{
 "schema": "CAIN42/NOW/v1",
 "system": "CAIN-42",
 "generated_at": "2026-09-28T06:50:01Z",
 "generator": "scripts/cain42_site/build_now.py",
 "overall_status": "LIVE_SELF_ATTESTED",
 "repository": {
  "head_commit": "7ead31dc1a7d2301cc404150506a2f30e0bad003",
  "head_subject": "evidence(public): publish the passing deployment gate result and refresh the signed inventory/index",
  "head_committed_at": "2026-09-28T06:04:08Z",
  "latest_tag": "cain-34.0-production",
  "tag_note": "tagged 2026-09-17; not a CAIN-42 release. There is no CAIN-42 release tag; the deployed code is identified by commit."
 },
 "deployment": {
  "service": "cain-platform-gateway",
  "gateway_started_at": "Mon 2026-09-28 05:42:54 UTC",
  "commit_at_gateway_start": "ac27feff434434627a14f9ba2476f43a6f7c8b9c",
  "working_tree_note": "20 Python file(s) under platform-gateway differ from git at build time (uncommitted or untracked); the running process may include uncommitted code",
  "mode_flags": {
   "FABRIC_ENFORCE": {
    "value": "false",
    "set": false,
    "default_defined_in": "fabric_control_plane.py",
    "gates": "master switch for the hosted decision pipeline"
   },
   "FABRIC_VERIFY_ENFORCE": {
    "value": "false",
    "set": false,
    "default_defined_in": "fabric_control_plane.py",
    "gates": "plan verification stage"
   },
   "FABRIC_APPROVAL_ENFORCE": {
    "value": "false",
    "set": false,
    "default_defined_in": "fabric_control_plane.py",
    "gates": "human-approval holds"
   },
   "OPA_ENFORCE": {
    "value": "false",
    "set": false,
    "default_defined_in": "main.py",
    "gates": "OPA policy on the proxied request path"
   },
   "FUZZER_BLOCKLIST_ENFORCE": {
    "value": "false",
    "set": false,
    "default_defined_in": "main.py",
    "gates": "adversarial-fuzzer blocklist on MCP tool calls"
   },
   "CAIN_FRONTIER_MODE": {
    "value": "shadow",
    "set": false,
    "default_defined_in": "cain/frontier/gate.py",
    "gates": "frontier gate"
   },
   "CAIN_MCP_ENFORCE": {
    "value": "true",
    "set": false,
    "default_defined_in": "mcp_runtime.py",
    "gates": "MCP runtime checks"
   },
   "CAIN_SECURITY_ENFORCE": {
    "value": "true",
    "set": false,
    "default_defined_in": "security_engine.py",
    "gates": "security engine"
   }
  },
  "hosts": "cainstudio.online, mcpgate.online and clawx.click resolve to one host; one gateway process serves the first two and the API paths of the third"
 },
 "live": {
  "fabric_mode": "enforce",
  "fabric_master_switch": true,
  "fabric_stage_count": 12,
  "fabric_enforcing_stages": [
   "authorization",
   "consensus",
   "execution",
   "identity",
   "mcpgate"
  ],
  "fabric_deployment": "studio",
  "demo_prompt_injection": {
   "verdict": "BLOCKED",
   "blocked_by": [
    "trust"
   ],
   "stages": [
    {
     "stage": "identity",
     "verdict": "allow",
     "enforcing": true
    },
    {
     "stage": "intent",
     "verdict": "allow",
     "enforcing": false
    },
    {
     "stage": "policy",
     "verdict": "allow",
     "enforcing": false
    },
    {
     "stage": "authorization",
     "verdict": "allow",
     "enforcing": true
    },
    {
     "stage": "risk",
     "verdict": "deny",
     "enforcing": false
    },
    {
     "stage": "trust",
     "verdict": "deny",
     "enforcing": true
    },
    {
     "stage": "verification",
     "verdict": "skipped",
     "enforcing": false
    },
    {
     "stage": "actionproof",
     "verdict": "skipped",
     "enforcing": true
    },
    {
     "stage": "approval",
     "verdict": "not_configured",
     "enforcing": false
    },
    {
     "stage": "consensus",
     "verdict": "allow",
     "enforcing": true
    },
    {
     "stage": "enforcement",
     "verdict": "allow",
     "enforcing": true
    },
    {
     "stage": "execution",
     "verdict": "deny",
     "enforcing": true
    },
    {
     "stage": "outcome",
     "verdict": "allow",
     "enforcing": true
    },
    {
     "stage": "evidence",
     "verdict": "allow",
     "enforcing": false
    }
   ],
   "note": "A real decision on a throwaway tenant, with enforcement forced on for the demonstration. This deployment's own default for verification is FABRIC_VERIFY_ENFORCE=false. ActionProof is not exercised here: it authenticates against your own API key, which a no-signup demo does not have."
  },
  "frontier_mode": "shadow",
  "frontier_decision_log_intact": false,
  "cluster_size": 4,
  "quorum": 3,
  "byzantine_f1_readiness": "PROVEN",
  "byzantine_f1_basis": "membership_count_only: N>=4 and >=4 trusted members. This is a topology check, not a fault-tolerance test; see the independent prober in /proof/bundle/byzantine-cluster-2026-09-21/",
  "state_proof_node": "node2",
  "state_proof_sequence": 0,
  "pbft_engine_version": "33.4-production-hardened",
  "conformance_summary": "status PARTIALLY_VERIFIED; security test suite 162/162 passed, of which 54 are reference-model-only; invariant evaluation dated 2026-09-18T05:52:00Z",
  "errors": {}
 },
 "claims": {
  "registry": "CAIN42/PUBLIC-CLAIMS/v2",
  "issued_at": "2026-09-28T04:03:15Z",
  "git_commit": "7b31afbbcb693b2b3638da02f6b11ef025088546",
  "registry_digest": "ee5834ef8e5f5ff7aeb2a2eb7f429f77c8615f28719db5f1f5838672a0e9cf1e",
  "by_status": {
   "BENCHMARKED": 2,
   "FAILED": 1,
   "NOT_IMPLEMENTED": 3,
   "SIMULATED": 2,
   "TESTED": 2,
   "UNVERIFIED": 3,
   "VERIFIED": 18
  },
  "claims": [
   {
    "claim_id": "C42-PBFT-QC",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "A 4-node CAIN-42 PBFT cluster produced authentic quorum certificates (>= 3 of 4 pinned Ed25519 members) with an identical decision chain on every node across a primary failover.",
    "limits": "disposable cluster on one host"
   },
   {
    "claim_id": "C42-FAST-PATH",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "The Evolution 3 fast path commits only with all 4 members' votes and its view-change rule was model-checked (the naive rule was shown unsafe); a real run produced FAST_COMMIT_QCs that verify.",
    "limits": "bounded model (single slot, 3 views); not deployed live"
   },
   {
    "claim_id": "C42-FAST-PATH-LATENCY",
    "status": "BENCHMARKED",
    "evidence_level": 2,
    "statement": "The fast path did NOT produce a measurable latency improvement on this host (paired A/B, 95% CI includes 0).",
    "limits": "negative result; host CPU-bound"
   },
   {
    "claim_id": "C42-DAG-ORDER",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "DAG data is availability-certified (3 of 4), anchored only through PBFT, and ordered identically on all 4 nodes including a crash-restarted one; the verifier recomputes the order.",
    "limits": "disposable cluster; ordering bias removed in Evolution 5 (measured), fairness beyond position bias not measured"
   },
   {
    "claim_id": "C42-MCPGATE-ENFORCES",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "MCPGate lets a tool call run only with a PBFT-committed authorization bound to the exact action, scope, identity, security context, expiry and single use. On the LIVE 4-region cluster cain-mr-02, through the MCPGate HTTP proxy to a separate MCP server process: 5 authorized calls ran (per the server's own execution log) and 12 attacks were blocked, each with a signed denial returned to the caller (replay, action and tool substitution, capability escalation, identity substitution, context drift, forged QC, forged body, post-consensus mutation, another cluster's certificate, no authorization, expiry).",
    "limits": "self-attested run by the operator; the downstream is a sandbox key-value MCP server; cainstudio.online does not route customer tool calls through this gate"
   },
   {
    "claim_id": "C42-AGENTS-CANNOT-SELF-AUTHORIZE",
    "status": "SIMULATED",
    "evidence_level": 5,
    "statement": "Agents propose; only PBFT authorizes. Plan mutation, model update or tool swap after consensus forces reauthorization; undeclared actions, impersonation, replay, forged trajectories, delegation escalation and aggregate-policy (salami) attacks are blocked.",
    "limits": "scripted agents, not LLMs; attestation SIMULATED; in-process"
   },
   {
    "claim_id": "C42-INVARIANTS",
    "status": "TESTED",
    "evidence_level": 4,
    "statement": "28 executable CAIN-42 invariants (I001-I028: no quorum -> no consensus -> no authorization -> no execution; agents, memory, DAG, delegation, trust and AI predictions cannot create authority; replay, expiry, substitution, tampering rejected) pass on the real code; 22 with full coverage, 6 partial with the gap named.",
    "limits": "executable tests, not formal verification; see each invariant's coverage/gap"
   },
   {
    "claim_id": "C42-1000-TRAJECTORIES",
    "status": "SIMULATED",
    "evidence_level": 2,
    "statement": "1,000 agent trajectories (9 kinds incl. 380 attacks) all ended as expected; all 620 allowed actions carry complete, re-verified proof chains; a 1,000-step trajectory accepted 0 stale authorizations.",
    "limits": "in-process; scripted agents"
   },
   {
    "claim_id": "C42-ORDERING-FAIRNESS",
    "status": "BENCHMARKED",
    "evidence_level": 2,
    "statement": "DAG within-round order is seeded by committed PBFT history: validator-position bias measured before (chi-square 542) and after (1.75).",
    "limits": "position bias only; censorship and economic bias not measured"
   },
   {
    "claim_id": "C42-LIVE-CLUSTER-EVO2",
    "status": "UNVERIFIED",
    "evidence_level": 1,
    "statement": "The live cain-vc cluster runs the Evolution 2 engine (upgraded node by node, state preserved).",
    "limits": "live cluster API is private; its first two decisions predate certificates"
   },
   {
    "claim_id": "C42-PRIVACY-FIREWALL",
    "status": "TESTED",
    "evidence_level": 2,
    "statement": "Every published evidence bundle passes the public-evidence privacy firewall (keys, tokens, credentials, private IPs, internal URLs, server paths, source).",
    "limits": "pattern-based; not a guarantee against every leak class"
   },
   {
    "claim_id": "C42-INDEPENDENT-FAILURE-DOMAINS",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Consensus runs on independent geographic failure domains: cain-mr-02 has 4 replicas on 4 servers in 4 regions (Atlanta, Los Angeles, Miami, Silicon Valley), one each; every server was taken offline in turn and the cluster kept committing, and with two down it refused to commit.",
    "limits": "one provider (Vultr) and one operator: a provider-wide outage or operator compromise is not covered"
   },
   {
    "claim_id": "C42-MULTI-PROVIDER",
    "status": "NOT_IMPLEMENTED",
    "evidence_level": 0,
    "statement": "Replicas on more than one infrastructure provider.",
    "limits": "every server is on Vultr; needs a second provider account"
   },
   {
    "claim_id": "C42-LIVE-MULTI-REGION",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Two live multi-region clusters: cain-mr-01 (4 replicas, 3 regions, WireGuard) and cain-mr-02 (4 servers, 4 regions); each publishes a 30-minute signed proof of its live state, and every decision carries signatures from at least 2 regions.",
    "limits": "region placement is stated by the operator"
   },
   {
    "claim_id": "C42-PARTITION-BYZANTINE",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Live network-partition tests (isolated host commits nothing; 2|2 split commits nothing on either side; agreement within ~3 s of heal) one-way (asymmetric) partitions on the 4-server cluster (deaf replica, one-way link, mute replica: commits continued, identical chains after each heal), and Byzantine tests on the production image (forged votes rejected; equivocating primary proven from its own signatures, quarantined and replaced).",
    "limits": "partitions: whole-host link loss and complete one-way loss (deaf replica, one-way link, mute replica) for 60 s; not flapping links, partial loss, delay or duplication; Byzantine tests on a disposable cluster with the same placement; f=1, two behaviours"
   },
   {
    "claim_id": "C42-DEGRADED-NETWORK",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Safety under a degraded network: with 10% packet loss, 120 +/- 40 ms delay, 5% duplication and reordering on all four replicas' traffic of the live 4-server cluster for 4 minutes, no fork (identical decision chains on all four, 341 certificates each). Liveness degraded sharply: 0.16 commits/s under the impairment versus 1.76/s before (39 of 61 writes committed within the client's 30 s timeout; p95 7173.9 ms), and fully recovered after (2.02/s, p95 644.0 ms). Re-run after engine 948b189 (backoff resets only on progress): 44 of 62 committed, 0.18/s, view changes cut from 14 to at most 6; throughput did not improve beyond noise, so the view-change storm was not the bottleneck. Safety held again.",
    "limits": "VERIFIED is for safety only; throughput under loss is a measured weakness, not a pass; one impairment profile, one client host"
   },
   {
    "claim_id": "C42-DISASTER-RECOVERY",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Disaster recovery on the live clusters: two replicas lost their storage at once and were rebuilt only from off-host backups in other regions (0 of 4 writes committed while quorum was lost; 0 decisions lost; identical height and state 10.3 s after restart); a single replica restored from a snapshot in 8.3 s under writes. Hourly backups of both clusters are copied to another region; every day each replica's newest off-host backup is proven to be a quorum-signed prefix of the live history.",
    "limits": "same provider; backups not encrypted at rest (they hold consensus data that is public by design; identity keys are never backed up); loss of 3 of 4 not drilled; the daily validation checks restorability of every off-host backup, it does not restore into a running replica"
   },
   {
    "claim_id": "C42-ROLLBACK",
    "status": "VERIFIED",
    "evidence_level": 3,
    "statement": "Live rollback to the previous engine and forward again, one replica at a time with the primary last; every replica caught up in 10-14 s, cluster HEALTHY 4/4 after each direction.",
    "limits": "both engines share one storage format"
   },
   {
    "claim_id": "C42-REPRODUCIBLE-RELEASE",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "The 4-server cluster runs an image that rebuilds bit-for-bit from its commit (two independent from-scratch builds produced the deployed image ID); pinned base and packages, SBOM, Ed25519-signed release manifest.",
    "limits": "source not published: the rebuild is reproducible by the operator; outsiders can check the manifest signature and digests"
   },
   {
    "claim_id": "C42-HOSTED-CONSENSUS",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "The hosted Fabric orders every recorded decision through the live PBFT cluster; since 2026-09-27 the gateway itself verifies the commit quorum certificate (>= 3 pinned Ed25519 signatures over the digest it computes for that decision) and a replica's unproven 'COMMITTED' counts as a denial. Each decision shows the check (certificate hash, signers), and GET /fabric/decisions/{id}/integrity re-checks a STORED decision against the commitment the quorum signed (consensus_anchor); every stored decision record is also Ed25519-signed by a key kept outside the database (GET /fabric/decision-signing-key).",
    "limits": "enforce mode is the default for every tenant since 2026-09-27 (GET /fabric/status: mode enforce); a tenant may opt down to shadow mode (logged), in which case its verdicts are recorded but not enforced"
   },
   {
    "claim_id": "C42-DECISION-RECORD-SIGNING",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Every hosted Fabric decision record written since 2026-09-27 is signed: the gateway signs the record's SHA-256 digest with an Ed25519 key kept outside its database, so a database writer who alters a record and recomputes its digest is detected. The published record's digest is recomputed from its own fields by a verifier with no CAIN code, the signature verifies against the key served by another site, and two tampered copies (verdict changed; verdict changed with the digest recomputed) both fail.",
    "limits": "does not protect against root on the gateway host, which holds both key and database; records before 2026-09-27 are unsigned; the full row of a live decision is not public (the demo shows the gateway's own check)"
   },
   {
    "claim_id": "C42-HARDWARE-ATTESTATION",
    "status": "NOT_IMPLEMENTED",
    "evidence_level": 0,
    "statement": "Hardware-backed attestation of nodes or agents.",
    "limits": "none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); attestation fields in security contexts are declared hashes, not hardware quotes; needs servers with that hardware"
   },
   {
    "claim_id": "C42-FORMAL-VERIFICATION",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "TLA+ models of the PBFT commit/view-change rules and of the MCPGate authorization gate, checked exhaustively by TLC within stated bounds: no violation of Agreement, CommitOnlyWhenPrepared, no-execution-without-quorum, action/identity/context binding, expiry or single use; every deliberately broken variant (pre-fix execute rule, NEW_VIEW ignoring reports, weakened quorum, each gate check removed) is caught with a counterexample.",
    "limits": "bounded models (N=4, f<=1, one sequence, two views; small action/identity/context/time domains), not a proof about the Python code; no machine-checked proof for unbounded parameters"
   },
   {
    "claim_id": "C42-SOAK-72H",
    "status": "FAILED",
    "evidence_level": 3,
    "statement": "72-hour adversarial soak (dedicated 4-node cluster, fast path + DAG, crash/restart every 10 min, started 2026-09-25T00:10Z): FAILED. PBFT stopped committing at sequence 4094 about 11 h in (2 replicas in view 39, 2 in view 40, every node HEALTHY, every later request denied), and the harness itself was killed when the host ran out of memory (last checkpoint 0024 at 24.15 h). Safety held: 0 cross-node divergences in 5,154 checks. Cause: no progress timer (only an unreachable primary triggered a view change) and NEW_VIEW replies were dropped, so a lagging replica never caught up; fixed in the engine with a regression test that reproduces the split. A new soak on the fixed build has not run.",
    "limits": "liveness failure, not a safety failure; one host; not the production cluster; the soak nodes ran image soak72-1b28cf3, without the fix; a passing 72-hour run on the fixed build is still required"
   },
   {
    "claim_id": "C42-SOAK-72H-MULTIREGION",
    "status": "UNVERIFIED",
    "evidence_level": 3,
    "statement": "72-hour soak on the live multi-region cluster cain-mr-01 on the fixed build (continuous writes, a random replica killed every 20 minutes, hourly signed hash-chained checkpoints each with an MCPGate-enforced authorization and its refused replay): IN PROGRESS since 2026-09-26.",
    "limits": "verdict only after 72 h; checkpoints so far are valid, which is not a pass"
   },
   {
    "claim_id": "C45-ZOD-LIVE",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Agent Hypervisor / ZoD runtime: an agent acts only inside a ZoD whose authorization the live cluster cain-mr-01 committed with a quorum certificate the hypervisor checks itself; code ran under real confinement (bubblewrap namespaces + cgroup v2, no network); 10 attacks were refused, each a signed DENIED entry in a hash-chained log.",
    "limits": "the hypervisor ran as a library on the gateway host, operator-run, not as a deployed service in front of customer agents; the approval is the operator's; software measurement only (no TPM/TEE); no seccomp filter; egress is deny-all only (no allowlist)"
   },
   {
    "claim_id": "C42-E6-AUTHORITY-LEASES",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Evolution #6 authority leases: for each of 9 conditions a ZoD authorized by the live cluster cain-mr-01 made one successful tool call, the condition was tripped, and the next call was refused without the tool running -- TTL expiry, trust below floor, agent identity swapped, tool schema changed, security context changed, trajectory fork, explicit revocation, parent quarantined (child loses authority), required evidence deleted (that row is SELF-REPORTED: hypervisor-signed, since the log proving it is the one deleted).",
    "limits": "the invalidation logic runs in the hypervisor library on the gateway host, not on the cluster nodes -- the cluster supplies the authority being invalidated; invalidation on policy, epoch or membership change and risk/blast-radius budgets are NOT implemented; the separate 4-node 'authoritative state' layer in cain45/ is SIMULATED and not used here"
   },
   {
    "claim_id": "C42-E7-AUTHORITY-LAPSE",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Evolution #7: authority granted by the live cluster cain-mr-01 lapses -- the next tool call is refused and the tool never runs -- when the policy root changes or cannot be read, when the risk or blast-radius budget is spent, and when a delegate has spent its parent's budget (delegates are charged up the whole chain, so splitting work cannot multiply authority). Every ZoD is bound to the cluster's real membership configuration, recomputed and quorum-agreed, re-read before every action; a changed epoch, a changed membership or an unknown membership refuses.",
    "limits": "the 3 membership/epoch trips are INJECTED into the hypervisor's view (the live cluster was not re-keyed); the policy and budget trips are real; enforcement is the hypervisor library on the gateway host, not the cluster nodes; only CALL_MCP_TOOL budgets were exercised live (classes C0-C4 unit-tested)"
   },
   {
    "claim_id": "C42-E8-GOVERNED-EVOLUTION",
    "status": "VERIFIED",
    "evidence_level": 5,
    "statement": "Evolutions #8/#9: a policy -- the authority ceiling for a tenant's ZoDs -- becomes active only when the live cluster cain-mr-01 commits its activation; an expansion needs a registered human who is not the proposer (an agent's self-approved expansion was refused and never reached the cluster); a restriction needs no human and revoked a running ZoD's authority; a ZoD above the ceiling was refused. A world-model prediction, a simulated ALLOW citing a real certified sequence, a 10-agent signed vote and a replayed memory were each presented as the basis for authority and each refused because the live cluster had not certified it.",
    "limits": "scripted identities, not a real LLM agent; CAIN contains no world model, digital twin or learning memory -- the run shows that such OUTPUTS cannot become authority; governor and hypervisor are a library on the gateway host, the cluster orders and certifies"
   },
   {
    "claim_id": "C42-LEGACY-SELF-ASSERTED",
    "status": "UNVERIFIED",
    "evidence_level": 0,
    "statement": "Seven older files still served on the sites assert strong statuses that no evidence in this registry supports: CAIN42_BYZANTINE_CERTIFICATION.json (CERTIFIED), CAIN42_ENTERPRISE_PERMANENT_MEMORY.json (A_PLUS_ENTERPRISE_CERTIFIED), CAIN42_RELEASE_MANIFEST.json (PRODUCTION_HARDENED) on clawx.click/evidence/; CAIN_13_STATUS.json and v13/CAIN_13_STATUS.json (OPERATIONAL_PROVEN), cain_14_agentic_trust_evidence.json and v2/kernel-self-defense-evidence.json (OPERATIONAL_AND_VERIFIED) on /proof/bundle/. They are kept for history; their statuses are SUPERSEDED by this registry and must not be read as current claims.",
    "limits": "self-asserted by earlier releases; no certification body, no reproducible verifier; found by the public evidence inventory (CAIN42_PUBLIC_EVIDENCE_INVENTORY.json)"
   },
   {
    "claim_id": "C42-THIRD-PARTY-REVIEW",
    "status": "NOT_IMPLEMENTED",
    "evidence_level": 0,
    "statement": "Independent third-party review or certification (SOC 2, ISO 27001, FedRAMP, ...).",
    "limits": "none exists"
   }
  ]
 },
 "soak_72h": {
  "checkpoint": 33,
  "at": "2026-09-28T06:42:10Z",
  "elapsed_hours": 33.045,
  "counters": {
   "allow": 16334,
   "anomalies": 0,
   "checkpoints": 33,
   "checks": 16041,
   "dag_submits": 0,
   "deny": 102,
   "divergences": 0,
   "errors": 105,
   "faults": 93,
   "requests": 16436,
   "restarts": 93,
   "view_changes_seen": 189
  },
  "enforcement_probe_error": null,
  "commit_heights": {
   "cain-mr-node-1": 17427,
   "cain-mr-node-2": 17427,
   "cain-mr-node-3": 17427,
   "cain-mr-node-4": 17427
  },
  "checkpoint_age_hours": 0.13,
  "harness": "RUNNING",
  "name": "soak-multiregion-2026-09-26",
  "verdict": "SEE claim C42-SOAK-72H-MULTIREGION and verify_soak.py"
 },
 "known_limitations": [
  "OPA_ENFORCE is off: OPA policy on the proxied request path is recorded, not enforced.",
  "FUZZER_BLOCKLIST_ENFORCE is off: adversarial-fuzzer blocklist on MCP tool calls is recorded, not enforced.",
  "The frontier gate runs in SHADOW mode.",
  "/frontier/status reports decision_log_intact=false (the frontier gate's decision log does not verify).",
  "The gateway's embedded PBFT node reports committed sequence 0; hosted decisions are ordered by the external multi-region cluster cain-mr-01 instead (claim C42-HOSTED-CONSENSUS), and block only for tenants in enforce mode.",
  "C42-PBFT-QC is VERIFIED only within: disposable cluster on one host.",
  "C42-FAST-PATH is VERIFIED only within: bounded model (single slot, 3 views); not deployed live.",
  "C42-FAST-PATH-LATENCY is BENCHMARKED: negative result; host CPU-bound.",
  "C42-DAG-ORDER is VERIFIED only within: disposable cluster; ordering bias removed in Evolution 5 (measured), fairness beyond position bias not measured.",
  "C42-MCPGATE-ENFORCES is VERIFIED only within: self-attested run by the operator; the downstream is a sandbox key-value MCP server; cainstudio.online does not route customer tool calls through this gate.",
  "C42-AGENTS-CANNOT-SELF-AUTHORIZE is SIMULATED: scripted agents, not LLMs; attestation SIMULATED; in-process.",
  "C42-INVARIANTS is TESTED: executable tests, not formal verification; see each invariant's coverage/gap.",
  "C42-1000-TRAJECTORIES is SIMULATED: in-process; scripted agents.",
  "C42-ORDERING-FAIRNESS is BENCHMARKED: position bias only; censorship and economic bias not measured.",
  "C42-LIVE-CLUSTER-EVO2 is UNVERIFIED: live cluster API is private; its first two decisions predate certificates.",
  "C42-PRIVACY-FIREWALL is TESTED: pattern-based; not a guarantee against every leak class.",
  "C42-INDEPENDENT-FAILURE-DOMAINS is VERIFIED only within: one provider (Vultr) and one operator: a provider-wide outage or operator compromise is not covered.",
  "C42-MULTI-PROVIDER is NOT_IMPLEMENTED: every server is on Vultr; needs a second provider account.",
  "C42-LIVE-MULTI-REGION is VERIFIED only within: region placement is stated by the operator.",
  "C42-PARTITION-BYZANTINE is VERIFIED only within: partitions: whole-host link loss and complete one-way loss (deaf replica, one-way link, mute replica) for 60 s; not flapping links, partial loss, delay or duplication; Byzantine tests on a disposable cluster with the same placement; f=1, two behaviours.",
  "C42-DEGRADED-NETWORK is VERIFIED only within: VERIFIED is for safety only; throughput under loss is a measured weakness, not a pass; one impairment profile, one client host.",
  "C42-DISASTER-RECOVERY is VERIFIED only within: same provider; backups not encrypted at rest (they hold consensus data that is public by design; identity keys are never backed up); loss of 3 of 4 not drilled; the daily validation checks restorability of every off-host backup, it does not restore into a running replica.",
  "C42-ROLLBACK is VERIFIED only within: both engines share one storage format.",
  "C42-REPRODUCIBLE-RELEASE is VERIFIED only within: source not published: the rebuild is reproducible by the operator; outsiders can check the manifest signature and digests.",
  "C42-HOSTED-CONSENSUS is VERIFIED only within: enforce mode is the default for every tenant since 2026-09-27 (GET /fabric/status: mode enforce); a tenant may opt down to shadow mode (logged), in which case its verdicts are recorded but not enforced.",
  "C42-DECISION-RECORD-SIGNING is VERIFIED only within: does not protect against root on the gateway host, which holds both key and database; records before 2026-09-27 are unsigned; the full row of a live decision is not public (the demo shows the gateway's own check).",
  "C42-HARDWARE-ATTESTATION is NOT_IMPLEMENTED: none of the 4 servers has a TPM, AMD SEV or Intel TDX (checked 2026-09-27); attestation fields in security contexts are declared hashes, not hardware quotes; needs servers with that hardware.",
  "C42-FORMAL-VERIFICATION is VERIFIED only within: bounded models (N=4, f<=1, one sequence, two views; small action/identity/context/time domains), not a proof about the Python code; no machine-checked proof for unbounded parameters.",
  "C42-SOAK-72H is FAILED: liveness failure, not a safety failure; one host; not the production cluster; the soak nodes ran image soak72-1b28cf3, without the fix; a passing 72-hour run on the fixed build is still required.",
  "C42-SOAK-72H-MULTIREGION is UNVERIFIED: verdict only after 72 h; checkpoints so far are valid, which is not a pass.",
  "C45-ZOD-LIVE is VERIFIED only within: the hypervisor ran as a library on the gateway host, operator-run, not as a deployed service in front of customer agents; the approval is the operator's; software measurement only (no TPM/TEE); no seccomp filter; egress is deny-all only (no allowlist).",
  "C42-E6-AUTHORITY-LEASES is VERIFIED only within: the invalidation logic runs in the hypervisor library on the gateway host, not on the cluster nodes -- the cluster supplies the authority being invalidated; invalidation on policy, epoch or membership change and risk/blast-radius budgets are NOT implemented; the separate 4-node 'authoritative state' layer in cain45/ is SIMULATED and not used here.",
  "C42-E7-AUTHORITY-LAPSE is VERIFIED only within: the 3 membership/epoch trips are INJECTED into the hypervisor's view (the live cluster was not re-keyed); the policy and budget trips are real; enforcement is the hypervisor library on the gateway host, not the cluster nodes; only CALL_MCP_TOOL budgets were exercised live (classes C0-C4 unit-tested).",
  "C42-E8-GOVERNED-EVOLUTION is VERIFIED only within: scripted identities, not a real LLM agent; CAIN contains no world model, digital twin or learning memory -- the run shows that such OUTPUTS cannot become authority; governor and hypervisor are a library on the gateway host, the cluster orders and certifies.",
  "C42-LEGACY-SELF-ASSERTED is UNVERIFIED: self-asserted by earlier releases; no certification body, no reproducible verifier; found by the public evidence inventory (CAIN42_PUBLIC_EVIDENCE_INVENTORY.json).",
  "C42-THIRD-PARTY-REVIEW is NOT_IMPLEMENTED: none exists."
 ]
}
