APRF v0.10.0 · working-draft

Stewardship & RFCs

Evolve APRF into a ratifiable, vendor-neutral production-readiness standard for AI systems through open technical consensus—not through a single commercial owner.

Open RFCs

Live proposals under review. Comment within the stated window via the interim contact below.

Current phase

Working draft

StackRail publishes the draft, hosts the machine-readable spec, and accepts RFCs. Normative intent is public; stewardship is not yet transferred.

  1. Working draftStackRail publishes the draft, hosts the machine-readable spec, and accepts RFCs. Normative intent is public; stewardship is not yet transferred.
  2. Interim advisory boardMulti-org advisors review RFCs and release plans. Publisher still ships releases but commits to advisory consensus for MAJOR/MINOR.
  3. Neutral working groupStanding technical WG owns the roadmap, RFC decisions, and release approvals. Publisher becomes one participant among peers.
  4. Foundation / SDO homeOptional later home under a foundation or standards body with IP assignment, trademark, and formal membership rules.

Interim advisory board

status: recruiting · target 5 seats · ≥3 independent orgs

StackRail is recruiting an interim advisory board (≥3 independent organizations) before MAJOR/MINOR releases require advisory consensus. Volunteer via the interim contact; a seat does not grant commercial preference or veto over peer RFCs.

  • Independent security / AppSec practitionerOpen — recruiting
  • AI platform or model vendor (non-publisher)Open — recruiting
  • Production AI operator (practitioner)Open — recruiting
  • Standards / SDO-adjacent participant (e.g. OWASP/CNCF)Open — recruiting
  • Researcher or academicOpen — recruiting

RFC decisions and rationales are published on /aprf/rfc/ and in the machine-readable `rfcs` index in /aprf/spec/. Until seats are filled, working-draft quorum applies: publisher decides after the review window with public rationale.

Single-vendor publication is temporary and explicit. Normative text and the machine-readable catalog remain freely available; transfer triggers and requirements are published; certification programs (if any) stay separate from normative stewardship.

Charter principles

  • Neutrality: no single vendor or publisher holds permanent veto over normative content.
  • Open process: substantive changes go through public RFCs with recorded decisions.
  • Evidence over marketing: checks stay measurable (artifact + pass condition); no vanity scores.
  • Stable identifiers: pillar and check IDs are immutable once published in a MINOR+; deprecate, do not reuse.
  • Separability: StackRail may publish implementations and services without owning the standard long-term.
  • Inclusive participation: vendors, practitioners, researchers, and OWASP/CNCF-adjacent contributors welcome.

Non-goals

  • Replacing NIST AI RMF, ISO/IEC 42001, SOC 2, or OWASP as peer frameworks.
  • Granting certification authority to the working-draft publisher by default.
  • Locking the taxonomy behind proprietary tooling or paywalled normative text.

APRF Request for Comments

Numbering: APRF-RFC-NNNN (zero-padded, monotonic; 0000 is the template). Minimum review: 14 days.

Working-draft phase: publisher decides after review window, with public rationale. Interim advisory+: majority of active advisors; ties escalate to published deadlock procedure.

Stages

  1. draft · Draft

    Author iterating privately or in a PR; not yet open for formal review.

  2. proposed · Proposed

    Submitted with checklist complete; awaiting scheduling into review.

  3. in-review · In review

    Public comment open for at least the minimum review window.

  4. accepted · Accepted

    Will ship in a named SemVer release; implementation PR linked.

  5. rejected · Rejected

    Will not ship as proposed; rationale recorded; may be revised and resubmitted.

  6. withdrawn · Withdrawn

    Author withdrew before decision.

  7. superseded · Superseded

    Replaced by a later RFC.

Submission checklist

  • Problem statement and who is affected
  • Proposed change (pillars, checks, profiles, lenses, crosswalks, scoring, or governance)
  • SemVer impact: MAJOR / MINOR / PATCH (with rationale)
  • Backward compatibility and deprecation plan if IDs change
  • Evidence that checks remain measurable (artifact + pass condition)
  • Crosswalk impact (if any)
  • Security / safety considerations
  • Open questions for reviewers

Decision criteria

  • Improves production readiness signal without diluting gate semantics
  • Does not introduce vanity scoring or unauditable prose-only controls
  • Fits taxonomy (prefer lenses/profiles over new top-level domains)
  • Preserves ID stability or provides a deprecation path
  • Feasible for adopters at the claimed criticality tier

Template: /aprf/rfc/0000-template.md

Transfer to a neutral steward

Triggers

  • At least three independent organizations actively reviewing RFCs for two consecutive MINOR cycles.
  • Published interim charter signed by advisory participants.
  • Public RFC backlog with decisions recorded for ≥90 days.
  • Willingness of a neutral host (foundation, consortium, or multi-party WG) to accept stewardship.

Requirements

  • Machine-readable APRF spec remains freely available under a permissive documentation license.
  • Check and pillar ID stability policy preserved.
  • StackRail (or any implementer) retains rights to build products against APRF without preferential gatekeeping.
  • Certification programs, if any, are separated from normative stewardship.

Normative APRF text and machine-readable catalogs are intended to transfer with stewardship. Product trademarks and commercial services remain with their owners.

Participate

Interim contact: prasoonanand@ymail.com (interim; transfers with steward)

  • File an RFC using the template and checklist.
  • Comment on open RFCs during the review window.
  • Propose lenses, crosswalks, or editorial fixes via PATCH/MINOR RFCs.
  • Volunteer for an interim advisory seat (open call while status is recruiting).

Machine-readable: /aprf/spec/ stewardship