTION — one host, no third-party review, BFT rejoin certification not yet passing, no customer traffic yet.

Three sites, one system

cainstudio.online

CAIN Studio. The trust runtime and product surface: identity, authority, evidence and verification for autonomous systems.

mcpgate.online

MCPGate. The enforcement boundary that sits in front of tool calls, so an action is checked before it runs.

clawx.click

CLAWX. The agent-facing security layer: what an agent, a channel or a person is allowed to do, and proof of what was done.

CAIN decides and enforces. CLAWX governs the agents and the channels they act through. MCPGate is where a tool call is stopped or allowed.

Live status of all three sites

checking the shared runtime…

SiteResolves toHTTPSChecked
checking…

Checked from this server just now, not cached from a report. A site that does not answer is shown as not answering.

Verify it yourself. No account, no trust required.

Every number we publish here is a real run, hashed and Ed25519-signed, and checked by a tool that imports none of our code. We publish what did not pass as well. Self-attested by one operator; pre-production. We publish outcomes, not implementation: our source code stays private.

curl -sO https://clawx.click/evidence/byzantine-cluster-2026-09-21/verify_cluster_bundle.py.txt && mv verify_cluster_bundle.py.txt verify_cluster_bundle.py
python3 verify_cluster_bundle.py https://clawx.click/evidence/byzantine-cluster-2026-09-21/ --live

What is built, and what is not

CapabilityStatusEvidence
Self-audit fabric: assumptions, controls, claims, release gateBUILT · TESTED75 invariants, each proven by an attack test
Guards tested by breaking them (mutation testing)BUILT · TESTEDsee evidence
Execution gate: claim, graph and context bindingBUILT · TESTEDsee evidence
Independent verification by a separate partyNOT DONEthe second verifier shares code and process with the first
Universal agent adapter, OpenClaw adapterNOT IMPLEMENTEDplanned (CLAWX 21)
Telegram and WhatsApp channels, approval cardsNOT IMPLEMENTEDplanned (CLAWX 21); needs real accounts to test
Prompt-injection firewall, credential broker, trust centerNOT IMPLEMENTEDplanned (CLAWX 21)
Production deployment at scaleNOT DONEpre-production; one server, no load testing

Status is pre-production. Nothing here should be read as a guarantee of security.

Known gaps

The full list is in the evidence page and in the forensic report.