Transparency

The protocol governs itself.

Every privileged action against the KYE™ codebase emits the same signed evidence-pack family KYE™ asks every customer to emit, and anyone can verify it offline from the published key.

2 · The receipts

IP-safe, signed, publicly verifiable.

Three live transparency surfaces. None disclose a KYE™ mechanism — only the canonical envelopes the protocol's clients consume. The proprietary track stays intact; the audit story stays auditable.

Self-governance run log

Every signed self-governance run published with its decision-map id, evidence-pack id, replay-proof id, signing key id, git SHA, and drift / replay-equivalence flags. /self-audit-runs/index.json

Reference envelope fixture

Three signed JSON artefacts — a self-audit run record, an engine-health snapshot, an audit-chain integrity check — signed with EdDSA over a canonical payload. Drop-in verifier; 30-line Python / Go equivalent. No mechanism content. trust-self-audit.html · trust/self-audit/self-audit-run.json

Public verification key

Single Ed25519 public key — everything in this transparency log verifies against it. Per-run public keys also published in each run directory under public-key.jwk so rotation is observable. trust/self-audit-jwks.json

3 · Verify it yourself

Two commands. No further dependency on us.

The fixture is small enough that a Python or Go verifier fits in 30 lines. The drop-in JavaScript verifier is in the public mirror.

# 1) Fetch the canonical verifier from the public mirror.
curl -fsSL https://raw.githubusercontent.com/KYE-Protocol/app/main/scripts/verify-self-audit.mjs -o /tmp/verify-self-audit.mjs

# 2) Run it against the live transparency log.
node /tmp/verify-self-audit.mjs

# Output (abridged):
#   Loaded JWKS — 1 key(s): kye:key:self-audit-fixture-2026-05
#   ✓ self-audit-run.json       alg=EdDSA kid=kye:key:self-audit-fixture-2026-05
#   ✓ engine-health.json        alg=EdDSA kid=kye:key:self-audit-fixture-2026-05
#   ✓ audit-integrity-check.json alg=EdDSA kid=kye:key:self-audit-fixture-2026-05

For each artefact: parse JSON, extract payload and signature, canonicalise payload (sorted keys, no whitespace), base64url-decode signature.sig, look up signature.kid in the JWKS, and verify EdDSA. No KYE-specific cryptography — vendor-documented primitives only.