What is verifiable today, what is in progress, what needs external action.
Trust is a runtime property, not a press release. We sign every claim. You replay every decision.
Every row runs against something published. Run it; replicate it.
Every command below operates exclusively on the Apache 2.0-licensed public surface — the mirror repositories under github.com/KYE-Protocol and the artefacts published at kyeprotocol.com. The proprietary master (KYE-Protocol/app) is never cloned and nothing here exposes implementation paths or internal artefacts. Rows are derived from the canonical public-mirror register, so a row cannot advertise a repository that does not exist.
| Public surface | Status | Reproduce |
|---|---|---|
JSON Schemas — KYE-Protocol/schemas | 112 published each served at its canonical $id | git clone https://github.com/KYE-Protocol/schemas && jq '."$id"' schemas/proof-bundle.json |
OpenAPI surface — KYE-Protocol/open-api | 572 operations across the published specs | git clone https://github.com/KYE-Protocol/open-api && grep -c 'operationId:' open-api/core.openapi.yaml |
TypeScript SDK — KYE-Protocol/sdk-typescript | test suite runs green from the public repo alone | git clone https://github.com/KYE-Protocol/sdk-typescript && cd sdk-typescript && npm ci && npm test |
Python SDK — KYE-Protocol/sdk-python | test suite runs green from the public repo alone | git clone https://github.com/KYE-Protocol/sdk-python && cd sdk-python && python3 -m pip install -e . && pytest -q |
Go SDK — KYE-Protocol/sdk-go | core surface builds and passes | git clone https://github.com/kye-protocol/sdk-go && cd sdk-go && go test ./... |
Vocabulary register — KYE-Protocol/vocabulary | 32 documents entity types, actions, lifecycle states, obligations, data classes, reason codes | git clone https://github.com/KYE-Protocol/vocabulary && ls vocabulary |
URN ID format — KYE-Protocol/id-format | parser conformance | git clone https://github.com/KYE-Protocol/id-format && cd id-format && npm ci && npm test |
Examples gallery — KYE-Protocol/examples | 908 payloads every schema carries ≥ 1 example | git clone https://github.com/KYE-Protocol/examples && find examples -name '*.json' | wc -l |
Public mirror total: the rows above replicate the public surface; nothing on this list requires access to the proprietary master.
Bank-grade hardening, covered under commercial licence.
The reference Gateway ships with a documented production-hardening posture — tenant authn (mTLS / OAuth2-CC), multi-tenant request scoping by trust_domain_id, per-tenant rate-limiting, security headers, append-only audit chain, swappable HSM/KMS key custody, policy-engine pluggability, structured observability, and a wired KYE™-on-KYE™ self-governing engine (operator actions like key rotation and self-audit runs route through the same engine and emit the same audit + evidence-pack format as external decisions; see protocol § self-govern). Operator runbooks cover Tier-1 onboarding, incident response, disaster recovery, GDPR (DPA / ROPA / DSR), customer SLA, sub-processor inventory, key rotation and regulator-comms templates. The full hardening register and runbook bundle are part of the procurement pack delivered to design partners under NDA, not published on the public web.
Where the protocol artefacts satisfy each control.
Each row maps a KYE™ artefact (entity record · delegation · scope · credential · attestation · audit event · proof bundle · signal · transparency receipt · capability grant · recovery proof · break-glass grant · compromise report · state transition) to the control it satisfies and the endpoint to extract it. The control-mapping register is served from kyeprotocol.com alongside the published schemas; the source-of-truth normative spec ships under commercial licence.
| Framework | Mappings |
|---|---|
| SOC 2 (TSC 2017) | ~25 control mappings |
| ISO/IEC 27001:2022 — Annex A | ~28 control mappings |
| PCI DSS 4.0 | ~22 control mappings |
| PSD2 / PSD3 (RTS Reg. 2018/389) | ~16 control mappings |
| DORA — Reg. (EU) 2022/2554 | ~22 control mappings |
| NIS2 — Dir. (EU) 2022/2555 | ~18 control mappings |
| EU AI Act — Reg. (EU) 2024/1689 | 10 controls (KYE-EUAIACT-001..010) |
| NIST SP 800-207 — Zero Trust Architecture | ~18 control mappings |
| ISO/IEC 42001 — AIMS | ~20 control mappings |
| NIST AI RMF 1.0 | ~24 control mappings |
| GDPR — Reg. (EU) 2016/679 | ~18 control mappings |
| FedRAMP — Federal Risk and Authorization Management | ~30 control mappings |
| NIST Cybersecurity Framework 2.0 | ~16 control mappings |
Detail for procurement teams — on request.
The full hardening register, runbook bundle, attestation roadmap (SOC 2 / ISO 27001 / FedRAMP timing), HSM-integration matrix, and supply-chain controls are packaged for procurement teams under NDA, alongside the reference-implementation architecture documents. We don’t publish gap lists or implementation inventories on the open web.
Sovereign / public-sector path.
Public-sector adoption follows a distinct path from commercial banks. The protocol artefacts that gov agencies will ask for:
| Artefact | Status |
|---|---|
| KYE Sovereign AI Profile™ — protocol surface | v1.1 preview · 9 sub-profiles + 5 planned apps |
| KYE Public Sector Profile™ | v1.1 preview |
| KYE Cross-Agency Delegation Profile™ | v1.1 preview |
| KYE Government API Authority Profile™ | v1.1 preview |
| NIST 800-207 Zero Trust mapping | published in control-mapping register |
| NIST AI RMF mapping | published in control-mapping register |
| FedRAMP control mapping | published in control-mapping register (no ATO yet) |
| OSCAL projection (component-definition / SSP / assessment-results / POA&M) | 7 / 7 tests pass |
| Public-sector decision evidence pack | v1.1 preview |
| Sovereign data-residency profile | v1.1 preview |
| FIPS 140-3 cryptographic compliance | requires HSM-vendor module + test report |
| StateRAMP / CCCS readiness | scoped via FedRAMP base mappings |
Holding a reference? Check it here.
A governed KYE Protocol™ surface shows you an opaque evidence reference when it acts. Paste one below to see which capture it came from, the governed outcome, when it was recorded, and the SHA-256 of the exact frame — so the identifier and the means to check it travel together.
This is an audit-reference index, not a signed Replay-Proof Evidence Pack™. It confirms a reference corresponds to a real governed capture with a real outcome and real bytes. Re-deriving the verdict itself from public keys is the sealed-report path, not this lookup. References that return nothing here are illustrative — every page that prints one says so.
In one paragraph.
The KYE Protocol™ contract is bank-grade and frozen. The Apache 2.0 public mirror repos — schemas, OpenAPI, three SDKs, vocabulary, ID format, examples — are reproducible today: clone, install, run the test commands above. The conformance pack is not among them: its fixtures are IP-track, so it ships under commercial licence rather than as a public mirror. The reference implementation is shipped under commercial licence to design partners with the full hardening register, the operator runbook bundle, and the procurement pack. Procurement and security teams should request that pack via /engage.
Ready to see your AI agents flagged?
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.
Machine-readable trust posture
Procurement teams can fetch a machine-readable trust posture as JSON. Detailed control attestations and procurement artefacts are shared with qualified buyers under NDA via this Trust Centre.
curl -s https://kyeprotocol.com/trust.json
{
"schema": "kye.trust_posture.v1",
"posture": "Pilot-ready. Enterprise certifications (SOC 2 Type II, ISO/IEC 27001) and independent assurance are in progress.",
"trust_centre": "https://kyeprotocol.com/trust.html"
}