APRF domains & pillars
Eight engineering domains with focused sub-pillars, plus cross-cutting platform concerns. Open any specification for purpose, checks, evidence, and practices.
Taxonomy
Select a sub-pillar to read the full specification.
Security
Adversarial resistance, identity, authorization, secrets, tool mediation, supply chain, and hardened runtime for AI systems.
- APRF-01Adversarial SecurityPrevent prompt injection, jailbreaks, exfiltration, and model/tool abuse from becoming a production incident.View specification →
- APRF-10AuthenticationStrong identity for users, services, agents, and MCP callers.View specification →
- APRF-11AuthorizationEnforce who/what may invoke which models, tools, data, and actions.View specification →
- APRF-12SecretsEliminate secret leakage into prompts, logs, tools, and client surfaces.View specification →
- APRF-05Tool SafetyMake tool/MCP invocation fail closed with least privilege and side-effect control.View specification →
- APRF-24Supply Chain IntegrityProve provenance and integrity of models, containers, MCP servers, and AI dependencies.View specification →
- APRF-20InfrastructureHarden runtime, network, isolation, and supply chain for AI workloads.View specification →
Safety & Responsible AI
Harm prevention, content safety, fairness, and transparency—NIST trustworthiness characteristics distinct from adversarial security.
Data
Privacy, corpus and index governance, data quality, and memory integrity across AI pipelines.
- APRF-18Data PrivacyMinimize, classify, and protect data flowing through AI pipelines.View specification →
- APRF-27Data Governance & QualityGovern corpora, indexes, labels, and feedback loops—distinct from privacy controls.View specification →
- APRF-04Memory ManagementControl retention, isolation, and poisoning of short- and long-term memory.View specification →
Model & Prompt Lifecycle
Model selection and versioning, prompt and context as production artifacts, and continuous evaluation gates.
- APRF-07Model GovernanceOwn model selection, versioning, deprecation, and capability boundaries.View specification →
- APRF-02Prompt EngineeringTreat prompts as versioned production artifacts with regression control.View specification →
- APRF-03Context EngineeringBound and structure what the model is allowed to see and use.View specification →
- APRF-08EvaluationContinuously prove quality, safety, and task success before and after release.View specification →
Agents & Autonomy
Agent charters, autonomy limits, A2A trust, and human oversight for high-impact actions.
Reliability & Operations
Observability, performance SLOs, graceful degradation and continuity, change management with rollback, and incident readiness.
- APRF-09ObservabilityMake every decision path reconstructable: traces, prompts, tools, costs, outcomes.View specification →
- APRF-28Performance & SLO EngineeringLatency, throughput, and error budgets for AI features—SRE discipline applied to GenAI.View specification →
- APRF-14Reliability & ContinuitySurvive provider outages and partial failures, and preserve critical AI capabilities under sustained disruption.View specification →
- APRF-15Change Management & ReleaseRepeatable promotion of models, prompts, tools, and agents—with tested, fast rollback.View specification →
- APRF-21Incident ReadinessDetect, contain, and learn from AI-specific production incidents.View specification →
Cost
Spend bounds, attribution, caching, routing, and denial-of-wallet controls for AI workloads.
Governance & Compliance
Organizational AI policy, ownership, risk acceptance, and auditable evidence of controls—without equating compliance with readiness.
Cross-cutting concerns
Concerns that apply across every domain. They are not peer domains; they enable safe delivery of all other pillars.