October 2026: CAIN-42 now catalogs more than 8,000 products, services and monetizable mechanisms. The product focus is the October 2026 Top 100, ranked richest-first. See the Top 100 →
Each of the 32 capability names CAIN-42 once advertised was measured, not asserted: does real code match the name, or is it narrower, or is there nothing? Then, for the nearest real component: do its tests pass right now (run in an isolated namespace so no test can touch live data), and does its public endpoint answer? The audit is signed by the evidence-root key and re-checkable with the verifier in this bundle.
Result: 15 live, 1 verified offline, 12 built and tested, 4 not offered. Of the 32 names, 8 match as named and 20 are narrower than the name (the note says how).
Honest limits: self-assessed against our own rule, not certified. "Narrower" means something real exists but less than the name promises. Not offered: ISO 42001 Certification, Cross-Chain Governance, Neural Governance, Quantum Governance. During the run the live gateway kept serving, so its data directory changed (app_data_unchanged: false); the tests themselves ran against an empty tmpfs.
| Capability | Status | Measured verdict | Closest real component | Scope note | Tests passed/failed |
|---|---|---|---|---|---|
| DID Identity (W3C) | Built and tested | IMPLEMENTED | W3C DID documents for every identity (did:key; opt-in did:web) | since 2026-10-03: each Ed25519 identity has a did:key (Multikey) and its owner may publish a did:web document at /did/<handle>/did.json that follows key rotation and resolves as deactivated once the identity is revoked | 81/0 |
| ML Anomaly Detection | Built and tested | NARROWER: IMPLEMENTED | trajectory anomaly detection (statistical rules) | rule and threshold based (drift, salami/cumulative, homoglyph); no trained ML model | 22/0 |
| Policy Cards | Live | IMPLEMENTED, LIVE ENDPOINT | Policy Cards library (policy_cards.py) compiling into enforced tool rules | since 2026-10-03: 8 parameterised templates (payments approval/cap, read-only database, internal email, shell approval, destructive tools off, redact outbound, hold agents) that compile into the tool rules the live pipeline enforces; preview is public, apply is owner-only | 6/0 |
| Agent Hypervisor (ZoD) | Live | NARROWER: LIVE + DISPOSABLE CLUSTER VERIFIED | MCPGate enforcement boundary + default-deny SDK guard | mediates the tool calls routed through it (authorization bound to action, identity, context, expiry, single use; default-deny for undeclared actions). No privilege rings, no process confinement, no hardware virtualization: a call that bypasses the boundary is not seen | 56/0 |
| Formal Verification (TLA+) | Verified offline | OFFLINE VERIFIED | TLA+ models of PBFT commit/view change and the MCPGate gate | bounded models checked by TLC; not a proof about the Python code | -/- |
| TEE Attestation | Live | NARROWER: IMPLEMENTED, LIVE ENDPOINT | tee-verifier: AWS Nitro + AMD SEV-SNP evidence verification | verifies attestation evidence produced by CUSTOMERS' enclaves and confidential VMs against pinned AWS and AMD roots (tested on real Nitro documents and a real SEV-SNP report); CAIN's own servers have no TPM/SEV/TDX and are not hardware-attested | 16/0 |
| PBFT Cluster | Live | LIVE VERIFIED | live PBFT clusters cain-mr-01 and cain-mr-02 (n=4, f=1, quorum 3) | one provider (Vultr) | -/- |
| Quantum-Resistant Crypto | Built and tested | NARROWER: IMPLEMENTED | ML-DSA-65 signing module (cain_pqc) | an ML-DSA-65 implementation with tests exists; consensus, certificates and decision records are signed with Ed25519, not post-quantum | 24/0 |
| Autonomic Self-Healing | Live | NARROWER: LIVE VERIFIED | quarantine and recovery engine; live restore drills | quarantine/recovery logic is automated and tested; the live disaster-recovery drills were operator-run | 14/0 |
| Predictive Threat Intel | Built and tested | NARROWER: IMPLEMENTED | blast-radius and counterfactual risk analysis | predicts an action's impact before it runs; there is no external threat-intelligence feed | 17/0 |
| Global Trust Mesh | Live | NARROWER: LIVE VERIFIED | two live multi-region clusters | 4 US regions on one provider; not global | -/- |
| Trust Tokenization | Built and tested | NARROWER: IMPLEMENTED | signed action-capability tokens | short-lived Ed25519 capability tokens bound to action, parameters and model; no ledger or tradeable token | 22/0 |
| EU AI Act Compliance | Built and tested | NARROWER: IMPLEMENTED | EU AI Act self-assessment and WORM evidence export tooling | tooling that maps controls and exports evidence; no conformity assessment or notified body has reviewed CAIN | 15/0 |
| ISO 42001 Certification | Not offered | NOT ESTABLISHED | ISO 42001 self-assessment endpoint | CAIN-42 is not ISO 42001 certified; no certification body has audited it | -/- |
| Delegation Marketplace | Live | NARROWER: IMPLEMENTED, LIVE ENDPOINT | bounded delegation chains; marketplace service | delegation with scope, limits, expiry and revocation is implemented and tested; the agent-marketplace service (agent discovery, publishing, compliance review) is live since 2026-10-03; organisations do not trade tool permissions through it | 29/0 |
| A2A + MCP Protocol | Live | LIVE + DISPOSABLE CLUSTER VERIFIED | MCPGate (MCP) and A2A trust layer | MCP enforcement on the live cluster; A2A trust layer tested in-process | 6/0 |
| Sovereign AI Control | Live | NARROWER: IMPLEMENTED, LIVE ENDPOINT | self-hosted MCPGate and sovereign SDK | self-hosted components exist and are tested; there is no public self-hosted installer (/install.sh 410) | 8/0 |
| Autonomous Governance | Built and tested | NARROWER: IMPLEMENTED | plan, conflict and delegation governance engines | governance rules are enforced on proposed plans; 'autonomous' means automated checks, not self-authorization | 30/0 |
| Cross-Chain Governance | Not offered | NOT ESTABLISHED | none | no blockchain or cross-chain component exists | -/- |
| Vertical Solutions | Live | NARROWER: IMPLEMENTED, LIVE ENDPOINT | vertical policy packs (finance, health, federal) | policy packs exist and are served; they are rule sets, not audited regulatory solutions | 11/0 |
| Neural Governance | Not offered | NOT ESTABLISHED | none | the term has no implementation | -/- |
| Quantum Governance | Not offered | NOT ESTABLISHED | none | the term has no implementation | -/- |
| Collective Intelligence | Built and tested | NARROWER: IMPLEMENTED | CLAWX collective trust fabric | shared trust, risk and incident state across agents; tested in-process | 104/0 |
| Evolutionary Architecture | Built and tested | NARROWER: IMPLEMENTED | CLAWX defensive evolution loop (self-hardening) | proposes and tests hardening changes; changes do not deploy themselves | 75/0 |
| Shadow AI Discovery | Live | NARROWER: IMPLEMENTED, LIVE ENDPOINT | host agent discovery + hosted shadow-agent-scanner (code repositories) | finds unregistered agent processes on hosts CAIN runs on, and LLM SDK use, MCP tool registrations and autonomous LLM loops in code repositories you submit (scanner live since 2026-10-03); not a network-wide scanner | 13/0 |
| Agent Registry & Identity | Built and tested | IMPLEMENTED | identity engine and console agent registry | registration, revocation and expiry enforced | 80/0 |
| Policy-as-Code Engine | Built and tested | IMPLEMENTED | OPA/Rego policy evaluation with signed policies | in the hosted pipeline the policy stage's verdict is recorded but does not block (identity, authorization, consensus, MCPGate and execution do) | 20/0 |
| Agent SRE | Live | NARROWER: IMPLEMENTED, LIVE ENDPOINT | console live decisions and traces | decision stream and traces are live in the console; the separate observability API was never built (22 of 23 engine methods missing); the hosted observability and agent-debugger services are live since 2026-10-03 (metrics, traces and logs; trace inspection) | 1/0 |
| Multi-Jurisdiction Compliance | Live | NARROWER: IMPLEMENTED, LIVE ENDPOINT | legal-auditor jurisdiction checks + EU AI Act classifier | live since 2026-10-03: required-clause checks for 2 jurisdictions (EU, US-California) and EU AI Act risk-tier screening; not a general multi-jurisdiction rules engine, and the fabric framework registry is still empty | 11/0 |
| Agent CI/CD Pipeline | Built and tested | NARROWER: IMPLEMENTED | conformance protocol v4 (run before deploy) | a conformance suite and deploy gate exist; there is no hosted CI/CD product for customers' agents | 10/0 |
| Third-Party AI Governance | Live | NARROWER: IMPLEMENTED, LIVE ENDPOINT | MCP tool pinning + default-deny egress stage | external tools and APIs an agent reaches through CAIN are governed (the MCP proxy drops changed or unlisted tools; the live egress stage denies destinations outside the tenant allowlist); third-party vendors themselves are not audited | 45/0 |
| Production Cluster | Live | LIVE VERIFIED / LIVE VERIFIED | hosted decisions ordered through the live cluster | every hosted decision carries a quorum certificate the gateway verifies; one operator, one provider | -/- |
sha256sum -c SHA256SUMSpython3 verify_capability_audit.py.txt CAPABILITY_AUDIT.json evidence-root.pub.json (DIGEST, SIGNATURE, RULE, TALLY)python3 ../_publisher/verify_publisher.py.txt ../capabilities-32-2026-10-03 ../_publisher/capabilities-32-2026-10-03.jsonMeasured at 2026-10-03T04:32:07Z at commit 469c733ca24f.