Skip to main content

PTI Conformance

Portable Trust Infrastructure (PTI) compatibility means an implementation satisfies the normative requirements of the PTI RFC series for a declared conformance profile. Compatibility is a technical claim testable through documented checklists — not marketing language.

What PTI-compatible means

A PTI-compatible implementation:

  1. Implements required RFCs for its profile — architecture (RFC-001), contexts (RFC-002), events (RFC-003), lookups (RFC-004), evidence (RFC-012), and profile-specific additions.
  2. Uses RFC 2119 semanticsMUST requirements are enforced, not documented-only.
  3. Passes conformance tests — automated and manual tests in conformance-tests.
  4. Declares a profile — Core, Enterprise, Government, or Edge (see profiles).
  5. Publishes a conformance statement — version, profile, supported contexts, known limitations.

A PTI-compatible implementation is not required to:

  • Operate a specific cloud or vendor stack
  • Support all twenty trust contexts on day one
  • Provide consumer-facing mobile applications
  • Implement proprietary scoring formulas (derivation rules must be versioned and evidenced)

What PTI-compatible does not mean

ClaimReality
"PTI-inspired"Non-normative; not certifiable
"Partial PTI"Must declare which profile capabilities are omitted
"PTI API wrapper" over non-PTI backendFails if evidence, context isolation, or governance are missing
"Credit bureau compatible"PTI is trust intelligence infrastructure, not tradeline file exchange

Conformance dimensions

DimensionPrimary RFCsTest focus
ArchitectureRFC-001Role separation, lifecycle
ContextsRFC-002Isolation, catalogue, enablement
EventsRFC-003Schema, idempotency, channels
LookupsRFC-004Tiers, entitlements, errors
GraphRFC-005Provenance traversal
ExchangeRFC-006Signing, federation (Enterprise+)
GovernanceRFC-007Consent, audit, deletion
SecurityRFC-008AuthN/Z, crypto
PrivacyRFC-009Minimization, DSAR
VersioningRFC-010Deprecation, compatibility
IdentityRFC-011PTI-ID, confidence thresholds
EvidenceRFC-012Manifests, verification

Self-assessment vs certification

LevelWho performsOutput
Self-assessmentImplementerInternal checklist completion
Accredited certificationIndependent labConformance certificate with profile and version

Self-assessment is sufficient for development and pilot. Production federation and government accreditation require certification.

Vendor neutrality

Conformance evaluates behavior against RFCs, not brand affiliation. Any organization may implement PTI and certify without platform membership.