Skip to content
One system, three sites
CAIN-42 CLAWX
Every hosted decision is ordered by a live 4-replica PBFT quorum4-node Byzantine consensus: 3-of-4 Ed25519 quorum certificatesSurvives network partitions and a Byzantine replicaEvery decision signed, hash-chained and verifiable offlineTLA+ model-checked: 7.3M states, 0 violationsDAG dissemination anchored and ordered by PBFTA tool call routed through MCPGate runs only with a quorum-committed authorization; calls that bypass the gate are not governed by itIn the CAIN-45 hypervisor, agent authority is a short-lived, single-use leaseAn agent cannot grant itself a new capability (tested with scripted agents)Hosted governor returns a signed verdict; your gate executes itA caught attacker loses autonomy; risk-weighted decisionsPhysical-action library: nine digests behind a single-use permit (reference simulator)Two replicas' storage lost at once: 0 decisions lostLive rollback and forward under traffic, no quarantinesThe deployed image rebuilds bit-for-bit4 replicas on 4 servers across 4 regionsConsensus live across three regions over WireGuardLive cluster — watch and verify nowProof: what is live nowVerify every claim yourselfVerification CenterDownload the evidence packSBOMFormal models (TLA+)Test reportFault-injection proofHosted-consensus proofMCPGate enforcement proofL5 hosted-evolution proofSpatial & physical proofStorage-loss drillRollback drillFour-server clusterFrontier AI research & proofChangelogLab

Don't trust CAIN-42. Verify CAIN-42.

Here are the receipts

Every public claim about CAIN-42 is listed below with its evidence. Your browser downloads each file, recomputes its fingerprint (SHA-256) and checks the signature itself; nothing on this page asks our servers whether the evidence is valid. A claim that is only tested, or only claimed, says so.

Verifier Room — verify CAIN-42 yourself, in seconds

You do not have to trust us or contact us. Every evidence bundle below ships a clean-room verifier that imports none of CAIN-42's code. Copy one block into a terminal on your own computer: it downloads that bundle and its verifiers, and runs two checks. verify_publisher.py must print PUBLISHED_BY_PINNED_KEY: the bytes are exactly what the CAIN publisher key signed, so an edited or re-signed bundle fails. The bundle's own verifier must then print "result": "INTACT": its internal hashes and signatures agree. You need both. Nothing on these sites is needed after the download.

Requires Python 3 and internet. The verifiers read published data only; they never touch the live service and never call our servers for a verdict. A changed byte in any bundle file makes the verifier report BROKEN. INTACT alone means only that the bundle agrees with the key shipped inside it, which anyone who re-signs a bundle can arrange. That is why every block also runs verify_publisher.py (verifier, pinned key at /.well-known/cain-publisher-key.json): it refuses an edited, added, removed or re-signed file. The publisher key is ours, so neither check is independent verification.

E42 · e42-supreme-governed-agentic-infrastructure-2026-10-01

— published result: INTACT (1460/1460 checks)

mkdir -p e42-supreme-governed-agentic-infrastructure-2026-10-01 && cd e42-supreme-governed-agentic-infrastructure-2026-10-01
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e42-supreme-governed-agentic-infrastructure-2026-10-01.json", "../e42-supreme-governed-agentic-infrastructure-2026-10-01.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e42-supreme-governed-agentic-infrastructure-2026-10-01.attestation.json"))["files"])
for f in names:
    get(E + "e42-supreme-governed-agentic-infrastructure-2026-10-01/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e42-supreme-governed-agentic-infrastructure-2026-10-01/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e42-supreme-governed-agentic-infrastructure-2026-10-01 ../e42-supreme-governed-agentic-infrastructure-2026-10-01.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e42.py.txt .   # what it says: INTACT

E41 · e41-machine-agency-exchange-2026-09-30

— published result: INTACT (1303/1303 checks)

mkdir -p e41-machine-agency-exchange-2026-09-30 && cd e41-machine-agency-exchange-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e41-machine-agency-exchange-2026-09-30.json", "../e41-machine-agency-exchange-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e41-machine-agency-exchange-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e41-machine-agency-exchange-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e41-machine-agency-exchange-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e41-machine-agency-exchange-2026-09-30 ../e41-machine-agency-exchange-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e41.py.txt .   # what it says: INTACT

E40 · e40-autonomous-enterprise-intelligence-2026-09-30

— published result: INTACT (1518/1518 checks)

mkdir -p e40-autonomous-enterprise-intelligence-2026-09-30 && cd e40-autonomous-enterprise-intelligence-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e40-autonomous-enterprise-intelligence-2026-09-30.json", "../e40-autonomous-enterprise-intelligence-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e40-autonomous-enterprise-intelligence-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e40-autonomous-enterprise-intelligence-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e40-autonomous-enterprise-intelligence-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e40-autonomous-enterprise-intelligence-2026-09-30 ../e40-autonomous-enterprise-intelligence-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e40.py.txt .   # what it says: INTACT

E37 · e37-autonomous-execution-mesh-2026-09-30

1132/1132 invariants · 2720/2720 scenarios held — published result: INTACT (2627/2627 checks)

mkdir -p e37-autonomous-execution-mesh-2026-09-30 && cd e37-autonomous-execution-mesh-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e37-autonomous-execution-mesh-2026-09-30.json", "../e37-autonomous-execution-mesh-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e37-autonomous-execution-mesh-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e37-autonomous-execution-mesh-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e37-autonomous-execution-mesh-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e37-autonomous-execution-mesh-2026-09-30 ../e37-autonomous-execution-mesh-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e37.py.txt .   # what it says: INTACT

E36 · e36-machine-agency-exchange-2026-09-30

842/842 invariants · 3340/3340 scenarios held — published result: INTACT (3601/3601 checks)

mkdir -p e36-machine-agency-exchange-2026-09-30 && cd e36-machine-agency-exchange-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e36-machine-agency-exchange-2026-09-30.json", "../e36-machine-agency-exchange-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e36-machine-agency-exchange-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e36-machine-agency-exchange-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e36-machine-agency-exchange-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e36-machine-agency-exchange-2026-09-30 ../e36-machine-agency-exchange-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e36.py.txt .   # what it says: INTACT

E35 · e35-governance-intelligence-2026-09-30

799/799 invariants · 3544/3544 scenarios held — published result: INTACT (3810/3810 checks)

mkdir -p e35-governance-intelligence-2026-09-30 && cd e35-governance-intelligence-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e35-governance-intelligence-2026-09-30.json", "../e35-governance-intelligence-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e35-governance-intelligence-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e35-governance-intelligence-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e35-governance-intelligence-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e35-governance-intelligence-2026-09-30 ../e35-governance-intelligence-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e35.py.txt .   # what it says: INTACT

E34 · e34-proof-carrying-machine-agency-2026-09-30

629/629 invariants · 2664/2664 scenarios held — published result: INTACT (3286/3286 checks)

mkdir -p e34-proof-carrying-machine-agency-2026-09-30 && cd e34-proof-carrying-machine-agency-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e34-proof-carrying-machine-agency-2026-09-30.json", "../e34-proof-carrying-machine-agency-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e34-proof-carrying-machine-agency-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e34-proof-carrying-machine-agency-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e34-proof-carrying-machine-agency-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e34-proof-carrying-machine-agency-2026-09-30 ../e34-proof-carrying-machine-agency-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e34.py.txt .   # what it says: INTACT

E33 · e33-governed-agentic-operating-fabric-2026-09-30

581/581 invariants · 2029/2029 scenarios held — published result: INTACT (2603/2603 checks)

mkdir -p e33-governed-agentic-operating-fabric-2026-09-30 && cd e33-governed-agentic-operating-fabric-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e33-governed-agentic-operating-fabric-2026-09-30.json", "../e33-governed-agentic-operating-fabric-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e33-governed-agentic-operating-fabric-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e33-governed-agentic-operating-fabric-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e33-governed-agentic-operating-fabric-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e33-governed-agentic-operating-fabric-2026-09-30 ../e33-governed-agentic-operating-fabric-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e33.py.txt .   # what it says: INTACT

E32 · e32-governed-autonomy-learning-2026-09-30

— published result: INTACT (1420/1420 checks)

mkdir -p e32-governed-autonomy-learning-2026-09-30 && cd e32-governed-autonomy-learning-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e32-governed-autonomy-learning-2026-09-30.json", "../e32-governed-autonomy-learning-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e32-governed-autonomy-learning-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e32-governed-autonomy-learning-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e32-governed-autonomy-learning-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e32-governed-autonomy-learning-2026-09-30 ../e32-governed-autonomy-learning-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e32.py.txt .   # what it says: INTACT

E31 · e31-universal-proof-of-governance-2026-09-30

— published result: INTACT (1676/1676 checks)

mkdir -p e31-universal-proof-of-governance-2026-09-30 && cd e31-universal-proof-of-governance-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e31-universal-proof-of-governance-2026-09-30.json", "../e31-universal-proof-of-governance-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e31-universal-proof-of-governance-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e31-universal-proof-of-governance-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e31-universal-proof-of-governance-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e31-universal-proof-of-governance-2026-09-30 ../e31-universal-proof-of-governance-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e31.py.txt .   # what it says: INTACT

E30 · e30-governed-machine-autonomy-2026-09-30

— published result: INTACT (1187/1187 checks)

mkdir -p e30-governed-machine-autonomy-2026-09-30 && cd e30-governed-machine-autonomy-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e30-governed-machine-autonomy-2026-09-30.json", "../e30-governed-machine-autonomy-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e30-governed-machine-autonomy-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e30-governed-machine-autonomy-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e30-governed-machine-autonomy-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e30-governed-machine-autonomy-2026-09-30 ../e30-governed-machine-autonomy-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e30.py.txt .   # what it says: INTACT

E29 · e29-machine-transaction-fabric-2026-09-30

— published result: INTACT (300/300 checks)

mkdir -p e29-machine-transaction-fabric-2026-09-30 && cd e29-machine-transaction-fabric-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e29-machine-transaction-fabric-2026-09-30.json", "../e29-machine-transaction-fabric-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e29-machine-transaction-fabric-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e29-machine-transaction-fabric-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e29-machine-transaction-fabric-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e29-machine-transaction-fabric-2026-09-30 ../e29-machine-transaction-fabric-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e29.py.txt .   # what it says: INTACT

E28 · e28-portable-execution-identity-2026-09-30

— published result: INTACT (243/243 checks)

mkdir -p e28-portable-execution-identity-2026-09-30 && cd e28-portable-execution-identity-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e28-portable-execution-identity-2026-09-30.json", "../e28-portable-execution-identity-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e28-portable-execution-identity-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e28-portable-execution-identity-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e28-portable-execution-identity-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e28-portable-execution-identity-2026-09-30 ../e28-portable-execution-identity-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e28.py.txt .   # what it says: INTACT

E27 · e27-agentic-internet-control-plane-2026-09-30

— published result: INTACT (4001/4001 checks)

mkdir -p e27-agentic-internet-control-plane-2026-09-30 && cd e27-agentic-internet-control-plane-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e27-agentic-internet-control-plane-2026-09-30.json", "../e27-agentic-internet-control-plane-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e27-agentic-internet-control-plane-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e27-agentic-internet-control-plane-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e27-agentic-internet-control-plane-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e27-agentic-internet-control-plane-2026-09-30 ../e27-agentic-internet-control-plane-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e27.py.txt .   # what it says: INTACT

E26 · e26-universal-machine-agency-trust-2026-09-30

— published result: INTACT (3115/3115 checks)

mkdir -p e26-universal-machine-agency-trust-2026-09-30 && cd e26-universal-machine-agency-trust-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e26-universal-machine-agency-trust-2026-09-30.json", "../e26-universal-machine-agency-trust-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e26-universal-machine-agency-trust-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e26-universal-machine-agency-trust-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e26-universal-machine-agency-trust-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e26-universal-machine-agency-trust-2026-09-30 ../e26-universal-machine-agency-trust-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e26.py.txt .   # what it says: INTACT

E25 · e25-universal-machine-agency-2026-09-30

— published result: INTACT (2977/2977 checks)

mkdir -p e25-universal-machine-agency-2026-09-30 && cd e25-universal-machine-agency-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e25-universal-machine-agency-2026-09-30.json", "../e25-universal-machine-agency-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e25-universal-machine-agency-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e25-universal-machine-agency-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e25-universal-machine-agency-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e25-universal-machine-agency-2026-09-30 ../e25-universal-machine-agency-2026-09-30.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e25.py.txt .   # what it says: INTACT

E24 · e24-governed-agentic-internet-2026-09-29

— published result: INTACT (1952/1952 checks)

mkdir -p e24-governed-agentic-internet-2026-09-29 && cd e24-governed-agentic-internet-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e24-governed-agentic-internet-2026-09-29.json", "../e24-governed-agentic-internet-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e24-governed-agentic-internet-2026-09-29.attestation.json"))["files"])
for f in names:
    get(E + "e24-governed-agentic-internet-2026-09-29/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e24-governed-agentic-internet-2026-09-29/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e24-governed-agentic-internet-2026-09-29 ../e24-governed-agentic-internet-2026-09-29.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e24.py.txt .   # what it says: INTACT

E23 · e23-governed-meta-intelligence-2026-09-29

— published result: INTACT (733/733 checks)

mkdir -p e23-governed-meta-intelligence-2026-09-29 && cd e23-governed-meta-intelligence-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e23-governed-meta-intelligence-2026-09-29.json", "../e23-governed-meta-intelligence-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e23-governed-meta-intelligence-2026-09-29.attestation.json"))["files"])
for f in names:
    get(E + "e23-governed-meta-intelligence-2026-09-29/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e23-governed-meta-intelligence-2026-09-29/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e23-governed-meta-intelligence-2026-09-29 ../e23-governed-meta-intelligence-2026-09-29.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e23.py.txt .   # what it says: INTACT

E21 · e21-open-ended-intelligence-2026-09-29

— published result: INTACT (218/218 checks)

mkdir -p e21-open-ended-intelligence-2026-09-29 && cd e21-open-ended-intelligence-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e21-open-ended-intelligence-2026-09-29.json", "../e21-open-ended-intelligence-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e21-open-ended-intelligence-2026-09-29.attestation.json"))["files"])
for f in names:
    get(E + "e21-open-ended-intelligence-2026-09-29/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e21-open-ended-intelligence-2026-09-29/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e21-open-ended-intelligence-2026-09-29 ../e21-open-ended-intelligence-2026-09-29.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e21.py.txt .   # what it says: INTACT

E20 · e20-agentic-institutions-2026-09-29

— published result: INTACT (179/179 checks)

mkdir -p e20-agentic-institutions-2026-09-29 && cd e20-agentic-institutions-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e20-agentic-institutions-2026-09-29.json", "../e20-agentic-institutions-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e20-agentic-institutions-2026-09-29.attestation.json"))["files"])
for f in names:
    get(E + "e20-agentic-institutions-2026-09-29/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e20-agentic-institutions-2026-09-29/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e20-agentic-institutions-2026-09-29 ../e20-agentic-institutions-2026-09-29.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e20.py.txt .   # what it says: INTACT

E19 · e19-governed-autonomy-2026-09-28

— published result: INTACT (117/117 checks)

mkdir -p e19-governed-autonomy-2026-09-28 && cd e19-governed-autonomy-2026-09-28
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://clawx.click/evidence/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e19-governed-autonomy-2026-09-28.json", "../e19-governed-autonomy-2026-09-28.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e19-governed-autonomy-2026-09-28.attestation.json"))["files"])
for f in names:
    get(E + "e19-governed-autonomy-2026-09-28/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e19-governed-autonomy-2026-09-28/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e19-governed-autonomy-2026-09-28 ../e19-governed-autonomy-2026-09-28.attestation.json   # who published it: PUBLISHED_BY_PINNED_KEY
python3 verify_e19.py.txt .   # what it says: INTACT

Newest published bundle: e42-supreme-governed-agentic-infrastructure-2026-10-01. Every bundle is also mirrored on the other two sites so the same verifier runs against an independent copy.

What exists right now

Loaded from the published, signed files as this page opens.

loading…

How to read a claim

REPRODUCIBLE

Verified, and the verifier is published: you can run the same check yourself and get the same answer.

TESTED

Automated tests pass, but no independent check has been published. A failed result stays visible as a failure.

CLAIMED or SUPERSEDED

Claimed: said, not yet shown. Superseded: replaced by a newer claim and kept for history. Nothing here is verified by a third party; no one has reviewed CAIN-42 independently yet.

Every signed claim

Pick a claim and follow it: claim, evidence, hash, signature, test, source, verifier.

Verify without this page

For engineers, auditors and AI agents. Python 3 and cryptography; the verifiers import nothing from CAIN-42.

curl -O https://clawx.click/evidence/proof-fabric/verify_proof_fabric.py.txt && mv verify_proof_fabric.py.txt verify_proof_fabric.py
python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric/ --claims --text
python3 verify_proof_fabric.py --pack https://clawx.click/evidence/proof-fabric/CAIN42_EVIDENCE_PACK.zip
curl -s https://cainstudio.online/api/v1/proof            # machine-readable index (a convenience, not a verifier)

What they recompute: the claims registry signature, every claim's artifact hash on all three sites, the build and deployment manifests, the test counts against the published JUnit XML, and every public test vector with independent code. The ten-step workflow is inside the evidence pack (VERIFY_WORKFLOW.md). Machine-readable: proof-fabric manifest · test vectors · provenance graph · SBOM · signed index.

Found something wrong? Tell us

A verification error, an inconsistent bundle, a claim the evidence does not support, or a result you could not reproduce: email security@cainstudio.online with the claim id, the file and what you ran. Evidence problems are handled like security reports under the disclosure policy (safe harbour, response targets). Please test against the published files and the public Lab, not by degrading the live service; there is no bug bounty.