---
title: "KYE™ Runtime Proxy Adapter™ — make your proxy enforce KYE™ decisions · KYE Protocol™"
description: "The KYE™ Runtime Proxy Adapter™ turns your existing runtime proxy, LLM gateway, or content firewall into a Policy Enforcement Point: it calls the KYE™ Policy Decision Point inline and enforces the authority decision at the wire, while KYE™ keeps Purpose Permission™, the Evidence Pack™, Replay-Proof™ and Authority Finality™. The proxy is the hands; KYE™ owns the decision."
url: https://kyeprotocol.com/runtime-proxy-adapter/
lang: en
source: "KYE Protocol"
---

> The KYE™ Runtime Proxy Adapter™ turns your existing runtime proxy, LLM gateway, or content firewall into a Policy Enforcement Point: it calls the KYE™ Policy Decision Point inline and enforces the authority decision at the wire, while KYE™ keeps Purpose Permission™, the Evidence Pack™, Replay-Proof™ and Authority Finality™. The proxy is the hands; KYE™ owns the decision.

# Make your proxy enforce the authority decision

The **KYE™ Runtime Proxy Adapter™** turns the runtime proxy you already run — an LLM gateway, a content firewall, or an egress guardrail — into a **Policy Enforcement Point**. On the hot path it calls the KYE Protocol™ **Policy Decision Point** inline and enforces the returned verdict at the wire, before any consequential action reaches a model or tool. The proxy is the hands; KYE™ owns the decision.

When an AML agent tries to close an alert, your gateway asks KYE™ "is this authorised?" and blocks, steps up, or forwards in one inline call — cutting exam-prep evidence-gathering from days to minutes, because every verdict ships with a replay-provable [Evidence Pack™](https://kyeprotocol.com/evidence-pack/).

[Start a governed pilot](https://kyeprotocol.com/poc/) [See the adapter port](https://kyeprotocol.com/policy-resolver/)

## The proxy enforces; KYE™ decides

You keep your runtime proxy. KYE Protocol™ supplies the one thing a proxy cannot: a replay-provable answer to _who was authorised_. The Adapter ships on the existing [Policy Resolver™](https://kyeprotocol.com/policy-resolver/) port, so it adds no new engine to your stack.

- **Inline call, fail-closed.** The proxy calls the KYE™ decision point synchronously (in-process, sidecar, or remote) and waits for the verdict. On timeout it fails closed — denies — the banking-grade default required under DORA operational-resilience expectations.
- **One decision vocabulary.** Every verdict maps to the locked outcome set (allow, allow-with-constraints, deny, quarantine, require-step-up, require-approval) — no parallel decision language, so a regulator reads one map, not two.
- **Evidence at the wire.** The raw proxy verdict is hashed and pinned into the [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) so the decision is **Replay-Proof™** from KYE™ public keys alone, mapped to EU AI Act™ Article 12 record-keeping and NIST AI RMF MEASURE.

## What it costs you to skip it

A proxy that blocks prompts but cannot prove who authorised an action leaves you, the CISO, assembling evidence by hand at audit time. The Adapter closes that gap at the point of action.

- **Days to minutes.** Inline evidence capture turns a multi-day exam-prep scramble into a signed export — every enforced action already carries its decision map.
- **One integration, every workflow.** Wire the Adapter into the proxy once and it governs every AI workflow behind it — no per-agent rebuild — so a 20-workflow estate is one rollout, not twenty.
- **Kill-switch safety.** A per-adapter kill switch falls back to deny-by-default, never fail-open, satisfying ISO/IEC 42001 clause 8 operational-control expectations.

## Where it sits

The Adapter is a port into the KYE™ decision point, aligned with the KYE™ MCP gateway (§15) and the **KYE™ Edge Arbiter™** (§25) — the same decision, enforced wherever your proxy runs.

- **LLM gateway PEP** — admits or blocks a prompt or tool-call in front of model APIs.
- **Content firewall PEP** — enforces the KYE™ verdict on a model output at egress.
- **Edge guardrail PEP** — enforces inline at the edge for low-latency action paths.

Ready to make your proxy provable? [Start a governed pilot](https://kyeprotocol.com/poc/) or [read the adapter port contract](https://kyeprotocol.com/policy-resolver/).

Canonical KYE™ surfaces referenced on this page: [KYE™ Edge Governance™](https://kyeprotocol.com/glossary/) · [KYE Protocol™](https://kyeprotocol.com/) · [Purpose Permission](https://kyeprotocol.com/glossary/).
