Skip to content

What KYD® Is NOT

Version 1.0 — Non-Normative


This document clarifies what KYD® does not define, does not claim, and does not replace.

Standards are defined as much by what they exclude as by what they include.

This document prevents misunderstanding and misuse.


❌ KYD® is NOT a threat prevention system

Section titled “❌ KYD® is NOT a threat prevention system”

What it is:
KYD® evaluates device trust based on observed behavior.

What it is NOT:

  • A firewall
  • An intrusion prevention system
  • An endpoint protection platform
  • A threat blocking mechanism

Why this matters:
Trust evaluation informs security decisions. It does not prevent threats directly.


What it is:
KYD® provides evidence-based trust evaluation.

What it is NOT:

  • A promise of security
  • A guarantee against compromise
  • A certification of safety
  • A warranty of protection

Why this matters:
High trust indicates behavioral consistency. It does not guarantee invulnerability.


What it is:
KYD® detects behavioral drift from established baselines.

What it is NOT:

  • A CVE scanner
  • A patch management tool
  • A vulnerability assessment platform
  • A penetration testing framework

Why this matters:
Vulnerability scanning identifies known weaknesses. KYD® evaluates trustworthiness based on behavior over time.


❌ KYD® is NOT an identity and access management (IAM) system

Section titled “❌ KYD® is NOT an identity and access management (IAM) system”

What it is:
KYD® evaluates device identity and trust.

What it is NOT:

  • User authentication
  • Role-based access control (RBAC)
  • Single sign-on (SSO)
  • Privileged access management (PAM)

Why this matters:
KYD® focuses on devices, not users. IAM focuses on users, not devices. They are complementary, not substitutes.


❌ KYD® is NOT network access control (NAC)

Section titled “❌ KYD® is NOT network access control (NAC)”

What it is:
KYD® evaluates device trust continuously.

What it is NOT:

  • Port-based access control (802.1X)
  • Network admission control
  • Enforcement of network segmentation
  • Connection blocking or quarantine

Why this matters:
NAC enforces network policy. KYD® provides trust data that NAC (or other systems) can use to inform enforcement decisions.


❌ KYD® is NOT a SIEM or log management platform

Section titled “❌ KYD® is NOT a SIEM or log management platform”

What it is:
KYD® retains historical trust data and drift records.

What it is NOT:

  • A general-purpose log aggregator
  • A security information and event management (SIEM) platform
  • A threat intelligence platform
  • A log storage solution

Why this matters:
KYD® records trust-specific events. SIEM aggregates all security events. KYD® can send data to SIEM, but it is not a replacement.


What it is:
KYD® can support compliance requirements related to device trust.

What it is NOT:

  • ISO 27001
  • SOC 2
  • NIST Cybersecurity Framework
  • PCI DSS
  • HIPAA technical requirements

Why this matters:
KYD® provides device trust evidence that may satisfy portions of compliance frameworks. It does not replace comprehensive compliance programs.


❌ KYD® is NOT a specific product or vendor

Section titled “❌ KYD® is NOT a specific product or vendor”

What it is:
KYD® is a standard. Multiple implementations may exist.

What it is NOT:

  • KYD Verify (that’s the reference implementation)
  • Any single vendor’s product
  • A proprietary technology
  • A locked ecosystem

Why this matters:
Standards are open. Products are implementations. Confusing the two kills credibility.


❌ KYD® does NOT claim to prevent all attacks

Section titled “❌ KYD® does NOT claim to prevent all attacks”

KYD® evaluates trust. Prevention requires additional controls.

❌ KYD® does NOT claim to detect all compromises

Section titled “❌ KYD® does NOT claim to detect all compromises”

KYD® detects behavioral drift. Sophisticated adversaries may mimic expected behavior.

❌ KYD® does NOT claim to replace existing security tools

Section titled “❌ KYD® does NOT claim to replace existing security tools”

KYD® complements firewalls, EDR, SIEM, IAM, and other security technologies.

Continuous device trust evaluation requires observation, correlation, and analysis. Implementations vary in complexity.

❌ KYD® does NOT claim to be necessary for all environments

Section titled “❌ KYD® does NOT claim to be necessary for all environments”

Some environments may not require continuous device trust evaluation. KYD® is designed for environments where device trust matters.


Devices must still authenticate to networks and systems.

Data in transit and at rest must still be protected.

❌ KYD® does NOT replace vulnerability management

Section titled “❌ KYD® does NOT replace vulnerability management”

Devices must still be patched and hardened.

❌ KYD® does NOT replace backup and recovery

Section titled “❌ KYD® does NOT replace backup and recovery”

Data must still be backed up and recoverable.

❌ KYD® does NOT replace incident response

Section titled “❌ KYD® does NOT replace incident response”

Organizations must still detect, respond to, and recover from incidents.

❌ KYD® does NOT replace security awareness training

Section titled “❌ KYD® does NOT replace security awareness training”

Users must still be educated about threats and secure practices.


❌ KYD® does NOT require specific hardware

Section titled “❌ KYD® does NOT require specific hardware”

Software-only, hardware-anchored, and hybrid implementations are all valid.

❌ KYD® does NOT require agents on all devices

Section titled “❌ KYD® does NOT require agents on all devices”

Observable network characteristics can establish identity and evaluate trust.

❌ KYD® does NOT require constant internet connectivity

Section titled “❌ KYD® does NOT require constant internet connectivity”

Implementations may operate offline or in air-gapped environments.

❌ KYD® does NOT require cloud infrastructure

Section titled “❌ KYD® does NOT require cloud infrastructure”

On-premise, cloud, edge, and hybrid deployments are all supported.

❌ KYD® does NOT require expensive infrastructure

Section titled “❌ KYD® does NOT require expensive infrastructure”

Implementations scale to environment size and complexity.


KYD® has clear boundaries. It does not claim to solve all problems or replace all controls.

KYD® provides specific, auditable evidence of device trust. It does not guarantee security outcomes.

KYD® fits into existing security architectures. It does not require rip-and-replace.

KYD® defines requirements, not implementation methods. Creativity and innovation are encouraged within the specification’s boundaries.


KYD® is focused by design.

It does one thing:
Evaluates device trust continuously based on observed evidence.

It does not:

  • Prevent threats
  • Guarantee security
  • Replace existing tools
  • Claim to solve all problems

This focus is a feature, not a limitation.

Standards that try to do everything become meaningless.
Standards that do one thing well become foundational.


KYD® — The Device Trust Standard

Focused. Foundational. Verifiable.


Last Updated: January 2026
Authority: knowyourdevices.org