Governing the Machine · Protocol IP for Autonomous Systems · Post-Quantum Era

Execution Authority for Autonomous Systems.
Pre-Decryption Admission Control for Encrypted Communications.

Yandeh Holdings Inc. — patent applications defining two protocol categories: XAP (Execution Authority Protocol, also AMIAP) for runtime governance of autonomous AI agents and machines, and VEMP (Verifiable Enterprise Messaging Protocol) for pre-decryption admission control of encrypted communications.

Each family addresses a layer existing categories do not. XAP operates above session-time authorization and below the operation itself, producing a cryptographic record of each decision an independent party can verify. VEMP enforces admission of encrypted communications before decryption, with state-machine-governed release and bounded post-release revocation.

Read the XAP Paper
2+2
Parents +
Continuations Filed
102
Claims Across
Nonprovisional Filings
2
Protocol Categories
Defined
Track
One
AMIAP Parent on
Prioritized Examination
Market Position
Compliance Gap
SOC 2 · ISO 27001 · NIST · FedRAMP · CMMC
These frameworks specify what authorization controls organizations must implement and how authorization decisions should be monitored. None specify a protocol-level mechanism for verifying that each governance decision was made correctly at execution time, against current machine state, with cryptographic evidence an independent party can reproduce. XAP addresses this gap with tamper-evident, independently verifiable execution authorization records applicable across commercial and regulated deployments alike.
Deployment Context
Alongside existing infrastructure
XAP deploys as an enforcement layer alongside existing OPA, Istio, Envoy, or API gateway infrastructure, not as a replacement. No infrastructure replacement required. No new trust root. Additive to zero-trust network architectures. The continuation extends category coverage to distributed enforcement topologies where no single component generates a complete proof structure.
Structural Differentiation
Beyond scoped access and persona definitions
Recent industry announcements have introduced infrastructure-level scoping for autonomous agents — defining what an agent may call, on whose behalf, with what credential. This is a starting point, not the destination. Execution authority is a different layer. It requires governance that operates at the moment of each operation, against the runtime conditions that exist at that moment, with cryptographic evidence an independent party can verify — not just static permissions evaluated at session start. XAP defines this layer as a coherent protocol category. The continuation extends category coverage to the distributed enforcement topologies real production deployments use.
Research Foundation
Practitioner-Developed Architecture
XAP reflects hands-on work with real-world enterprise deployment architectures, drawing on fifteen-plus years of operational experience across cybersecurity architecture, automation, and applied cryptography. The protocol is grounded in production reality, not academic abstraction.
Patent Portfolio
YH-AMIAP-001
March 2026
Nonprovisional · Track One
30 total
Patent Pending · Pre-examination

The foundational application defining the Execution Authority Protocol (XAP) category: a new layer of the security stack addressing per-operation execution authority with cryptographic proof an independent party can verify. The category is complementary to authentication, access authorization, and channel security; each governs a distinct function at a distinct point in the execution lifecycle. Specific claim language is held in the filed application and made available to qualified evaluators under NDA.

YH-AMIAP-CON-1
April 2026
Continuation under 35 U.S.C. § 120
YH-AMIAP-001
22 total
Patent Pending · Pre-examination

Extends category coverage to distributed enforcement topologies: the architectures real production deployments use, where governance is performed by cooperating components rather than a single point. Specifies how XAP category membership applies in these settings, so that the category matches the systems it is designed to govern. Specific claim language is held in the filed application and made available to qualified evaluators under NDA.

Prosecution Posture
Independent patentable basis
Stands on subject matter distinct from the Parent. Prosecution history firewall preserved between applications.
Insulated
Communication Governance Family — VEMP
YH-VEMP-001
March 2026
Nonprovisional
30 total
Patent Pending · Pre-examination

Defines the Pre-Decryption Admission Control category: a communication governance architecture in which an encrypted communication is admitted into a controlled communication plane only after artifact-bound, state-machine-governed evaluation of admission preconditions, and decryption keys are released only upon affirmative state machine advancement. The category is distinct from encrypted email (S/MIME, OpenPGP), transport-layer security (TLS), secure email gateways, information rights management, and zero-trust network access. Specific claim language is held in the filed application and made available to qualified evaluators under NDA.

YH-VEMP-CON-1
April 2026
Continuation under 35 U.S.C. § 120
YH-VEMP-001
20 total
Patent Pending · Pre-examination

Extends VEMP coverage to alternative architectural patterns: cloud-hosted key management and trusted execution environment boundaries, reduced-state-count governance state machines, and governance records implemented as a plurality of cooperating signed objects rather than a single binary artifact. The continuation preserves VEMP's core governance relationships across diverse implementation architectures, foreclosing design-arounds based on alternative key-protection mechanisms or alternative structural forms of the governance record. Specific claim language is held in the filed application and made available to qualified evaluators under NDA.

Prosecution Posture
Independent patentable basis
Stands on subject matter distinct from the Parent. Prosecution history firewall preserved between applications.
Insulated
Category Architecture
Category Layer
Defines the new protocol category
XAP PARENT · YH-AMIAP-001
Autonomous Machine Identity & Authority Protocol
Defines the protocol category at the level of per-operation execution authority, with cryptographic evidence an independent party can verify.
Structural Layer
Covers distributed enforcement topologies
CONTINUATION · YH-AMIAP-CON-1
Continuation Application — Distributed Execution Authority
Extends category coverage to distributed enforcement topologies, where governance is performed by cooperating components rather than a single point.
XAP · AMIAP Parent + Implicit Derivability Continuation
The Execution Authority Protocol (XAP) Category
The AMIAP Parent defines the category. The Implicit Derivability continuation specifies how category membership applies to distributed enforcement as a structural property. Prosecution history firewall preserved between applications.
Both Filed
Category Layer
Defines the second protocol category
VEMP PARENT · YH-VEMP-001
Verifiable Enterprise Messaging Protocol
Defines the pre-decryption admission control category: artifact-bound, state-machine-governed admission evaluation operating after delivery and before decryption key release, with verifiable receipts and post-release revocation within bounded enforcement latency.
Structural Layer
Covers alternative implementation architectures
CONTINUATION · YH-VEMP-CON-1
VEMP Continuation — Admission Before Decryption
Extends VEMP coverage to cloud-hosted key management, TEE-based key protection, reduced-state-count governance, and governance records implemented as cooperating data structures rather than a single binary artifact.
VEMP · Parent + Admission Before Decryption Continuation
The Pre-Decryption Admission Control Category
The VEMP Parent defines the category. The Admission Before Decryption continuation specifies how category membership applies across alternative key-protection and governance-record architectures. Prosecution history firewall preserved between applications.
Both Filed