{
  "schema": "cain42.evolution9.master_proof.v1",
  "bundle_name": "e9-agent-passport-2026-09-28",
  "generated_at": "2026-09-28T23:07:25+00:00",
  "commit": "3106ea9e1626871a44d15b879d1a864ca6846e6e",
  "invariants_passed": 15,
  "invariants_checked": 15,
  "tests_passed": 46,
  "tests_failed": 0,
  "modules": {
    "e9_passport": "f73bbb438a86e2ad7d267d4f3b7bb12d83c245c81e64ba6c8eca6821905302d3",
    "e9_kernel_provenance_bindings": "e70cc8cd43d1a1f2a32f3aba7733298aea0cda19495676662091ec04d380b673",
    "e9_control_plane": "64156f70c30ff27d6d150436f56ffbd8260f13caede908b4570d4281b96366c2",
    "e9_cli": "54928f453b739cc6f8388a42c6b969ba01351ef9543af1995dc91168774edac3"
  },
  "evidence_level": "TESTED",
  "limitations": [
    "TESTED library: the passport/provenance fabric is part of the L5 kernel library on the operator host; it is not a hosted identity service.",
    "Attestation here is over canonical software/configuration digests and a supplied measurement. It is NOT hardware attestation (no TPM/TEE); unknown hardware attestation stays UNKNOWN.",
    "No vulnerability database is embedded: vulnerability_status is UNKNOWN unless a real source provided it.",
    "Delegation-link signature verification checks presence in the library; end-to-end cryptographic verification of every link is delegated to the existing authority fabric / PBFT path.",
    "The transaction guarantees are stated for the GOVERNED evidence/state layer only; arbitrary external systems are not claimed to support rollback (compensating controls instead).",
    "Framework adapters (E9 Part 31) are not claimed: no adapter is published, therefore none is described as supported.",
    "No third party has reviewed this bundle; the clean-room verifier shares no CAIN imports but was written by the same operator.",
    "Performance numbers are from a single in-process run on the build host with the stated workload; they are not a production benchmark."
  ],
  "signature_b64": "u7T3kk/SNJDBgmUTvw4LD9qkTd/aAluwb+A2gUIHUX5ljX7SyrQePigFuMywfYS8D5PK6401IT+aUiiqfeFyBw==",
  "signer_public_key_b64": "GiCSufxPJY7zcwLcZ+BMtu9NES+f+ZyiQdVAlQsK7mU="
}
