Skip to content
CAI
Software that uses CAICheck a score

CAI Founding Papers

From Score to Evidence

Recomputation, provenance, and measurement boundaries.

Version 1.0 · signed 17 September 2026 by Jimmy Borch · Canine Development · 38 pages

Abstract

What the paper argues.

A CAI result includes the evidence and rule identity needed to inspect and recompute the published score. The Code Assurance Index is designed so that a result can carry its evidence, identify the rules under which it was calculated, be recomputed by a recipient from the supplied evidence under the published rules, and travel with provenance that makes its origin inspectable. Under the current CAI design, the scoring contract is deterministic: given the same eligible evidence and the same rubric version, the scoring process produces the same result. The versioned rubric identifies the score-moving semantics, allowing a recipient to inspect both the result and the rule set that produced it.

A recipient can therefore work backwards from the published result into the scoring inputs, the governing rubric and the provenance of the delivered artifact. Those checks establish different things. Recomputation establishes that a result follows from stated evidence and rules; provenance establishes where an artifact came from and what it claims to describe; cryptographic integrity can establish that a signed payload has not been altered under the applicable trust model; and measurement validity concerns whether the evidence correctly represents the repository that was measured. CAI treats these as separate assurance layers rather than reporting them under a single undifferentiated claim of being "verified".

This paper describes those layers, the boundaries between them, and the information a technically meaningful CAI verification surface should expose. Each claim is tied to the mechanism that can establish or challenge it, so the recipient can see what has been tested and where the remaining evidential responsibility sits.

Check that you have the signed document.

The PDF is the signed artefact. Same bytes, same hash, whoever you got it from. Run this against the file you downloaded, and compare the result with the digest below it.

sha256sum from-score-to-evidence.pdf
2ca95aeef7d7718c105cc5c1c24161db842a8f6a0517bb5c892fe53da791cb13