Change Calendar · forward-looking

Every planned change — announced before it lands.

Tier-1 procurement teams need to plan their own change-management cycles. We publish ours: every breaking change, sub-processor addition, maintenance window, and policy revision — with the announce-date and effective-date, before they take effect. The minimum-notice policy is locked.

90 daysminimum notice for breaking changes to APIs, schemas, or wire formats
30 daysminimum notice before any new sub-processor begins processing customer data (GDPR Art. 28(2))
7 daysminimum notice for planned maintenance touching customer-visible surfaces
1 · Upcoming scheduled changes

Every entry has an announce-date and an effective-date.

Procurement scripts: curl -s https://kyeprotocol.com/change-calendar.json | jq '.entries[] | select(.status == "scheduled")'. Schema: kye.change_calendar.v1.

feature launch scheduled

Pilot 1 onboarding window opens (tier-1 banks)

Audit Pilot™ engagements open for tier-1 global bank pilots. Pilot scope is shadow-mode AI-agent governance against a published baseline; outputs are 30-day evidence packs.

Announced 2026-05-20 · Effective 2026-06-15 · Scope tier-1 pilots · Customer action not required · Apply for pilot

feature launch scheduled

EU data-residency router — operational verification (per-tenant)

Gateway data-residency middleware ships — operational per-tenant verification rolls out to EU tenants. Default-deny if region tag missing.

Announced 2026-05-20 · Effective 2026-07-01 · Scope EU tenants · Customer action not required · EU AI Act mapping

feature launch scheduled

Production HSM provisioning for BYOK signing keys

Production HSM-backed signing keys (@kye/byok) provisioned by operator. Replay-Proof™ envelopes verifiable from operator-rooted public keys alone.

Announced 2026-05-20 · Effective 2026-09-30 · Scope all tenants · Customer action not required

policy revision scheduled

SOC 2 Type II auditor engagement (SSAE 18)

SSAE 18 auditor engagement begins for SOC 2 Type II attestation. Control mapping is already shipped. Expected report delivery 3-6 months from engagement start.

Announced 2026-05-20 · Effective 2026-11-30 · Scope all tenants · Customer action not required · Trust Centre

policy revision scheduled

ISO/IEC 27001 external audit engagement

External audit engagement for ISO/IEC 27001 certification. SoA (Statement of Applicability) shipped. Expected certification 2-4 months from engagement start.

Announced 2026-05-20 · Effective 2026-09-30 · Scope all tenants · Customer action not required · Trust Centre

policy revision scheduled

External penetration test (Q2/Q3 2026)

Threat-led penetration test engagement, ~2-4 weeks. Report becomes available to tier-1 pilot customers under NDA + published Trust Centre status update.

Announced 2026-05-20 · Effective 2026-08-15 · Scope all tenants · Customer action not required

feature launch scheduled

v1.1 profile preview (additive only — no breaking changes to v1.0)

v1.1 introduces additional rule-pack + sector-pack additions on top of the 10 canonical profiles locked in v1.0. v1.133 conformance fixtures remain bit-for-bit stable.

Announced 2026-05-20 · Effective 2026-09-15 · Scope all tenants · Customer action not required · Historical changelog

2 · Notice policy

The policy is locked. Notice windows are minimum-floors, not targets.

  • Breaking changes to published APIs, JSON Schemas, OpenAPI surfaces, wire formats, or signed-envelope shapes carry ≥ 90 days notice from the announcement to the effective date. Customer-side opt-out window is included.
  • Sub-processor additions (new third-parties touching customer data) carry ≥ 30 days notice (GDPR Art. 28(2) + customer DPA ). Customers can object to a specific sub-processor; if KYE cannot accommodate the objection, the customer's right to terminate is preserved.
  • Maintenance windows on customer-visible surfaces carry ≥ 7 days notice. Emergency maintenance for security incidents is announced immediately via the status page and customer security contact.
  • Every entry on this page is also represented in the machine-readable JSON at /change-calendar.json, schema kye.change_calendar.v1. Procurement scripts can ingest it directly.
3 · Related

Trust Centre

Current attestation state, machine-readable at /trust.json.