PageSourceSearch

https://tumitrust.com/docs/assets/js/089badf5.59f9bed0.js

js tumitrust.com collected 2026-09-28 06:42:43 UTC 12,228 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkdocs_new=globalThis.webpackChunkdocs_new||[]).push([[1766],{28453:(e,n,i)=>{i.d(n,{R:()=>c,x:()=>o});var t=i(96540);const r={},s=t.createContext(r);function c(e){const n=t.useContext(s);return t.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function o(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:c(e.components),t.createElement(s.Provider,{value:n},e.children)}},91604:(e,n,i)=>{i.r(n),i.d(n,{assets:()=>a,contentTitle:()=>o,default:()=>h,frontMatter:()=>c,metadata:()=>t,toc:()=>l});const t=JSON.parse('{"id":"pti/governance/public-governance-statement","title":"Public Governance Statement","description":"Public commitment of the PTI ecosystem to open, vendor-neutral, security-conscious governance.","source":"@site/docs/pti/governance/public-governance-statement.md","sourceDirName":"pti/governance","slug":"/pti/governance/public-governance-statement","permalink":"/docs/pti/governance/public-governance-statement","draft":false,"unlisted":false,"tags":[],"version":"current","sidebarPosition":20,"frontMatter":{"title":"Public Governance Statement","description":"Public commitment of the PTI ecosystem to open, vendor-neutral, security-conscious governance.","sidebar_position":20},"sidebar":"ptiSidebar","previous":{"title":"Future Foundation Model","permalink":"/docs/pti/governance/future-foundation-model"},"next":{"title":"Ecosystem Roadmap","permalink":"/docs/pti/governance/ecosystem-roadmap"}}');var r=i(74848),s=i(28453);const c={title:"Public Governance Statement",description:"Public commitment of the PTI ecosystem to open, vendor-neutral, security-conscious governance.",sidebar_position:20},o="Public Governance Statement",a={},l=[{value:"Our commitment",id:"our-commitment",level:2},{value:"1. Vendor neutrality",id:"1-vendor-neutrality",level:3},{value:"2. Open participation",id:"2-open-participation",level:3},{value:"3. Technical merit and compatibility",id:"3-technical-merit-and-compatibility",level:3},{value:"4. Security and privacy responsibility",id:"4-security-and-privacy-responsibility",level:3},{value:"5. Honest compatibility claims",id:"5-honest-compatibility-claims",level:3},{value:"6. Stewardship transition",id:"6-stewardship-transition",level:3},{value:"7. Subject dignity",id:"7-subject-dignity",level:3},{value:"What we ask of participants",id:"what-we-ask-of-participants",level:2},{value:"Accountability",id:"accountability",level:2},{value:"Current steward",id:"current-steward",level:2},{value:"Scope clarification",id:"scope-clarification",level:2},{value:"Related documents",id:"related-documents",level:2}];function d(e){const n={a:"a",em:"em",h1:"h1",h2:"h2",h3:"h3",header:"header",hr:"hr",li:"li",p:"p",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,s.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(n.header,{children:(0,r.jsx)(n.h1,{id:"public-governance-statement",children:"Public Governance Statement"})}),"\n",(0,r.jsxs)(n.p,{children:["The Portable Trust Infrastructure (PTI) ecosystem commits to governance that serves ",(0,r.jsx)(n.strong,{children:"subjects:"})," ",(0,r.jsx)(n.strong,{children:"institutions:"})," and ",(0,r.jsx)(n.strong,{children:"implementers:"})," not the commercial interests of any single vendor."]}),"\n",(0,r.jsxs)(n.p,{children:["This statement summarizes public commitments. Process detail appears in companion governance documents; normative platform behavior appears in ",(0,r.jsx)(n.a,{href:"/docs/pti/rfcs/rfc-007-governance",children:"RFC-007"})," and ",(0,r.jsx)(n.a,{href:"/docs/pti/specification/v1.0/",children:"Specification v1.0"}),"."]}),"\n",(0,r.jsx)(n.p,{children:(0,r.jsxs)(n.em,{children:["Effective as published. Amendments require Working Group supermajority per ",(0,r.jsx)(n.a,{href:"/docs/pti/governance/decision-making",children:"Decision Making"}),"."]})}),"\n",(0,r.jsx)(n.hr,{}),"\n",(0,r.jsx)(n.h2,{id:"our-commitment",children:"Our commitment"}),"\n",(0,r.jsxs)(n.p,{children:["We hold that ",(0,r.jsx)(n.strong,{children:"trust infrastru
1cture must be portable, explainable, and governed in the open"}),". PTI exists as a specification category any qualified organization may implement. No company owns the definition of portable trust."]}),"\n",(0,r.jsx)(n.p,{children:"We commit to:"}),"\n",(0,r.jsx)(n.h3,{id:"1-vendor-neutrality",children:"1. Vendor neutrality"}),"\n",(0,r.jsxs)(n.p,{children:["The PTI specification ",(0,r.jsx)(n.strong,{children:"will remain implementation-independent"}),". Conformance ",(0,r.jsx)(n.strong,{children:"will"})," be measured against public RFCs and tests, not affiliation with a steward or reference vendor."]}),"\n",(0,r.jsx)(n.h3,{id:"2-open-participation",children:"2. Open participation"}),"\n",(0,r.jsxs)(n.p,{children:["Any party ",(0,r.jsx)(n.strong,{children:"may"})," contribute RFCs, tests, and reviews without membership fees. Working Group proceedings ",(0,r.jsx)(n.strong,{children:"will"})," be documented publicly subject to ",(0,r.jsx)(n.a,{href:"/docs/pti/governance/security-disclosure",children:"Security Disclosure"})," embargoes."]}),"\n",(0,r.jsx)(n.h3,{id:"3-technical-merit-and-compatibility",children:"3. Technical merit and compatibility"}),"\n",(0,r.jsxs)(n.p,{children:["Specification decisions ",(0,r.jsx)(n.strong,{children:"will"})," weigh evidence, interoperability, security, and privacy before convenience. Stable specifications ",(0,r.jsx)(n.strong,{children:"will"})," change in breaking ways only through published ",(0,r.jsx)(n.a,{href:"/docs/pti/governance/breaking-changes-policy",children:"Breaking Changes Policy"})," and major versioning."]}),"\n",(0,r.jsx)(n.h3,{id:"4-security-and-privacy-responsibility",children:"4. Security and privacy responsibility"}),"\n",(0,r.jsxs)(n.p,{children:["We ",(0,r.jsx)(n.strong,{children:"will"})," maintain coordinated vulnerability disclosure, require security review for sensitive RFCs, and treat privacy regressions as blocking defects alongside interoperability failures."]}),"\n",(0,r.jsx)(n.h3,{id:"5-honest-compatibility-claims",children:"5. Honest compatibility claims"}),"\n",(0,r.jsxs)(n.p,{children:[(0,r.jsx)(n.strong,{children:"PTI Certified"})," and ",(0,r.jsx)(n.strong,{children:"PTI Compatible"})," marks ",(0,r.jsx)(n.strong,{children:"will"})," be reserved for implementations that meet ",(0,r.jsx)(n.a,{href:"/docs/pti/governance/certification-process",children:"Certification Process"})," requirements. Self-assessed and partial implementations ",(0,r.jsx)(n.strong,{children:"must"})," be labeled accurately (",(0,r.jsx)(n.a,{href:"/docs/pti/governance/trademark-branding",children:"Trademark and Branding"}),")."]}),"\n",(0,r.jsx)(n.h3,{id:"6-stewardship-transition",children:"6. Stewardship transition"}),"\n",(0,r.jsxs)(n.p,{children:["Founding stewardship ",(0,r.jsx)(n.strong,{children:"is transitional"}),". We ",(0,r.jsx)(n.strong,{children:"will"})," pursue a multi-stakeholder governance model culminating in an independent foundation or equivalent neutral home (",(0,r.jsx)(n.a,{href:"/docs/pti/governance/future-foundation-model",children:"Future Foundation Model"}),", ",(0,r.jsx)(n.a,{href:"/docs/pti/governance/ecosystem-roadmap",children:"Ecosystem Roadmap"}),")."]}),"\n",(0,r.jsx)(n.h3,{id:"7-subject-dignity",children:"7. Subject dignity"}),"\n",(0,r.jsxs)(n.p,{children:["Governance ",(0,r.jsx)(n.strong,{children:"will"})," solicit input on consent, explainability, deletion, and adverse-action support. Trust infrastru
1cture exists to serve people crossing institutional boundaries, not to entrench opaque scores."]}),"\n",(0,r.jsx)(n.hr,{}),"\n",(0,r.jsx)(n.h2,{id:"what-we-ask-of-participants",children:"What we ask of participants"}),"\n",(0,r.jsxs)(n.table,{children:[(0,r.jsx)(n.thead,{children:(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.th,{children:"Stakeholder"}),(0,r.jsx)(n.th,{children:"Commitment"})]})}),(0,r.jsxs)(n.tbody,{children:[(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Contributors"})}),(0,r.jsx)(n.td,{children:"Royalty-free licensing for normative contributions; good-faith review"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Implementers"})}),(0,r.jsx)(n.td,{children:"Accurate conformance claims; timely security patching"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Institutions"})}),(0,r.jsx)(n.td,{children:"Procure on RFC and profile basis where feasible"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.strong,{children:"Stewards"})}),(0,r.jsx)(n.td,{children:"Recuse on conflicts; fund neutral infrastructure"})]})]})]}),"\n",(0,r.jsx)(n.hr,{}),"\n",(0,r.jsx)(n.h2,{id:"accountability",children:"Accountability"}),"\n",(0,r.jsxs)(n.table,{children:[(0,r.jsx)(n.thead,{children:(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.th,{children:"Mechanism"}),(0,r.jsx)(n.th,{children:"Frequency"})]})}),(0,r.jsxs)(n.tbody,{children:[(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:"Public RFC and decision logs"}),(0,r.jsx)(n.td,{children:"Continuous"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:"Security advisories"}),(0,r.jsx)(n.td,{children:"As needed"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:"Stewardship transparency report"}),(0,r.jsx)(n.td,{children:"Annual from Phase 2"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:"Conformance registry"}),(0,r.jsx)(n.td,{children:"Continuous"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:"Governance document review"}),(0,r.jsx)(n.td,{children:"Annual"})]})]})]}),"\n",(0,r.jsxs)(n.p,{children:["Questions or concerns ",(0,r.jsx)(n.strong,{children:"may"})," be raised via public issue tracker or Working Group mailing list. Security issues ",(0,r.jsx)(n.strong,{children:"must"})," use ",(0,r.jsx)(n.a,{href:"/docs/pti/governance/security-disclosure",children:"Security Disclosure"})," channels."]}),"\n",(0,r.jsx)(n.hr,{}),"\n",(0,r.jsx)(n.h2,{id:"current-steward",children:"Current steward"}),"\n",(0,r.jsxs)(n.p,{children:[(0,r.jsx)(n.strong,{children:"TumiTrust"})," currently serves as ",(0,r.jsx)(n.strong,{children:"founding steward and reference implementation"})," for PTI. This role includes operational support for early Working Group activity and maintenance of a flagship compatible platform. TumiTrust ",(0,r.jsx)(n.strong,{children:"does not"})," own Portable Trust Infrastructure as a proprietary product category."]}),"\n",(0,r.jsxs)(n.p,{children:["Independent implementers ",(0,r.jsx)(n.strong,{children:"are encouraged"})," to build, certify, and participate in governance regardless of relationship to TumiTrust."]}),"\n",(0,r.jsx)(n.hr,{}),"\n",(0,r.jsx)(n.h2,{id:"scope-clarification",children:"Scope clarification"}),"\n",(0,r.jsxs)(n.p,{children:["This governance statement addresses ",(0,r.jsx)(n.strong,{children:"ecosystem and specification stewardship"}),". Operational governance inside deployments (consent records, retention, audit) ",(0,r.jsx)(n.strong,{children:"remains"})," defined by ",(0,r.jsx)(n.a,{href:"/docs/pti/rfcs/rfc-007-governance",children:"RFC-007"})," and applicable law."]}),"\n",(0,r.jsx)(n.hr,{}),"\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.em,{children:"Portable Trust Infrastructure, governed in the open for portable trust."})}),"\n",(0,r.jsx)(n.h2,{id:"related-documents",children:"Related documents"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:(0,r.jsx)(n.a,{href:"/docs/pti/governance/governance-principles",children:"Governance Principles"})}),"\n",(0,r.jsx)(n.li,{children:(0,r.jsx)(n.a,{href:"/docs/pti/governance/why-governance-matters",children:"Why Governance Matters"})}),"\n",(0,r.jsx)(n.li,{children:(0,r.jsx)(n.a,{href:"/docs/pti/governance/specification-vs-implementation",children:"Specification vs Implementation"})}),"\n",(0,r.jsx)(n.li,{children:(0,r.jsx)(n.a,{href:"/docs/pti/governance/community-participation",children:"Community Participation"})}),"\n"]})]})}function h(e={}){const{wrapper:n}={...(0,s.R)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(d,{...e})}):d(e)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.