Risk Disclosures
1. Not legal advice
MNNR LLC is a software vendor. MNNR is not a law firm. No employee, contractor, or representative of MNNR is acting as your attorney. The mnnr.app website, the EU brief, the federal brief, the compliance brief, the 14-point engineering checklist, the A50 SKU page, every published attestation, and every communication from MNNR are provided for informational purposes only and do not constitute legal, regulatory, accounting, tax, or investment advice. Customer is solely responsible for obtaining advice of qualified licensed counsel in the relevant jurisdiction before relying on any MNNR statement for compliance, contracting, or regulatory purposes. No attorney-client relationship is formed by accessing the website, downloading materials, executing an Order Form, or using the Service.
2. Forward-looking statements
Statements in MNNR materials about regulatory timelines (including the EU AI Act Article 50 applicability date of 2026-08-02, PSD3/PSR adoption following the November 2025 Council/Parliament provisional political agreement, with Official Journal publication and implementation timelines pending, NSPM-11 implementation, CNSA 2.0 milestones, and FedRAMP authorization), product roadmap milestones, and integration availability are forward-looking and subject to change. Actual regulatory text, dates, interpretations, and enforcement priorities may differ from MNNR's good-faith summaries. MNNR undertakes no obligation to update forward-looking statements except as required by law.
3. Regulatory interpretation risk
MNNR's compliance interpretations, including the framing of Article 50 self-identification obligations as machine-verifiable AI-actor tags, the application of PSD3/PSR to agentic flows, and the mapping of NSPM-11 to a cross-vendor policy layer, represent MNNR's good-faith reading of public sources. These interpretations are not endorsed by the European Commission, the European AI Office, the European Banking Authority, BaFin, the Federal Trade Commission, the U.S. Securities and Exchange Commission, the Executive Office of the President, or any other regulator or supervisory authority. A regulator may adopt a different interpretation. Customer's score on any MNNR-published checklist does not constitute a safe harbor against enforcement.
4. Penalty exposure
Penalties under EU AI Act Article 99 may reach the higher of EUR 15,000,000 or 3% of worldwide annual turnover. Penalties under GDPR Art. 83 may reach the higher of EUR 20,000,000 or 4% of worldwide annual turnover. Penalties under PSD3/PSR will be set in the final adopted text following Official Journal publication; the November 2025 provisional political agreement informs current expectations but is not yet binding law. MNNR is not liable for any fine, penalty, or sanction assessed against Customer or any third party by any regulator. See Section 12 of the Terms of Service.
5. Certification status
The following certifications and authorizations are aspirational or in progress as of the date of this disclosure and have not been obtained:
- SOC 2 Type I — targeted Q4 2026 audit window
- ISO/IEC 27001 — controls mapping in build, certification track 2027
- FedRAMP Moderate — path in scoping
- SDVOSB — SDVOSB verification with SBA VetCert is in preparation and not yet complete; no set-aside eligibility is claimed; SAM.gov registration ACTIVE (UEI UHP9VKN8FX99, CAGE 224V3)
- PCI DSS — not applicable; MNNR does not store cardholder data
- HIPAA / HITRUST — not applicable to current scope
Customer must not rely on the eventual achievement of any of the foregoing as a condition of using the Service unless expressly warranted in a fully-executed Order Form.
6. Cryptographic and post-quantum risk
The post-quantum primitives published at /crypto/ implement NIST FIPS 203 (ML-KEM-768) and FIPS 204 (ML-DSA-65). These standards are recent. Future cryptanalysis may reveal weaknesses. MNNR commits to migrate to a successor standard within a commercially reasonable period of any formal NIST deprecation notice. MNNR's signing keys are cold-stored offline under founder custody pending HSM migration scheduled for Q3 2026; until that migration is complete, key-compromise risk is operationally mitigated through cold-storage and access controls but not eliminated.
7. Third-party rails
MNNR is a governance layer that sits above third-party agentic-payment rails (Visa Agentic Ready, Mastercard Agent Pay, Stripe Tempo MPP, PayPal Agent Ready, Crossmint Agentic Cards, AWS Bedrock AgentCore Payments, Adyen Agentic, Google Cloud UCP, Chrome WebMCP, and any successor). MNNR makes no representation or warranty regarding the availability, security, performance, or compliance of any third-party rail. "Integration roadmap" means engineering in progress; "Interest accepted" means initial buyer-side conversations underway. Neither status constitutes a commercial partnership, endorsement, or affiliation.
8. Service-availability risk
The Service depends on infrastructure operated by Cloudflare, Amazon Web Services, Stripe, and other sub-processors. MNNR's Service Level Agreement, when published, will set out service-availability commitments and remedies. Service availability does not equal compliance.
9. Cyber, fraud, and adversarial-AI risk
Agentic payments are an emerging domain. Adversarial agents, prompt injection, mandate-scope evasion, and supply-chain attacks present residual risks that no current technology eliminates. MNNR's governance layer is designed to reduce, not eliminate, these risks. Customer remains responsible for end-to-end fraud, abuse, and operational-risk management.
10. Insurance
MNNR maintains the insurance coverage described in its Trust Center page when published. Coverage limits, retentions, and exclusions apply. Insurance does not increase MNNR's contractual liability cap set out in Section 12 of the Terms of Service.
11. Veteran-owned status
MNNR is founded by a 100% service-connected disabled U.S. military veteran. Veteran-owned status is a corporate fact and does not constitute, on its own, any specific contracting set-aside eligibility absent the certifications listed in Section 5.
12. Material changes
MNNR will update these Risk Disclosures from time to time. Continued use of the website, materials, or Service after the "Last updated" date constitutes acceptance of the revised disclosures.
13. Contact
MNNR LLC, 1603 Capitol Ave, Suite 413 PMB #1750, Cheyenne, WY 82001, USA. Email: legal@mnnr.app.