Keep your GRC controls. Add the proof.
Already on Drata, Vanta, or ServiceNow GRC? KYE Protocol™ plugs in, maps to your existing controls, and feeds them action-by-action runtime proof — no rip-and-replace. Your system of record stays; KYE™ adds the system of proof.
On onboarding, KYE™ imports the control catalog and framework mappings you already maintain, so every governed action it decides is auto-mapped to a control you track. From then on it exports a replay-provable Evidence Pack™ straight into your control-evidence and Trust Center — turning a control that was attested once a year into one backed by proof at the moment of every action.
System of record, meet system of proof
Your GRC platform records what controls exist. KYE Protocol™ proves what each AI agent and human actually did against them. The adapter is the bridge — it reuses the KYE™ connector data contract, never a parallel one.
- Import on onboarding. KYE™ pulls your control catalog and framework mappings and maps each source row into its canonical compliance entities — control, obligation, evidence item, AI system — so your existing structure is honoured, not rebuilt.
- Crosswalk you can trust. Every control is crosswalked through the KYE Framework Mapping Rail™, so a SOC 2 control and the ISO/IEC 27001 clause that touches it resolve to the same proof — coverage is honest, never inflated.
- Export as proof. Each governed decision becomes an Evidence Pack™ pushed into your control-evidence and Trust Center, mapped to SOC 2, ISO/IEC 27001, ISO/IEC 42001, DORA, and the EU AI Act™ — replay-verifiable from public keys alone with Authority Finality™.
The platforms KYE™ plugs into
Each target is a declared adapter — import on the way in, Evidence Pack™ export on the way out — not a bespoke one-off. The same contract serves every system of record.
- Drata, Vanta, and Secureframe. The continuous-compliance platforms — KYE™ maps its runtime proof onto the SOC 2 and ISO/IEC 27001 controls they already automate for you.
- ServiceNow GRC, OneTrust, AuditBoard, and Archer. The enterprise risk and IRM systems — KYE™ imports their control and authority-document catalogs and returns governed-action evidence.
- Solytics model-risk management. For regulated model risk, KYE™ maps each agent decision to your model-risk controls, mapped through DORA and the EU AI Act™.
What it changes for your team
No migration project. No second control catalog to maintain. The adapter routes proof to the one place it changes an audit outcome — the control your auditor already opens.
- Onboard in days, not quarters. KYE™ adopts your existing controls instead of asking you to re-author them, so a pilot starts against your real catalog from day one.
- One evidence trail, every framework. A DPO sees governed-action proof flow into the GRC tool they already use, crosswalked across frameworks — not five disconnected exports.
- No new platform to run. You keep your stack; KYE™ adds the proof layer behind it, with no parallel system to maintain.
What KYE™ does not do
Clarity on the boundary is the product. KYE Protocol™ owns the proof — the decision and its replay-verifiable evidence — and leaves your GRC platform exactly where it is.
- Not a GRC tool. KYE™ does not author your controls or replace your system of record; it imports their structure and returns proof. The live per-platform connection is provisioned per tenant at activation, against credentials you hold.
- Not a parallel evidence format. KYE™ exports the one Evidence Pack™ it produces everywhere else — the same replay-provable record, mapped to your controls.
Ready to keep your GRC and add the proof? Connect your GRC or see the Compliance Observability Adapter™ it ships with.