Audience: Security and identity teams
48 pages. Search every page with Ctrl K, or open the menu.
The platform 4 pages
- ConceptsThe six clickable KYE Protocol™ primitives — Identity, Authority, Scope, State, Audit, On-Behalf-Of
- Whitepaper v1.0The KYE Protocol™ whitepaper: an open contract for identity, authority and audit across humans, businesses, AI agents, services, models and workflows
- The Business Case for Authority Finality™The internal-memo business case for Authority Finality™: inventories, policies and committee approvals don't prove authorised action. KYE Protocol™ proves each…
- The Unowned Centre™Observability, identity, access, evidence and model-governance are each owned by someone. The centre they surround — whether a consequential AI-agent action…
Products 3 pages
- KYE™ Connector Profiles™KYE™ Connector Profiles™ make authority portable across 11 domain families — Commerce, Payment, Open Finance, Health, Pension, Agent Runtime, Security &…
- KYE™ Threat Response Authority Agent™KYE™ Threat Response Authority Agent™ — a bounded, single-purpose KYE™ Governed Agent™ that governed block/revoke/isolate/disable/escalate/notify. It is a…
- KYE™ Starter PacksKYE™ Starter Packs are turn-key bundles for specific sector x role x jurisdiction buyer contexts — UK Tier-1 bank SMF24, UK insurer CISO, EU DORA ICT Risk…
By sector 4 pages
- KYE™ for Clinical AIWhen AI shapes care, the authority chain must be provable before it is challenged. KYE Protocol™ is the identity, delegation, policy and evidence layer for…
- KYE™ Cyber Resilience & Incident Authority Pack™The KYE™ Cyber Resilience & Incident Authority Pack™ governs the authority and evidence of AI-assisted cybersecurity, SOC, and incident-response decisions so…
- KYE™ Offensive Security Authority Pack™The KYE™ Offensive Security Authority Pack governs offensive-security actions at the action boundary — the moment a pentest engagement starts, an exploit…
- KYE™ Publisher Access Ledger™The KYE™ Publisher Access Ledger™ operates the Movement for an Open Web (MOW) Search Only Terms Contract (SOC): classify every automated access against the…
Compliance, conformance & certification 15 pages
- Compliance frameworksPer-framework reference: which KYE Protocol™ controls map to which obligation, with framework scope, official source, and the canonical KYE™ Compliance…
- OSCAL compatibilityKYE Protocol™ is OSCAL-native: every signed evidence pack maps deterministically to NIST OSCAL component-definition, system-security-plan and…
- Example reports by roleOne shelf of representative report envelopes, one per stakeholder — auditor, board, CISO, consultant, customer, dispute resolution, DPO, general counsel…
- NIS2NIS2 — Network and Information Security Directive coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.
- PCI DSS 4.0PCI DSS 4.0 — Payment Card Industry Data Security Standard coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.
- SOC 2SOC 2 — Trust Services Criteria coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.
- NIST 800-53 Rev 5 hub (universal control taxonomy)NIST 800-53 Rev 5 is the universal control taxonomy KYE Protocol™ uses as the hub for every regulatory crosswalk. 20 control families, 25 headline controls…
- CERT-In Cyber Security DirectionsCERT-In Cyber Security Directions coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.
- CISO stakeholder reportRepresentative report envelope for a Chief Information Security Officer. Synthetic tenant — Security posture & ISO 27001 SoA evidence. Signed HTML; anyone with…
- ISO/IEC 27001:2022ISO/IEC 27001:2022 — Information Security Management Annex A + Clauses 4-10 coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact…
- NIST SP 800-207NIST SP 800-207 — Zero Trust Architecture coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.
- PCI DSS v4.0PCI DSS v4.0 — Payment Card Industry Data Security Standard — control mappings to KYE Protocol™ canonical artefacts. Any entity that stores, processes, or…
- Production Action AuthorityProduction Action Authority — SOC 2 CC8 Change Management coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact that enforces it.
- HM Land RegistryHM Land Registry — Registration & Digital Identity Standard (Safe Harbour) coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact…
- MOW Search Only Terms Contract (SOC)MOW Search Only Terms Contract (SOC) — publisher content-access authority coverage by KYE Protocol™ — every requirement bijection-mapped to the KYE™ artefact…
Solutions 5 pages
- For AuditorsKYE Protocol™ gives auditors signed, replay-proof Evidence Packs™ mapped to SOC 2, ISO 27001, EU AI Act, DORA, PSD3 and 16 other frameworks — verified offline…
- For CISOsKYE Protocol™ gives CISOs a delegated-authority + evidence layer on top of existing IAM, OAuth, SIEM and GRC — runtime accountability for AI agents without…
- API & identity scope authority for AI agentsA tangible walk-through for API and identity teams: an AI integration agent about to call a privileged API it was never delegated — refused at the action…
- Automated-response authority for AI security agentsA tangible walk-through for SOC and SIEM teams: an AI security agent about to disable a privileged account outside its runbook — refused at the action boundary…
- Failure to Prevent FraudUnder the UK Failure to Prevent Fraud offence (ECCTA, enforcement 2027) the statutory defence is reasonable procedures — replay-provable evidence that a…
Developer portal 1 page
- KYE Protocol™ TerminalAn interactive demo of the KYE Protocol™ terminal: an agent requests an action; identity, on-behalf-of, authority, scope, state and audit are checked; the…
Engage 3 pages
- Pilot overviewThe non-technical overview of a KYE™ pilot. In 4–10 weeks you receive a signed Evidence Pack™, a regulator-mapped control crosswalk, and a replay-proof bundle…
- KYE™ Consultant Program™The KYE™ Consultant Program™ lets CISO, DPO and AI-governance consultants deliver cryptographically-signed governance to clients in weeks
- KYE™ Consultant Marketplace™The public directory of KYE-certified consultants. AI-governance, data-privacy, and CISO advisors who deliver KYE Protocol™ to their clients
Resources 13 pages
- Risk & mitigationThe KYE Protocol™ threat model: signing-key compromise, registry availability, false-positive denials, time-skew, replay, supply-chain risk…
- SecurityKYE Protocol™ responsible-disclosure page. How you report a vulnerability, what the response SLA looks like, and which supply-chain controls run…
- Acceptable Use Policy (v1.0)KYE Protocol™ Acceptable Use Policy. Prohibited uses, prohibited content, automated-behaviour limits, security obligations, abuse reporting, suspension.
- Data Processing Addendum (v1.0)KYE Protocol™ Data Processing Addendum, GDPR Article 28 compliant. SCCs incorporated, sub-processor list, security measures, data-subject rights…
- KYE Protocol™ brand kitThe KYE Protocol™ brand kit: the KYE™ monogram in the rail-and-node frame, the wordmark, colours with their codes, Inter and JetBrains Mono, usage rules and…
- Identity Is Not AuthorityKnowing who an AI agent is answers the door; it does not decide what the agent may do. Where agent identity stops and Authority Finality™ begins.
- Turncoat agentsThe headline insider threat of 2026 is not a disgruntled employee — it is an AI agent that was manipulated into turning against the organisation that runs it.
- Control mappingControl mapping: The named link from a protocol artefact to a regulatory control — e.g., evidence pack → SOC 2 CC7.2.
- Entity PassportEntity Passport: At-a-glance identity for any agent / human / system / external app — verification status, authority profile, allowed capabilities, restricted…
- NIST 800-207NIST 800-207 — Zero Trust Architecture: — Zero Trust Architecture
- OAuth 2.0 / OIDCOAuth 2.0 / OIDC: Human-centric authorisation + identity federation.
- OSCALOSCAL — Open Security Controls Assessment Language (NIST): (NIST)
- SPIFFE / SPIRESPIFFE / SPIRE: Workload identity for services.