# CLAWX / CAIN-42: verify, do not trust
> https://clawx.click/llms.txt (same operator as https://cainstudio.online and https://mcpgate.online; all three sites are one gateway on one host; the PBFT cluster spans three regions)
## CAIN-42 current state (generated 2026-10-02T00:50:03Z from the signed claims registry; do not edit)
Machine-readable, signed: https://cainstudio.online/cain42-evidence-index.json (same file on mcpgate.online and clawx.click)
Signed claims registry: https://clawx.click/evidence/claims/CAIN42_FINAL_PUBLIC_CLAIMS.json (2 BENCHMARKED, 2 FAILED, 3 NOT_IMPLEMENTED, 2 SIMULATED, 33 TESTED, 3 UNVERIFIED, 22 VERIFIED)
Production gates: A-O 14 of 15 PASS; P-X 5 of 9 PASS
Verify everything in one command (no CAIN code): curl -so verify_all.py https://clawx.click/verify_all.py.txt && python3 verify_all.py --json
Every public evidence file on the 3 sites, crawled, with its registry status: https://cainstudio.online/proof/bundle/CAIN42_PUBLIC_EVIDENCE_INVENTORY.json (a file no signed claim covers is NOT evidence, whatever status it asserts about itself)
Self-attested: three operators run the clusters, the tests and the signing key; no third party has reviewed or reproduced this. Every VERIFIED item below has a checker that imports no CAIN code. Check, do not trust.
### Live now (ask the system itself)
- cluster_status: https://cainstudio.online/api/v1/live-cluster/status
- cluster_health_mr02: https://cainstudio.online/api/v1/live-cluster/health?cluster=cain-mr-02
- quorum_certificate: https://cainstudio.online/api/v1/live-cluster/qc/{sequence}
- hosted_decision_demo: POST https://cainstudio.online/fabric/try?scenario=safe-read (no account)
- hosted_pipeline_status: https://cainstudio.online/fabric/status
- system_state: https://cainstudio.online/now.json
- proof_every_30_min_mr01: https://clawx.click/evidence/hourly-proof/index.json
- proof_every_30_min_mr02: https://clawx.click/evidence/hourly-proof-mr02/index.json
- soak_72h_latest: https://clawx.click/evidence/soak-multiregion-2026-09-26/latest.json
- daily_restore_validation: https://clawx.click/evidence/restore-validation/latest.json
### VERIFIED (status, claim, how to check, limits)
- C42-PBFT-QC: A 4-node CAIN-42 PBFT cluster produced authentic quorum certificates (>= 3 of 4 pinned Ed25519 members) with an identical decision chain on every node across a primary failover.
check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json (or index.html in a browser) | https://clawx.click/evidence/pbft-evolution2-2026-09-24/REPRODUCE.txt
limits: disposable cluster on one host
- C42-FAST-PATH: The Evolution 3 fast path commits only with all 4 members' votes and its view-change rule was model-checked (the naive rule was shown unsafe); a real run produced FAST_COMMIT_QCs that verify.
check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json | https://clawx.click/evidence/pbft-evolution3-2026-09-24/REPRODUCE.txt
limits: bounded model (single slot, 3 views); not deployed live
- C42-DAG-ORDER: DAG data is availability-certified (3 of 4), anchored only through PBFT, and ordered identically on all 4 nodes including a crash-restarted one; the verifier recomputes the order.
check: python3 verify_dag_bundle.py DAG_CLUSTER_EVIDENCE.json | https://clawx.click/evidence/dag-evolution4-2026-09-24/REPRODUCE.txt
limits: disposable cluster; ordering bias removed in Evolution 5 (measured), fairness beyond position bias not measured
- C42-MCPGATE-ENFORCES: MCPGate lets a tool call run only with a PBFT-committed authorization bound to the exact action, scope, identity, security context, expiry and single use. On the LIVE 4-region cluster cain-mr-02, through the MCPGate HTTP proxy to a separate MCP server process: 5 authorized calls ran (per the server's own execution log) and 12 attacks were blocked, each with a signed denial returned to the caller (replay, action and tool substitution, capability escalation, identity substitution, context drift, forged QC, forged body, post-consensus mutation, another cluster's certificate, no authorization, expiry).
check: python3 verifiers/cain_proof_verify.py . (see mcpgate-live-2026-09-27/REPRODUCE.txt) | https://clawx.click/evidence/cain42-proof-package-2026-09-24/REPRODUCE.txt
limits: self-attested run by the operator; the downstream is a sandbox key-value MCP server; cainstudio.online does not route customer tool calls through this gate
- C42-INDEPENDENT-FAILURE-DOMAINS: Consensus runs on independent geographic failure domains: cain-mr-02 has 4 replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; every server was taken offline in turn and the cluster kept committing, and with two down it refused to commit.
check: python3 verify_host_loss_bundle.py PBFT_QC_BUNDLE.json | https://clawx.click/evidence/four-server-cluster-2026-09-27/REPRODUCE.txt
limits: one provider (Vultr) and one operator: a provider-wide outage or operator compromise is not covered
- C42-LIVE-MULTI-REGION: Two live multi-region clusters: cain-mr-01 (4 replicas, 3 regions, WireGuard) and cain-mr-02 (4 servers, 4 regions); each publishes a 30-minute signed proof of its live state, and every decision carries signatures from at least 2 regions.
check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; python3 verify_hourly_proofs.py | https://clawx.click/evidence/hourly-proof-mr02/REPRODUCE.txt
limits: region placement is stated by the operator
- C42-PARTITION-BYZANTINE: Live network-partition tests (isolated host commits nothing; 2|2 split commits nothing on either side; agreement within ~3 s of heal) one-way (asymmetric) partitions on the 4-server cluster (deaf replica, one-way link, mute replica: commits continued, identical chains after each heal), and Byzantine tests on the production image (forged votes rejected; equivocating primary proven from its own signatures, quarantined and replaced).
check: python3 verify_pbft_qc_bundle.py / verify_byzantine_bundle.py | https://clawx.click/evidence/asymmetric-partition-2026-09-27/REPRODUCE.txt
limits: partitions: whole-host link loss and complete one-way loss (deaf replica, one-way link, mute replica) for 60 s; not flapping links, partial loss, delay or duplication; Byzantine tests on a disposable cluster with the same placement; f=1, two behaviours
- C42-DEGRADED-NETWORK: Safety under a degraded network: with 10% packet loss, 120 +/- 40 ms delay, 5% duplication and reordering on all four replicas' traffic of the live 4-server cluster for 4 minutes, no fork (identical decision chains on all four, 341 certificates each). Liveness degraded sharply: 0.16 commits/s under the impairment versus 1.76/s before (39 of 61 writes committed within the client's 30 s timeout; p95 7173.9 ms), and fully recovered after (2.02/s, p95 644.0 ms). Re-run after engine 948b189 (backoff resets only on progress): 44 of 62 committed, 0.18/s, view changes cut from 14 to at most 6; throughput did not improve beyond noise, so the view-change storm was not the bottleneck. Safety held again.
check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json | https://clawx.click/evidence/degraded-network-2026-09-27/REPRODUCE.txt
limits: VERIFIED is for safety only; throughput under loss is a measured weakness, not a pass; one impairment profile, one client host
- C42-DISASTER-RECOVERY: Disaster recovery on the live clusters: two replicas lost their storage at once and were rebuilt only from off-host backups in other regions (0 of 4 writes committed while quorum was lost; 0 decisions lost; identical height and state 10.3 s after restart); a single replica restored from a snapshot in 8.3 s under writes. Hourly backups of both clusters are copied to another region; every day each replica's newest off-host backup is proven to be a quorum-signed prefix of the live history.
check: python3 verify_pbft_qc_bundle.py PBFT_QC_BUNDLE.json; daily: python3 verify_restore_validation.py --key | https://clawx.click/evidence/restore-drill-2026-09-26/REPRODUCE.txt
limits: same provider; backups not encrypted at rest (they hold consensus data that is public by design; identity keys are never backed up); loss of 3 of 4 not drilled; the daily validation checks restorability of every off-host backup, it does not restore into a running replica
- C42-ROLLBACK: Live rollback to the previous engine and forward again, one replica at a time with the primary last; every replica caught up in 10-14 s, cluster HEALTHY 4/4 after each direction.
check: compare the per-step status in ROLLBACK.json
limits: both engines share one storage format
- C42-REPRODUCIBLE-RELEASE: The 4-server cluster runs an image that rebuilds bit-for-bit from its commit (two independent from-scratch builds produced the deployed image ID); pinned base and packages, SBOM, Ed25519-signed release manifest.
check: python3 verify_release_manifest.py RELEASE_MANIFEST.json
limits: source not published: the rebuild is reproducible by the operator; outsiders can check the manifest signature and digests
- C42-HOSTED-CONSENSUS: The hosted Fabric orders every recorded decision through the live PBFT cluster; since 2026-09-27 the gateway itself verifies the commit quorum certificate (>= 3 pinned Ed25519 signatures over the digest it computes for that decision) and a replica's unproven 'COMMITTED' counts as a denial. Each decision shows the check (certificate hash, signers), and GET /fabric/decisions/{id}/integrity re-checks a STORED decision against the commitment the quorum signed (consensus_anchor); every stored decision record is also Ed25519-signed by a key kept outside the database (GET /fabric/decision-signing-key).
check: python3 verify_hosted_decision.py --live https://cainstudio.online membership.json (see REPRODUCE.txt) | https://clawx.click/evidence/hosted-consensus-2026-09-27/REPRODUCE.txt
limits: enforce mode is the default for every tenant since 2026-09-27 (GET /fabric/status: mode enforce); a tenant may opt down to shadow mode (logged), in which case its verdicts are recorded but not enforced
- C42-DECISION-RECORD-SIGNING: Every hosted Fabric decision record written since 2026-09-27 is signed: the gateway signs the record's SHA-256 digest with an Ed25519 key kept outside its database, so a database writer who alters a record and recomputes its digest is detected. The published record's digest is recomputed from its own fields by a verifier with no CAIN code, the signature verifies against the key served by another site, and two tampered copies (verdict changed; verdict changed with the digest recomputed) both fail.
check: python3 verify_decision_record.py record.json --key https://mcpgate.online/fabric/decision-signing-key --self-test (see REPRODUCE.txt) | https://clawx.click/evidence/decision-signing-2026-09-27/REPRODUCE.txt
limits: does not protect against root on the gateway host, which holds both key and database; records before 2026-09-27 are unsigned; the full row of a live decision is not public (the demo shows the gateway's own check)
- C42-FORMAL-VERIFICATION: TLA+ models of the PBFT commit/view-change rules and of the MCPGate authorization gate, checked exhaustively by TLC within stated bounds: no violation of Agreement, CommitOnlyWhenPrepared, no-execution-without-quorum, action/identity/context binding, expiry or single use; every deliberately broken variant (pre-fix execute rule, NEW_VIEW ignoring reports, weakened quorum, each gate check removed) is caught with a counterexample.
check: java -cp tla2tools.jar tlc2.TLC -deadlock (see formal-2026-09-27/REPRODUCE.txt) | https://clawx.click/evidence/formal-2026-09-27/REPRODUCE.txt
limits: bounded models (N=4, f<=1, one sequence, two views; small action/identity/context/time domains), not a proof about the Python code; no machine-checked proof for unbounded parameters
- C45-ZOD-LIVE: Agent Hypervisor / ZoD runtime: an agent acts only inside a ZoD whose authorization the live cluster cain-mr-01 committed with a quorum certificate the hypervisor checks itself; code ran under real confinement (bubblewrap namespaces + cgroup v2, no network); 10 attacks were refused, each a signed DENIED entry in a hash-chained log.
check: python3 verify_cain45_zod.py . (see cain45-zod-live-2026-09-27/REPRODUCE.txt; expect 10 PASS and VERIFIED) | https://clawx.click/evidence/cain45-zod-live-2026-09-27/REPRODUCE.txt
limits: the hypervisor ran as a library on the gateway host, operator-run, not as a deployed service in front of customer agents; the approval is the operator's; software measurement only (no TPM/TEE); no seccomp filter; egress is deny-all only (no allowlist)
- C42-E6-AUTHORITY-LEASES: Evolution #6 authority leases: for each of 9 conditions a ZoD authorized by the live cluster cain-mr-01 made one successful tool call, the condition was tripped, and the next call was refused without the tool running -- TTL expiry, trust below floor, agent identity swapped, tool schema changed, security context changed, trajectory fork, explicit revocation, parent quarantined (child loses authority), required evidence deleted (that row is SELF-REPORTED: hypervisor-signed, since the log proving it is the one deleted).
check: python3 verify_e6_lease.py . (see e6-live-lease-2026-09-28/REPRODUCE.txt; expect 48/48 checks, VERIFIED) | https://clawx.click/evidence/e6-live-lease-2026-09-28/REPRODUCE.txt
limits: the invalidation logic runs in the hypervisor library on the gateway host, not on the cluster nodes -- the cluster supplies the authority being invalidated; invalidation on policy, epoch or membership change and risk/blast-radius budgets are NOT implemented; the separate 4-node 'authoritative state' layer in cain45/ is SIMULATED and not used here
- C42-E7-AUTHORITY-LAPSE: Evolution #7: authority granted by the live cluster cain-mr-01 lapses -- the next tool call is refused and the tool never runs -- when the policy root changes or cannot be read, when the risk or blast-radius budget is spent, and when a delegate has spent its parent's budget (delegates are charged up the whole chain, so splitting work cannot multiply authority). Every ZoD is bound to the cluster's real membership configuration, recomputed and quorum-agreed, re-read before every action; a changed epoch, a changed membership or an unknown membership refuses.
check: python3 verify_e7_lease.py . (see e7-lease-2026-09-28/REPRODUCE.txt; expect 60/60 checks, VERIFIED) | https://clawx.click/evidence/e7-lease-2026-09-28/REPRODUCE.txt
limits: the 3 membership/epoch trips are INJECTED into the hypervisor's view (the live cluster was not re-keyed); the policy and budget trips are real; enforcement is the hypervisor library on the gateway host, not the cluster nodes; only CALL_MCP_TOOL budgets were exercised live (classes C0-C4 unit-tested)
- C42-E8-GOVERNED-EVOLUTION: Evolutions #8/#9: a policy -- the authority ceiling for a tenant's ZoDs -- becomes active only when the live cluster cain-mr-01 commits its activation; an expansion needs a registered human who is not the proposer (an agent's self-approved expansion was refused and never reached the cluster); a restriction needs no human and revoked a running ZoD's authority; a ZoD above the ceiling was refused. A world-model prediction, a simulated ALLOW citing a real certified sequence, a 10-agent signed vote and a replayed memory were each presented as the basis for authority and each refused because the live cluster had not certified it.
check: python3 verify_e8_governance.py . (see e8-governance-2026-09-28/REPRODUCE.txt; expect 19/19 checks, VERIFIED) | https://clawx.click/evidence/e8-governance-2026-09-28/REPRODUCE.txt
limits: scripted identities, not a real LLM agent; CAIN contains no world model, digital twin or learning memory -- the run shows that such OUTPUTS cannot become authority; governor and hypervisor are a library on the gateway host, the cluster orders and certifies
- C42-CAG-L5-HOSTED-GOVERNOR: The CAG-L5 system governor runs in the production gateway (CAIN_SYSTEM_GOVERNOR=1): /fabric/mcp/enforce refuses every tenant without a registered, governance-signed system manifest and every request not signed by the agent's registered key, and for a registered system applies policy precedence, the agent/delegator/system/lease authority intersection, model identity, tool registry, emergency controls and cluster-certified governance state. On the live gateway, through all three public domains: 13/13 cases as expected (in-scope read allowed on each domain; unregistered tenant, unsigned, key substitution, replay, outside system authority, model swap, subagent WRITE, unlisted tool and emergency freeze refused; one-operator recovery refused, two-operator recovery restored service); governance state certified by cain-mr-01 (3 signers); 8/8 decision signatures valid; 18-event chain verifies.
check: python3 verify_hosted_governor_run.py CAIN42_CAG_L5_HOSTED_LIVE_RUN.json --live (see cag-l5-hosted-governor-2026-09-28/REPRODUCE.txt) | https://clawx.click/evidence/cag-l5-hosted-governor-2026-09-28/REPRODUCE.txt
limits: operator self-test tenant and a scripted agent -- no customer and no LLM agent governed end to end; the endpoint returns a signed verdict and commitment, the caller's gate executes; CAG-L5 is CAIN's own governance designation, not SAE Level 5; see the matrix for which capabilities are only PARTIAL
- C42-L5-ADAPTIVE-HOSTED-EVOLUTION: The Prompt 6 evolution gate is wired into the production gateway and MCPGate: after registration an agent's model and MCP tool configuration change only through it (agent-signed proposal, tenant-evaluator-signed report, operator approval that is never the proposer), and a deployed change gives a new capability commitment, so the old cluster certificate and every lease stop authorizing until cain-mr-01 certifies the new commitment and a lease is re-issued. Live, through all three public domains: 17/17 enforcement cases as expected (model swapped outside the gate, old lease after a capability change, the disabled tool on each domain and the rolled-back model refused; the enabled tool, the upgraded model and the restored version allowed); gate refusals: no evaluator report REJECT, authority-widening tool change QUARANTINE and undeployable, unapproved model REJECT, deploy without approval or with the agent's own approval refused, agent-signed rollback refused; 4 cain-mr-01 certifications (sequences 22515, 22517, 22518, 22517) whose own records carry each certified commitment; 42-event chain verifies; a clean-room verifier recomputes all 5 hosted evolution decisions (VALID). Found and fixed on the way: the certified governance state did not cover the MCP tool map or per-agent tool configuration.
check: python3 verify_hosted_evolution_run.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN.json --live ; python3 verify_adaptive_bundle.py CAIN42_L5_HOSTED_EVOLUTION_LIVE_RUN_EXPORT.json (see l5-hosted-evolution-2026-09-28/REPRODUCE.txt) | https://clawx.click/evidence/l5-hosted-evolution-2026-09-28/REPRODUCE.txt
limits: operator self-test tenant, scripted agent and scripted evaluator -- no customer and no LLM agent; hosted evolution covers MODEL and TOOL_CONFIGURATION only (authority is never evolvable; memory/skill/model-router registries are not hosted); rollback is operator-signed, automatic regression rollback is not wired; the evaluator's raw measurements are not recomputed; PRE-PRODUCTION
- C42-TRUST-INTEGRITY-LIVE: A caught attacker no longer gains autonomy on the production gateway. Before 2026-09-28 a new account that sent two prompt injections (both BLOCKED) fell from UNKNOWN to DEGRADED trust, which the matrix answered more permissively than UNKNOWN, so its $250,000 transfer, rm -rf / and DROP TABLE came back ALLOWED. Now the trust matrix is monotone with a runtime floor (no state carrying negative evidence beats UNKNOWN), the independent verifier builds its table from a published spec instead of copying production, every action is scored by tool class, destructiveness, amount and target (high and critical go to a human), deny rules match every spelling of a path, trust is per agent and capped by its key, a trust hold is queued for approval, an approval binds the call's arguments, and an account can mint agent keys so the agent asks and the owner approves. Live, with a fresh free account on each of cainstudio.online, mcpgate.online and clawx.click: every case as specified, including the solo-developer path (agent held, cannot approve itself, owner approves, retry runs, its next low-risk call runs with no approval, a critical action is still held), and all 48 decisions match cain-mr-01's own public record (decision id, verdict, commitment, 3-of-4 commit certificate); clean-room verifier VALID.
check: python3 verify_trust_integrity_run.py CAIN42_TRUST_INTEGRITY_LIVE_RUN.json --live (see trust-integrity-2026-09-28/REPRODUCE.txt) | https://clawx.click/evidence/trust-integrity-2026-09-28/REPRODUCE.txt
limits: action risk reads the tool name and arguments the agent declares, so a tool whose name hides what it does is scored on its arguments only; decision latency is unchanged (about 1.2 to 14 s in this run); signup has no email delivery or captcha; operator-run accounts, no customer traffic; no third-party review; PRE-PRODUCTION
- C42-PUBLIC-PROOF-FABRIC: The CAIN-42 public proof fabric is published and verifiable by anyone: a build manifest and per-file artifact list of the running gateway (990 source files, 958 byte-identical to the commit, the other 32 named), a CycloneDX SBOM (177 installed distributions with content hashes) and a dependency-drift record, a deployment attestation (deployment id, configuration hash of non-secret switches, running code == artifact, hardware attestation NOT AVAILABLE), a test manifest from a real run with its JUnit XML, 76 public test vectors, a provenance graph, a failure ledger, and Byzantine and performance indexes, all signed by the evidence-root key; a clean-room verifier recomputes every value.
check: python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric-2026-09-28/ (see its REPRODUCE.txt) | https://clawx.click/evidence/proof-fabric-2026-09-28/REPRODUCE.txt
limits: software measurement by the operator, not hardware attestation; the gateway has no build step and its source is not public, so the artifact can be hash-checked but not rebuilt by a stranger; the performance index shows every published benchmark lacks at least one required condition
### NOT verified (stated so nobody has to guess)
- C42-FAST-PATH-LATENCY [BENCHMARKED]: negative result; host CPU-bound
- C42-AGENTS-CANNOT-SELF-AUTHORIZE [SIMULATED]: scripted agents, not LLMs; attestation SIMULATED; in-process
- C42-INVARIANTS [TESTED]: executable tests, not formal verification; see each invariant's coverage/gap
- C42-1000-TRAJECTORIES [SIMULATED]: in-process; scripted agents
- C42-ORDERING-FAIRNESS [BENCHMARKED]: position bias only; censorship and economic bias not measured
- C42-LIVE-CLUSTER-EVO2 [UNVERIFIED]: live cluster API is private; its first two decisions predate certificates
- C42-PRIVACY-FIREWALL [TESTED]: pattern-based; not a guarantee against every leak class
- C42-MULTI-PROVIDER [NOT_IMPLEMENTED]: every server is on Vultr; needs a second provider account
- C42-HARDWARE-ATTESTATION [NOT_IMPLEMENTED]: none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); attestation fields in security contexts are declared hashes, not hardware quotes; needs servers with that hardware
- C42-SOAK-72H [FAILED]: liveness failure, not a safety failure; one host; not the production cluster; the soak nodes ran image soak72-1b28cf3, without the fix; a passing 72-hour run on the fixed build is still required
- C42-SOAK-72H-MULTIREGION [FAILED]: one missing hourly enforcement proof, not a safety failure: consensus agreement held throughout; the cause of the hour-32 timeout is not yet diagnosed; a 72-hour run in which every checkpoint carries enforcement evidence is still required
- C42-CAG-L5-SYSTEM-GOVERNANCE [TESTED]: reference system with ephemeral keys, run in one process; the live counterpart is C42-CAG-L5-HOSTED-GOVERNOR
- C42-L5-TRAJECTORY-GOVERNANCE [TESTED]: library; ephemeral keys; the hosted governor uses it for every decision but long live trajectories were not run
- C42-L5-TRAJECTORY-FAIL-OPEN-FOUND [TESTED]: the 'before' column is the recorded probe output, not re-runnable from git history
- C42-L5-IDENTITY-AUTHORITY [TESTED]: library; the hosted L5 identity router is opt-in (CAIN_L5_GATEWAY) and off
- C42-L5-UNIFIED-V1-SUPERSEDED [UNVERIFIED]: kept for history; must not be read as a current claim
- C42-LEGACY-SELF-ASSERTED [UNVERIFIED]: self-asserted by earlier releases; no certification body, no reproducible verifier; found by the public evidence inventory (CAIN42_PUBLIC_EVIDENCE_INVENTORY.json)
- C42-L5-ADAPTIVE-EVOLUTION [TESTED]: in-process library, NOT wired into the hosted gateway or MCPGate; deterministic reference runner, no LLM; no multi-day run; role keys are generated fresh for each build, so the bundle shows internal consistency and decision correctness, not provenance, and it is not signed by the evidence-root key; PRE-PRODUCTION
- C42-E15-SPATIAL-PHYSICAL [TESTED]: in-process library exercised against a REFERENCE robot adapter and a reference kinematic simulator; CAIN-42 is not a vehicle or a robot, drives nothing and does not guarantee physical safety; no real sensor, vehicle, robot or actuator integration (NOT_IMPLEMENTED); sensor keys are software keys (hardware attestation UNKNOWN); world-model accuracy and sim-to-real fidelity UNKNOWN; real-world attack validation NOT_PERFORMED; not hosted; single host; proof signed with an ephemeral build key; no third-party review; PRE-PRODUCTION
- C42-E17-MULTI-AGENT [TESTED]: in-process library exercised against a governed REFERENCE collective; CAIN-42 deploys no fleet, robot, drone, vehicle or customer collective and drives nothing; no real sensor/actuator integration and no deployed multi-agent collective (NOT_IMPLEMENTED); no hardware attestation (UNKNOWN); Sybil-detection completeness and the semantic truth of observations, predictions or causal claims are UNKNOWN; world-model accuracy and sim-to-real fidelity UNKNOWN; real-world attack validation and third-party review NOT_PERFORMED; not hosted; single host; proof signed with an ephemeral build key; PRE-PRODUCTION
- C42-E18-4D-SPATIAL [TESTED]: in-process library exercised against a governed REFERENCE 4D world; CAIN-42 contains no autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack and drives nothing; no real vehicle / drone / robot / sensor / actuator / airspace integration (NOT_IMPLEMENTED); no physical safety guarantee and no certified autonomy (NOT_IMPLEMENTED); hardware attestation (UNKNOWN); world-model and prediction accuracy and sim-to-real fidelity (UNKNOWN); real sensor validation and real-world adversarial validation (NOT_PERFORMED); third-party review (NOT_PERFORMED); not hosted; single host; proof signed with an ephemeral build key; PRE-PRODUCTION
- C42-E19-GOVERNED-AUTONOMY [TESTED]: in-process library exercised against a governed REFERENCE system (a digital agent, a vehicle abstraction, a drone abstraction, a collective and a human in the E18 4D world); execution in the scenario is SIMULATED; CAIN-42 drives, flies and controls nothing and guarantees no physical safety (NOT_IMPLEMENTED); not hosted (NOT_IMPLEMENTED); semantic truth of beliefs and outcomes and hardware attestation UNKNOWN; multi-host behaviour UNVERIFIED; real-world adversarial validation and third-party review NOT_PERFORMED; single host; proof signed with an ephemeral build key; PRE-PRODUCTION
- C42-E20-AGENTIC-INSTITUTIONS [TESTED]: in-process library exercised against deterministic REFERENCE institutions; every economy, market and settlement is SIMULATED over abstract units and real money is refused (real financial settlement NOT_IMPLEMENTED); control of any real economy, society, agent population, vehicle, drone or robot NOT_IMPLEMENTED; not hosted (NOT_IMPLEMENTED); the 10,000-agent / 1,000-institution runs are single-process simulations; multi-host behaviour UNVERIFIED; collusion-detector recall and semantic truth of evidence UNKNOWN; real-world adversarial validation and third-party review NOT_PERFORMED; proof signed with an ephemeral build key; PRE-PRODUCTION
- C42-E21-OPEN-ENDED-INTELLIGENCE [TESTED]: in-process library exercised against a deterministic SYNTHETIC research problem; it contains no scientific model and runs no real laboratory; scientific truth of any hypothesis UNKNOWN (E21 checks how evidence was produced, not whether a hypothesis is true); novelty only against a supplied corpus; collusion by controllers off-system UNKNOWN; not hosted (NOT_IMPLEMENTED); the 100,000-agent / 100,000-hypothesis runs are single-process SIMULATIONS; multi-host behaviour UNVERIFIED; research bounties SIMULATED; real-world adversarial validation and third-party review NOT_PERFORMED; does not create AGI, solve alignment or guarantee safe self-improvement; proof signed with an ephemeral build key; PRE-PRODUCTION
- C42-E23-META-INTELLIGENCE [TESTED]: in-process library; the performance model is synthetic; not hosted; bundle status INCOMPLETE pending the full regression gate; ephemeral build key; PRE-PRODUCTION
- C42-E24-AGENTIC-INTERNET [TESTED]: in-process library; protocol adapters normalise reference messages and are not network servers; no third-party agent governed; economics SIMULATED; the 10,000-agent run is a single-process model; PRE-PRODUCTION
- C42-E25-MACHINE-AGENCY [TESTED]: in-process library plus a reference HTTP service; cross-organization, third-party and hardware-attestation gates NOT VERIFIED; OAuth/OIDC mapped, not implemented; PRE-PRODUCTION
- C42-E26-AGENCY-TRUST [TESTED]: in-process library; hardware attestation, zero-knowledge proofs and third-party interoperability NOT VERIFIED; PRE-PRODUCTION
- C42-E27-CONTROL-PLANE [TESTED]: in-process library; kernel/eBPF enforcement, OTLP export, real identity federation and research capabilities NOT IMPLEMENTED; its mutation self-test covers only 2 mutants; PRE-PRODUCTION
- C42-E28-EXECUTION-IDENTITY [TESTED]: in-process library, not hosted; the envelope is a CAIN experimental reference protocol with no external adoption; zero-knowledge proofs NOT IMPLEMENTED; hardware attestation UNKNOWN; cross-domain revocation does not propagate; one mutant (the E28 replay cache) survives because E25 stops the same replays; scale runs synthetic and in-process; ephemeral build key; PRE-PRODUCTION
- C42-E29-MACHINE-TRANSACTIONS [TESTED]: in-process library, not hosted; synthetic TEST units only, real currencies refused, no payment rail; reference agents in one process; competitive radar has no researched competitor data; no novelty claimed; no moat adopted; 10,000/100,000-agent rows synthetic; ephemeral build key; PRE-PRODUCTION
- C42-E33-OPERATING-FABRIC [TESTED]: in-process library, not hosted and not wired into the gateway, MCPGate or the clusters; the sidecar runs locally over stdio against a reference world; adapters are in-process reference adapters; the Governance Cloud is NOT DEPLOYED; Go/REST/gRPC SDKs NOT IMPLEMENTED; code execution is a whitelisted pure-function runner; no content steganalysis; mutation self-test targeted per component; large scale rows routing/hashing only; PRE-PRODUCTION
- C42-E34-PROOF-CARRYING-AGENCY [TESTED]: in-process library, not hosted; zero-knowledge proofs NOT implemented (salted commitments + Merkle only); interchange protocols are reference adapters; physical/vehicle/robot boundaries refused not governed; Proof Exchange, federation and marketplace are library surfaces only; PRE-PRODUCTION
- C42-E39-AGENT-FACTORY [TESTED]: in-process library on one host; the world run provisions a handful of real governed agents, scale runs create records only; the mission compiler is deterministic (not an LLM); model routing is over registry entries; twins and 1M/10M action runs are SIMULATED; the factory API is not hosted; conformance counterparts are mocks; PRE-PRODUCTION
- C42-E38-PROOF-CARRYING-AGENCY [TESTED]: in-process library on one host; the second trust domain and the conformance counterparts are reference/mock implementations; CAIN-GIP is a reference layer, not an Internet, MCP or A2A standard; zero-knowledge proofs NOT implemented; hardware attestation UNKNOWN; third-party verification NOT AVAILABLE; network revocation latency NOT TESTED; a proof shows governance conditions and provenance, not safety; PRE-PRODUCTION
- C42-E37-AUTONOMOUS-EXECUTION-MESH [TESTED]: in-process library on one host; declared destinations, regions and clouds are governance records, not deployed nodes; hardware attestation UNKNOWN (no TEE); adapters tested against a reference harness only; cloud targets ARCHITECTURE; the governance quorum is in-process, not the networked PBFT cluster; scale runs are single-host; no customers; PRE-PRODUCTION
- C42-E39-GOVERNED-AGENT-FACTORY [TESTED]: in-process library, not hosted; deterministic, no LLM; PRE-PRODUCTION
- C42-E36-MACHINE-AGENCY-EXCHANGE [TESTED]: in-process library, not a deployed network; the directory and marketplace are local registries; NOT a bank, custodian or regulator; settlement units SYNTHETIC, no payment rail; CAIN-MSDP experimental; A2A/MCP via reference adapters only; dispute/arbitration not legal advice; no insurance or underwriting; no customers or market data; PRE-PRODUCTION
- C42-E35-GOVERNANCE-INTELLIGENCE [TESTED]: in-process library, not hosted and NOT in the trusted root; predictions modelled over synthetic features, not calibrated against real incidents; red/blue team, lab, tournament and marketplace run in-process with no external ecosystem; internal multi-dimensional views, not certifications; PRE-PRODUCTION
- C42-E32-GOVERNED-LEARNING [TESTED]: in-process library, not hosted; learning results are SIMULATED (synthetic workload, labelled harm oracle), not learned from production traffic; learning can only change a restrict-only overlay; world models are small statistical learners; hidden set hidden from code, not from host access; one human reviewer key; no external research sources ingested; large scale rows learn without execution or hash only; PRE-PRODUCTION
- C42-E31-PROOF-OF-GOVERNANCE [TESTED]: in-process library, not hosted and not wired into the gateway, MCPGate or the clusters; witnesses are separate code and keys in the same process, not separate organizations; CAIN-GIP carriers are in-process adapters and CAIN-GIP is not a standard; trust anchors are published with the proofs; no trusted time source; partition not addressed; G0-G8 is CAIN's internal profile; scale rows synthetic; ephemeral build key; PRE-PRODUCTION
- C42-E30-MACHINE-AUTONOMY [TESTED]: in-process integration library, not hosted and not wired into the gateway, MCPGate or the clusters; paths outside the E25/E8 boundary are UNCONTROLLED or UNKNOWN and physical actuators are refused, not governed; perception agreement is not physical truth; injection detection is a marker list with UNKNOWN recall; the TypeScript SDK verifies only; research engine and frontier lab are registers; 10,000/100,000-agent rows synthetic; ephemeral build key; PRE-PRODUCTION
- C42-MCPGATE-SCHEMA-RESIDENCY [TESTED]: the flag is OFF in production, so no production traffic has used it; A+++ gate 6 passes on the proxy code path, the overall A+++ verdict stays BLOCKED; single-host in-process measurements
- C42-TEST-SUITE-RUN [TESTED]: operator-run on the gateway host, not independent CI; the suites need the repository, which is not public
- C42-THIRD-PARTY-REVIEW [NOT_IMPLEMENTED]: none exists
### Gates still open
- O Independent reproduction: NOT YET -- no third party has reproduced the results yet
- R Hardware attestation: BLOCKED -- none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); nothing is labelled hardware-attested. Needs servers with that hardware
- T Independent security review: NOT YET -- no third party has reviewed CAIN-42
- V Multi-provider failure domains: NOT YET -- every server is on one provider (Vultr); needs a second provider account
- W 72-hour production soak: RUNNING -- A clean 72-hour soak is running now on the live multi-region cluster cain-mr-01: continuous writes, a random replica killed on its own host every 20 minutes, and a signed hash-chained checkpoint every hour carrying a fresh MCPGate-enforced authorization and its refused replay. soak clock: loading… T
Status: live, self-attested: the same operator runs the cluster, the tests and the signing key. Every item below is a real run,
hashed and Ed25519-signed, and can be re-derived by a checker that imports no CAIN code.
## Four-server cluster cain-mr-02 (2026-09-27)
4 PBFT replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; any single server can fail.
Live: https://clawx.click/api/v1/live-cluster/health?cluster=cain-mr-02 resilience: https://clawx.click/api/v1/live-cluster/resilience?cluster=cain-mr-02
Whole-server loss evidence (264 certificates, verifier 40/40):
for f in verify_pbft_qc_bundle.py verify_host_loss_bundle.py; do curl -so $f https://clawx.click/evidence/four-server-cluster-2026-09-27/$f.txt; done
curl -so B.json https://clawx.click/evidence/four-server-cluster-2026-09-27/PBFT_QC_BUNDLE.json && python3 verify_host_loss_bundle.py B.json
Limit: one provider (Vultr); a provider-wide outage is not covered.
## Live multi-region PBFT cluster (deployed 2026-09-26)
cain-mr-01: 4 PBFT replicas on 3 hosts in 3 regions (Atlanta, Los Angeles x2, Miami) over WireGuard; n=4, f=1, quorum 3; auto-restart on crash and reboot.
Is it operational right now? Ask it: https://clawx.click/api/v1/live-cluster/status
Watch and verify in a browser (every Ed25519 vote checked client-side): https://clawx.click/live-cluster.html
Fault-injection run on the live cluster (336 certificates, standalone verifiers 49/49):
for f in verify_pbft_qc_bundle.py verify_multi_region_bundle.py; do curl -so $f https://clawx.click/evidence/multi-region-cluster-2026-09-26/$f.txt; done
curl -so MULTI_REGION_BUNDLE.json https://clawx.click/evidence/multi-region-cluster-2026-09-26/PBFT_QC_BUNDLE.json && python3 verify_multi_region_bundle.py MULTI_REGION_BUNDLE.json
Limits: one operator, one provider; placement operator-attested; losing the two-replica Los Angeles host halts progress (never unsafe). Superseded as the primary cluster by cain-mr-02 (one replica per server, above).
## Byzantine cluster: probe it yourself
Bundle: https://clawx.click/evidence/byzantine-cluster-2026-09-21/manifest.json (bundle root 93c8a5f8fe0b3d5ae91e53581162bbf7...)
curl -sO https://clawx.click/evidence/byzantine-cluster-2026-09-21/verify_cluster_bundle.py.txt && mv verify_cluster_bundle.py.txt verify_cluster_bundle.py
python3 verify_cluster_bundle.py https://clawx.click/evidence/byzantine-cluster-2026-09-21/ --live
It probes every node directly, verifies Ed25519 state-proof signatures, derives N, f and the Byzantine quorum 2f+1, and prints
BFT_F1_ESTABLISHED or NOT_ESTABLISHED with reasons. Recorded verdict on 2026-09-21: NOT_ESTABLISHED (three remote nodes report a quorum
of 2 where 3 is required; only one node serves a signed state proof; the other nodes report no software version). node2's signed state
proof verifies independently; the consensus logic passes its tests (120 tests, 10 files). No fault was injected into the live cluster.
Run --live for the current verdict, not this text.
## Hardening round (defects found by attacking our own controls)
https://clawx.click/evidence/hardening-2026-09-21/manifest.json checker: verify_bundle.py.txt in that directory
## Frontier bundle
https://clawx.click/evidence/frontier/manifest.json checker: verify_frontier_bundle.py.txt
## Byzantine experiments with raw signed messages
https://clawx.click/evidence/frontier/bft/honest.json (also equivocation.json, crash_one_node.json, crash_two_nodes.json, forged_and_relabeled_votes.json, byzantine_wrong_commitment.json) checker: https://clawx.click/evidence/frontier/verify_bft_evidence.py.txt (stdlib + cryptography, imports no CAIN code)
Real OS processes with their own keys on ONE host (test harness, N=4, quorum 3): honest, wrong-commitment node, equivocating node (cryptographic proof derived from the messages), forged and relabeled votes,
one crashed node, two crashed nodes. A liveness bug it found is preserved as crash_one_node__before_fix.json. This does NOT establish f=1 for the live cluster (see the verdict above).
## Daily evidence
https://clawx.click/evidence/daily/latest.json
Files are published with a .txt suffix where needed because this site only serves .html .css .js .json .txt .ico .svg .xml.