90 days
minimum notice for breaking changes to APIs, schemas, or wire formats
Change Calendar · forward-looking
Tier-1 procurement teams need to plan their own change-management cycles. We publish ours: every breaking change, sub-processor addition, maintenance window, and policy revision — with the announce-date and effective-date, before they take effect. The minimum-notice policy is locked.
You learn: What happens at each step. You can: Step through it.
Step 1 of 4
KYE Protocol™
Breaking changes
to published APIs, JSON Schemas, OpenAPI surfaces, wire formats, or signed-envelope shapes carry ≥ 90 days notice from the announcement to the effective date. Customer-side opt-out window is included.
Step 2 of 4
KYE Protocol™
Sub-processor additions
(new third-parties touching customer data) carry ≥ 30 days notice (GDPR Art. 28(2) + customer DPA ). Customers can object to a specific sub-processor; if KYE™ cannot accommodate the objection, the customer's right to…
Step 3 of 4
KYE Protocol™
Maintenance windows
on customer-visible surfaces carry ≥ 7 days notice. Emergency maintenance for security incidents is announced immediately via the status page and customer security contact.
Step 4 of 4
KYE Protocol™
Every entry on this page is also represented in the machine-readable JSON at…
minimum notice for breaking changes to APIs, schemas, or wire formats
minimum notice before any new sub-processor begins processing customer data (GDPR Art. 28(2))
minimum notice for planned maintenance touching customer-visible surfaces
1 · Upcoming scheduled changes
Procurement scripts: curl -s https://kyeprotocol.com/change-calendar.json | jq '.entries[] | select(.status == "scheduled")'. Schema: kye.change_calendar.v1.
feature launch
scheduled
Audit Pilot™ engagements open for tier-1 global bank pilots. Pilot scope is shadow-mode AI-agent governance against a published baseline; outputs are 30-day evidence packs.
Announced 2026-05-20 · Effective 2026-06-15 · Scope tier-1 pilots · Customer action not required · Apply for pilot
feature launch
scheduled
Gateway data-residency middleware ships — operational per-tenant verification rolls out to EU tenants. Default-deny if region tag missing.
Announced 2026-05-20 · Effective 2026-07-01 · Scope EU tenants · Customer action not required · EU AI Act mapping
feature launch
scheduled
Production HSM-backed signing keys (@kye/byok) provisioned by operator. Replay-Proof™ envelopes verifiable from operator-rooted public keys alone.
Announced 2026-05-20 · Effective 2026-09-30 · Scope all tenants · Customer action not required
policy revision
scheduled
SSAE 18 auditor engagement begins for SOC 2 Type II attestation. Control mapping is already shipped. Expected report delivery 3-6 months from engagement start.
Announced 2026-05-20 · Effective 2026-11-30 · Scope all tenants · Customer action not required · Trust Centre
policy revision
scheduled
External audit engagement for ISO/IEC 27001 certification. SoA (Statement of Applicability) shipped. Expected certification 2-4 months from engagement start.
Announced 2026-05-20 · Effective 2026-09-30 · Scope all tenants · Customer action not required · Trust Centre
policy revision
scheduled
Threat-led penetration test engagement, ~2-4 weeks. Report becomes available to tier-1 pilot customers under NDA + published Trust Centre status update.
Announced 2026-05-20 · Effective 2026-08-15 · Scope all tenants · Customer action not required
feature launch
scheduled
v1.1 introduces additional rule-pack + sector-pack additions on top of the 10 canonical profiles locked in v1.0. v1.135 conformance fixtures remain bit-for-bit stable.
Announced 2026-05-20 · Effective 2026-09-15 · Scope all tenants · Customer action not required · Historical changelog
2 · Notice policy
/change-calendar.json, schema kye.change_calendar.v1. Procurement scripts can ingest it directly.3 · Related
Canonical KYE™ surfaces referenced on this page: Audit Pilot · Evidence Pack™ · KYE Protocol™.