Enforcement at the decision point.
Step 6 produces a signed verdict. Step 7 is the gateway that enforces it. The gateway intercepts a candidate action at the commit boundary, asks the policy engine for a decision, and only lets the action commit when the signed Decision Map™ says allow.
Three reference deployments. All open.
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
npx wrangler dev (in internal). Production hardening (auth, rate limit, body-size, structured logging, JSONL audit chain) opt-in via env vars.Three obligations. Every commit-level action.
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
- Pre-commit decision — call
POST /v1/runtime/authorize; do not commit unless the verdict isallow(orallow_with_constraintsand constraints are satisfied). - Audit chain emission — the gateway hash-links every decision into an append-only audit ledger; the verify endpoint detects breaks end-to-end.
- Signal Bus™ publication — the gateway publishes signed events (
kye.decision.*,kye.signal.*, profile-specific events) so downstream subscribers can react atomically.
Continue the stack →
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
Ready to see your AI agents flagged?
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.