CAIN BYZANTINE CLUSTER -- PUBLIC EVIDENCE
For AI agents, security researchers, and anyone who wants to verify CAIN's Byzantine consensus claims without trusting this website.
THE SHORT VERSION
- CAIN runs a real PBFT (Castro-Liskov) Byzantine-fault-tolerant consensus cluster: 4 nodes, tolerates 1 Byzantine/failed node (f=1).
- Every consequential decision produces a machine-verifiable
AuthorizationProofObjectcontaining an Ed25519QuorumCertificate-- not just a log line saying "trust me." - This bundle gives you the actual proof objects and the actual verifier code. You run the verification yourself, offline. We do not ask you to trust our server's word for it.
WHAT WAS FOUND AND FIXED (we are not hiding this)
The first time this quorum-certificate code ran on the real live cluster, it had a real bug: the client received "decision": "ALLOW" while the accompanying certificate had 0 of 4 signatures verify. That is a silent violation of "no proof, no consequent action." It was root-caused (a payload-mismatch between what was signed and what was checked) and fixed at the source, then re-verified live: 4/4 valid signers under normal operation, 3/4 valid signers with a node deliberately stopped (real f=1 tolerance), and a tampered proof correctly rejected. Full root-cause writeup: CAIN_35_FINAL_FORENSIC_REPORT.md, section 7.
VERIFY IT YOURSELF (3 commands, no trust required)
curl -O https://cainstudio.online/proof/bundle/cain35-byzantine/cain_35_independent_verifier.py
curl -O https://cainstudio.online/proof/bundle/cain35-byzantine/live_proof_4of4_signers.json
python3 -c "import json; k=json.load(open('live_proof_4of4_signers.json'))['quorum_certificate']['membership_config']; json.dump(k, open('keys.json','w'))"
python3 cain_35_independent_verifier.py live_proof_4of4_signers.json --keys-file keys.json
Expected: {"verdict": "VALID", "reason": "INDEPENDENTLY_VERIFIED", ...}, exit code 0.
Full walkthrough including the tamper-rejection negative control: HOW_TO_VERIFY.md.
WHY THIS IS TRUSTWORTHY EVIDENCE, NOT A CLAIM
- The verifier is zero-import.
cain_35_independent_verifier.pynever imports CAIN's production authorization code -- confirmed by static AST analysis in an automated test, not just a docstring promise. A bug in CAIN's own certificate class (there was one -- see above) cannot be silently inherited by this verifier, because it doesn't share any code with it. - The proof includes a negative control.
live_proof_TAMPERED_demo.jsonis the valid proof with one field deliberately altered. If the verifier saysVALIDfor that file, something is broken and you should not trust anything else here. - Quorum is derived, not asserted. The verifier independently computes
Q = 2f+1from the certificate's own membership list -- it does not trust a caller-supplied "3 of 4 signed" number.
EVIDENCE BUNDLE CONTENTS
GET /proof/bundle/cain35-byzantine/index.json # Machine-readable manifest with SHA-256 of every file GET /proof/bundle/cain35-byzantine/HOW_TO_VERIFY.md # Copy-pasteable verification walkthrough GET /proof/bundle/cain35-byzantine/cain_35_independent_verifier.py # The actual verifier -- download and run it GET /proof/bundle/cain35-byzantine/live_proof_4of4_signers.json # Real live proof, normal operation, 4/4 signers VALID GET /proof/bundle/cain35-byzantine/live_proof_3of4_byzantine_f1.json # Real live proof captured with 1 node stopped, 3/4 signers VALID GET /proof/bundle/cain35-byzantine/live_proof_TAMPERED_demo.json # Negative control -- must verify as CORRUPTED GET /proof/bundle/cain35-byzantine/CAIN_35_FINAL_FORENSIC_REPORT.md # Full forensic report: what was built, what broke, what was fixed, what remains unproven GET /proof/bundle/cain35-byzantine/CAIN_35_PRODUCTION_READINESS.json # Structured readiness record -- overall verdict GET /proof/bundle/cain35-byzantine/CAIN_35_BASELINE_FREEZE.json # Frozen CAIN 34.0 baseline: commit, image digest, live node identities GET /proof/bundle/cain35-byzantine/CAIN_35_COMPETITOR_CAPABILITY_MATRIX.md # Capability comparison vs Prisma AIRS, SPIFFE/SPIRE, Cloudflare, AWS Nitro, CometBFT, etc., with sources
HONEST SCOPE -- WHAT THIS DOES NOT CLAIM
- This evidence describes a 4-container Byzantine test cluster running on a single host. That is a documented, undisputed limitation (see report section 11, "Witness Independence" and section 15, "Common-Mode Failure") -- it is not operator-, storage-, or network-path-independent across the 4 "nodes."
- Hardware attestation is explicitly
NOT AVAILABLEon this infrastructure and is never claimed otherwise (report section 13). - It is not labeled "production grade," "certified," "formally verified," or "autonomously safe" -- see
CAIN_35_PRODUCTION_READINESS.json'sunproven_claimslist for the exact things we are explicitly NOT claiming. - Roughly 20 of the 30 phases in the CAIN 35.0 specification (formal model-checking, multi-cluster federation, long-horizon chaos campaigns, differential verification) were not attempted this session and are itemized, not hidden, in the final report.
VULNERABILITY / DISCREPANCY REPORTING
If your independent verification produces a different result than documented here, please report it to: security@cainstudio.online