October 2026: CAIN-42 now catalogs more than 8,000 products, services and monetizable mechanisms. The product focus is the October 2026 Top 100, ranked richest-first. See the Top 100 →
104 of 105 catalog services are live (measured by the gateway's own probe, GET /catalog),
up from 6 on 2026-10-02. The 98 services deployed in this release each passed an acceptance probe against
its production port before the gateway was pointed at them (the other 6 were already running before this release):
health, every endpoint once, and a cross-customer test (write as customer A, read as customer B). Seven services are new.
Every number below is copied from a file in this bundle.
Honest limits: self-attested, not independently audited; one host, one container per service, no second instance of any catalog service; some features need credentials this deployment does not hold. See LIMITATIONS.json.
| Check | Result | File |
|---|---|---|
| Live acceptance probe | 98 / 98 PASS, 0 cross-customer leaks | CATALOG_PROBE_LIVE.json |
| Hand-written A/B isolation tests (live) | 7 / 7 ISOLATED | ISOLATION_AB_LIVE.json |
| New-service unit tests | 36 passed | MEASUREMENTS.json |
| Consensus group-commit + anchor tests | 39 passed | MEASUREMENTS.json |
| Live cluster: 64 concurrent decisions | 1 PBFT round, 1.31 s, 64 / 64 certificates independently verified | MEASUREMENTS.json |
Before (each recorded decision waited for its own round): c1 4.0 decisions/s, c4 1.7 decisions/s, p95 6.222 s. After (concurrent decisions share a round; each keeps an RFC 6962 inclusion proof, so it is still verifiable alone):
| Concurrent clients | Recorded decisions/s | p50 s | p95 s |
|---|---|---|---|
| 1 | 7.73 | 0.072 | 0.247 |
| 4 | 3.0 | 1.561 | 2.573 |
| 8 | 4.7 | 1.797 | 2.902 |
| 16 | 7.3 | 2.278 | 3.402 |
| Service | What it does |
|---|---|
| cainbudget | Per-principal spend budgets: atomic, fail-closed reservations with signed decisions |
| cainpay | Card-style spend authorization for agents: hold, capture, void, refund under policy; hash-chained ledger |
| lexisguardian | Who decided, under what mandate, with what dissent: a mandate-checked decision register |
| memorymesh | Persistent agent memory with BM25 retrieval; injected instructions are quarantined |
| nexusmind | Shared knowledge graph: facts with provenance, conflict detection, path queries |
| omegarouter | Pick the model for each request from your own cost, latency and capability rules, with reasons |
| veritasengine | Deterministic, signed checks of outputs and claims before anything trusts them |
| tee-verifier | Verify AWS Nitro Enclaves documents and AMD SEV-SNP reports against pinned vendor roots |
| Defect | Fix |
|---|---|
| 11 services could not start | a bad edit put 'from pathlib import Path' above 'from __future__', or left '))))' |
| 1 more could not start (mcts-engine) | same __future__ ordering defect |
| cross-customer data exposure in 11 services (first probe) | per-caller SQLite isolation or per-caller stores |
| 31 more SQLite services had no per-caller scoping | per-caller SQLite isolation, verified by per-owner DB files |
| 9 services served one shared in-memory store to every caller | one instance per caller |
| knowledge-graph returned one customer's entities to another (verified live before the fix) | per-caller instance, each loaded from that caller's own database |
| WebSocket proxy dropped the caller's key, so every WebSocket caller looked alike | key forwarded as a header |
| talos-coder: any caller holding a session id could delete it | owner check on delete |
| quorum-oaas: any caller could add or overwrite global product definitions | per-caller products; built-ins read-only |
| a2a-guard listed every customer's agent cards | listing is per owner; single-card lookup stays public (A2A) |
| trust-state-engine: 'identity_compromised' read but never set, so every trust event raised KeyError | signal initialised and counted; a compromise now revokes |
| trust-state-engine crashed on every restart (CREATE INDEX without IF NOT EXISTS) | idempotent schema |
| caindrift POST /baselines always failed (read a field that does not exist) | fixed |
| 11 services returned raw exception text on bad input | 400 for bad input; 500 without internals |
| action-firewall needed a service that does not exist | verdicts signed by its own published Ed25519 key |
| decision-intelligence/trust-state-engine cached one DB connection across callers | cache keyed by caller |
Overall B (was B-), same rubric as the 2026-10-02 audit, self-assessed. Not higher because: two gateway instances (blue/green) now share the load balancer, but on one host; no completed 24 h soak since the 2026-10-02 host reboot; no independent third-party audit; no disaster-recovery restore exercised in this audit; the catalog services run on one host, one container each (no HA); the multi-region PBFT cluster orders decisions, it does not host the services; recorded decisions still wait ~1.1-1.9 s for a cross-region round (now shared by many); the SDK is not on PyPI.
sha256sum -c SHA256SUMSpython3 ../_publisher/verify_publisher.py.txt ../catalog-go-live-2026-10-03 ../_publisher/catalog-go-live-2026-10-03.jsoncurl -s -H 'Accept: application/json' https://cainstudio.online/catalogcurl -s -X POST https://cainstudio.online/veritasengine/verify -H "X-API-Key: $CAIN_API_KEY" -H 'Content-Type: application/json' -d '{"checks":[{"type":"arithmetic","subject":"19.99 * 3 = 60"}]}' (answers REFUTED)Built at 2026-10-03T04:32:42Z from commit 469c733.