Skip to main content

Public Governance Statement

The Portable Trust Infrastructure (PTI) ecosystem commits to governance that serves subjects, institutions, and implementers — not the commercial interests of any single vendor.

This statement summarizes public commitments. Process detail appears in companion governance documents; normative platform behavior appears in RFC-007 and Specification v1.0.

Effective as published. Amendments require Working Group supermajority per Decision Making.


Our commitment

We hold that trust infrastructure must be portable, explainable, and governed in the open. PTI exists as a specification category any qualified organization may implement. No company owns the definition of portable trust.

We commit to:

1. Vendor neutrality

The PTI specification will remain implementation-independent. Conformance will be measured against public RFCs and tests, not affiliation with a steward or reference vendor.

2. Open participation

Any party may contribute RFCs, tests, and reviews without membership fees. Working Group proceedings will be documented publicly subject to Security Disclosure embargoes.

3. Technical merit and compatibility

Specification decisions will weigh evidence, interoperability, security, and privacy before convenience. Stable specifications will change in breaking ways only through published Breaking Changes Policy and major versioning.

4. Security and privacy responsibility

We will maintain coordinated vulnerability disclosure, require security review for sensitive RFCs, and treat privacy regressions as blocking defects alongside interoperability failures.

5. Honest compatibility claims

PTI Certified and PTI Compatible marks will be reserved for implementations that meet Certification Process requirements. Self-assessed and partial implementations must be labeled accurately (Trademark and Branding).

6. Stewardship transition

Founding stewardship is transitional. We will pursue a multi-stakeholder governance model culminating in an independent foundation or equivalent neutral home (Future Foundation Model, Ecosystem Roadmap).

7. Subject dignity

Governance will solicit input on consent, explainability, deletion, and adverse-action support. Trust infrastructure exists to serve people crossing institutional boundaries — not to entrench opaque scores.


What we ask of participants

StakeholderCommitment
ContributorsRoyalty-free licensing for normative contributions; good-faith review
ImplementersAccurate conformance claims; timely security patching
InstitutionsProcure on RFC and profile basis where feasible
StewardsRecuse on conflicts; fund neutral infrastructure

Accountability

MechanismFrequency
Public RFC and decision logsContinuous
Security advisoriesAs needed
Stewardship transparency reportAnnual from Phase 2
Conformance registryContinuous
Governance document reviewAnnual

Questions or concerns may be raised via public issue tracker or Working Group mailing list. Security issues must use Security Disclosure channels.


Current steward

TumiTrust currently serves as founding steward and reference implementation for PTI. This role includes operational support for early Working Group activity and maintenance of a flagship compatible platform. TumiTrust does not own Portable Trust Infrastructure as a proprietary product category.

Independent implementers are encouraged to build, certify, and participate in governance regardless of relationship to TumiTrust.


Scope clarification

This governance statement addresses ecosystem and specification stewardship. Operational governance inside deployments (consent records, retention, audit) remains defined by RFC-007 and applicable law.


Portable Trust Infrastructure — governed in the open for portable trust.