Air-gapped governance lifecycle

Cut the cable. The governance still runs.

If your agents act inside an enclave, a submarine, a substation or a classified network, you do not get to make an outbound call. KYE Protocol™ decides, enforces, seals its evidence, reconciles and self-assures from local state alone — no control plane to reach, no vendor to be up. For an incident review, that turns reconstruction from days of log archaeology into minutes of replay.

The whole lifecycle, inside the boundary

Most governance tooling is offline-tolerant in one place and network-bound everywhere else — the check runs locally but the verdict, the log, or the attestation still leaves the building. KYE™ holds the property across all five stages, so there is no stage that quietly needs the wire.

The KYE governance lifecycle running inside an air-gapped boundary Five stages — decide, enforce, emit, reconcile, assure — sit inside a dashed air-gapped boundary and flow left to right. Evidence is sealed locally under the emit stage. A cable to an external vendor control plane is drawn severed outside the boundary. A separate dashed arrow leaves the boundary toward the operator's own archive and verifier, labelled as an optional sync when reconnected. AIR-GAPPED BOUNDARY everything the verdict needs is already inside Decide local policy → verdict Enforce admit or refuse Emit evidence, sealed Reconcile declared vs actual Assure self-check sealed at the moment of the action — not on reconnect Vendor control plane unreachable — and unneeded no call on the verdict path Your archive + verifier yours, not ours sync when reconnected — optional, never required
The five stages and the boundary are the shape of the contract, not a product screenshot: the severed cable is the point, and the dashed arrow only ever runs outward.
  1. Decide. The verdict comes from policy already on the device and the request in front of it. No remote policy fetch, no directory round-trip, no telemetry call standing between an agent and an answer.
  2. Enforce. The action is admitted or refused in-line. When certainty drops, capability shrinks to the safest pre-authorised behaviour — the KYE Safety Floor™ — and never to "permit by default".
  3. Emit. The Evidence Pack™ is hash-chained and sealed at the moment of the action. Nothing waits for a network to become auditable.
  4. Reconcile. What was declared is checked against what actually happened, from local records, so drift is caught inside the enclave rather than at the next sync window.
  5. Assure. The self-checks that answer "is this deployment still governed?" are pure functions of what is on disk. An assurance answer that needs a reachable host is availability, not assurance.

Why a hosted control plane cannot match this

This is not a feature gap a competitor closes in a sprint. If your architecture puts the decision in someone else's cloud, you inherit their availability, their jurisdiction and their outage — and no amount of uptime changes what happens when your accreditation forbids the connection outright.

How each posture behaves when the link is down — pick a side:

Can an agent get a verdict?
Yes, from local policy and context.
Is the action evidenced?
Sealed locally, at the moment it happens.
Who can verify the record?
Anyone, from published public keys alone.
What fails if the vendor fails?
Nothing on the verdict path.
Can an agent get a verdict?
No — or a cached guess with unknown freshness.
Is the action evidenced?
Buffered raw, sealed later.
Who can verify the record?
The vendor’s console.
What fails if the vendor fails?
Governance.

Three failure shapes this design rules out by construction. Phone-home verdict — a decision that calls out, so a partition becomes a governance outage. Seal-on-reconnect — buffering an unsealed action and sealing only once the link returns, which leaves an unevidenced window exactly where an inquiry looks first. Offline-as-a-mode — an "offline" checkbox on one deployment while the shared engine underneath it quietly grew a network dependency.

Who this is actually for

If you are reading this, you probably already know which of these you are — and you have likely been told by a vendor that a private region is close enough. Segregation of networks is a named control, not a preference: ISO/IEC 27001:2022 Annex A control 8.22, NIST SP 800-53 Rev 5 SC-7, and the zones-and-conduits model of IEC 62443 all assume some boundary an agent must not reach across.

In each case the deployment is the Disconnected Edge mode of KYE Edge Governance™, and the properties you are buying are the same ones your accreditor asks about: a decision that is reproducible, an Action Admissibility™ record that stands on its own, and Authority Finality™ that can still be suspended when a control fails.

What we do not claim

An honest boundary is worth more to you than a bigger claim, because the bigger claim is the one that collapses under audit. Two limits, stated plainly.

Air-gap-ability is a constitutional invariant on the KYE™ governance lifecycle, not a deployment option someone remembers to tick — it is checked mechanically on every change, and a new network dependency on the verdict path fails the build.