CAIN hosted decision records are signed, 2026-09-27. record.json is one complete stored row of the hosted Fabric's decision table (cainstudio.online), from a public demo decision on a throwaway tenant (cus_demo_649a89350451). The gateway signs each record's SHA-256 digest with an Ed25519 key kept outside its database; the public key is served at /fabric/decision-signing-key on every site (signing-key.json is a snapshot, key id 8fcdf85b4a675f0e). Verify (Python 3.8+, pip install cryptography, no CAIN code): B=https://clawx.click/evidence/decision-signing-2026-09-27 curl -so record.json "$B/record.json" curl -so verify_decision_record.py "$B/verify_decision_record.py.txt" python3 verify_decision_record.py record.json --key https://mcpgate.online/fabric/decision-signing-key --self-test The verifier recomputes the digest from the record's own fields, checks the key id, verifies the signature, and (--self-test) requires two tampered copies to fail: a changed verdict (DIGEST fails) and a changed verdict with the digest recomputed, as a database writer without the key would do (SIGNATURE fails). For a decision made right now, POST https://cainstudio.online/fabric/try?scenario=safe-read and read evidence.integrity.record_signature (the gateway's own check; the full row of a live decision is not public). Your own decisions (customers): export the stored signed row and check it with the same verifier: curl -s -H "X-API-Key: $KEY" https://cainstudio.online/fabric/decisions//signed-record > record.json python3 verify_decision_record.py record.json --key https://mcpgate.online/fabric/decision-signing-key Not claimed: protection against someone with root on the gateway host, which holds both the key and the database; records written before 2026-09-27 are unsigned and reported as unsigned.