Assure and conform
ARPA treats conformance as an evidence-producing activity. A claim should identify the protocol/profile surface tested, the implementation under test, the evidence retained and the assurance boundary.
Core assurance path
- Conformance overview
- Conformance Guide
- Select Profile A, B, C or D
- Run the repository gate:
make release-check-all
- Review generated evidence under
artifacts/and implementation reports underconformance/reports/.
Current cross-runtime evidence
The v0.9.5 development track adds two distinct assurance layers:
- same-corpus equivalence: Python and TypeScript independently evaluate shared deterministic and historical vectors;
- network interoperability: the implementations exchange ARPA data and decisions across their HTTP boundaries.
Repository-controlled implementation diversity is useful pre-v1.0 evidence, but it does not satisfy the requirement for externally independent implementation evidence.
Evidence is not authority
Passing a conformance test does not establish legal authority, production security, issuer competence or governance recognition beyond the declared test scope.
Governance and privacy assurance
The governance and security assurance profile adds negative conformance vectors for high-impact administrative control, revocation convergence, federation recognition conflicts, disclosure filtering, and compromise restoration. The evidence bundle is generated by python3 scripts/validate_governance_assurance.py and is part of make validate.