cainstudio.online
CAIN Studio. The trust runtime and product surface: identity, authority, evidence and verification for autonomous systems.
Verify, don't trust (PRE-PRODUCTION, same-operator evidence, implementation not published): Lab · AI_VERIFY.json · Changelog · Evidence
A security fabric for AI agents. The agent proposes an action. CLAWX decides whether it is allowed, records what happened, and leaves evidence anyone can check.
CAIN Studio. The trust runtime and product surface: identity, authority, evidence and verification for autonomous systems.
MCPGate. The enforcement boundary that sits in front of tool calls, so an action is checked before it runs.
CLAWX. The agent-facing security layer: what an agent, a channel or a person is allowed to do, and proof of what was done.
CAIN decides and enforces. CLAWX governs the agents and the channels they act through. MCPGate is where a tool call is stopped or allowed.
checking the shared runtime…
| Site | Resolves to | HTTPS | Checked |
|---|---|---|---|
| checking… | |||
Checked from this server just now, not cached from a report. A site that does not answer is shown as not answering.
Every number we publish here is a real run, hashed and Ed25519-signed, and checked by a tool that imports none of our code. We publish what did not pass as well. Self-attested by one operator; pre-production. We publish outcomes, not implementation: our source code stays private.
python3 verify_soak.py https://clawx.click/evidence/soak-72h-2026-09-25/ prints VERDICT: RUNNING now, and PASS or FAIL after 72 hours.verify_claims.py. The registry includes 28 executable invariants (all pass; 6 only partially covered, each gap named) and 1,000 agent trajectories. Self-attested, pre-production.cain_proof_verify: VERIFIED.python3 verifiers/cain_proof_verify.py . checks manifest, membership, consensus, authorization, enforcement, execution, evidence chain and DAG, and prints FINAL RESULT: VERIFIED only if every section passes. Disposable cluster on one host; the live MCPGate does not run this gate yet.c188442 committed 20 decisions. Its primary was killed and the survivors changed view (0 to 1) and kept committing. That produced 160 quorum certificates carrying the original Ed25519-signed votes. In a few seconds your browser re-checks every signature, the 3-of-4 quorum, the decision chain and agreement across all four nodes, and it confirms that seven kinds of tampering are rejected (29/29 checks). The cluster ran on one host. Since 2026-09-24 the live cain-vc cluster runs this build too. Its API is not public, and its first two decisions predate certificates.93c8a5f8fe0b3d5a…). A checker probes every node, verifies signatures, derives the Byzantine quorum and prints BFT_F1_ESTABLISHED or NOT_ESTABLISHED with reasons. Recorded verdict on 2026-09-21: NOT_ESTABLISHED (three remote nodes report a quorum of 2 where 3 is required; only one node serves a signed state proof). node2's signed state proof does verify independently. Run --live for the current verdict.26449783615937cc…): 114 attack types exercised, 97 blocked by a real control, 17 inconclusive (no real control to attack yet), 0 succeeded; 222/222 formal invariants; 585 tests passed in a serial run.curl -sO https://clawx.click/evidence/byzantine-cluster-2026-09-21/verify_cluster_bundle.py.txt && mv verify_cluster_bundle.py.txt verify_cluster_bundle.py python3 verify_cluster_bundle.py https://clawx.click/evidence/byzantine-cluster-2026-09-21/ --live
| Capability | Status | Evidence |
|---|---|---|
| Self-audit fabric: assumptions, controls, claims, release gate | BUILT · TESTED | 75 invariants, each proven by an attack test |
| Guards tested by breaking them (mutation testing) | BUILT · TESTED | see evidence |
| Execution gate: claim, graph and context binding | BUILT · TESTED | see evidence |
| Independent verification by a separate party | NOT DONE | the second verifier shares code and process with the first |
| Universal agent adapter, OpenClaw adapter | NOT IMPLEMENTED | planned (CLAWX 21) |
| Telegram and WhatsApp channels, approval cards | NOT IMPLEMENTED | planned (CLAWX 21); needs real accounts to test |
| Prompt-injection firewall, credential broker, trust center | NOT IMPLEMENTED | planned (CLAWX 21) |
| Production deployment at scale | NOT DONE | pre-production; one server, no load testing |
Status is pre-production. Nothing here should be read as a guarantee of security.
The full list is in the evidence page and in the forensic report.