Pilot 1 onboarding window opens (tier-1 banks)
Audit Pilot™ engagements open for tier-1 global bank pilots. Pilot scope is shadow-mode AI-agent governance against a published baseline; outputs are 30-day evidence packs.
Tier-1 procurement teams need to plan their own change-management cycles. We publish ours: every breaking change, sub-processor addition, maintenance window, and policy revision — with the announce-date and effective-date, before they take effect. The minimum-notice policy is locked.
Procurement scripts: curl -s https://kyeprotocol.com/change-calendar.json | jq '.entries[] | select(.status == "scheduled")'. Schema: kye.change_calendar.v1.
Audit Pilot™ engagements open for tier-1 global bank pilots. Pilot scope is shadow-mode AI-agent governance against a published baseline; outputs are 30-day evidence packs.
Gateway data-residency middleware ships — operational per-tenant verification rolls out to EU tenants. Default-deny if region tag missing.
Production HSM-backed signing keys (@kye/byok) provisioned by operator. Replay-Proof™ envelopes verifiable from operator-rooted public keys alone.
SSAE 18 auditor engagement begins for SOC 2 Type II attestation. Control mapping is already shipped. Expected report delivery 3-6 months from engagement start.
External audit engagement for ISO/IEC 27001 certification. SoA (Statement of Applicability) shipped. Expected certification 2-4 months from engagement start.
Threat-led penetration test engagement, ~2-4 weeks. Report becomes available to tier-1 pilot customers under NDA + published Trust Centre status update.
v1.1 introduces additional rule-pack + sector-pack additions on top of the 10 canonical profiles locked in v1.0. v1.133 conformance fixtures remain bit-for-bit stable.
/change-calendar.json, schema kye.change_calendar.v1. Procurement scripts can ingest it directly.Current attestation state, machine-readable at /trust.json.
Canonical list of sub-processors, with DORA risk classification.
Dated release notes — what already shipped.