Research & Technical Publications
Public papers, technical whitepapers, and capability briefs across the Yandeh Holdings protocol portfolio. Category-defining publications, dated briefing notes, and provisional capability briefs for practitioners, standards bodies, and commercial evaluators.
The category-defining public paper on XAP, the Execution Authority Protocol. Introduces the thesis that security has been organized around identity, and the next layer is execution authority: verifiable execution, one operation at a time. Covers the five architectural principles of the category, position relative to authentication, access control, policy engines, audit, and hardware attestation, and deployment relevance across AI agents, zero-trust infrastructure, CI/CD, and post-quantum environments. Cited references include Lampson 1992 capabilities model, NIST SP 800-207, NIST SP 800-53, CNSA 2.0, and related foundational work.
Briefing Note v2 supplementing the canonical category-definition paper. Addresses what has changed in the operating environment for the XAP category between April and June 2026: NIST CAISI launches and Federal Register RFI, IETF WIMSE and SCITT working-group activity, EU AI Act Article 17 milestones and August 2 effective date, ISO/IEC 42001 adoption, and adjacent published work. Positions XAP relative to standards-formation cadence and the January 2027 CNSA 2.0 NSS procurement window.
The full technical reference for the XAP category, organized under the AMIAP docket family. Covers the category's architectural principles, enforcement design, governance properties for agentic AI, threat model considerations, and the continuation's distributed enforcement framing. Includes compliance mapping to SOC 2, ISO/IEC 27001, NIST SP 800-53, NIST SP 800-207, FedRAMP, and CMMC. Available to qualified licensees and commercial evaluators under mutual non-disclosure.
Capability-level briefs for the remaining protocols in the Yandeh Holdings family. Each is supported by a provisional application on a planned conversion path to nonprovisional. The provisional roster covers AIRAP (autonomous incident response), CVEAR (cross-domain receipt verification), AGIV (adversarial governance integrity verification), CGGA (capability-governance gap architecture), VIATE (voice-initiated authority chains), and TAEA (trust-aware endpoint authority). Full technical whitepapers for each protocol are in active development and made available to qualified licensees and evaluators under mutual non-disclosure.
The category-defining technical whitepaper on VEMP, the Verifiable Enterprise Messaging Protocol. Sets out the architectural framing, six coordinated mechanisms (two-plane architecture, message authority artifact, formally defined communication state machine, protected-boundary key management, lineage-bound constraint propagation, verifiable receipt generation), eight-threat-category catalog, architectural comparison across five governance-critical dimensions, distinctions from seven adjacent categories (S/MIME, OpenPGP, TLS, secure email gateways, IRM/DLP, secure portals, ZTNA, hierarchical governance), deployment relevance for enterprise messaging, government and sovereign communication, regulated industries, and post-quantum migration programs, and compliance mapping across SOC 2, ISO/IEC 27001, NIST SP 800-53, FedRAMP, CMMC, EU AI Act Article 17, ISO/IEC 42001, and CNSA 2.0.
Continuation extending VEMP coverage to alternative key-management and governance-record architectural patterns: cloud-hosted key management and trusted execution environment boundaries, reduced-state-count governance state machines, and governance records implemented as cooperating signed objects rather than a single binary artifact. The continuation preserves VEMP's core governance relationships across diverse implementation architectures, foreclosing design-arounds based on alternative key-protection mechanisms or alternative structural forms of the governance record. Capability brief available under NDA.
Bounded delegation of remediation authority to autonomous incident response and SOAR systems. Provides cryptographic enforcement of remediation scope at execution time, with each action bound to a verifiable record of the authority under which it was taken. Designed to support compliance audit and post-incident review for autonomous response operating under CMMC and FedRAMP control sets. Provisional application on planned conversion path; capability brief available under NDA.
Tamper-evident, independently verifiable evidence layer for execution decisions across multiple enforcement domains. Receipt structure supports cross-domain verification without shared infrastructure or third-party intermediary, making it directly applicable to continuous monitoring, audit log integrity, and multi-domain compliance architectures. Provisional application on planned conversion path; capability brief available under NDA.
Methodology for empirical verification of governance system integrity under adversarial probing. Provides structured testing and verification approaches for organizations operating execution authority enforcement at scale, where governance properties must be continuously validated rather than assumed. Provisional application on planned conversion path; capability brief available under NDA.
Governance architecture for advanced and super-intelligent AI systems operating at or above the detection ceiling — the regime in which the governed system's capability exceeds the detection capability of any single governing system. Addresses the architectural question that emerges when behavioral evaluation alone is no longer sufficient to bound AI system behavior. Provisional application on planned conversion path; capability brief available under NDA.
Verifiable authority chains for voice-initiated autonomous task execution by agentic systems. Addresses the gap in which voice as a request modality produces tasks that downstream agents execute without a verifiable chain from speaker identity through agent authorization to the operation actually performed. Provisional application on planned conversion path; capability brief available under NDA.
Execution authority governance for mobile and endpoint devices with runtime trust evaluation. Extends the execution authority category to operations originating from mobile devices and endpoints where device posture, attestation freshness, and operating environment all factor into per-operation authorization at the moment of execution. Provisional application on planned conversion path; capability brief available under NDA.