CAG-L5 system governor, live on the production gateway (2026-09-28)
===================================================================
Save verify_hosted_governor_run.py.txt as .py (Python 3 + `cryptography`; it imports nothing from CAIN):

  python3 verify_hosted_governor_run.py CAIN42_CAG_L5_HOSTED_LIVE_RUN.json           # offline: signatures, commitments, cases
  python3 verify_hosted_governor_run.py CAIN42_CAG_L5_HOSTED_LIVE_RUN.json --live    # also: all 3 sites publish the same key,
                                                          and cain-mr-01's record of sequence 20167
                                                          names this run's certified state digest

Try the live gate yourself (no account): an unregistered tenant is refused.
  curl -s -X POST https://cainstudio.online/fabric/mcp/enforce -H 'content-type: application/json' \
       -d '{"tenant":"me","agent_id":"a","tool_name":"db_read","runtime_digest":"r","container_id":"c"}'
  -> allowed: false, reason: CAG-L5 system governance: NO_GOVERNED_SYSTEM
  curl -s https://mcpgate.online/fabric/mcp/system/key        # the governance public key

What this is NOT: a customer deployment, an LLM agent, hardware attestation or a third-party review.
