Implementation note: This page describes TumiTrust operational trust governance. For PTI ecosystem governance (spec evolution, Working Group), see PTI Governance. For normative requirements, see RFC-007 and Specification v1.0 Governance.
Trust Governance Framework
Governance
Banks and regulators need documented obligations — not promises in a pitch deck.
Scope
This framework describes how TumiTrust governs trust lookups, identity resolution, and context-scoped trust intelligence on Portable Trust Infrastructure. We are a trust platform in a regulated-risk-adjacent category — not a traditional credit bureau.
Principles
- Consent first — sharing trust data with third parties requires explicit consent
- Data minimization — lookups request only entitled fields for the decision context
- Explainability — structured drivers and provenance, not black-box outcomes
- Accountability — producers and consumers have documented roles
- Rights by default — access, correction, deletion, export
Consent & ownership
| Actor | Obligation |
|---|---|
| Individual | Controls sharing of Trust CV; grants consent per lookup where required |
| Institution (consumer) | Documents lawful basis for trust lookups; uses explainable outcomes for adverse action |
| Partner (producer) | Emits only contract-covered events; attributes signals to entitled contexts |
| TumiTrust | Enforces context policy, audit trails, and data-subject request workflows |
Borrower consent is required before institutional sharing beyond what Privacy Policy and app flows describe. Google Play data-safety disclosures and Terms reinforce these obligations.
Data subject rights
| Right | Mechanism |
|---|---|
| Access | Profile export and trust data visibility in app |
| Correction | Profile and document update flows |
| Deletion | Account deletion with 30-day grace period (Privacy Policy) |
| Portability | Export of trust-related personal data on request |
| Withdraw consent | Consent management in app and institution settings |
Retention & deletion
- Account deletion schedules permanent removal after 30-day grace
- Legal/regulatory holds may retain minimal audit or billing records
- Retention limits documented in Privacy Policy — not indefinite hoarding
- Partners must not send prohibited categories (full PAN, raw biometrics without contract)
Data provenance & evidence chains
Every trust lookup outcome should trace to:
- Source type — partner event, endorsement, badge, document verification
- Context ID — one of 20 documented contexts
- Timestamp & provider — when and who attested the signal
- Verification hook — QR verify portal matches hub/PDF scores
Institutions receive trust_intelligence.v1 and optional compliance_intelligence with provenance fields suitable for committee review.
Institution roles (consumer)
- Run trust lookups only for entitled workflows
- Store reports under your retention policy; respect data-subject requests
- Use explainability fields for adverse-action workflows
- Do not republish raw trust data outside contract
Producer responsibilities
- Configure enabled contexts only
- Map events to catalogued
event_type+context_id - Honor TCU billing and ingest validation errors
- See Partner integration guide
Privacy & jurisdictions
TumiTrust documents GDPR-style rights in Privacy Policy. Jurisdiction-specific playbooks (PDPA, local DPA) are configured in institution hub Compliance settings.