APRF v0.10.0 · working-draft
Stewardship & RFCs
Evolve APRF into a ratifiable, vendor-neutral production-readiness standard for AI systems through open technical consensus—not through a single commercial owner.
Open RFCs
Live proposals under review. Comment within the stated window via the interim contact below.
APRF-RFC-0001
in-review · MINOR
Establish working-draft RFC process and public Open RFCs list
Editorial RFC that ratifies the stewardship RFC stages on the site, publishes this index, and records the first open review window—no taxonomy changes.
Created 2026-07-24
Current phase
Working draft
StackRail publishes the draft, hosts the machine-readable spec, and accepts RFCs. Normative intent is public; stewardship is not yet transferred.
- Working draftStackRail publishes the draft, hosts the machine-readable spec, and accepts RFCs. Normative intent is public; stewardship is not yet transferred.
- Interim advisory boardMulti-org advisors review RFCs and release plans. Publisher still ships releases but commits to advisory consensus for MAJOR/MINOR.
- Neutral working groupStanding technical WG owns the roadmap, RFC decisions, and release approvals. Publisher becomes one participant among peers.
- Foundation / SDO homeOptional later home under a foundation or standards body with IP assignment, trademark, and formal membership rules.
Interim advisory board
status: recruiting · target 5 seats · ≥3 independent orgs
StackRail is recruiting an interim advisory board (≥3 independent organizations) before MAJOR/MINOR releases require advisory consensus. Volunteer via the interim contact; a seat does not grant commercial preference or veto over peer RFCs.
- Independent security / AppSec practitionerOpen — recruiting
- AI platform or model vendor (non-publisher)Open — recruiting
- Production AI operator (practitioner)Open — recruiting
- Standards / SDO-adjacent participant (e.g. OWASP/CNCF)Open — recruiting
- Researcher or academicOpen — recruiting
RFC decisions and rationales are published on /aprf/rfc/ and in the machine-readable `rfcs` index in /aprf/spec/. Until seats are filled, working-draft quorum applies: publisher decides after the review window with public rationale.
Single-vendor publication is temporary and explicit. Normative text and the machine-readable catalog remain freely available; transfer triggers and requirements are published; certification programs (if any) stay separate from normative stewardship.
Charter principles
- Neutrality: no single vendor or publisher holds permanent veto over normative content.
- Open process: substantive changes go through public RFCs with recorded decisions.
- Evidence over marketing: checks stay measurable (artifact + pass condition); no vanity scores.
- Stable identifiers: pillar and check IDs are immutable once published in a MINOR+; deprecate, do not reuse.
- Separability: StackRail may publish implementations and services without owning the standard long-term.
- Inclusive participation: vendors, practitioners, researchers, and OWASP/CNCF-adjacent contributors welcome.
Non-goals
- Replacing NIST AI RMF, ISO/IEC 42001, SOC 2, or OWASP as peer frameworks.
- Granting certification authority to the working-draft publisher by default.
- Locking the taxonomy behind proprietary tooling or paywalled normative text.
APRF Request for Comments
Numbering: APRF-RFC-NNNN (zero-padded, monotonic; 0000 is the template). Minimum review: 14 days.
Working-draft phase: publisher decides after review window, with public rationale. Interim advisory+: majority of active advisors; ties escalate to published deadlock procedure.
Stages
draft · Draft
Author iterating privately or in a PR; not yet open for formal review.
proposed · Proposed
Submitted with checklist complete; awaiting scheduling into review.
in-review · In review
Public comment open for at least the minimum review window.
accepted · Accepted
Will ship in a named SemVer release; implementation PR linked.
rejected · Rejected
Will not ship as proposed; rationale recorded; may be revised and resubmitted.
withdrawn · Withdrawn
Author withdrew before decision.
superseded · Superseded
Replaced by a later RFC.
Submission checklist
- Problem statement and who is affected
- Proposed change (pillars, checks, profiles, lenses, crosswalks, scoring, or governance)
- SemVer impact: MAJOR / MINOR / PATCH (with rationale)
- Backward compatibility and deprecation plan if IDs change
- Evidence that checks remain measurable (artifact + pass condition)
- Crosswalk impact (if any)
- Security / safety considerations
- Open questions for reviewers
Decision criteria
- Improves production readiness signal without diluting gate semantics
- Does not introduce vanity scoring or unauditable prose-only controls
- Fits taxonomy (prefer lenses/profiles over new top-level domains)
- Preserves ID stability or provides a deprecation path
- Feasible for adopters at the claimed criticality tier
Template: /aprf/rfc/0000-template.md
Transfer to a neutral steward
Triggers
- At least three independent organizations actively reviewing RFCs for two consecutive MINOR cycles.
- Published interim charter signed by advisory participants.
- Public RFC backlog with decisions recorded for ≥90 days.
- Willingness of a neutral host (foundation, consortium, or multi-party WG) to accept stewardship.
Requirements
- Machine-readable APRF spec remains freely available under a permissive documentation license.
- Check and pillar ID stability policy preserved.
- StackRail (or any implementer) retains rights to build products against APRF without preferential gatekeeping.
- Certification programs, if any, are separated from normative stewardship.
Normative APRF text and machine-readable catalogs are intended to transfer with stewardship. Product trademarks and commercial services remain with their owners.
Participate
Interim contact: prasoonanand@ymail.com (interim; transfers with steward)
- File an RFC using the template and checklist.
- Comment on open RFCs during the review window.
- Propose lenses, crosswalks, or editorial fixes via PATCH/MINOR RFCs.
- Volunteer for an interim advisory seat (open call while status is recruiting).
Machine-readable: /aprf/spec/ → stewardship