CAIN-42 CAIN Studio

Trust

Trust center

Security, data handling, legal, and the evidence you can check yourself, in one place.

Last reviewed 31 August 2026

Verify it yourself

What is live now

Generated from the running system and git, with its build time.

Verification Center

Every public claim, signed; your browser checks it.

Live cluster

The multi-region consensus cluster, read live, signatures checked in your browser.

Lab

Crash nodes in a sandbox twin and verify the result yourself.

Security

Security and disclosure

Safe harbour, scope, and how to report a vulnerability.

Threat model

What we defend against and what we do not.

What we don't do yet

The gaps, itemised: no SOC 2, no third-party review, one provider.

Roadmap

What we are building next, in the order we think matters.

Data and legal

Privacy notice

What we collect, never store, and delete on request.

Data processing addendum

Processor commitments; a countersignable DPA on request.

Sub-processors

Every third party that touches data, and what reaches it.

Service levels

Objectives and how they are measured, not yet a contractual SLA.

Terms

The published policies that apply today.

No third-party audit yet. Everything here is published by the operator. Where a claim can be checked without trusting us, the page says how; where it cannot, it says that too.