CAIN-42 CAIN Studio

Developer documentation

Self-Hosted MCPGate

Last reviewed 31 August 2026

All docs

MCPGate brings CAIN's policy enforcement, agent security verification, and auditable execution directly into your own infrastructure.

Deployment Model#

CAIN is delivered in two deployment models with identical trust control logic:

  • CAIN Studio (https://cainstudio.online): Hosted AI infrastructure runtime and managed trust control plane.
  • MCPGate (https://mcpgate.online): Self-hosted AI infrastructure runtime and self-hosted enforcement boundary operating within your private VPC or on-premise network.

In the self-hosted model, all prompt traffic, agent tool calls, policy evaluations, and evidence records remain entirely within your security boundary.

Architecture#

Autonomous AI Agent
        │
        ▼ (Tool Call / Consequential Action)
┌──────────────────────────────────────────────┐
│ MCPGate Self-Hosted Enforcement Boundary     │
│                                              │
│  ├─ Moat #1: Trust State Engine              │
│  ├─ Moat #2: Security Context Continuity     │
│  ├─ Moat #3: Trust Graph Reachability        │
│  ├─ Moat #4: Execution Provenance            │
│  ├─ Moat #5: Predictive Trust & Blast Radius │
│  ├─ Moat #6: Adversarial Engine              │
│  └─ Moat #7: Autonomous Sentinel Control     │
└──────────────────────┬───────────────────────┘
                       │
       ┌───────────────┴───────────────┐
       ▼                               ▼
    ALLOW                           BLOCK
       │                               │
       ▼                               ▼
Downstream Tool / MCP Server    Execution Terminated
(Action Executed & Recorded)    (Evidence Preserved)

Prerequisites#

  • Linux OS (Ubuntu 22.04+ / RHEL 9+ recommended)
  • Container Runtime: Docker Engine 24.0+ and Docker Compose v2, or Kubernetes 1.28+
  • Network: Local port 8000/8420 for enforcement boundary; no outbound internet required for air-gapped environments
  • Hardware: 2 CPU cores, 4 GB RAM minimum

Quickstart Deployment (Docker Compose)#

1. Clone or download your licensed MCPGate bundle:

git clone https://github.com/cain-trust/mcpgate.git
cd mcpgate

2. Configure your environment:

cp .env.example .env
# Edit .env with your cluster secret and signing key parameters
chmod 0600 .env

3. Launch the enforcement boundary:

docker compose -f docker-compose.prod.yml up -d

4. Verify operational health:

curl -f http://localhost:8000/health

Expected output:

{"status": "healthy", "service": "platform-gateway"}

Air-Gapped & Fail-Closed Semantics#

MCPGate operates under strict fail-closed security principles:

  • NO AUTHORIZATION → NO EXECUTION: An action is never permitted without explicit policy allowance.
  • UNKNOWN and ERROR never become ALLOW or TRUSTED: If a dependency, database, or policy service is unavailable or times out, the gate immediately returns BLOCK / DENY.
  • Tamper-Evident Evidence Chain: All decisions generate SHA-256 chained audit records stored in local SQLite or external WORM volumes.

Integration#

Point your agent framework or MCP client directly to your local MCPGate instance:

from cain import trust

# Route consequential tool execution through your local boundary
@trust(gateway_url="http://localhost:8000", action="execute_query", resource="prod_db")
def run_query(sql: str):
    ...

Verifying Conformance#

Run the built-in conformance suite against your local instance to verify all 7 moats:

cain test --runtime --mcp