Air-gapped governance lifecycle
Cut the cable. The governance still runs.
If your agents act inside an enclave, a submarine, a substation or a classified network, you do not get to make an outbound call. KYE Protocol™ decides, enforces, seals its evidence, reconciles and self-assures from local state alone — no control plane to reach, no vendor to be up. For an incident review, that turns reconstruction from days of log archaeology into minutes of replay.
The whole lifecycle, inside the boundary
Most governance tooling is offline-tolerant in one place and network-bound everywhere else — the check runs locally but the verdict, the log, or the attestation still leaves the building. KYE™ holds the property across all five stages, so there is no stage that quietly needs the wire.
- Decide. The verdict comes from policy already on the device and the request in front of it. No remote policy fetch, no directory round-trip, no telemetry call standing between an agent and an answer.
- Enforce. The action is admitted or refused in-line. When certainty drops, capability shrinks to the safest pre-authorised behaviour — the KYE Safety Floor™ — and never to "permit by default".
- Emit. The Evidence Pack™ is hash-chained and sealed at the moment of the action. Nothing waits for a network to become auditable.
- Reconcile. What was declared is checked against what actually happened, from local records, so drift is caught inside the enclave rather than at the next sync window.
- Assure. The self-checks that answer "is this deployment still governed?" are pure functions of what is on disk. An assurance answer that needs a reachable host is availability, not assurance.
Why a hosted control plane cannot match this
This is not a feature gap a competitor closes in a sprint. If your architecture puts the decision in someone else's cloud, you inherit their availability, their jurisdiction and their outage — and no amount of uptime changes what happens when your accreditation forbids the connection outright.
How each posture behaves when the link is down — pick a side:
- Can an agent get a verdict?
- Yes, from local policy and context.
- Is the action evidenced?
- Sealed locally, at the moment it happens.
- Who can verify the record?
- Anyone, from published public keys alone.
- What fails if the vendor fails?
- Nothing on the verdict path.
- Can an agent get a verdict?
- No — or a cached guess with unknown freshness.
- Is the action evidenced?
- Buffered raw, sealed later.
- Who can verify the record?
- The vendor’s console.
- What fails if the vendor fails?
- Governance.
Three failure shapes this design rules out by construction. Phone-home verdict — a decision that calls out, so a partition becomes a governance outage. Seal-on-reconnect — buffering an unsealed action and sealing only once the link returns, which leaves an unevidenced window exactly where an inquiry looks first. Offline-as-a-mode — an "offline" checkbox on one deployment while the shared engine underneath it quietly grew a network dependency.
Who this is actually for
If you are reading this, you probably already know which of these you are — and you have likely been told by a vendor that a private region is close enough. Segregation of networks is a named control, not a preference: ISO/IEC 27001:2022 Annex A control 8.22, NIST SP 800-53 Rev 5 SC-7, and the zones-and-conduits model of IEC 62443 all assume some boundary an agent must not reach across.
- Defence and intelligenceClassified enclaves where a cross-domain transfer is a governed event of its own. Authority has to be decidable on the low side and the high side, independently.
- Central banks and market infrastructureWhere the operational-resilience question under DORA Article 11 is "does this keep working when the third party does not?" — and "we would call the vendor" is not an answer.
- Critical infrastructure and industrial controlGrid, water, rail and plant networks under NIS2 Article 21, where the operational technology segment is deliberately unrouted and your agents still take consequential actions there.
- Sovereign and regulated enterpriseData-residency regimes where the governance decision itself — not just the payload — must never leave the jurisdiction. See KYE Sovereign AI Profile™.
In each case the deployment is the Disconnected Edge mode of KYE Edge Governance™, and the properties you are buying are the same ones your accreditor asks about: a decision that is reproducible, an Action Admissibility™ record that stands on its own, and Authority Finality™ that can still be suspended when a control fails.
What we do not claim
An honest boundary is worth more to you than a bigger claim, because the bigger claim is the one that collapses under audit. Two limits, stated plainly.
- This is air-gapped governance, not an air-gapped productKYE™ still talks to the outside world for ordinary work — publishing, notifying, observing a deployed surface. The invariant is narrower and sharper: the decision and its evidence for any such event seal locally, with nothing external on the verdict path. An outside system can be the subject of governance; it is never a dependency of the verdict.
- Offline does not mean unaccountableRunning unplugged is not a way to avoid scrutiny. The sealed record is the same record, verifiable by anyone holding the published keys, whether it is read inside the enclave today or from your archive next year.
Air-gap-ability is a constitutional invariant on the KYE™ governance lifecycle, not a deployment option someone remembers to tick — it is checked mechanically on every change, and a new network dependency on the verdict path fails the build.