All reports

KYE Governed Research Rail · Proposal · Edition 2026-W26

KYE Governed Proposal Authority™: SERPRO Governed Data-Query Partnership

seriesRoadmap to AI Governance formatProposal sectorFinancial Services audiencePartners cadenceWeekly Free edition

Ed25519-sealed · fingerprint 097515d916aa894a · verify it yourself ↓

KYE Protocol governs actions and authorities, not outcomes, diagnoses, or results. This report synthesises public sources under the evidence / no-hallucination gate — every claim below is pinned to a cited source.

A proposal you can prove, not just generate.

This is a worked instance of KYE Governed Proposal Authority™ — the responder/bidder-side companion to the Tender/Procurement pack. It is a governed §62 report with format = proposal: its input is a partner / engagement context record (here, the SERPRO governed-connector partnership), and its output is a proposal whose every factual claim is grounded in a pinned public source, rendered byte-deterministically, and sealed into Replay-Proof™ evidence that any reader can verify from the published JWKS alone.

KYE Governed Proposal Authority™ governs that the proposal is grounded, deterministic and evidence-sealed. It does NOT auto-write novel strategy or positioning — that stays human judgment. The scope and commercial terms below are authored by the proposal owner; the rail's job is to make every factual claim in them provable.

Executive tear-sheet (60 seconds)

KYE Governed Proposal Authority™ turns a SERPRO governed data-query partnership context into a deterministic, fully-cited, replay-sealed proposal.

  • Who it is for: the responder/bidder building a partner or commercial proposal that a regulated counterparty (or a procurement panel) will scrutinise claim-by-claim.
  • What it does: turns a partner/engagement context record into a governed proposal — every factual claim cited, the render byte-stable, the whole proposal sealed and replay-verifiable.
  • Worked input here: the SERPRO governed-connector partnership — an authoritative Brazilian government entity-data source (CPF / CNPJ / CND / NF-e from the Receita Federal do Brasil) feeding the KYE Protocol™ Entity Registry / KYB for the br trust domain.
  • The §0 boundary: the rail proves the proposal's claims; it does not invent them. No customer is fabricated; no claim ships uncited.

Key findings

1. SERPRO is an authoritative verification input — it answers who an entity is, per the register; it is not an authority and does not resolve whether an action is authorised. Data verification is not authority. 2. The governed-connector contract is satisfiable by construction: every query crosses the KYE Protocol™ purpose/admissibility boundary before SERPRO is contacted, and the raw CPF/CNPJ payload is never persisted — only a tenant-salted digest, result field-names and a content hash. 3. The proposal's commercial terms bind to a §26 SKU (KYE-PROPOSAL-AUTHORITY-001) with a §26 pricing-disclosure record, so the bid's price posture is itself governed.

1. Engagement context (the proposal input)

TL;DR SERPRO (Serviço Federal de Processamento de Dados) exposes authoritative

SERPRO (Serviço Federal de Processamento de Dados) exposes authoritative Brazilian government entity-data APIs sourced from the Receita Federal do Brasil: Consulta CPF (individual taxpayer register), CNPJ (company register), CND (tax-debt clearance) and NF-e (electronic invoice). In the KYE Protocol™ architecture SERPRO is an input-layer adjacency on the §0.33 category map — the same class as Trulioo / Sumsub / ID.me — feeding the Entity Registry / KYB for the br trust domain (kye:entity:br:company:<cnpj>, kye:entity:br:person:<cpf-scoped-ref>).

The proposal's input record is the partner-context record for this engagement: partner class (authoritative entity-data source), trust domain (br), the governed query surface (CPF / CNPJ / CND / NF-e), and the legal regime the partnership operates under (LGPD).

2. Grounded capability claims (each cited)

TL;DR The proposal's substantive claims are grounded in pinned public sources —

The proposal's substantive claims are grounded in pinned public sources — no claim ships without one. The governing claims of this partnership are:

  • CPF is personal data under Brazil's Lei Geral de Proteção de Dados (LGPD), so every query carries a purpose and a legal basis, and the returned payload is minimised.
  • SERPRO publishes the CPF/CNPJ consultation APIs with a documented dummy-data sandbox for proof-of-concept work ahead of the credentialed production endpoint.
  • The Receita Federal do Brasil is the federal authority whose registers SERPRO exposes — the authoritative source of the CPF and CNPJ records.
  • The NIST AI Risk Management Framework (Govern / Map / Measure / Manage) is the backbone the deployer adapts for the governance programme wrapping the connector.

Each of these claims resolves to a citation in this report's evidence ledger, pinned via kye.evidence.tool_call_pin.v1 into the sealed kye.evidence.pack.v1.

3. Governed scope + commercial terms (§26)

TL;DR The proposal scope is the governed query flow: an agent/engine requests a

The proposal scope is the governed query flow: an agent/engine requests a SERPRO query with a KYE Protocol™ authority envelope (actor, on-behalf-of, authority chain, trust domain, purpose, legal basis); the request is admissibility-checked at the KYE Protocol™ gateway (kye.purpose.request.v1kye.purpose.admissibility.v1); on admit the connector issues the tenant-keyed query and emits the §0.3 evidence family. Fail-closed: an out-of-scope or no-lawful-basis query is refused and SERPRO is never called.

The commercial terms bind to the §26 SKU KYE-PROPOSAL-AUTHORITY-001 with a §26 pricing-disclosure record. The proposal owner authors the specific tier, scope and consideration; the rail makes the factual claims underneath them provable.

4. Personal-data minimisation (LGPD / SERPRO contract)

TL;DR The connector never gives an agent raw, ungoverned access to SERPRO.

The connector never gives an agent raw, ungoverned access to SERPRO. The raw CPF/CNPJ payload is never persisted: the Evidence Pack™ reference carries only a tenant-salted hash of the queried number, the result field names plus a content hash, and raw_payload_persisted: false. The record proves which query ran, what shape returned, who acted and under what purpose and legal basis — without re-exposing the personal data. This is the §6-determinism rule (cited inputs, never the raw payload) applied to a governed data-query connector.

5. Evidence + replay-verify

TL;DR This proposal is rendered once (web · email_html · pdf) by the §62 / §14

This proposal is rendered once (web · email_html · pdf) by the §62 / §14 deterministic-render machinery — there is no parallel renderer. It is sealed with the §13 kye.replay.context_seal.v1 Ed25519 signature over the canonical-JCS-encoded envelope (with the body hash bound in), and the seal verifies against the published JWKS at /trust/self-audit-jwks.json. Any reader can confirm the seal from the published keys alone — the proposal is a proof, not just a document.

§0 boundary (stated honestly)

TL;DR KYE Governed Proposal Authority™ governs that a proposal is **grounded

KYE Governed Proposal Authority™ governs that a proposal is grounded (every claim cited), deterministic (byte-stable render) and evidence-sealed (replay-verifiable from public keys). It does NOT auto-write novel strategy or positioning — that is human judgment. It is a REUSE of the KYE Governed Research Rail™ (a new proposal format on the existing rail), never a new engine, renderer or key system; it inherits the §62 non-competition lock vs the §14 Reporting Engine.

Claims → sources — every claim mapped to a pinned source

This is the claims→source map: no claim ships without a cited, pinned public source (evidence gate). Each numbered claim below is pinned into this edition's sealed evidence pack kye:evidence-pack:research:governed-proposal-serpro-partnership:2026-w26.

  1. CPF is personal data under Brazil's Lei Geral de Proteção de Dados (LGPD), so processing requires a purpose and a legal basis and the data must be minimised. https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htmPresidência da República — Casa Civil (Brazil) (retrieved 2026-06-27T08:30:00Z)
  2. SERPRO publishes the Consulta CPF and Consulta CNPJ APIs sourced from the Receita Federal do Brasil, with a documented dummy-data sandbox available for proof-of-concept integration ahead of the credentialed production endpoint. https://www.gov.br/conecta/catalogo/apis/consulta-cpfSERPRO / Governo Federal do Brasil (retrieved 2026-06-27T08:30:00Z)
  3. The Receita Federal do Brasil is the federal tax authority whose CPF and CNPJ registers SERPRO exposes — the authoritative source of the Brazilian taxpayer and company records. https://www.gov.br/receitafederal/pt-brReceita Federal do Brasil (retrieved 2026-06-27T08:30:00Z)
  4. The NIST AI Risk Management Framework organises trustworthy-AI practice into four functions — Govern, Map, Measure, Manage — that a deployer adapts as the backbone of an AI governance programme. https://www.nist.gov/itl/ai-risk-management-frameworkNational Institute of Standards and Technology (retrieved 2026-06-27T08:30:00Z)
  5. The OECD AI Principles call for accountability and traceability across the AI system lifecycle, supporting an evidence trail for automated decisions and the data queries that feed them. https://oecd.ai/en/ai-principlesOrganisation for Economic Co-operation and Development (retrieved 2026-06-27T08:30:00Z)
  6. ISO/IEC 42001 specifies requirements for an AI management system, providing the management-system spine an organisation uses to govern AI-assisted entity-verification processes. https://www.iso.org/standard/81230.htmlInternational Organization for Standardization (retrieved 2026-06-27T08:30:00Z)

Replay-verifiable

This edition is sealed and Ed25519-signed over the published keys. Any reader can confirm the seal offline — no KYE service required.

Signature algorithm
EdDSA
Key id
kye:key:self-audit-fixture-2026-06
Seal fingerprint
097515d916aa894a (sha256 of the signature, first 16 hex)
Published keys (JWKS)
/trust/self-audit-jwks.json
Report envelope
kye:research-report:governed-proposal-serpro-partnership-2026-w26 · schema kye.research_report.v1

Verify it yourself: fetch the published JWKS, recompute the Ed25519 signature over this edition's canonicalised envelope (minus seal) bound to the body hash, and confirm it matches the key id above — from public keys alone, no KYE service in the loop.

How verification works