APRF v0.11.0 · working-draft

Stewardship & RFCs

Evolve APRF into a ratifiable, vendor-neutral production-readiness standard for AI systems through open technical consensus—not through a single commercial owner.

Normative repository: github.com/stackrail-io/APRF (spec, schemas, RFCs, CHANGELOG). Architecture: five-layer design.

Open RFCs

Draft and in-review proposals. Comment via the interim contact below.

  • APRF-RFC-0001

    in-review · MINOR

    Establish working-draft RFC process and public Open RFCs list

    Editorial RFC that ratifies the stewardship RFC stages on the site, publishes this index, and records the first open review window—no taxonomy changes.

    Created 2026-07-24

  • APRF-RFC-0012

    draft · MINOR

    Cognitive Assurance Experimental Extension (COG)

    Proposes an optional future Cognitive Assurance (COG) Experimental Extension for long-lived persistent autonomous agents—objective governance, memory lineage, policy evolution, decision provenance, and behavioral continuity—without changing APRF 1.x Core/Regulated philosophy or Checks.

    Created 2026-08-16

  • APRF-RFC-0013

    draft · MINOR

    Assessment Target Kinds and Framework Profile

    Adds systemType classification, official aprf-profile-framework, applicationCapabilities→lenses, and resolveAssessmentTarget() so assessments select Checks from framework-definition SoT without mislabeling frameworks as Core.

    Created 2026-08-18

  • APRF-RFC-0014

    draft · MINOR

    Threat Composition from Multi-Kind Signals

    Adds a signal registry (production-mechanism kinds) and threat-first composition with a formal evaluator; Checks remain the sole gate unit; threats drive suspected/confirmed exposure only.

    Created 2026-08-26

View all published RFCs (14)

Current phase

Working draft

StackRail publishes the draft, hosts the machine-readable spec, and accepts RFCs. Normative intent is public; stewardship is not yet transferred.

  1. Working draftStackRail publishes the draft, hosts the machine-readable spec, and accepts RFCs. Normative intent is public; stewardship is not yet transferred.
  2. Interim advisory boardMulti-org advisors review RFCs and release plans. Publisher still ships releases but commits to advisory consensus for MAJOR/MINOR.
  3. Neutral working groupStanding technical WG owns the roadmap, RFC decisions, and release approvals. Publisher becomes one participant among peers.
  4. Foundation / SDO homeOptional later home under a foundation or standards body with IP assignment, trademark, and formal membership rules.

Interim advisory board

status: recruiting · target 5 seats · ≥3 independent orgs

StackRail is recruiting an interim advisory board (≥3 independent organizations) before MAJOR/MINOR releases require advisory consensus. Volunteer via the interim contact; a seat does not grant commercial preference or veto over peer RFCs.

  • Independent security / AppSec practitionerOpen — recruiting
  • AI platform or model vendor (non-publisher)Open — recruiting
  • Production AI operator (practitioner)Open — recruiting
  • Standards / SDO-adjacent participant (e.g. OWASP/CNCF)Open — recruiting
  • Researcher or academicOpen — recruiting

RFC decisions and rationales are published on /aprf/rfc/ and in the machine-readable `rfcs` index in /aprf/spec/. Until seats are filled, working-draft quorum applies: publisher decides after the review window with public rationale.

Single-vendor publication is temporary and explicit. Normative text and the machine-readable catalog remain freely available; transfer triggers and requirements are published; certification programs (if any) stay separate from normative stewardship.

Charter principles

  • Neutrality: no single vendor or publisher holds permanent veto over normative content.
  • Open process: substantive changes go through public RFCs with recorded decisions.
  • Evidence over marketing: checks stay measurable (artifact + pass condition); no vanity scores.
  • Stable identifiers: pillar and check IDs are immutable once published in a MINOR+; deprecate, do not reuse.
  • Separability: StackRail may publish implementations and services without owning the standard long-term.
  • Inclusive participation: vendors, practitioners, researchers, and OWASP/CNCF-adjacent contributors welcome.

Non-goals

  • Replacing NIST AI RMF, ISO/IEC 42001, SOC 2, or OWASP as peer frameworks.
  • Granting certification authority to the working-draft publisher by default.
  • Locking the taxonomy behind proprietary tooling or paywalled normative text.

APRF Request for Comments

Numbering: APRF-RFC-NNNN (zero-padded, monotonic; 0000 is the template). Minimum review: 14 days.

Working-draft phase: publisher decides after review window, with public rationale. Interim advisory+: majority of active advisors; ties escalate to published deadlock procedure.

Stages

  1. draft · Draft

    Author iterating privately or in a PR; not yet open for formal review.

  2. proposed · Proposed

    Submitted with checklist complete; awaiting scheduling into review.

  3. in-review · In review

    Public comment open for at least the minimum review window.

  4. accepted · Accepted

    Will ship in a named SemVer release; implementation PR linked.

  5. rejected · Rejected

    Will not ship as proposed; rationale recorded; may be revised and resubmitted.

  6. withdrawn · Withdrawn

    Author withdrew before decision.

  7. superseded · Superseded

    Replaced by a later RFC.

Submission checklist

  • Problem statement and who is affected
  • Proposed change (pillars, checks, profiles, lenses, crosswalks, scoring, or governance)
  • SemVer impact: MAJOR / MINOR / PATCH (with rationale)
  • Backward compatibility and deprecation plan if IDs change
  • Evidence that checks remain measurable (artifact + pass condition)
  • Crosswalk impact (if any)
  • Security / safety considerations
  • Open questions for reviewers

Decision criteria

  • Improves production readiness signal without diluting gate semantics
  • Does not introduce vanity scoring or unauditable prose-only controls
  • Fits taxonomy (prefer lenses/profiles over new top-level domains)
  • Preserves ID stability or provides a deprecation path
  • Feasible for adopters at the claimed criticality tier

Template: /aprf/rfc/0000-template.md

Transfer to a neutral steward

Triggers

  • At least three independent organizations actively reviewing RFCs for two consecutive MINOR cycles.
  • Published interim charter signed by advisory participants.
  • Public RFC backlog with decisions recorded for ≥90 days.
  • Willingness of a neutral host (foundation, consortium, or multi-party WG) to accept stewardship.

Requirements

  • Machine-readable APRF spec remains freely available under a permissive documentation license.
  • Check and pillar ID stability policy preserved.
  • StackRail (or any implementer) retains rights to build products against APRF without preferential gatekeeping.
  • Certification programs, if any, are separated from normative stewardship.

Normative APRF text and machine-readable catalogs are intended to transfer with stewardship. Product trademarks and commercial services remain with their owners.

Participate

Interim contact: anu.v.apps@gmail.com (interim; transfers with steward)

Normative repository: github.com/stackrail-io/APRF

  • File an RFC using the template and checklist.
  • Comment on open RFCs during the review window.
  • Propose lenses, crosswalks, or editorial fixes via PATCH/MINOR RFCs.
  • Volunteer for an interim advisory seat (open call while status is recruiting).

Machine-readable: /aprf/spec/ stewardship