Skip to main content

Reference implementation

TumiTrust: The PTI Reference Implementation

A production deployment that demonstrates how PTI principles operate under real load — not a substitute for the open specification.

Production Founding steward

A reference implementation demonstrates that a specification is implementable, operable, and useful at scale. It contributes operational learnings to RFCs and specification revisions.

TumiTrust provides the first commercial reference implementation of PTI. Future PTI-compatible implementations may adopt different architectures, languages, and deployment models while conforming to the same RFCs and profiles.

What TumiTrust demonstrates

PTI conceptReference capability
Trust profilesSubject and institution views of graph-backed trust state
Trust eventsPartner webhook, API, and CSV ingest channels
Trust graphsRelationship-aware resolution and signal materialization
Identity resolutionEntity-to-pti_id mapping — RFC-011
Trust contexts20+ documented primaries and lenses — catalogue
Trust lookup APIInstitution decision-time intelligence — RFC-004
ExplainabilityDrivers, provenance, and coverage gaps on outcomes
GovernanceConsent, retention, and audit aligned with RFC-007

Platform capabilities

  • Trust Platform API — search, generate, poll, webhooks for institutions and partners
  • Partner connectors — configurable screening and event ingest
  • Institutional integrations — lookup studio, reports, packages, sovereign deployments
  • Developer infrastructure — OpenAPI, sandbox keys, conformance-oriented integration paths
  • Operational runbooks — production feedback into specification design

Product documentation describes how TumiTrust implements PTI:

Specification documentation describes what any compatible implementation must do:

Relationship to the specification

When TumiTrust behavior diverges from published RFCs, the RFCs govern compatibility claims until amended through governance.

Becoming a reference implementation

Implementers may apply for reference listing when they:

  1. Achieve PTI Core Certified or higher
  2. Operate production traffic for ≥12 months
  3. Publish anonymized operational metrics
  4. Participate in RFC review for dependencies

See Reference implementations (governance) and Reference implementation policy.