ZTDS.ai Open AI Security Standard
Home / Consortium / Governance & Charter
RFC-8821 GOVERNANCE · RAND-Z PATENT COVENANT · GITOPS CONSENSUS

Consortium Governance & Charter

The ZTDS AI Consortium is an independent, vendor-neutral standard-setting body dedicated to zero-trust data sanitization in generative AI and automated agent systems. Governed under open consensus, academic peer review, and irrevocable royalty-free patent covenants.

Governance Model
Multi-Stakeholder
2/3 Supermajority Voting
Patent Covenant
RAND-Z License
Irrevocable Worldwide
Active Working Groups
3 Domain WGs
Crypto, GRC, Tooling
Contribution Model
GitOps RFC
Open Pull Requests

01. Executive Charter & Architectural Mission

The primary purpose of the ZTDS AI Consortium is to establish, maintain, and verify provable industry standards that guarantee unmasked personally identifiable information (PII), protected health information (PHI), and confidential secrets are mathematically incapable of crossing runtime execution perimeters.

Principle 01

Architectural Neutrality

The ZTDS standard operates independent of specific cloud providers, AI model vendors, or SaaS intermediaries. Specifications are formal mathematical contracts, not proprietary product lock-ins.

Principle 02

Empirical Reproducibility

Every specification requirement MUST be auditable via verifiable network telemetry interception, cryptographic checksum validation, or reproducible unit benchmarks.

Principle 03

Public Domain Integrity

All normative specification documents are published under Creative Commons Attribution 4.0 (CC-BY-4.0) with immutable DOI anchors registered via Zenodo, OSF, and CERN registries.

Institutional Demarcation & Legal Shield

Boundary Definition per ZTDS Legal Treatise

Under international jurisprudence (United States, European Union, United Kingdom, Israel), technical standard-setting is an exercise of technical publishing and academic peer consensus (following the precedent of W3C, IETF, and OWASP). To preserve absolute legal safety, ZTDS.ai maintains strict boundary demarcations:

Institutional Capacity What ZTDS.ai Is What ZTDS.ai Is NOT (Strict Boundary)
Standard Setting Open Technical Consortium & RFC Maintainer (W3C / IETF model). Not a statutory state standards body (e.g. NIST, DIN, ISO national member).
Verification & Seals Git-backed automated code linter & zero-egress packet inspector. Not an accredited Conformity Assessment Body (ISO/IEC 17025/17065) or EU Notified Body.
Audit & Assurance Objective runtime telemetry & cryptographic hash receipt generator. Not a commercial CPA firm issuing AICPA SOC 2 Type II or financial audit opinions.
Legal Compliance Technical invariant verification mapping to statutory safe harbors. Not legal counsel; does not sign Data Processing Agreements (DPAs) or BAAs.
Consortium Terminology Governance Policy
Accreditation Authority Specification Maintainer
Certification Body Open Standard Consortium
Certified Software Verified Conformance
Legal Guarantee Invariant Adherence

02. Active Working Groups (WGs) & Charters

Consortium activities are partitioned into three domain-specific working groups. Each working group is co-chaired by an accredited ZTDS Fellow and an industry member representative, operating under open consensus and public GitOps tracking.

WG-1

Architecture & Cryptography

Invariants 1 & 3 · RFC Core
Mandate & Scope

Formulates mathematical proof definitions for Zero External Egress (ΔEgress ≡ 0.00 bytes) and hardware enclave isolation (AWS Nitro, Apple Secure Enclave, sandboxed WebAssembly). Enforces bijective mapping entropy and auto-purge volatile memory guarantees.

Key Deliverables
  • RFC v1.0 Mathematical Core & Formulations
  • WASM Sandbox Isolation Test Harness
  • Asymmetric Ed25519 Audit Receipt Schema
  • AES-256-GCM Ephemeral Vault Spec
Governance & Cadence
Co-Chairs: Ilya Sibiryakov (Founding Fellow) & Open Academic Seat
Cadence: Bi-weekly asynchronous triage on GitHub
Artifact: /docs/rfc-v1-crypto-proofs.md
WG-2

GRC & Regulatory Compliance

Invariant 4 · Legal Defense
Mandate & Scope

Maintains cross-jurisdictional compliance cross-mappings between technical invariants and international privacy statutes. Drafts formal legal memorandums demonstrating why local in-memory execution renders vendor Data Processing Agreements (DPAs) legally superfluous.

Key Deliverables
  • Executive Memo ZTDS-CISO-2026-V1
  • GDPR Recital 26 / Art. 28 Exemption Matrix
  • EU AI Act Article 10 Data Governance Guide
  • HIPAA Safe Harbor 45 CFR §164.514 Protocol
Governance & Cadence
Co-Chairs: Invited CISO Member & Privacy Regulatory Counsel
Cadence: Monthly plenary & regulatory alert bulletins
Artifact: /docs/ciso-procurement-pack.md
WG-3

Developer Ecosystem & Tooling

Invariant 2 · Reference Implementations
Mandate & Scope

Builds and standardizes open-source client-side developer SDKs, Model Context Protocol (MCP) stdio gateways, and automated CI/CD verification harnesses. Validates real-world AI pipelines against sub-2ms latency performance ceilings.

Key Deliverables
  • Automated CLI Auditor (npx ztds-audit)
  • MCP Stdio Sanitization Gateway Protocol
  • 10 Canonical Architectural Blueprints
  • Dynamic SVG Trust Badge Generator (/badge/)
Governance & Cadence
Co-Chairs: SDK Core Maintainer & Developer Community Representative
Cadence: Bi-weekly sprint review & automated GitOps triage
Artifact: /packages/ztds-sdk-core

03. Multi-Stakeholder Consensus & Voting

To prevent vendor capture and maintain strict neutrality, consortium decisions adhere to the RFC-8821 consensus protocol with cryptographically signed ballots.

Voting Threshold
2/3 Supermajority

Ratification of new RFC versions or deprecation of existing standards requires a 66.7% affirmative vote of all accredited Voting Fellows.

Anti-Cartelization
One Entity, One Vote

Corporate affiliates, subsidiaries, and related holding companies share a single collective vote to prevent hyperscaler domination.

Ballot Integrity
Signed Git Ballots

All plenary votes are cast via GPG or Ed25519 cryptographically signed commits on the public consortium repository for auditability.

Public Review
30-Day Comment Period

Every candidate RFC undergoes a mandatory 30-day public comment window prior to ratification, with all objections publicly addressed.

04. RFC Specification Lifecycle

All changes to the ZTDS technical specification progress through five formal lifecycle states modeled after IETF RFC procedures, requiring peer consensus and empirical proof.

Stage 01
Draft Proposal

Initial GitOps RFC pull request opened with invariant impact statement.

Entry: Open PR
Stage 02
Working Draft

Active technical refinement under relevant Working Group oversight.

Entry: WG Adoption
Stage 03
Candidate

Requires 2+ independent, interoperable implementations passing benchmarks.

Entry: 2x Reference Impl
Stage 04
Ratified Standard

Consortium 2/3 supermajority consensus vote & immutable DOI allocation.

Entry: 2/3 Vote + DOI
Stage 05
Historic / Depr.

Superseded specifications permanently archived for backward auditability.

Entry: Successor Standard
Intellectual Property & Patent Governance

RAND-Z Royalty-Free Patent Covenant

All specification contributors and working group members are bound by the RAND-Z (Reasonable and Non-Discriminatory with Zero Royalties) patent covenant to ensure the ZTDS standard remains unencumbered and accessible to all developers worldwide.

Irrevocable Worldwide Patent Grant

Every contributor unconditionally grants an irrevocable, worldwide, perpetual, royalty-free, non-exclusive patent license to any individual or organization implementing software conforming to the normative requirements of the ZTDS specification.

Defensive Termination Shield

If any entity asserts patent infringement claims against a conforming ZTDS implementation regarding technology covered by the specification, all patent rights granted to that asserting entity under the ZTDS covenant are automatically and immediately terminated.

Developer Certificate of Origin (DCO 1.1): All Git commits require git commit -s (Signed-off-by).
Read Complete Patent Policy →

06. Join a Working Group via GitOps

The ZTDS AI Consortium maintains zero bureaucratic barriers. Any engineer, CISO, or researcher can propose technical revisions, participate in working group deliberations, or submit code implementations through our GitOps workflow.

1
Fellow Nomination: Researchers submit peer preprints via Track C Fellow Application.
2
Corporate Adoption: Enterprises commit internal AI policies via Corporate Member Registry.
3
Tool Verification: AI software developers verify client-side invariants via Track A Product Certification.
GitOps RFC Workflow git bash
# 1. Clone the canonical consortium repository
$ git clone https://github.com/ztds-ai/standards.git
$ cd standards && git checkout -b rfc/wg1-streaming-tokens

# 2. Run automated invariant conformance test suite
$ npx ztds-audit --strict --egress-check
[PASS] 0 invariant violations. Audit hash generated.

# 3. Commit with DCO sign-off and push pull request
$ git commit -s -m "rfc(wg1): propose streaming tokenization spec"
$ git push origin rfc/wg1-streaming-tokens
Opening Pull Request: https://github.com/ztds-ai/standards/pull/42