Understand the rail — concepts, glossary, frameworks.
KYE Protocol™ is the accountability rail for AI-driven action — it admits or refuses every privileged action against a Purpose Permission™ grant and emits a signed Evidence Pack™ anyone can verify offline. Start here with the concepts, glossary, frameworks, and reference material.
Full reference index — every page in the understand stage (134) ↓
134 pages in the understand stage.
This page is a derived view over internal — a secondary projection over the canonical kye-stage enum (the buyer-journey spine). Adding or retagging a page rebuilds this landing on the next CI run — no hand-curated list to maintain.
Learn — 57 pages
Learn the rail — glossary, frameworks, frameworks-explained.
-
A Permit Is Not Authority · KYE Protocol™ Doctrine
A runtime permit checks the action; it never checks whether the principal held authority to take it. Authority is decided at the boundary — that is Authority Finality™.
-
A Trace Is Not Authority · KYE Protocol™ Doctrine
A trace records what an AI agent did; it holds no grant proving the action was authorised. Authority is decided at the boundary — that is Authority Finality™.
-
Adaptive AI Governance Needs a Runtime Authority Layer — Q3 2026 Edition · KYE Research Library™ · KYE Protocol™
AI governance is converging on a single structural conclusion: written policy and pre-deployment assessment are necessary but not sufficient.
-
Agentic Governance™ — the category KYE Protocol™ defines · KYE Protocol™
What is Agentic Governance™? The category KYE Protocol™ defines — governance FOR agentic systems (humans, AI agents, hybrid authority) resolved to Authority Finality™.
-
AI Exponential → Runtime Authority — governance at model speed · KYE Protocol™
Why must governance become executable as AI moves exponentially? Policy cycles take years; capability compounds in months — the execution boundary is the only layer fast enough.
-
AI governance — 12 do's and don'ts before procurement signs · KYE Learn™
Twelve do
-
AI Legal Brief: a German court holds an AI provider responsible for its AI's answers — June 2026 · KYE Research Library™ · KYE Protocol™
A German court has held that an AI provider is responsible for the answers its AI presents, and that the responsibility cannot be shifted to the reader — reporting based on publicly available…
-
AI Legal Brief: the FSB asks for engineered controls, not well-worded prompts — June 2026 · KYE Research Library™ · KYE Protocol™
A financial-stability regulator has, in effect, told the market that a paragraph of instructions is not a control — reporting based on publicly available sources, not legal or compliance advice.
-
An API Key Is Not Authority · KYE Protocol™ Doctrine
An API key grants reach to an endpoint; it never grants a per-action verdict on whether the actor was authorised. Authority is decided at the boundary — that is Authority Finality™.
-
Analyst Briefing — Agentic Governance™ · KYE Protocol™
What is in the KYE Protocol™ analyst briefing? An Agentic Governance™ category definition, a company fact sheet, and a competitive-landscape map versus adjacent vendors.
-
Analyst Category Definition — Agentic Governance™ · KYE Protocol™
How is the Agentic Governance™ category defined for analysts? Governance FOR agentic systems on five primitives — act, authority, purpose, scope, evidence — resolved to finality.
-
Authority Court — The Agent on Trial · KYE Protocol™ Doctrine
In the Authority Court, the defendant is the agent
-
Authority Governance™ — the missing layer of AI governance · KYE Protocol™
What is Authority Governance™? The category KYE Protocol™ defines: governing who is allowed to let an AI take a consequential action — the authority layer above describe-and-monitor AI governance.
-
Decision Provenance Is Not Authority Provenance · KYE Protocol™ Doctrine
Decision provenance shows how an AI outcome was produced; authority provenance proves the actor was institutionally entitled to cause the effect — settled at the boundary as Authority Finality™.
-
Decision-Admissibility Is Not Action-Authority · KYE Protocol™ Doctrine
Decision-admissibility validates a decision against a compiled rule; it does not entitle an actor to act. Action-authority is decided at the boundary — that is Authority Finality™.
-
Get Certified — KYE™ Certificate Programs · KYE Protocol™
How do I get certified to build governed AI agents? Earn a KYE™ certificate — the Builder credential or its Insurance specialisation — by building an agent whose Evidence Pack™ replays, not by quiz.
-
Glossary · KYE Learn™
Canonical definitions for AI governance terms — AI governance, delegated authority, Purpose Permission, evidence pack, Replay-Proof, authority gap, shadow mode, four-eyes, and more.
-
How KYE™ Works · KYE Protocol™
How does KYE Protocol™ work? It resolves authority before an action, then seals replayable evidence — eight steps: actor, authority, scope, policy, decision, evidence, replay, revocation.
-
Identity Is Not Authority · KYE Protocol™ Doctrine
Agent identity proves who is acting; it does not decide what they may do. Authority is decided at the boundary from the principal
-
ISO/IEC 42001 — AI management system, in 8 minutes · KYE Learn™
What is ISO/IEC 42001 and how do you certify — clauses 4-10 explained, Annex A
-
KYE Authority Fellows™ — a free certificate program for under-represented AI practitioners · KYE Protocol™
KYE Authority Fellows™ is a free, self-serve authority certificate program for women, minorities, and developing-country AI practitioners — Bronze to Gold via credited contributions.
-
KYE Authority Pulse™ — what changed in the canon this week — 2026-W26 · KYE Research Library™ · KYE Protocol™
The KYE Authority Pulse™ is the weekly bulletin of what changed inside the KYE Protocol™ canon — new governance chapters, new frameworks under mapping, new commercial products, and new governed…
-
KYE Community™ — the open community for provable AI authority · KYE Protocol™
KYE Community™ is a zero-cost open community for AI practitioners learning to prove agent authority — free KYE Learn™ courses, the open-source Constitution Kit, and the Authority Fellows™ program.
-
KYE Consequential Actor™ Framework™ · KYE Protocol™
Not all agents are equal. The KYE Consequential Actor™ Framework™ grades AI agents across five levels — L0 Informational to L4 Systemic — by how much governance each requires.
-
KYE Governed Proposal Authority™: SERPRO Governed Data-Query Partnership · KYE Research Library™ · KYE Protocol™
KYE Governed Proposal Authority™ turns a SERPRO governed data-query partnership context into a deterministic, fully-cited, replay-sealed proposal.
-
KYE Learn™ · AI governance education centre
KYE Learn™ — the canonical education centre for AI governance, agentic AI risk, model risk frameworks, and players landscape.
-
KYE Protocol™ — Certification program | Five-tier conformance ladder
The KYE Protocol™ certification program. Five-tier ladder — Declared → KYE Self-Tested™ → KYE Self-Attested™ → KYE Conformant™ → KYE Certified™ — backed by 133 conformance fixtures
-
KYE Protocol™ — Concepts | The 6 protocol primitives: Identity, Authority, Scope, State, Audit, On-Behalf-Of
The six clickable KYE Protocol™ primitives — Identity, Authority, Scope, State, Audit, On-Behalf-Of — each with its canonical schema, endpoint, JSON example, decision role, audit event
-
KYE Protocol™ — FAQ
Frequently asked questions about KYE Protocol™ — Authority Finality™, conformance, deployment, integration, regulation, governance, profiles, roadmap.
-
KYE Protocol™ — Glossary | Plain-English definitions of every protocol term
Plain-English definitions of every KYE Protocol™ term: Authority Graph™, Decision Map™, Authority Finality™, on-behalf-of, attenuation, cascade, evidence pack, ePDP, PEP / PDP, decision codes
-
KYE Protocol™ — Governance for the AI Web
Governance for the AI Web reduces Systemic Authority Risk™ — who authorised what across the web of humans and AI agents — via four products over the existing KYE™ rails.
-
KYE Protocol™ — Training & enablement | Engineers · Architects · Auditors · Regulators · Boards
Learn KYE™ by your role and your time budget — KYE Protocol™ training. Self-paced learning paths, live workshops (Authority Mapping, Pilot Kickoff, Auditor Replay), train-the-trainer for partners, and
-
KYE Protocol™ — Vocabulary | entity types, action types, decision codes, reason codes
Canonical KYE Protocol™ vocabulary: entity types, action types, decision codes, reason codes, capability kinds, side-effect levels, data classes, signal types, redaction fields, taxonomies
-
KYE Protocol™ — Dictionaries — canonical vocabulary
Dictionaries are versioned lists of canonical terms — definitions, categories, severities, control mappings. Rules reference dictionaries by reason_code; the Rules Gateway™&trade
-
Observability Is Not Authority · KYE Protocol™ Doctrine
Observability watches what an AI agent does; it never decides whether the agent was authorised to act. Authority is settled at the boundary — that is Authority Finality™.
-
Open Agent Governance™ Foundation™ — charter & call for participation · KYE Protocol™
What is the Open Agent Governance™ Foundation™? The open working group convened to standardise Agentic Governance™ — shared schemas, evidence-pack formats, and conformance tests.
-
Published Reports — KYE Research Library™ · KYE Protocol™
Where can I read KYE Protocol™
-
Reasoning Control Is Not Authority · KYE Protocol™ Doctrine
Inference-time reasoning control shapes a model
-
Returns to Expertise: Why Governance Is the Moat — June 2026 · KYE Research Library™ · KYE Protocol™
As agentic tools get better at execution, the durable value moves to judgment — and judgment, made enforceable at the moment of action, is what governance is.
-
Roadmap to AI Adoption in Healthcare — June 2026 Edition · KYE Research Library™ · KYE Protocol™
Healthcare organisations are adopting AI into clinical and operational decisions — triage, diagnosis support, documentation, scheduling, prior authorisation — while sitting on the most sensitive…
-
Roadmap to AI Governance for Financial Services — Q3 2026 Edition · KYE Research Library™ · KYE Protocol™
Financial institutions are deploying AI into decisions that regulators already supervise — creditworthiness, fraud, market and model risk — faster than their governance programmes can keep up.
-
Securing enterprise AI agents: where the controls live, and where authority begins — June 2026 · KYE Research Library™ · KYE Protocol™
The industry now agrees on how to secure an enterprise AI agent — and that agreement stops one layer short of authority.
-
SR 11-7 for AI agents · KYE Learn™
How does SR 11-7 model risk guidance apply to AI agents — the four classic categories extended to action risk, the three-line model, documentation expectations, KYE Protocol™ mapping.
-
The 26-Hour Governed Run — live · KYE Protocol™
What is the KYE™ 26-Hour Governed Run? A fully autonomous agent working 26 continuous hours with no human in the loop, every action governed and replay-verifiable under KYE Protocol™, streamed live.
-
The Agent on Trial · KYE Protocol™ Doctrine
A successful AI-agent action is not a legitimate one. The Authority Court puts the action on trial and asks whether it was authorised, in scope, at t=0 — and the verdict is Authority Finality™.
-
The authority that outlived its purpose — why standing permission is the quiet governance risk · KYE Research Library™ · KYE Protocol™
The loudest AI-governance fear is the rogue agent.
-
The EU AI Act, explained for AI agents · KYE Learn™
What does the EU AI Act actually demand of AI agents — risk tiers, prohibited practices, high-risk obligations, GPAI rules, the four obligations that bite hardest, timeline 2025-2027.
-
The KYE Protocol™ Blog · ― Is Not Authority
The KYE Protocol™ Blog argues doctrine: the layers mistaken for authority — observability, traces, permits, identity, keys — and the boundary that separates each from Authority Finality™.
-
The Map of KYE™ · KYE Protocol™
What is the Map of KYE™? The protocol drawn as a cypress — its canopy is the chain of legitimacy (Purpose to Finality), and selecting a stage lights that foliage.
-
The noyb question: proving rights, consent and contestability at execution time — June 2026 · KYE Research Library™ · KYE Protocol™
Digital-rights enforcement has moved from "do you have a privacy policy?" to "prove what happened" — and most organisations cannot answer at execution time.
-
The Research Program — governed, evidence-sealed publishing · KYE Protocol™
What is the Research Program? Governed publishing — no claim without a cited source, every report evidence-sealed and replay-verifiable; institutes co-author via the Publishing Authority Track™.
-
The ROI of Governed AI Action — governance is the unlock, not the tax — June 2026 · KYE Research Library™ · KYE Protocol™
The return on AI is no longer in doubt — and that is precisely why governance is now the constraint that matters.
-
The Say-Do Gap in AI Governance: why stated controls fail their first incident — June 2026 · KYE Research Library™ · KYE Protocol™
There is a measurable gap between what organisations say about their AI governance and what they can actually prove — and that gap is invisible until the first incident, when it becomes the whole…
-
The Trust Layer for Consequential Action · KYE Protocol™
What is the trust layer for consequential action? The layer that decides whether an action may proceed, records why, and makes that authority final and provable — KYE Protocol™.
-
Turncoat agents: the AI insider threat — and why authority, not trust, is the control · KYE Research Library™ · KYE Protocol™
The headline insider threat of 2026 is not a disgruntled employee — it is an AI agent that was manipulated into turning against the organisation that runs it.
-
Who's in AI governance — a 2026 map of the players · KYE Learn™
Who plays in AI governance — GRC suites, AI-risk newcomers, model-eval platforms, agent-governance specialists — where each falls short and how to choose.
-
You present it, you own it — accountability for what AI presents · KYE Protocol™
Who is accountable for an AI answer? The party that presents it as authoritative — KYE Protocol™ records the authority and cited basis so it is provable. Reporting, not legal advice.
Reference — 77 pages
Look up the canonical definition — schemas, dictionaries, ID format.
-
Basel Governance Hub — BCBS 239 per-principle bijection, SR 11-7 / SS1/23 model authority & a live risk-report lineage proof · KYE Protocol™
How does a bank prove BCBS 239 lineage and SR 11-7 / SS1/23 model authority? The hub maps every principle to the KYE™ artefact, event family, and gate that binds it — with a live SHA-256 lineage proof.
-
DORA — Digital Operational Resilience Act — KYE Protocol™
DORA — Digital Operational Resilience Act: control mappings to KYE Protocol™ canonical artefacts. Financial entities in the EU — credit institutions, payment institutions, e-money institutions, inve…
-
Entity Hierarchy — KYE Protocol™
The v3 KYE Protocol™ entity containment tree: Tenant siblings, Workspace siblings, and first-class Model, Tool, External App, and Audit Stream entities — each with its own ID, state machine
-
EU AI Act — Articles 14 + 15 (Human Oversight + Accuracy/Robustness) — KYE Protocol™
EU AI Act — Articles 14 + 15 (Human Oversight + Accuracy/Robustness): control mappings to KYE Protocol™ canonical artefacts.
-
ISO/IEC 42001:2023 — AI Management Systems — KYE Protocol™
ISO/IEC 42001:2023 — AI Management Systems: control mappings to KYE Protocol™ canonical artefacts. Any organisation that provides, develops, or uses AI systems — irrespective of sector. The first for…
-
KYE Authority Finality™ Diagnostic — 24 questions, 6 lenses, regulator-grade signed report
Authority Finality™ Diagnostic — 24 questions × 6 lenses scoring your agentic AI authority posture. Free score in IDE; signed report envelope (3 / month / email free; unlimited on paid pilot).
-
KYE Data Governance Pack™ — runtime data governance for delegated AI actions
KYE Data Governance Pack™ — runtime data governance for delegated AI-agent actions. data_use PDP stage + 7 default-deny rules + 268 dictionaries + signed evidence per access
-
KYE DSAR Evidence™ Pack™ — signed, offline-verifiable subject access response
KYE DSAR Evidence™ Pack™ — signed bundle of every audit-chain entry involving a named data subject. GDPR Art. 15 / UK DPA Pt 3 Ch 3 / CCPA. Offline-verifiable by the requesting subject
-
KYE GovernedUI™ — Seven governance modules
Buyers — what are the seven KYE GovernedUI™ modules? Action Approval, Entity Passport, Authority Scope, Critical Point Review, Evidence Timeline, Approval Queue, Authority Drift.
-
KYE Informed Approval™ — No blind approvals for AI-agent actions
No blind approvals for AI-agent actions — KYE Approval Brief™ assembles actor, principal, authority, scope, state, and risk into a structured, signed brief — so human approvers decide informed
-
KYE Protocol™ — Acceptable Use Policy (v1.0)
KYE Protocol™ Acceptable Use Policy. Prohibited uses, prohibited content, automated-behaviour limits, security obligations, abuse reporting, suspension.
-
KYE Protocol™ — Action Admissibility™ · before authority, before commit
KYE Action Admissibility™ Profile™ — checks whether a proposed action is admissible into the authority pipeline before any authority, formal-rule or commit-boundary check runs. Six decision values
-
KYE Protocol™ — Apache 2.0 Licence
The public KYE Protocol™ schemas, OpenAPI definitions, examples and SDKs are released under the Apache License 2.0. This page reproduces the full text.
-
KYE Protocol™ — Brand kit · canonical reference
KYE Protocol™ brand kit: master logo, indigo brand colour (#6366f1), charcoal ink, type, spacing, clear-space and the misuse list. Source of truth for every surface.
-
KYE Protocol™ — Change Calendar · forward-looking customer change notices
Procurement: when planned KYE™ changes take effect — 90-day breaking-change notice, 30-day sub-processor notice, 7-day maintenance notice. Machine-readable at /change-calendar.json.
-
KYE Protocol™ — Changelog · dated release notes for v1.0 and v1.1 preview
Upgrade your build here s what s new — KYE Protocol™ chronological release notes. v1.0.0 frozen April 2026; rolling v1.0.x patch series; v1.1 preview profiles in flight. Per-release scope, breaking-ch
-
KYE Protocol™ — CKAN & Open Data Portal Consultants
Find consultants who can deploy, migrate, extend and govern CKAN-based data portals with KYE Protocol™ authority, evidence, control mapping and audit-ready publication workflows
-
KYE Protocol™ — Compliance frameworks | 13 horizontal (SOC 2, ISO 27001, PCI DSS, PSD3, DORA, NIS2, EU AI Act, ISO 42001, NIST) + 5 sectoral (HIPAA, MiCA, FFIEC, IEC 62443, 42 CFR Part 2)
Per-framework reference: which KYE Protocol™ controls map to which obligation, with framework scope, official source, and the canonical KYE Compliance Mapping Rail™ binding.
-
KYE Protocol™ — Continuity Module™ · preserve authorised meaning across delegation
The KYE Continuity Module™ checks whether the authorised meaning of an action survives delegation, interpretation, memory, context, incentives, timing
-
KYE Protocol™ — Continuity Profile · preserve the chain from intent to action
KYE Continuity Profile™ preserves the chain between intent, interpretation, delegated authority, state, decision, execution and evidence. Detect intent drift, authority drift, scope drift
-
KYE Protocol™ — Cookie Policy (v1.0)
KYE Protocol™ Cookie Policy. No first-party cookies, no analytics or advertising trackers; a few localStorage keys for theme and update read-state; strictly-necessary host security cookies only.
-
KYE Protocol™ — Data Processing Addendum (v1.0)
KYE Protocol™ Data Processing Addendum, GDPR Article 28 compliant. SCCs incorporated, sub-processor list, security measures, data-subject rights handling, return/deletion on termination.
-
KYE Protocol™ — Decision Engine · step 6 of the KYE™ stack
What is the KYE™ Decision Engine? Step 6 PDP that walks the Authority Graph™, evaluates vocabulary-bound predicates, runs continuity + discoverability checks, and emits a signed Decision Map™.
-
KYE Protocol™ — Discoverability Profile · make delegated agency findable
Make delegated agency findable — KYE Discoverability Profile™ turns the authority graph into a policy-filtered discovery layer for entities, agents, capabilities, delegations, decisions, evidence pack
-
KYE Protocol™ — Documentation hub · curated reading order
KYE Protocol™ documentation: vocabulary, ID format, schemas, SDKs, conformance pack, sector profiles, whitepaper. Curated reading order.
-
KYE Protocol™ — Event-driven by constitution
Buyer — what makes KYE Protocol™ different from Vanta / Drata / AWS Config? Event-driven by constitution, not by cron. 38 event families declared, 16 post-facto-forbidden, CI gate enforces it.
-
KYE Protocol™ — Evidence Pack™ · step 8 of the KYE™ stack
KYE Evidence Pack™ — the signed, replayable bundle of audit-chain entries, Decision Maps™, signatures and public-key set that a regulator or auditor verifies offline
-
KYE Protocol™ — For regulators & legal
how do you verify any vendor
-
KYE Protocol™ — Formal Rules · rights, obligations, prohibitions, powers
KYE Formal Rules Profile™ — model permissions, obligations, prohibitions, powers, exceptions and governance meta-rules as machine-readable authority objects. KYE Gateway™ enforces them at runtime
-
KYE Protocol™ — Integrations · what KYE™ composes with
KYE™ doesn t replace your stack it binds authority across it — What KYE Protocol™ composes with: OAuth/OIDC, SAML, SPIFFE/SPIRE, mTLS, passkeys, OPA, Cerbos, Cedar, MCP, AuthZEN, payment rails, KYC/KY
-
KYE Protocol™ — Knowledge graph · step 5 of the KYE™ stack
KYE™ knowledge graph — the live, instance-level graph of entities, authorities, delegations, capabilities, scopes, decisions and evidence. Step 5 of the canonical 8-step KYE™ stack
-
KYE Protocol™ — KYE CKAN Connector™
Govern CKAN datasets, resources, harvests, metadata changes and publication workflows with KYE Protocol™ authority, purpose, evidence and replay. V1 read-only + advisory; V2 write-back
-
KYE Protocol™ — KYE Connector Profiles™ | Commerce · Payment · Open Finance · Health · Pension · Agent Runtime · Security · Compliance Evidence · Legal
KYE Connector Profiles™ make authority portable across 11 domain families — Commerce, Payment, Open Finance, Health, Pension, Agent Runtime, Security & SIEM, Compliance Evidence, Insurance
-
KYE Protocol™ — KYE Plugin Marketplace™ | MCP tools, webhook verifiers, policy packs, evidence exporters
The KYE Plugin Marketplace™. Install lightweight plugins for MCP tools, webhook verification, policy adapters, evidence exports, conformance tests, sandbox flows, dashboard widgets
-
KYE Protocol™ — Legal · what's open, what's protected, what you can build
Everything is open — Plain-English legal page: Apache 2.0 across schemas, SDKs, OpenAPI, conformance, reference Gateway. Patent-track mechanism algorithms and KYE™ trademarks are protected. FAQ on lic
-
KYE Protocol™ — Mutual Evaluation Agreement (v1.0)
KYE Protocol™ Mutual Evaluation Agreement: compulsory clickwrap confidentiality and no-competing-use terms accepted in every pilot, PoC, partner, trainer and auditor intake, pinned by version hash.
-
KYE Protocol™ — NIST 800-53 Rev 5 hub (universal control taxonomy)
NIST 800-53 Rev 5 is the universal hub KYE Protocol™ uses as the canonical control taxonomy. Every regulatory framework crosswalks INTO this hub. One hop, deterministic, machine-readable.
-
KYE Protocol™ — Ontology Profile · semantic authority across systems
KYE Ontology Profile™ is the semantic layer of KYE™ — shared meaning of entities, authorities, capabilities, scopes, states, decisions, evidence, profiles, connectors and sectors. Map OAuth scopes
-
KYE Protocol™ — Open Data & Data Portals
Public-sector portals, regulator data portals, smart-city hubs, research catalogues, health data catalogues, NGO portals, infrastructure transparency portals
-
KYE Protocol™ — Operating Model Profile · readiness to runtime control
KYE Operating Model Profile™ — the enterprise adoption layer of KYE™. From use-case intake to readiness, authority records, authority gates, commit boundaries, runtime decisions
-
KYE Protocol™ — OSCAL compatibility | NIST 800-53A · FedRAMP · component definition · SSP · assessment results
KYE Protocol™ is OSCAL-native: every signed evidence pack maps deterministically to NIST OSCAL component-definition, system-security-plan and assessment-results documents. The mapping spec
-
KYE Protocol™ — Press · media kit
KYE Protocol™ press kit: boilerplate, logo, screenshots, contact for journalists / analysts / partners.
-
KYE Protocol™ — Privacy Policy (v1.0)
KYE Protocol™ Privacy Policy. Data controller: KYE Protocol™ Ltd. Data we collect, lawful basis, retention, sub-processors, data subject rights under GDPR Articles 15-22, international transfers
-
KYE Protocol™ — Regulatory coverage · 249 frameworks, 456/853 requirement groups Enforced
Regulatory coverage map for 249 frameworks: 456 of 853 requirement groups Enforced at runtime, 244 Designed, 153 Out of scope — all projected from one schema-backed registry.
-
KYE Protocol™ — Risk & mitigation | Threat model · failure modes · operational guarantees
What can go wrong — The KYE Protocol™ threat model: signing-key compromise, registry availability, false-positive denials, time-skew, replay, supply-chain risk
-
KYE Protocol™ — Roadmap · v1.0 · v1.1 preview · v2.0 horizon
v1 — KYE Protocol™ roadmap with dated milestones — v1.0 frozen April 2026, v1.0.x patch series, v1.1 preview profiles (Conformance Certification, Authority Graph™, Payload Trust, Self-Audit Attestation
-
KYE Protocol™ — Schemas · step 4 of the KYE™ stack
KYE™ schemas — JSON Schema 2020-12 contracts that validate every payload at runtime. Step 4 of the canonical 8-step KYE™ stack. 103 published schemas
-
KYE Protocol™ — Self-Governance · the protocol governs itself
The KYE Protocol™ governs itself under its own contract. Every privileged action emits the same signed evidence-pack family any customer would. Patent-safe envelopes; public JWKS.
-
KYE Protocol™ — Sitemap
Every page on the KYE Protocol™ public site, with a one-line description of each.
-
KYE Protocol™ — State Library · open-source state machines for every regulated industry
KYE State Library™ — open-source, versioned, signed reference state machines for 9 regulated industries. Adopt for your tenant, derive tightened variants, replay in audit
-
KYE Protocol™ — Sub-processor list (v1.0)
Sub-processors — KYE Protocol™ sub-processor list. Cloudflare for hosting, Pages Functions, D1, R2, KV, Workers AI, AI Gateway and Email Routing.
-
KYE Protocol™ — Taxonomies · step 2 of the KYE™ stack
KYE™ taxonomies — parent / child classification of the names in the KYE™ vocabulary
-
KYE Protocol™ — Terms of Service (v1.0)
KYE Protocol™ Terms of Service — minimum-viable B2B SaaS terms for the Audit Pilot program. Governing law: England & Wales. Notices: [email protected].
-
KYE Protocol™ — Trust Center · what is verifiable, by whom, today
KYE Protocol™ Trust Center — the procurement-grade summary. What is verifiable today (with reproducible commands), what is in progress, what requires external attestation. Hardening register
-
KYE Protocol™ — Manifests — installable / verifiable / sellable units
Every installable / verifiable / billable unit in KYE™ is a signed manifest. Connectors, widgets, SKUs, rule packs, sector packs, MCP tools, proof bundles, consultants
-
KYE Protocol™ — Profiles — 10 canonical conformance modes
KYE™ has 10 canonical profiles, locked by constitution. Profiles define the conformance contract an implementation MUST support; behavioural logic lives in rule packs
-
KYE Protocol™ — Rule packs — behavioural logic
Rule packs are bundles of rules — condition + effect + reason code — loaded by the Rules Gateway™ at request time. Sector packs, compliance regimes
-
KYE Protocol™ — Security · responsible disclosure · threat model · supply chain
KYE Protocol™ responsible-disclosure page. How you report a vulnerability, what the response SLA looks like, and which supply-chain controls run against the repository
-
KYE Protocol™ for Australia — runtime authority for sovereign AI (APRA CPS 230 · AI Guardrails · Privacy Act 1988 · ASD Essential Eight)
Australian organisations: runtime authority and signed evidence for AI under APRA CPS 230, the AI Guardrails, the Privacy Act 1988 and the ASD Essential Eight — Australian-sovereign deployable.
-
KYE Protocol™ for Canada — runtime authority for sovereign AI (PIPEDA · PHIPA · Health Canada · OSFI · FINTRAC)
Canadian organisations: runtime authority and signed evidence for AI under PIPEDA, PHIPA, Health Canada SaMD, OSFI and FINTRAC — bijection-mapped + Canadian-sovereign deployable.
-
KYE Protocol™ for Japan — runtime authority for sovereign AI (APPI · FSA AI · PMDA SaMD)
Japanese organisations: runtime authority and signed evidence for AI under the APPI, the FSA
-
KYE Protocol™ for New Zealand — runtime authority for sovereign AI (Privacy Act 2020 · RBNZ BS11 · Algorithm Charter)
New Zealand organisations: runtime authority and signed evidence for AI under the Privacy Act 2020, RBNZ BS11 and the Algorithm Charter — bijection-mapped + New-Zealand-sovereign deployable.
-
KYE Protocol™ for Singapore — runtime authority for sovereign AI (MAS TRM · AI Verify · MAS FEAT)
Singapore organisations: runtime authority and signed evidence for AI under the MAS TRM Guidelines, IMDA AI Verify and the MAS FEAT principles — bijection-mapped + Singapore-sovereign deployable.
-
KYE Protocol™ for the EU — runtime authority for the AI Act, GDPR, DORA, NIS2
EU organisations: runtime authority and signed evidence for AI under the AI Act, GDPR, DORA, NIS2 and EDPB guidance — bijection-mapped + deployable on EU-sovereign regions.
-
KYE Protocol™ for the Gulf — runtime authority for sovereign AI (UAE · KSA · Bahrain · Qatar)
Gulf organisations: runtime authority and signed evidence for AI under UAE PDPL, Saudi PDPL, Bahrain PDPL, Qatar PDPL, SAMA AI, DIFC and ADGM — sovereign-deployable on the customer
-
KYE Protocol™ for the public sector — runtime authority for citizen-facing AI
Public-sector AI: runtime authority and signed evidence for citizen-facing AI under ATRS, OECD AI Principles, NIST AI RMF and public-sector AI assurance — sovereign deployment, offline verifier.
-
KYE Protocol™ for the UK — runtime authority for sovereign AI (FCA · PRA · MHRA · NHS · DSIT)
UK organisations: runtime authority and signed evidence for AI under FCA, PRA, MHRA, NHS, DSIT and HAARF — bijection-mapped and deployable on UK-sovereign regions.
-
KYE Protocol™ for the United States — runtime authority for sovereign AI (HIPAA · FDA · OCC · NYDFS · SEC · CISA)
US organisations: runtime authority and signed evidence for AI under HIPAA, FDA SaMD, OCC, NYDFS Part 500, SEC, FFIEC, NIST AI RMF — bijection-mapped + US-sovereign deployable.
-
KYE Protocol™ Trust Center — live receipts, signed evidence, open verifier
Trust Center: every KYE Protocol™ claim is pointable to a live artefact — signed self-audit receipts, framework coverage attestations, JWKS, and the responsible-disclosure contract.
-
KYE Reality Coupling™ — stable-drift detection for delegated AI actions
Authorised — KYE Reality Coupling™ detects stable drift — when a delegated AI action remains locally valid (authority OK, purpose OK, scope OK
-
KYE Scenario Testing™ — Future-state testing for delegated AI actions
KYE Scenario Testing™ runs a proposed agent action through a deterministic stress evaluator before it executes — surfacing risk, recommended controls
-
PCI DSS v4.0 — Payment Card Industry Data Security Standard — KYE Protocol™
PCI DSS v4.0 — Payment Card Industry Data Security Standard: control mappings to KYE Protocol™ canonical artefacts.
-
Platform Map · 3D component diagnostic · KYE Protocol™
Interactive 3D platform map: every canonical KYE™ component as a dot on a rotatable dotted globe (longitude=stage · shell=rail), coloured by connectivity health — islands & broken chains.
-
Software Constitution Standard · KYE Protocol™
The Software Constitution Standard is a language-agnostic specification for projects that want to enforce their own design principles at CI time, with versioned rules and drift gates.
-
SR 11-7 — Model Risk Management — KYE Protocol™
SR 11-7 — Model Risk Management: control mappings to KYE Protocol™ canonical artefacts. Banking — model risk management for all regulated banking organisations supervised by the Federal Re…
-
State Registry — KYE Protocol™
State as a first-class primitive in KYE Protocol™: every entity carries a registered state machine; every transition is evidence-guarded and append-only
-
Taxonomy Color Key — one hue per component family · KYE Protocol™
What does each colour mean across KYE Protocol™? Every top-level component family has one WCAG-AA hue, light and dark: sector blue, framework violet, program teal, agent amber, sku green, and more.
Ready to evaluate KYE Protocol™?
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.