---
title: "KYE Protocol™ — Trust Center · what is verifiable, by whom, today"
description: "KYE Protocol™ Trust Center — the procurement-grade summary. What is verifiable today (with reproducible commands), what is in progress, what requires…"
url: https://kyeprotocol.com/trust/
lang: en
source: "KYE Protocol"
---

> KYE Protocol™ Trust Center — the procurement-grade summary. What is verifiable today (with reproducible commands), what is in progress, what requires…

Trust Center

# What is verifiable today, what is in progress, what needs external action.

Trust is a runtime property, not a press release. We sign every claim. You replay every decision.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Read the docs](https://kyeprotocol.com/docs/)

### v1.0

contract frozen, Apache 2.0

### 10

public mirror repos — reproducible

### 13

compliance frameworks mapped

### NDA

procurement pack on request

1 · Verifiable today · reproducible by anyone

## Every row runs against something published. Run it; replicate it.

Every command below operates exclusively on the Apache 2.0-licensed public surface — the mirror repositories under [github.com/KYE-Protocol](https://github.com/KYE-Protocol) and the artefacts published at `kyeprotocol.com`. The proprietary master (`KYE-Protocol/app`) is never cloned and nothing here exposes implementation paths or internal artefacts. Rows are derived from the canonical public-mirror register, so a row cannot advertise a repository that does not exist.

| Public surface | Status | Reproduce |
| --- | --- | --- |
| **JSON Schemas** — `KYE-Protocol/schemas` | 112 published each served at its canonical `$id` | `git clone https://github.com/KYE-Protocol/schemas && jq '."$id"' schemas/proof-bundle.json` |
| **OpenAPI surface** — `KYE-Protocol/open-api` | 591 operations across the published specs | `git clone https://github.com/KYE-Protocol/open-api && grep -c 'operationId:' open-api/core.openapi.yaml` |
| **SDKs (TypeScript · Python · Go)** | publication pending the SDK test suites run in the platform’s own CI on every change; a public, standalone-verifiable SDK mirror has not yet had its first governed publication | tracked in the canonical public-mirror register — this table will carry the clone-and-test command the day the mirror actually delivers it |
| **Vocabulary register** — `KYE-Protocol/vocabulary` | 32 documents entity types, actions, lifecycle states, obligations, data classes, reason codes | `git clone https://github.com/KYE-Protocol/vocabulary && ls vocabulary` |
| **URN ID format** — `KYE-Protocol/id-format` | parser conformance | `git clone https://github.com/KYE-Protocol/id-format && cd id-format && npm ci && npm test` |
| **Examples gallery** — `KYE-Protocol/examples` | 1449 payloads every schema carries ≥ 1 example | `git clone https://github.com/KYE-Protocol/examples && find examples -name '*.json' \| wc -l` |

**Public mirror total:** the rows above replicate the public surface; nothing on this list requires access to the proprietary master.

2 · Reference-implementation posture

## Bank-grade hardening, covered under commercial licence.

The reference Gateway ships with a documented production-hardening posture — tenant authn (mTLS / OAuth2-CC), multi-tenant request scoping by `trust_domain_id`, per-tenant rate-limiting, security headers, append-only audit chain, swappable HSM/KMS key custody, policy-engine pluggability, structured observability, and a wired KYE™-on-KYE™ self-governing engine (operator actions like key rotation and self-audit runs route through the same engine and emit the same audit + evidence-pack format as external decisions; [see protocol § self-govern](https://kyeprotocol.com/protocol/#self-govern)). Operator runbooks cover Tier-1 onboarding, incident response, disaster recovery, GDPR (DPA / ROPA / DSR), customer SLA, sub-processor inventory, key rotation and regulator-comms templates. The full hardening register and runbook bundle are part of the procurement pack delivered to design partners under NDA, not published on the public web.

[Public self-audit fixture (signed) →](https://kyeprotocol.com/trust-self-audit/) [Request the procurement pack →](https://kyeprotocol.com/engage/#procurement-pack)

3 · Framework mappings · 289 controls × 249 frameworks

## Where the protocol artefacts satisfy each control.

Each row maps a KYE™ artefact (entity record · delegation · scope · credential · attestation · audit event · proof bundle · signal · transparency receipt · capability grant · recovery proof · break-glass grant · compromise report · state transition) to the control it satisfies and the endpoint to extract it. The control-mapping register is served from `kyeprotocol.com` alongside the published schemas; the source-of-truth normative spec ships under commercial licence.

| Framework | Mappings |
| --- | --- |
| SOC 2 (TSC 2017) | ~25 control mappings |
| ISO/IEC 27001:2022 — Annex A | ~28 control mappings |
| PCI DSS 4.0 | ~22 control mappings |
| PSD2 / PSD3 (RTS Reg. 2018/389) | ~16 control mappings |
| DORA — Reg. (EU) 2022/2554 | ~22 control mappings |
| NIS2 — Dir. (EU) 2022/2555 | ~18 control mappings |
| EU AI Act — Reg. (EU) 2024/1689 | 10 controls (KYE-EUAIACT-001..010) |
| NIST SP 800-207 — Zero Trust Architecture | ~18 control mappings |
| ISO/IEC 42001 — AIMS | ~20 control mappings |
| NIST AI RMF 1.0 | ~24 control mappings |
| GDPR — Reg. (EU) 2016/679 | ~18 control mappings |
| FedRAMP — Federal Risk and Authorization Management | ~30 control mappings |
| NIST Cybersecurity Framework 2.0 | ~16 control mappings |

4 · Procurement pack · under NDA

## Detail for procurement teams — on request.

The full hardening register, runbook bundle, attestation roadmap (SOC 2 / ISO 27001 / FedRAMP timing), HSM-integration matrix, and supply-chain controls are packaged for procurement teams under NDA, alongside the reference-implementation architecture documents. We don’t publish gap lists or implementation inventories on the open web.

[Request the procurement pack →](https://kyeprotocol.com/engage/#procurement-pack) [Public framework mappings →](https://kyeprotocol.com/compliance/)

5 · Government agency readiness

## Sovereign / public-sector path.

Public-sector adoption follows a distinct path from commercial banks. The protocol artefacts that gov agencies will ask for:

| Artefact | Status |
| --- | --- |
| **KYE™ Sovereign AI Profile™** — protocol surface | v1.1 preview · 9 sub-profiles + 5 planned apps |
| **KYE™ Public Sector Profile™** | v1.1 preview |
| **KYE™ Cross-Agency Delegation Profile™** | v1.1 preview |
| **KYE™ Government API Authority Profile™** | v1.1 preview |
| NIST 800-207 Zero Trust mapping | published in control-mapping register |
| NIST AI RMF mapping | published in control-mapping register |
| FedRAMP control mapping | published in control-mapping register (no ATO yet) |
| OSCAL projection (component-definition / SSP / assessment-results / POA&M) | 7 / 7 tests pass |
| Public-sector decision evidence pack | v1.1 preview |
| Sovereign data-residency profile | v1.1 preview |
| FIPS 140-3 cryptographic compliance | requires HSM-vendor module + test report |
| StateRAMP / CCCS readiness | scoped via FedRAMP base mappings |

6 · Resolve an evidence reference

## Holding a reference? Check it here.

A governed KYE Protocol™ surface shows you an opaque evidence reference when it acts. Paste one below to see which capture it came from, the governed outcome, when it was recorded, and the SHA-256 of the exact frame — so the identifier and the means to check it travel together.

This is an **audit-reference index**, not a signed Replay-Proof Evidence Pack™. It confirms a reference corresponds to a real governed capture with a real outcome and real bytes. Re-deriving the verdict itself from public keys is the sealed-report path, not this lookup. References that return nothing here are illustrative — every page that prints one says so.

Evidence reference

## In one paragraph.

**The KYE Protocol™ contract is bank-grade and frozen.** The Apache 2.0 public mirror repos — schemas, OpenAPI, three SDKs, vocabulary, ID format, examples — are reproducible today: clone, install, run the test commands above. The conformance pack is _not_ among them: its fixtures are IP-track, so it ships under commercial licence rather than as a public mirror. The reference implementation is shipped under commercial licence to design partners with the full hardening register, the operator runbook bundle, and the procurement pack. Procurement and security teams should request that pack via [/engage](https://kyeprotocol.com/engage/).

[Request the procurement pack →](https://kyeprotocol.com/engage/#procurement-pack) [Live status →](https://kyeprotocol.com/status/sla/) [Legal →](https://kyeprotocol.com/legal/)

## Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Try the sandbox →](https://kyeprotocol.com/sandbox/demos/)

## Machine-readable trust posture

Procurement teams can fetch a machine-readable trust posture as JSON. Detailed control attestations and procurement artefacts are shared with qualified buyers under NDA via this Trust Centre.

```
curl -s https://kyeprotocol.com/trust.json
{
  "schema": "kye.trust_posture.v1",
  "posture": "Pilot-ready. Enterprise certifications (SOC 2 Type II, ISO/IEC 27001) and independent assurance are in progress.",
  "trust_centre": "https://kyeprotocol.com/trust.html"
}
```

Canonical KYE™ surfaces referenced on this page: [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) · [KYE Protocol™](https://kyeprotocol.com/).
