Skip to main content

PTI Conformance

Portable Trust Infrastructure (PTI) compatibility means an implementation satisfies the normative requirements of the PTI RFC series for a declared conformance profile. Compatibility is a technical claim testable through documented checklists, not marketing language.

What PTI-compatible means​

A PTI-compatible implementation:

  1. Implements required RFCs for its profile, architecture (RFC-001), contexts (RFC-002), events (RFC-003), lookups (RFC-004), evidence (RFC-012), and profile-specific additions.
  2. Uses RFC 2119 semantics. MUST requirements are enforced, not documented-only.
  3. Passes conformance tests: automated and manual tests in conformance-tests.
  4. Declares a profile. Core, Enterprise, Government, or Edge (see profiles).
  5. Publishes a conformance statement: version, profile, supported contexts, known limitations.

A PTI-compatible implementation is not required to:

  • Operate a specific cloud or vendor stack
  • Support all twenty trust contexts on day one
  • Provide consumer-facing mobile applications
  • Implement proprietary scoring formulas (derivation rules must be versioned and evidenced)

What PTI-compatible does not mean​

ClaimReality
"PTI-inspired"Non-normative; not certifiable
"Partial PTI"Must declare which profile capabilities are omitted
"PTI API wrapper" over non-PTI backendFails if evidence, context isolation, or governance are missing
"Credit bureau compatible"PTI is trust intelligence infrastructure, not tradeline file exchange

Conformance dimensions​

DimensionPrimary RFCsTest focus
ArchitectureRFC-001Role separation, lifecycle
ContextsRFC-002Isolation, catalogue, enablement
EventsRFC-003Schema, idempotency, channels
LookupsRFC-004Tiers, entitlements, errors
GraphRFC-005Provenance traversal
ExchangeRFC-006Signing, federation (Enterprise+)
GovernanceRFC-007Consent, audit, deletion
SecurityRFC-008AuthN/Z, crypto
PrivacyRFC-009Minimization, DSAR
VersioningRFC-010Deprecation, compatibility
IdentityRFC-011PTI-ID, confidence thresholds
EvidenceRFC-012Manifests, verification

Self-assessment vs certification​

LevelWho performsOutput
Self-assessmentImplementerInternal checklist completion
Accredited certificationIndependent labConformance certificate with profile and version

Self-assessment is sufficient for development and pilot. Production federation and government accreditation require certification.

Vendor neutrality​

Conformance evaluates behavior against RFCs: not brand affiliation. Any organization may implement PTI and certify without platform membership.