Trust Center · reproducible by anyone

What is verifiable today, what is in progress, what needs external action.

Trust is a runtime property, not a press release. We sign every claim. You replay every decision.

v1.0contract frozen, Apache 2.0
10public mirror repos — reproducible
13compliance frameworks mapped
NDAprocurement pack on request
1 · Verifiable today · reproducible by anyone

Every row runs against something published. Run it; replicate it.

Every command below operates exclusively on the Apache 2.0-licensed public surface — the mirror repositories under github.com/KYE-Protocol and the artefacts published at kyeprotocol.com. The proprietary master (KYE-Protocol/app) is never cloned and nothing here exposes implementation paths or internal artefacts. Rows are derived from the canonical public-mirror register, so a row cannot advertise a repository that does not exist.

Public surfaceStatusReproduce
JSON SchemasKYE-Protocol/schemas112 published each served at its canonical $idgit clone https://github.com/KYE-Protocol/schemas && jq '."$id"' schemas/proof-bundle.json
OpenAPI surfaceKYE-Protocol/open-api572 operations across the published specsgit clone https://github.com/KYE-Protocol/open-api && grep -c 'operationId:' open-api/core.openapi.yaml
TypeScript SDKKYE-Protocol/sdk-typescripttest suite runs green from the public repo alonegit clone https://github.com/KYE-Protocol/sdk-typescript && cd sdk-typescript && npm ci && npm test
Python SDKKYE-Protocol/sdk-pythontest suite runs green from the public repo alonegit clone https://github.com/KYE-Protocol/sdk-python && cd sdk-python && python3 -m pip install -e . && pytest -q
Go SDKKYE-Protocol/sdk-gocore surface builds and passesgit clone https://github.com/kye-protocol/sdk-go && cd sdk-go && go test ./...
Vocabulary registerKYE-Protocol/vocabulary32 documents entity types, actions, lifecycle states, obligations, data classes, reason codesgit clone https://github.com/KYE-Protocol/vocabulary && ls vocabulary
URN ID formatKYE-Protocol/id-formatparser conformancegit clone https://github.com/KYE-Protocol/id-format && cd id-format && npm ci && npm test
Examples galleryKYE-Protocol/examples908 payloads every schema carries ≥ 1 examplegit clone https://github.com/KYE-Protocol/examples && find examples -name '*.json' | wc -l

Public mirror total: the rows above replicate the public surface; nothing on this list requires access to the proprietary master.

2 · Reference-implementation posture

Bank-grade hardening, covered under commercial licence.

The reference Gateway ships with a documented production-hardening posture — tenant authn (mTLS / OAuth2-CC), multi-tenant request scoping by trust_domain_id, per-tenant rate-limiting, security headers, append-only audit chain, swappable HSM/KMS key custody, policy-engine pluggability, structured observability, and a wired KYE™-on-KYE™ self-governing engine (operator actions like key rotation and self-audit runs route through the same engine and emit the same audit + evidence-pack format as external decisions; see protocol § self-govern). Operator runbooks cover Tier-1 onboarding, incident response, disaster recovery, GDPR (DPA / ROPA / DSR), customer SLA, sub-processor inventory, key rotation and regulator-comms templates. The full hardening register and runbook bundle are part of the procurement pack delivered to design partners under NDA, not published on the public web.

3 · Framework mappings · 289 controls × 249 frameworks

Where the protocol artefacts satisfy each control.

Each row maps a KYE™ artefact (entity record · delegation · scope · credential · attestation · audit event · proof bundle · signal · transparency receipt · capability grant · recovery proof · break-glass grant · compromise report · state transition) to the control it satisfies and the endpoint to extract it. The control-mapping register is served from kyeprotocol.com alongside the published schemas; the source-of-truth normative spec ships under commercial licence.

FrameworkMappings
SOC 2 (TSC 2017)~25 control mappings
ISO/IEC 27001:2022 — Annex A~28 control mappings
PCI DSS 4.0~22 control mappings
PSD2 / PSD3 (RTS Reg. 2018/389)~16 control mappings
DORA — Reg. (EU) 2022/2554~22 control mappings
NIS2 — Dir. (EU) 2022/2555~18 control mappings
EU AI Act — Reg. (EU) 2024/168910 controls (KYE-EUAIACT-001..010)
NIST SP 800-207 — Zero Trust Architecture~18 control mappings
ISO/IEC 42001 — AIMS~20 control mappings
NIST AI RMF 1.0~24 control mappings
GDPR — Reg. (EU) 2016/679~18 control mappings
FedRAMP — Federal Risk and Authorization Management~30 control mappings
NIST Cybersecurity Framework 2.0~16 control mappings
4 · Procurement pack · under NDA

Detail for procurement teams — on request.

The full hardening register, runbook bundle, attestation roadmap (SOC 2 / ISO 27001 / FedRAMP timing), HSM-integration matrix, and supply-chain controls are packaged for procurement teams under NDA, alongside the reference-implementation architecture documents. We don’t publish gap lists or implementation inventories on the open web.

5 · Government agency readiness

Sovereign / public-sector path.

Public-sector adoption follows a distinct path from commercial banks. The protocol artefacts that gov agencies will ask for:

ArtefactStatus
KYE Sovereign AI Profile™ — protocol surfacev1.1 preview · 9 sub-profiles + 5 planned apps
KYE Public Sector Profile™v1.1 preview
KYE Cross-Agency Delegation Profile™v1.1 preview
KYE Government API Authority Profile™v1.1 preview
NIST 800-207 Zero Trust mappingpublished in control-mapping register
NIST AI RMF mappingpublished in control-mapping register
FedRAMP control mappingpublished in control-mapping register (no ATO yet)
OSCAL projection (component-definition / SSP / assessment-results / POA&M)7 / 7 tests pass
Public-sector decision evidence packv1.1 preview
Sovereign data-residency profilev1.1 preview
FIPS 140-3 cryptographic compliancerequires HSM-vendor module + test report
StateRAMP / CCCS readinessscoped via FedRAMP base mappings
6 · Resolve an evidence reference

Holding a reference? Check it here.

A governed KYE Protocol surface shows you an opaque evidence reference when it acts. Paste one below to see which capture it came from, the governed outcome, when it was recorded, and the SHA-256 of the exact frame — so the identifier and the means to check it travel together.

This is an audit-reference index, not a signed Replay-Proof Evidence Pack. It confirms a reference corresponds to a real governed capture with a real outcome and real bytes. Re-deriving the verdict itself from public keys is the sealed-report path, not this lookup. References that return nothing here are illustrative — every page that prints one says so.

In one paragraph.

The KYE Protocol™ contract is bank-grade and frozen. The Apache 2.0 public mirror repos — schemas, OpenAPI, three SDKs, vocabulary, ID format, examples — are reproducible today: clone, install, run the test commands above. The conformance pack is not among them: its fixtures are IP-track, so it ships under commercial licence rather than as a public mirror. The reference implementation is shipped under commercial licence to design partners with the full hardening register, the operator runbook bundle, and the procurement pack. Procurement and security teams should request that pack via /engage.

Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

Machine-readable trust posture

Procurement teams can fetch a machine-readable trust posture as JSON. Detailed control attestations and procurement artefacts are shared with qualified buyers under NDA via this Trust Centre.

curl -s https://kyeprotocol.com/trust.json
{
  "schema": "kye.trust_posture.v1",
  "posture": "Pilot-ready. Enterprise certifications (SOC 2 Type II, ISO/IEC 27001) and independent assurance are in progress.",
  "trust_centre": "https://kyeprotocol.com/trust.html"
}