October 2026: CAIN-42 now catalogs more than 8,000 products, services and monetizable mechanisms. The product focus is the October 2026 Top 100, ranked richest-first. See the Top 100 →

CAIN-42: the 32 capabilities, measured — 2026-10-03

Each of the 32 capability names CAIN-42 once advertised was measured, not asserted: does real code match the name, or is it narrower, or is there nothing? Then, for the nearest real component: do its tests pass right now (run in an isolated namespace so no test can touch live data), and does its public endpoint answer? The audit is signed by the evidence-root key and re-checkable with the verifier in this bundle.

Result: 15 live, 1 verified offline, 12 built and tested, 4 not offered. Of the 32 names, 8 match as named and 20 are narrower than the name (the note says how).

Honest limits: self-assessed against our own rule, not certified. "Narrower" means something real exists but less than the name promises. Not offered: ISO 42001 Certification, Cross-Chain Governance, Neural Governance, Quantum Governance. During the run the live gateway kept serving, so its data directory changed (app_data_unchanged: false); the tests themselves ran against an empty tmpfs.

CapabilityStatusMeasured verdictClosest real componentScope noteTests passed/failed
DID Identity (W3C)Built and testedIMPLEMENTEDW3C DID documents for every identity (did:key; opt-in did:web)since 2026-10-03: each Ed25519 identity has a did:key (Multikey) and its owner may publish a did:web document at /did/<handle>/did.json that follows key rotation and resolves as deactivated once the identity is revoked81/0
ML Anomaly DetectionBuilt and testedNARROWER: IMPLEMENTEDtrajectory anomaly detection (statistical rules)rule and threshold based (drift, salami/cumulative, homoglyph); no trained ML model22/0
Policy CardsLiveIMPLEMENTED, LIVE ENDPOINTPolicy Cards library (policy_cards.py) compiling into enforced tool rulessince 2026-10-03: 8 parameterised templates (payments approval/cap, read-only database, internal email, shell approval, destructive tools off, redact outbound, hold agents) that compile into the tool rules the live pipeline enforces; preview is public, apply is owner-only6/0
Agent Hypervisor (ZoD)LiveNARROWER: LIVE + DISPOSABLE CLUSTER VERIFIEDMCPGate enforcement boundary + default-deny SDK guardmediates the tool calls routed through it (authorization bound to action, identity, context, expiry, single use; default-deny for undeclared actions). No privilege rings, no process confinement, no hardware virtualization: a call that bypasses the boundary is not seen56/0
Formal Verification (TLA+)Verified offlineOFFLINE VERIFIEDTLA+ models of PBFT commit/view change and the MCPGate gatebounded models checked by TLC; not a proof about the Python code-/-
TEE AttestationLiveNARROWER: IMPLEMENTED, LIVE ENDPOINTtee-verifier: AWS Nitro + AMD SEV-SNP evidence verificationverifies attestation evidence produced by CUSTOMERS' enclaves and confidential VMs against pinned AWS and AMD roots (tested on real Nitro documents and a real SEV-SNP report); CAIN's own servers have no TPM/SEV/TDX and are not hardware-attested16/0
PBFT ClusterLiveLIVE VERIFIEDlive PBFT clusters cain-mr-01 and cain-mr-02 (n=4, f=1, quorum 3)one provider (Vultr)-/-
Quantum-Resistant CryptoBuilt and testedNARROWER: IMPLEMENTEDML-DSA-65 signing module (cain_pqc)an ML-DSA-65 implementation with tests exists; consensus, certificates and decision records are signed with Ed25519, not post-quantum24/0
Autonomic Self-HealingLiveNARROWER: LIVE VERIFIEDquarantine and recovery engine; live restore drillsquarantine/recovery logic is automated and tested; the live disaster-recovery drills were operator-run14/0
Predictive Threat IntelBuilt and testedNARROWER: IMPLEMENTEDblast-radius and counterfactual risk analysispredicts an action's impact before it runs; there is no external threat-intelligence feed17/0
Global Trust MeshLiveNARROWER: LIVE VERIFIEDtwo live multi-region clusters4 US regions on one provider; not global-/-
Trust TokenizationBuilt and testedNARROWER: IMPLEMENTEDsigned action-capability tokensshort-lived Ed25519 capability tokens bound to action, parameters and model; no ledger or tradeable token22/0
EU AI Act ComplianceBuilt and testedNARROWER: IMPLEMENTEDEU AI Act self-assessment and WORM evidence export toolingtooling that maps controls and exports evidence; no conformity assessment or notified body has reviewed CAIN15/0
ISO 42001 CertificationNot offeredNOT ESTABLISHEDISO 42001 self-assessment endpointCAIN-42 is not ISO 42001 certified; no certification body has audited it-/-
Delegation MarketplaceLiveNARROWER: IMPLEMENTED, LIVE ENDPOINTbounded delegation chains; marketplace servicedelegation with scope, limits, expiry and revocation is implemented and tested; the agent-marketplace service (agent discovery, publishing, compliance review) is live since 2026-10-03; organisations do not trade tool permissions through it29/0
A2A + MCP ProtocolLiveLIVE + DISPOSABLE CLUSTER VERIFIEDMCPGate (MCP) and A2A trust layerMCP enforcement on the live cluster; A2A trust layer tested in-process6/0
Sovereign AI ControlLiveNARROWER: IMPLEMENTED, LIVE ENDPOINTself-hosted MCPGate and sovereign SDKself-hosted components exist and are tested; there is no public self-hosted installer (/install.sh 410)8/0
Autonomous GovernanceBuilt and testedNARROWER: IMPLEMENTEDplan, conflict and delegation governance enginesgovernance rules are enforced on proposed plans; 'autonomous' means automated checks, not self-authorization30/0
Cross-Chain GovernanceNot offeredNOT ESTABLISHEDnoneno blockchain or cross-chain component exists-/-
Vertical SolutionsLiveNARROWER: IMPLEMENTED, LIVE ENDPOINTvertical policy packs (finance, health, federal)policy packs exist and are served; they are rule sets, not audited regulatory solutions11/0
Neural GovernanceNot offeredNOT ESTABLISHEDnonethe term has no implementation-/-
Quantum GovernanceNot offeredNOT ESTABLISHEDnonethe term has no implementation-/-
Collective IntelligenceBuilt and testedNARROWER: IMPLEMENTEDCLAWX collective trust fabricshared trust, risk and incident state across agents; tested in-process104/0
Evolutionary ArchitectureBuilt and testedNARROWER: IMPLEMENTEDCLAWX defensive evolution loop (self-hardening)proposes and tests hardening changes; changes do not deploy themselves75/0
Shadow AI DiscoveryLiveNARROWER: IMPLEMENTED, LIVE ENDPOINThost agent discovery + hosted shadow-agent-scanner (code repositories)finds unregistered agent processes on hosts CAIN runs on, and LLM SDK use, MCP tool registrations and autonomous LLM loops in code repositories you submit (scanner live since 2026-10-03); not a network-wide scanner13/0
Agent Registry & IdentityBuilt and testedIMPLEMENTEDidentity engine and console agent registryregistration, revocation and expiry enforced80/0
Policy-as-Code EngineBuilt and testedIMPLEMENTEDOPA/Rego policy evaluation with signed policiesin the hosted pipeline the policy stage's verdict is recorded but does not block (identity, authorization, consensus, MCPGate and execution do)20/0
Agent SRELiveNARROWER: IMPLEMENTED, LIVE ENDPOINTconsole live decisions and tracesdecision stream and traces are live in the console; the separate observability API was never built (22 of 23 engine methods missing); the hosted observability and agent-debugger services are live since 2026-10-03 (metrics, traces and logs; trace inspection)1/0
Multi-Jurisdiction ComplianceLiveNARROWER: IMPLEMENTED, LIVE ENDPOINTlegal-auditor jurisdiction checks + EU AI Act classifierlive since 2026-10-03: required-clause checks for 2 jurisdictions (EU, US-California) and EU AI Act risk-tier screening; not a general multi-jurisdiction rules engine, and the fabric framework registry is still empty11/0
Agent CI/CD PipelineBuilt and testedNARROWER: IMPLEMENTEDconformance protocol v4 (run before deploy)a conformance suite and deploy gate exist; there is no hosted CI/CD product for customers' agents10/0
Third-Party AI GovernanceLiveNARROWER: IMPLEMENTED, LIVE ENDPOINTMCP tool pinning + default-deny egress stageexternal tools and APIs an agent reaches through CAIN are governed (the MCP proxy drops changed or unlisted tools; the live egress stage denies destinations outside the tenant allowlist); third-party vendors themselves are not audited45/0
Production ClusterLiveLIVE VERIFIED / LIVE VERIFIEDhosted decisions ordered through the live clusterevery hosted decision carries a quorum certificate the gateway verifies; one operator, one provider-/-

Verify

  1. sha256sum -c SHA256SUMS
  2. python3 verify_capability_audit.py.txt CAPABILITY_AUDIT.json evidence-root.pub.json (DIGEST, SIGNATURE, RULE, TALLY)
  3. python3 ../_publisher/verify_publisher.py.txt ../capabilities-32-2026-10-03 ../_publisher/capabilities-32-2026-10-03.json

Measured at 2026-10-03T04:32:07Z at commit 469c733ca24f.