APRF v0.11.0
Published RFCs
Full index (14): open proposals and decided RFCs. Machine-readable in /aprf/spec/ → rfcs.
APRF-RFC-0001
in-review · MINOR
Establish working-draft RFC process and public Open RFCs list
Editorial RFC that ratifies the stewardship RFC stages on the site, publishes this index, and records the first open review window—no taxonomy changes.
Created 2026-07-24
APRF-RFC-0002
accepted · MINOR
Demote incident-readiness INC-M3 and INC-M4 to recommended
Demotes INC-M3→INC-R2 and INC-M4→INC-R4; documents pre-release exception for removing IDs without deprecated stubs before the first tagged version.
Created 2026-08-01
APRF-RFC-0003
accepted · MINOR
Demote observability OBS-M2 to recommended (OBS-R4)
Demotes OBS-M2→OBS-R4 (token/cost attribution); removes from Core/Regulated mandatories; pre-release ID-removal exception.
Created 2026-08-01
APRF-RFC-0004
accepted · MINOR
Split PERF-M2 dashboards — metrics stay mandatory; dashboards → PERF-R4
Rewrites PERF-M2 as mandatory ops metrics; adds PERF-R4 for near-real-time dashboards as recommended maturity.
Created 2026-08-01
APRF-RFC-0005
accepted · MINOR
Demote reliability-continuity REL-M4 to recommended (REL-R3)
Demotes REL-M4→REL-R3 (process continuity options with owners); pre-release ID-removal exception.
Created 2026-08-01
APRF-RFC-0006
accepted · MINOR
Demote reliability-continuity REL-M7 to recommended (REL-R5)
Demotes REL-M7→REL-R5 (AI-dependency chaos); removes from Regulated mandatories; pre-release ID-removal exception.
Created 2026-08-01
APRF-RFC-0007
accepted · MINOR
Demote reliability-continuity REL-M8 to recommended (REL-R7)
Demotes REL-M8→REL-R7 (multi-provider Level-5 continuity); removes from Regulated mandatories; pre-release ID-removal exception.
Created 2026-08-01
APRF-RFC-0008
accepted · MINOR
Demote explainability EXP-M4 to recommended (EXP-R3)
Demotes EXP-M4→EXP-R3 (change/counterfactual summaries); removes from Regulated mandatories; pre-release ID-removal exception.
Created 2026-08-01
APRF-RFC-0009
accepted · MINOR
Demote adversarial-security SEC-M5 to recommended (SEC-R3)
Demotes SEC-M5→SEC-R3 (exfiltration detection; canaries optional among equivalents); removes from Regulated mandatories; pre-release ID-removal exception.
Created 2026-08-01
APRF-RFC-0010
accepted · MINOR
Fine-grained peer crosswalks (AISVS, ASVS, OpenCRE, MAESTRO, FIASSE)
Adds informative section-level crosswalks for OWASP AISVS 1.0 (`aisvs:v1.0-C*.*`), ASVS, OpenCRE, MAESTRO, and FIASSE; enriches OWASP LLM Top 10 controls with AISVS `relatedPeerControlIds` bridges.
Created 2026-08-10
APRF-RFC-0011
accepted · MINOR
Evidence Assurance Tiers (E0–E5)
Adds normative Evidence Assurance Tiers (E0–E5) and Check evidencePolicy.minimumTier so PASS requires evidence at or above a declared floor; UNVERIFIED is a verification outcome on PARTIAL, not a sixth control status.
Created 2026-08-11
APRF-RFC-0012
draft · MINOR
Cognitive Assurance Experimental Extension (COG)
Proposes an optional future Cognitive Assurance (COG) Experimental Extension for long-lived persistent autonomous agents—objective governance, memory lineage, policy evolution, decision provenance, and behavioral continuity—without changing APRF 1.x Core/Regulated philosophy or Checks.
Created 2026-08-16
APRF-RFC-0013
draft · MINOR
Assessment Target Kinds and Framework Profile
Adds systemType classification, official aprf-profile-framework, applicationCapabilities→lenses, and resolveAssessmentTarget() so assessments select Checks from framework-definition SoT without mislabeling frameworks as Core.
Created 2026-08-18
APRF-RFC-0014
draft · MINOR
Threat Composition from Multi-Kind Signals
Adds a signal registry (production-mechanism kinds) and threat-first composition with a formal evaluator; Checks remain the sole gate unit; threats drive suspected/confirmed exposure only.
Created 2026-08-26