---
title: "KYE Protocol™ — For regulators & legal"
description: "Replayable, signed proof of who or what acted, on whose authority. Vendor-neutral, public-key-verifiable"
url: https://kyeprotocol.com/regulators/
lang: en
source: "KYE Protocol"
---

> Replayable, signed proof of who or what acted, on whose authority. Vendor-neutral, public-key-verifiable

For regulators

# Verify any vendor with one open contract.

KYE Protocol™ is an open standard (Apache 2.0). Every conformant gateway hands you the same signed Evidence Pack™ format. You replay one chain from public keys alone — not six vendor logs, not a deposition cycle.

Authority Finality™

## Replayable proof of who or what acted.

Every governed action answers six questions, signed: who or what is acting, on whose behalf, using which capability, under what authority, in what state, with what audit trail. The Decision Map™ visualises the answer per decision; the evidence pack carries the signed chain offline.

Frameworks

## 289 control mappings. 13 horizontal frameworks.

All bound to runtime controls through the KYE™ Compliance Mapping Rail™. Sector overlays (HIPAA, MiCA, FFIEC, IEC 62443, 42 CFR Part 2) layer on top of the horizontal mappings. Per-framework reference: [frameworks.html](https://kyeprotocol.com/frameworks/).

- **EU AI Act** (Regulation (EU) 2024/1689) — KYE™ EU AI Act Profile™; 10 controls (KYE-EUAIACT-001..010).
- **ISO/IEC 42001** — AI management system: clauses 4-10 + Annex A.
- **NIST AI Risk Management Framework** — Govern / Map / Measure / Manage.
- **SOC 2 (TSC 2017)**, **ISO/IEC 27001:2022**, **PCI DSS 4.0**.
- **PSD2/PSD3** + EBA SCA RTS, **DORA**, **NIS2**.
- **NIST SP 800-207** Zero Trust, **NIST Cybersecurity Framework 2.0**.
- **GDPR** (Articles 5, 7, 13-15, 17, 22, 25, 30, 32-35).
- **FedRAMP** (NIST SP 800-53 AC, AU, IA, SI, CM, IR families).

Live Evidence Pack™ Viewer

## Verify a sample evidence pack in your browser.

Drop a pack URL. Verify the signature offline against the publisher’s JWKS. Replay the bound Decision Map™ against the snapshot inputs. Walk the audit chain. Project to SOC 2 / ISO 27001 / EU AI Act / PSD3 / DORA. The same flow your assessor would run on a production pack — with no install, no signup.

## Verify a vendor’s claim.

Any KYE-conformant gateway can be tested with the same 129-fixture conformance pack — byte-for-byte the same as the reference Gateway.

[Read the whitepaper](https://kyeprotocol.com/whitepaper/) [Conformance pack](https://github.com/KYE-Protocol) [Per-framework reference](https://kyeprotocol.com/frameworks/) [OSCAL projection](https://kyeprotocol.com/oscal/)

## Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Try the sandbox →](https://kyeprotocol.com/sandbox/demos/)

Canonical KYE™ surfaces referenced on this page: [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) · [KYE™ Conformance Pack™](https://kyeprotocol.com/compliance/) · [KYE Protocol™](https://kyeprotocol.com/).
