Skip to main content

PTI Ecosystem Governance

Portable Trust Infrastructure (PTI) is an open, vendor-neutral specification category for trust intelligence infrastructure. Ecosystem governance defines how the specification evolves, how participants collaborate, and how compatibility claims are validated.

This section covers ecosystem governance — the processes, roles, and policies that steward PTI as a public standard. It does not define operational trust governance inside a running platform (consent, retention, audit, subject rights). Those requirements live in RFC-007 Governance and the PTI Specification v1.0 Governance document.

What ecosystem governance covers

DomainGoverned byExamples
Specification evolutionPTI Working GroupRFC proposals, version releases, deprecation
Technical directionArchitecture Review BoardCross-RFC coherence, breaking-change review
Security of the standardSecurity Review GroupThreat models, disclosure coordination
Compatibility claimsConformance ProgramProfiles, certification, test suites
Community participationContribution process · ContributingIssues, PRs, public review
Brand and trademarksTrademark policyPermitted use of PTI marks

What ecosystem governance does not cover

  • Product roadmaps, pricing, or commercial terms of any single vendor
  • Legal compliance of a specific deployment (implementers remain responsible)
  • Day-to-day operation of a trust exchange, registry, or intelligence engine
  • Assignment of pti_id values or registry operator selection in production networks

Governance stakeholders

Relationship to other documentation

Document setScope
PTI Specification v1.0Normative requirements for compatible implementations
PTI RFCsModular normative documents with defined lifecycle
PTI ConformanceProfiles, tests, and certification
Build Your Own PTIIndependent implementer guide
RFC-007 / spec governanceIn-platform trust data governance

Current stewardship

During Phase 1 (Founder Stewardship), the PTI Working Group is convened and initially staffed by contributors from the founding steward organization. TumiTrust currently serves as the reference steward and reference implementation — not as owner of PTI. Stewardship is transitional; see The Origin of PTI, Ecosystem Roadmap and Future Foundation Model.

Normative language

Process rules in this section use RFC 2119 keywords where indicated: MUST, MUST NOT, SHOULD, SHOULD NOT, MAY, and RECOMMENDED.

Reading guide

If you want to…Start here
Understand why open governance mattersWhy Governance Matters
Distinguish spec from productsSpecification vs Implementation
Contribute an RFC or fixContribution Process
Certify an implementationConformance Program
Review public commitmentsPublic Governance Statement

Document index

  1. Why Governance Matters
  2. Specification vs Implementation
  3. Governance Principles
  4. Governance Model
  5. Working Group
  6. Specification Lifecycle
  7. RFC Process
  8. Contribution Process
  9. Decision Making
  10. Version Management
  11. Breaking Changes Policy
  12. Security Disclosure
  13. Community Participation
  14. Conformance Program
  15. Certification Process
  16. Trademark and Branding
  17. Reference Implementation Policy
  18. Future Foundation Model
  19. Public Governance Statement
  20. Ecosystem Roadmap