Skip to content
One system, three sites
CAIN-42 CAIN Studio
Every hosted decision is ordered by a live 4-replica PBFT quorum4-node Byzantine consensus: 3-of-4 Ed25519 quorum certificatesSurvives network partitions and a Byzantine replicaEvery decision signed, hash-chained and verifiable offlineTLA+ model-checked: 7.3M states, 0 violationsDAG dissemination anchored and ordered by PBFTA tool call routed through MCPGate runs only with a quorum-committed authorization; calls that bypass the gate are not governed by itIn the CAIN-45 hypervisor, agent authority is a short-lived, single-use leaseAn agent cannot grant itself a new capability (tested with scripted agents)Hosted governor returns a signed verdict; your gate executes itA caught attacker loses autonomy; risk-weighted decisionsPhysical-action library: nine digests behind a single-use permit (reference simulator)Two replicas' storage lost at once: 0 decisions lostLive rollback and forward under traffic, no quarantinesThe deployed image rebuilds bit-for-bit4 replicas on 4 servers across 4 regionsConsensus live across three regions over WireGuardLive cluster — watch and verify nowProof: what is live nowVerify every claim yourselfVerification CenterDownload the evidence packSBOMFormal models (TLA+)Test reportFault-injection proofHosted-consensus proofMCPGate enforcement proofL5 hosted-evolution proofSpatial & physical proofStorage-loss drillRollback drillFour-server clusterFrontier AI research & proof101 AI services live: 95 newly deployed, each acceptance-tested32 capabilities, measured: signed auditChangelogLabNew: CAINBudgetNew: CAINPayNew: VeritasEngineNew: MemoryMeshNew: NexusMindNew: LexisGuardianNew: OmegaRouterNew: TEE VerifierNew: BLUiZZARD Governance

Don't trust CAIN-42. Verify CAIN-42.

Here are the receipts

Every public claim about CAIN-42 is listed below with its evidence. Your browser downloads each file, recomputes its fingerprint (SHA-256) and checks the signature itself; nothing on this page asks our servers whether the evidence is valid. A claim that is only tested, or only claimed, says so.

Verifier Room — verify CAIN-42 yourself, in seconds

You do not have to trust us or contact us. Every evidence bundle below ships a clean-room verifier that imports none of CAIN-42's code. Copy one block into a terminal on your own computer: it downloads that bundle and its verifiers, and runs two chained checks. verify_publisher.py must print PUBLISHED_BY_PINNED_KEY: the bytes are exactly what the CAIN publisher key signed, so an edited or re-signed bundle fails. Only then does the bundle's own verifier run, and it must print "result": "INTACT": its internal hashes and signatures agree. The block ends with one line, VERIFIED or NOT VERIFIED. Do not run the bundle verifier on its own. Nothing on these sites is needed after the download.

Requires Python 3 and internet. The verifiers read published data only; they never touch the live service and never call our servers for a verdict. A changed byte in any bundle file makes the verifier report BROKEN. INTACT alone means only that the bundle agrees with the key shipped inside it, which anyone who re-signs a bundle can arrange. That is why every block also runs verify_publisher.py (verifier, pinned key at /.well-known/cain-publisher-key.json): it refuses an edited, added, removed or re-signed file. The publisher key is ours, so neither check is independent verification.

BFTIP · bft-ip-forensics-2026-10-05

— published result: INTACT (58/59 checks)

mkdir -p bft-ip-forensics-2026-10-05 && cd bft-ip-forensics-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/bft-ip-forensics-2026-10-05.json", "../bft-ip-forensics-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../bft-ip-forensics-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "bft-ip-forensics-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "bft-ip-forensics-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../bft-ip-forensics-2026-10-05 ../bft-ip-forensics-2026-10-05.attestation.json \
  && python3 verify_bftip.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E38 · e38-byzantine-mission-integrity-2026-10-05

— published result: INTACT (127/127 checks)

mkdir -p e38-byzantine-mission-integrity-2026-10-05 && cd e38-byzantine-mission-integrity-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e38-byzantine-mission-integrity-2026-10-05.json", "../e38-byzantine-mission-integrity-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e38-byzantine-mission-integrity-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e38-byzantine-mission-integrity-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e38-byzantine-mission-integrity-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e38-byzantine-mission-integrity-2026-10-05 ../e38-byzantine-mission-integrity-2026-10-05.attestation.json \
  && python3 verify_e38.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E37 · e37-byzantine-autonomous-federation-2026-10-05

30/30 invariants · 30/30 scenarios held — published result: INTACT (70/70 checks)

mkdir -p e37-byzantine-autonomous-federation-2026-10-05 && cd e37-byzantine-autonomous-federation-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e37-byzantine-autonomous-federation-2026-10-05.json", "../e37-byzantine-autonomous-federation-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e37-byzantine-autonomous-federation-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e37-byzantine-autonomous-federation-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e37-byzantine-autonomous-federation-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e37-byzantine-autonomous-federation-2026-10-05 ../e37-byzantine-autonomous-federation-2026-10-05.attestation.json \
  && python3 verify_e37.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E36 · e36-byzantine-collective-governance-2026-10-05

23/30 invariants · 30/30 scenarios held — published result: INTACT (69/76 checks)

mkdir -p e36-byzantine-collective-governance-2026-10-05 && cd e36-byzantine-collective-governance-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e36-byzantine-collective-governance-2026-10-05.json", "../e36-byzantine-collective-governance-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e36-byzantine-collective-governance-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e36-byzantine-collective-governance-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e36-byzantine-collective-governance-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e36-byzantine-collective-governance-2026-10-05 ../e36-byzantine-collective-governance-2026-10-05.attestation.json \
  && python3 verify_e36.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E35 · e35-continuous-autonomy-integrity-2026-10-05

27/30 invariants · 30/30 scenarios held — published result: INTACT (108/111 checks)

mkdir -p e35-continuous-autonomy-integrity-2026-10-05 && cd e35-continuous-autonomy-integrity-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e35-continuous-autonomy-integrity-2026-10-05.json", "../e35-continuous-autonomy-integrity-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e35-continuous-autonomy-integrity-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e35-continuous-autonomy-integrity-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e35-continuous-autonomy-integrity-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e35-continuous-autonomy-integrity-2026-10-05 ../e35-continuous-autonomy-integrity-2026-10-05.attestation.json \
  && python3 verify_e35.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E34 · e34-decision-provenance-2026-10-05

0/0 invariants · 0/0 scenarios held — published result: PARTIAL (0/0 checks)

mkdir -p e34-decision-provenance-2026-10-05 && cd e34-decision-provenance-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e34-decision-provenance-2026-10-05.json", "../e34-decision-provenance-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e34-decision-provenance-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e34-decision-provenance-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e34-decision-provenance-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e34-decision-provenance-2026-10-05 ../e34-decision-provenance-2026-10-05.attestation.json \
  && python3 verify_e34.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E32 · e32-global-trust-settlement-2026-10-05

mkdir -p e32-global-trust-settlement-2026-10-05 && cd e32-global-trust-settlement-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e32-global-trust-settlement-2026-10-05.json", "../e32-global-trust-settlement-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e32-global-trust-settlement-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e32-global-trust-settlement-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e32-global-trust-settlement-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e32-global-trust-settlement-2026-10-05 ../e32-global-trust-settlement-2026-10-05.attestation.json \
  && python3 verify_e32.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E31 · e31-governance-proof-fabric-2026-10-05

mkdir -p e31-governance-proof-fabric-2026-10-05 && cd e31-governance-proof-fabric-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e31-governance-proof-fabric-2026-10-05.json", "../e31-governance-proof-fabric-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e31-governance-proof-fabric-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e31-governance-proof-fabric-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e31-governance-proof-fabric-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e31-governance-proof-fabric-2026-10-05 ../e31-governance-proof-fabric-2026-10-05.attestation.json \
  && python3 verify_e31.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E30 · e30-governance-network-2026-10-05

mkdir -p e30-governance-network-2026-10-05 && cd e30-governance-network-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e30-governance-network-2026-10-05.json", "../e30-governance-network-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e30-governance-network-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e30-governance-network-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e30-governance-network-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e30-governance-network-2026-10-05 ../e30-governance-network-2026-10-05.attestation.json \
  && python3 verify_e30.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E28 · e28-catcp-ip-commercial-2026-10-05

mkdir -p e28-catcp-ip-commercial-2026-10-05 && cd e28-catcp-ip-commercial-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e28-catcp-ip-commercial-2026-10-05.json", "../e28-catcp-ip-commercial-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e28-catcp-ip-commercial-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e28-catcp-ip-commercial-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e28-catcp-ip-commercial-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e28-catcp-ip-commercial-2026-10-05 ../e28-catcp-ip-commercial-2026-10-05.attestation.json \
  && python3 verify_e28.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E27 · e27-catcp-control-2026-10-05

mkdir -p e27-catcp-control-2026-10-05 && cd e27-catcp-control-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e27-catcp-control-2026-10-05.json", "../e27-catcp-control-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e27-catcp-control-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e27-catcp-control-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e27-catcp-control-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e27-catcp-control-2026-10-05 ../e27-catcp-control-2026-10-05.attestation.json \
  && python3 verify_e27.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E26 · e26-byzantine-trust-2026-10-05

mkdir -p e26-byzantine-trust-2026-10-05 && cd e26-byzantine-trust-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e26-byzantine-trust-2026-10-05.json", "../e26-byzantine-trust-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e26-byzantine-trust-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e26-byzantine-trust-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e26-byzantine-trust-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e26-byzantine-trust-2026-10-05 ../e26-byzantine-trust-2026-10-05.attestation.json \
  && python3 verify_e26.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E23 · e23-continuous-assurance-2026-10-05

mkdir -p e23-continuous-assurance-2026-10-05 && cd e23-continuous-assurance-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e23-continuous-assurance-2026-10-05.json", "../e23-continuous-assurance-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e23-continuous-assurance-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e23-continuous-assurance-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e23-continuous-assurance-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e23-continuous-assurance-2026-10-05 ../e23-continuous-assurance-2026-10-05.attestation.json \
  && python3 verify_e23.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E22 · e22-byzantine-global-verification-2026-10-05

mkdir -p e22-byzantine-global-verification-2026-10-05 && cd e22-byzantine-global-verification-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e22-byzantine-global-verification-2026-10-05.json", "../e22-byzantine-global-verification-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e22-byzantine-global-verification-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e22-byzantine-global-verification-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e22-byzantine-global-verification-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e22-byzantine-global-verification-2026-10-05 ../e22-byzantine-global-verification-2026-10-05.attestation.json \
  && python3 verify_e22.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E21 · e21-byzantine-economic-coordination-2026-10-05

mkdir -p e21-byzantine-economic-coordination-2026-10-05 && cd e21-byzantine-economic-coordination-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e21-byzantine-economic-coordination-2026-10-05.json", "../e21-byzantine-economic-coordination-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e21-byzantine-economic-coordination-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e21-byzantine-economic-coordination-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e21-byzantine-economic-coordination-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e21-byzantine-economic-coordination-2026-10-05 ../e21-byzantine-economic-coordination-2026-10-05.attestation.json \
  && python3 verify_e21.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E18 · e18-byzantine-counterfactual-governance-2026-10-05

— published result: VALID (31/31 checks)

mkdir -p e18-byzantine-counterfactual-governance-2026-10-05 && cd e18-byzantine-counterfactual-governance-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e18-byzantine-counterfactual-governance-2026-10-05.json", "../e18-byzantine-counterfactual-governance-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e18-byzantine-counterfactual-governance-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e18-byzantine-counterfactual-governance-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e18-byzantine-counterfactual-governance-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e18-byzantine-counterfactual-governance-2026-10-05 ../e18-byzantine-counterfactual-governance-2026-10-05.attestation.json \
  && python3 verify_e18.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E13 · e13-bpf-governance-execution-2026-10-05

— published result: INTACT (24/24 checks)

mkdir -p e13-bpf-governance-execution-2026-10-05 && cd e13-bpf-governance-execution-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e13-bpf-governance-execution-2026-10-05.json", "../e13-bpf-governance-execution-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e13-bpf-governance-execution-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e13-bpf-governance-execution-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e13-bpf-governance-execution-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e13-bpf-governance-execution-2026-10-05 ../e13-bpf-governance-execution-2026-10-05.attestation.json \
  && python3 verify_e13.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E12 · e12-trust-network-state-2026-10-05

— published result: INTACT (20/20 checks)

mkdir -p e12-trust-network-state-2026-10-05 && cd e12-trust-network-state-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e12-trust-network-state-2026-10-05.json", "../e12-trust-network-state-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e12-trust-network-state-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e12-trust-network-state-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e12-trust-network-state-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e12-trust-network-state-2026-10-05 ../e12-trust-network-state-2026-10-05.attestation.json \
  && python3 verify_e12.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E11 · e11-governance-proof-2026-10-05

— published result: INTACT (32/32 checks)

mkdir -p e11-governance-proof-2026-10-05 && cd e11-governance-proof-2026-10-05
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e11-governance-proof-2026-10-05.json", "../e11-governance-proof-2026-10-05.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e11-governance-proof-2026-10-05.attestation.json"))["files"])
for f in names:
    get(E + "e11-governance-proof-2026-10-05/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e11-governance-proof-2026-10-05/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e11-governance-proof-2026-10-05 ../e11-governance-proof-2026-10-05.attestation.json \
  && python3 verify_e11.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E42 · e42-supreme-governed-agentic-infrastructure-2026-10-01

— published result: INTACT (1460/1460 checks)

mkdir -p e42-supreme-governed-agentic-infrastructure-2026-10-01 && cd e42-supreme-governed-agentic-infrastructure-2026-10-01
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e42-supreme-governed-agentic-infrastructure-2026-10-01.json", "../e42-supreme-governed-agentic-infrastructure-2026-10-01.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e42-supreme-governed-agentic-infrastructure-2026-10-01.attestation.json"))["files"])
for f in names:
    get(E + "e42-supreme-governed-agentic-infrastructure-2026-10-01/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e42-supreme-governed-agentic-infrastructure-2026-10-01/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e42-supreme-governed-agentic-infrastructure-2026-10-01 ../e42-supreme-governed-agentic-infrastructure-2026-10-01.attestation.json \
  && python3 verify_e42.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E41 · e41-machine-agency-exchange-2026-09-30

— published result: INTACT (1303/1303 checks)

mkdir -p e41-machine-agency-exchange-2026-09-30 && cd e41-machine-agency-exchange-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e41-machine-agency-exchange-2026-09-30.json", "../e41-machine-agency-exchange-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e41-machine-agency-exchange-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e41-machine-agency-exchange-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e41-machine-agency-exchange-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e41-machine-agency-exchange-2026-09-30 ../e41-machine-agency-exchange-2026-09-30.attestation.json \
  && python3 verify_e41.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E40 · e40-autonomous-enterprise-intelligence-2026-09-30

— published result: INTACT (1518/1518 checks)

mkdir -p e40-autonomous-enterprise-intelligence-2026-09-30 && cd e40-autonomous-enterprise-intelligence-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e40-autonomous-enterprise-intelligence-2026-09-30.json", "../e40-autonomous-enterprise-intelligence-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e40-autonomous-enterprise-intelligence-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e40-autonomous-enterprise-intelligence-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e40-autonomous-enterprise-intelligence-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e40-autonomous-enterprise-intelligence-2026-09-30 ../e40-autonomous-enterprise-intelligence-2026-09-30.attestation.json \
  && python3 verify_e40.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E37 · e37-autonomous-execution-mesh-2026-09-30

1132/1132 invariants · 2720/2720 scenarios held — published result: INTACT (2627/2627 checks)

mkdir -p e37-autonomous-execution-mesh-2026-09-30 && cd e37-autonomous-execution-mesh-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e37-autonomous-execution-mesh-2026-09-30.json", "../e37-autonomous-execution-mesh-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e37-autonomous-execution-mesh-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e37-autonomous-execution-mesh-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e37-autonomous-execution-mesh-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e37-autonomous-execution-mesh-2026-09-30 ../e37-autonomous-execution-mesh-2026-09-30.attestation.json \
  && python3 verify_e37.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E36 · e36-machine-agency-exchange-2026-09-30

842/842 invariants · 3340/3340 scenarios held — published result: INTACT (3601/3601 checks)

mkdir -p e36-machine-agency-exchange-2026-09-30 && cd e36-machine-agency-exchange-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e36-machine-agency-exchange-2026-09-30.json", "../e36-machine-agency-exchange-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e36-machine-agency-exchange-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e36-machine-agency-exchange-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e36-machine-agency-exchange-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e36-machine-agency-exchange-2026-09-30 ../e36-machine-agency-exchange-2026-09-30.attestation.json \
  && python3 verify_e36.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E35 · e35-governance-intelligence-2026-09-30

799/799 invariants · 3544/3544 scenarios held — published result: INTACT (3810/3810 checks)

mkdir -p e35-governance-intelligence-2026-09-30 && cd e35-governance-intelligence-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e35-governance-intelligence-2026-09-30.json", "../e35-governance-intelligence-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e35-governance-intelligence-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e35-governance-intelligence-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e35-governance-intelligence-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e35-governance-intelligence-2026-09-30 ../e35-governance-intelligence-2026-09-30.attestation.json \
  && python3 verify_e35.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E34 · e34-proof-carrying-machine-agency-2026-09-30

629/629 invariants · 2664/2664 scenarios held — published result: INTACT (3286/3286 checks)

mkdir -p e34-proof-carrying-machine-agency-2026-09-30 && cd e34-proof-carrying-machine-agency-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e34-proof-carrying-machine-agency-2026-09-30.json", "../e34-proof-carrying-machine-agency-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e34-proof-carrying-machine-agency-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e34-proof-carrying-machine-agency-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e34-proof-carrying-machine-agency-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e34-proof-carrying-machine-agency-2026-09-30 ../e34-proof-carrying-machine-agency-2026-09-30.attestation.json \
  && python3 verify_e34.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E33 · e33-governed-agentic-operating-fabric-2026-09-30

581/581 invariants · 2029/2029 scenarios held — published result: INTACT (2603/2603 checks)

mkdir -p e33-governed-agentic-operating-fabric-2026-09-30 && cd e33-governed-agentic-operating-fabric-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e33-governed-agentic-operating-fabric-2026-09-30.json", "../e33-governed-agentic-operating-fabric-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e33-governed-agentic-operating-fabric-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e33-governed-agentic-operating-fabric-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e33-governed-agentic-operating-fabric-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e33-governed-agentic-operating-fabric-2026-09-30 ../e33-governed-agentic-operating-fabric-2026-09-30.attestation.json \
  && python3 verify_e33.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E32 · e32-governed-autonomy-learning-2026-09-30

— published result: INTACT (1420/1420 checks)

mkdir -p e32-governed-autonomy-learning-2026-09-30 && cd e32-governed-autonomy-learning-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e32-governed-autonomy-learning-2026-09-30.json", "../e32-governed-autonomy-learning-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e32-governed-autonomy-learning-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e32-governed-autonomy-learning-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e32-governed-autonomy-learning-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e32-governed-autonomy-learning-2026-09-30 ../e32-governed-autonomy-learning-2026-09-30.attestation.json \
  && python3 verify_e32.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E31 · e31-universal-proof-of-governance-2026-09-30

— published result: INTACT (1676/1676 checks)

mkdir -p e31-universal-proof-of-governance-2026-09-30 && cd e31-universal-proof-of-governance-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e31-universal-proof-of-governance-2026-09-30.json", "../e31-universal-proof-of-governance-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e31-universal-proof-of-governance-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e31-universal-proof-of-governance-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e31-universal-proof-of-governance-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e31-universal-proof-of-governance-2026-09-30 ../e31-universal-proof-of-governance-2026-09-30.attestation.json \
  && python3 verify_e31.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E30 · e30-governed-machine-autonomy-2026-09-30

— published result: INTACT (1187/1187 checks)

mkdir -p e30-governed-machine-autonomy-2026-09-30 && cd e30-governed-machine-autonomy-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e30-governed-machine-autonomy-2026-09-30.json", "../e30-governed-machine-autonomy-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e30-governed-machine-autonomy-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e30-governed-machine-autonomy-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e30-governed-machine-autonomy-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e30-governed-machine-autonomy-2026-09-30 ../e30-governed-machine-autonomy-2026-09-30.attestation.json \
  && python3 verify_e30.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E29 · e29-machine-transaction-fabric-2026-09-30

— published result: INTACT (300/300 checks)

mkdir -p e29-machine-transaction-fabric-2026-09-30 && cd e29-machine-transaction-fabric-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e29-machine-transaction-fabric-2026-09-30.json", "../e29-machine-transaction-fabric-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e29-machine-transaction-fabric-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e29-machine-transaction-fabric-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e29-machine-transaction-fabric-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e29-machine-transaction-fabric-2026-09-30 ../e29-machine-transaction-fabric-2026-09-30.attestation.json \
  && python3 verify_e29.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E28 · e28-portable-execution-identity-2026-09-30

— published result: INTACT (243/243 checks)

mkdir -p e28-portable-execution-identity-2026-09-30 && cd e28-portable-execution-identity-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e28-portable-execution-identity-2026-09-30.json", "../e28-portable-execution-identity-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e28-portable-execution-identity-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e28-portable-execution-identity-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e28-portable-execution-identity-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e28-portable-execution-identity-2026-09-30 ../e28-portable-execution-identity-2026-09-30.attestation.json \
  && python3 verify_e28.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E27 · e27-agentic-internet-control-plane-2026-09-30

— published result: INTACT (4001/4001 checks)

mkdir -p e27-agentic-internet-control-plane-2026-09-30 && cd e27-agentic-internet-control-plane-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e27-agentic-internet-control-plane-2026-09-30.json", "../e27-agentic-internet-control-plane-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e27-agentic-internet-control-plane-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e27-agentic-internet-control-plane-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e27-agentic-internet-control-plane-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e27-agentic-internet-control-plane-2026-09-30 ../e27-agentic-internet-control-plane-2026-09-30.attestation.json \
  && python3 verify_e27.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E26 · e26-universal-machine-agency-trust-2026-09-30

— published result: INTACT (3115/3115 checks)

mkdir -p e26-universal-machine-agency-trust-2026-09-30 && cd e26-universal-machine-agency-trust-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e26-universal-machine-agency-trust-2026-09-30.json", "../e26-universal-machine-agency-trust-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e26-universal-machine-agency-trust-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e26-universal-machine-agency-trust-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e26-universal-machine-agency-trust-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e26-universal-machine-agency-trust-2026-09-30 ../e26-universal-machine-agency-trust-2026-09-30.attestation.json \
  && python3 verify_e26.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E25 · e25-universal-machine-agency-2026-09-30

— published result: INTACT (2977/2977 checks)

mkdir -p e25-universal-machine-agency-2026-09-30 && cd e25-universal-machine-agency-2026-09-30
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e25-universal-machine-agency-2026-09-30.json", "../e25-universal-machine-agency-2026-09-30.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e25-universal-machine-agency-2026-09-30.attestation.json"))["files"])
for f in names:
    get(E + "e25-universal-machine-agency-2026-09-30/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e25-universal-machine-agency-2026-09-30/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e25-universal-machine-agency-2026-09-30 ../e25-universal-machine-agency-2026-09-30.attestation.json \
  && python3 verify_e25.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E24 · e24-governed-agentic-internet-2026-09-29

— published result: INTACT (1952/1952 checks)

mkdir -p e24-governed-agentic-internet-2026-09-29 && cd e24-governed-agentic-internet-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e24-governed-agentic-internet-2026-09-29.json", "../e24-governed-agentic-internet-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e24-governed-agentic-internet-2026-09-29.attestation.json"))["files"])
for f in names:
    get(E + "e24-governed-agentic-internet-2026-09-29/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e24-governed-agentic-internet-2026-09-29/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e24-governed-agentic-internet-2026-09-29 ../e24-governed-agentic-internet-2026-09-29.attestation.json \
  && python3 verify_e24.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E23 · e23-governed-meta-intelligence-2026-09-29

— published result: INTACT (733/733 checks)

mkdir -p e23-governed-meta-intelligence-2026-09-29 && cd e23-governed-meta-intelligence-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e23-governed-meta-intelligence-2026-09-29.json", "../e23-governed-meta-intelligence-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e23-governed-meta-intelligence-2026-09-29.attestation.json"))["files"])
for f in names:
    get(E + "e23-governed-meta-intelligence-2026-09-29/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e23-governed-meta-intelligence-2026-09-29/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e23-governed-meta-intelligence-2026-09-29 ../e23-governed-meta-intelligence-2026-09-29.attestation.json \
  && python3 verify_e23.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E21 · e21-open-ended-intelligence-2026-09-29

— published result: INTACT (218/218 checks)

mkdir -p e21-open-ended-intelligence-2026-09-29 && cd e21-open-ended-intelligence-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e21-open-ended-intelligence-2026-09-29.json", "../e21-open-ended-intelligence-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e21-open-ended-intelligence-2026-09-29.attestation.json"))["files"])
for f in names:
    get(E + "e21-open-ended-intelligence-2026-09-29/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e21-open-ended-intelligence-2026-09-29/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e21-open-ended-intelligence-2026-09-29 ../e21-open-ended-intelligence-2026-09-29.attestation.json \
  && python3 verify_e21.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E20 · e20-agentic-institutions-2026-09-29

— published result: INTACT (179/179 checks)

mkdir -p e20-agentic-institutions-2026-09-29 && cd e20-agentic-institutions-2026-09-29
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e20-agentic-institutions-2026-09-29.json", "../e20-agentic-institutions-2026-09-29.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e20-agentic-institutions-2026-09-29.attestation.json"))["files"])
for f in names:
    get(E + "e20-agentic-institutions-2026-09-29/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e20-agentic-institutions-2026-09-29/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e20-agentic-institutions-2026-09-29 ../e20-agentic-institutions-2026-09-29.attestation.json \
  && python3 verify_e20.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

E19 · e19-governed-autonomy-2026-09-28

— published result: INTACT (117/117 checks)

mkdir -p e19-governed-autonomy-2026-09-28 && cd e19-governed-autonomy-2026-09-28
python3 - <<'PY'
import json, time, urllib.request
def get(url, dest):  # retries: a busy host can drop a request
    for i in range(4):
        try:
            return urllib.request.urlretrieve(url, dest)
        except Exception:
            if i == 3:
                raise
            time.sleep(2 * (i + 1))
E = "https://cainstudio.online/proof/bundle/"
# The publisher attestation lists every published file and is signed by the pinned CAIN key.
get(E + "_publisher/e19-governed-autonomy-2026-09-28.json", "../e19-governed-autonomy-2026-09-28.attestation.json")
get(E + "_publisher/verify_publisher.py.txt", "../verify_publisher.py")
names = sorted(json.load(open("../e19-governed-autonomy-2026-09-28.attestation.json"))["files"])
for f in names:
    get(E + "e19-governed-autonomy-2026-09-28/" + f, f)
try:  # served pages are not attested (site chrome is injected), but some verifiers check index.html
    urllib.request.urlretrieve(E + "e19-governed-autonomy-2026-09-28/index.html", "index.html")
except Exception:
    pass
print("downloaded the bundle:", len(names), "files")
PY
python3 -m pip install --quiet cryptography 2>/dev/null || true
python3 ../verify_publisher.py ../e19-governed-autonomy-2026-09-28 ../e19-governed-autonomy-2026-09-28.attestation.json \
  && python3 verify_e19.py.txt . \
  && echo "VERIFIED: published by the pinned CAIN key, and internally INTACT" \
  || { echo "NOT VERIFIED: do not trust this bundle"; false; }

Newest published bundle: bft-ip-forensics-2026-10-05. Every bundle is also mirrored on the other two sites so the same verifier runs against an independent copy.

What exists right now

Loaded from the published, signed files as this page opens.

loading…

How to read a claim

REPRODUCIBLE

Verified, and the verifier is published: you can run the same check yourself and get the same answer.

TESTED

Automated tests pass, but no independent check has been published. A failed result stays visible as a failure.

CLAIMED or SUPERSEDED

Claimed: said, not yet shown. Superseded: replaced by a newer claim and kept for history. Nothing here is verified by a third party; no one has reviewed CAIN-42 independently yet.

Every signed claim

Pick a claim and follow it: claim, evidence, hash, signature, test, source, verifier.

Verify without this page

For engineers, auditors and AI agents. Python 3 and cryptography; the verifiers import nothing from CAIN-42.

curl -O https://clawx.click/evidence/proof-fabric/verify_proof_fabric.py.txt && mv verify_proof_fabric.py.txt verify_proof_fabric.py
python3 verify_proof_fabric.py https://clawx.click/evidence/proof-fabric/ --claims --text
python3 verify_proof_fabric.py --pack https://clawx.click/evidence/proof-fabric/CAIN42_EVIDENCE_PACK.zip
curl -s https://cainstudio.online/api/v1/proof            # machine-readable index (a convenience, not a verifier)

What they recompute: the claims registry signature, every claim's artifact hash on all three sites, the build and deployment manifests, the test counts against the published JUnit XML, and every public test vector with independent code. The ten-step workflow is inside the evidence pack (VERIFY_WORKFLOW.md). Machine-readable: proof-fabric manifest · test vectors · provenance graph · SBOM · signed index.

Found something wrong? Tell us

A verification error, an inconsistent bundle, a claim the evidence does not support, or a result you could not reproduce: email security@cainstudio.online with the claim id, the file and what you ran. Evidence problems are handled like security reports under the disclosure policy (safe harbour, response targets). Please test against the published files and the public Lab, not by degrading the live service; there is no bug bounty.