For regulators

Verify any vendor with one open contract.

KYE Protocol™ is an open standard (Apache 2.0). Every conformant gateway hands you the same signed Evidence Pack™ format. You replay one chain from public keys alone — not six vendor logs, not a deposition cycle.

For regulators & legal, step by step

Demo data

You learn: What happens at each step. You can: Step through it.

  1. Step 1 of 8

    KYE Protocol™

    EU AI Act

    (Regulation (EU) 2024/1689) — KYE™ EU AI Act Profile™; 10 controls (KYE-EUAIACT-001..010).

  2. Step 2 of 8

    KYE Protocol™

    ISO/IEC 42001

    AI management system: clauses 4-10 + Annex A.

  3. Step 3 of 8

    KYE Protocol™

    NIST AI Risk Management Framework

    Govern / Map / Measure / Manage.

  4. Step 4 of 8

    KYE Protocol™

    SOC 2 (TSC 2017)

    , ISO/IEC 27001:2022 , PCI DSS 4.0 .

  5. Step 5 of 8

    KYE Protocol™

    PSD2/PSD3

    + EBA SCA RTS, DORA , NIS2 .

  6. Step 6 of 8

    KYE Protocol™

    NIST SP 800-207

    Zero Trust, NIST Cybersecurity Framework 2.0 .

  7. Step 7 of 8

    KYE Protocol™

    GDPR

    (Articles 5, 7, 13-15, 17, 22, 25, 30, 32-35).

  8. Step 8 of 8

    KYE Protocol™

    FedRAMP

    (NIST SP 800-53 AC, AU, IA, SI, CM, IR families).

How this widget is built
Demonstrates
KYE Protocol™
Components
  • The steps this page describes
Flow
Each step in order, as the page sets it out. Architecture diagram
Used on

Authority Finality™

Replayable proof of who or what acted.

Every governed action answers six questions, signed: who or what is acting, on whose behalf, using which capability, under what authority, in what state, with what audit trail. The Decision Map™ visualises the answer per decision; the evidence pack carries the signed chain offline.

Frameworks

289 control mappings. 13 horizontal frameworks.

All bound to runtime controls through the KYE™ Compliance Mapping Rail™. Sector overlays (HIPAA, MiCA, FFIEC, IEC 62443, 42 CFR Part 2) layer on top of the horizontal mappings. Per-framework reference: frameworks.html.

  • EU AI Act (Regulation (EU) 2024/1689) — KYE™ EU AI Act Profile™; 10 controls (KYE-EUAIACT-001..010).
  • ISO/IEC 42001 — AI management system: clauses 4-10 + Annex A.
  • NIST AI Risk Management Framework — Govern / Map / Measure / Manage.
  • SOC 2 (TSC 2017), ISO/IEC 27001:2022, PCI DSS 4.0.
  • PSD2/PSD3 + EBA SCA RTS, DORA, NIS2.
  • NIST SP 800-207 Zero Trust, NIST Cybersecurity Framework 2.0.
  • GDPR (Articles 5, 7, 13-15, 17, 22, 25, 30, 32-35).
  • FedRAMP (NIST SP 800-53 AC, AU, IA, SI, CM, IR families).

Live Evidence Pack™ Viewer

Verify a sample evidence pack in your browser.

Drop a pack URL. Verify the signature offline against the publisher’s JWKS. Replay the bound Decision Map™ against the snapshot inputs. Walk the audit chain. Project to SOC 2 / ISO 27001 / EU AI Act / PSD3 / DORA. The same flow your assessor would run on a production pack — with no install, no signup.

Verify a vendor’s claim.

Any KYE-conformant gateway can be tested with the same 129-fixture conformance pack — byte-for-byte the same as the reference Gateway.

Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

Canonical KYE™ surfaces referenced on this page: Evidence Pack™ · KYE™ Conformance Pack™ · KYE Protocol™.