Institutional review, verifiable.
Every artifact your procurement, risk, and InfoSec leads will ask for — published as a canonical URL, versioned on GitHub, and open source under Apache 2.0. Hand this page to your team.
Open specification.
The MNNR Standard defines the schemas, adapter contracts, domain objects, and brand kit that mnnr implements. Every claim on this site is grounded in a versioned artifact in the spec repo.
mnnr-org/mnnr-standard
Latest release v0.1.2. Contracts, schemas, security posture, brand kit. Apache 2.0.
github.com/mnnr-org/mnnr-standard →11 first-class objects
Agent Actor · Mandate · Merchant Acceptance Record · Transaction Intent · Transaction Envelope · Article 50 Disclosure · Post-Quantum Audit Entry · Reconciliation Event · Dispute Case · Compliance Attestation · Partner Integration Manifest.
Read the objects →Canonical adapter contract
One PaymentRailAdapter interface. Rail-specific specs for x402, AP2, UCP, ACP, MCP.
Read the adapters →mnnr.reconciliation.v1
JSON Schema draft-2020-12. Five validated example events. ML-DSA-65 audit receipts. Article 50 self-ID + PSD3 SCA metadata.
Inspect schema →Security posture.
Threat model, data flows, sub-processors, incident response, disclosure policy, and SOC 2 readiness — all in the open. Reviewable before you sign anything.
STRIDE across 6 surfaces
Agent API · rail adapters · persistence · audit trail · admin console · public spec repo. Risk register attached.
Download threat model (PDF) → · sourceFive Mermaid sequences
Transaction intent → envelope; settlement reconciliation; dispute open; compliance attestation; post-quantum audit chain. Trust boundaries + data classification.
Download data flow (PDF) → · sourceNine vendors
Cloudflare · Netlify · Supabase · Stripe · Sentry · GitHub · Resend · Google Workspace · Cloudflare KMS. Regions + certifications + data classes.
Download sub-processor list (PDF) → · source5-phase IRP
SEV levels, GDPR Article 33 72-hour notification, holding-statement + 72h-notification templates.
Download IRP (PDF) → · sourceRFC 9116-aligned
Private advisories via GitHub Security. Safe harbor. Acknowledge in 3 business days.
Download VDP (PDF) → · sourceTSC applicability + priorities
Type I readiness target Q4 2026. Formal engagement to follow.
Download SOC 2 tracker (PDF) → · sourceRFC 9116 endpoint
Machine-readable contact for vulnerability reporters and security researchers.
/.well-known/security.txt →Public surfaces + build state
Real-time posture of every published surface. Reference-implementation components labeled by build state per Claims Register.
View status →ML-KEM-768 + ML-DSA-65
Published public keys with SHA-256 fingerprints and signed operational attestation. Verifiable at /crypto/.
Verify live keys →Contract templates.
Publishable MSA, SOW, DPA, and AUP. Adapt to your counterparty; every artifact is drafted for institutional review with SCC Module 2 incorporation.
Master Services Agreement
EU / UK arbitration variant + US Delaware / JAMS variant. Confidentiality, IP, indemnity, LoL, DPA references.
Download MSA (PDF) → · sourceStatement of Work
Deliverables, acceptance criteria, milestone payments. Adapts to A50 Emergency Retrofit and Full Pilot engagements.
Download SOW (PDF) → · sourceData Processing Addendum
GDPR + UK-GDPR + Swiss addendum. SCC Module 2 (Controller-to-Processor). Annexes: processing details, TOMs, sub-processors, SCC reference.
Download DPA (PDF) → · sourceAcceptable Use Policy
Sanctions + AML + agent-actor requirements. Enforcement + reporting via security@mnnr.app.
Download AUP (PDF) → · sourceRegulatory alignment.
Direct citations, no vendor talking points.
Transparency + self-ID
Applicability date 2026-08-02, subject to exceptions. MNNR implements Art. 50 self-ID at the transaction-envelope layer.
SCA delegation + mandate + dispute
Final implementation details pending legislative completion. MNNR implements controls designed to satisfy anticipated obligations.
Identity assurance level routing
Compatible with EUDI Wallet trajectory.
Data residency + EU rep
EU-resident processing infrastructure available. Article 27 representative appointment under review.
ICT third-party risk
Hooks for in-scope financial-entity reporting.
Federal agentic AI guardrails
Signed 2026-06-05. mnnr is the cross-vendor policy layer.
Positioning honesty.
Machine-readable capabilities.
For AI agents, RFP tools, and Gemini/Perplexity/ChatGPT extraction.
AI-crawler map
Value prop, buyer personas, pilot pricing, briefs, security, and canonical URLs.
/llms.txt →ai-agents-manifest.json
Actions, personas, rails, recognized agent user-agents. Machine-readable capability declaration.
/.well-known/ai-agents-manifest.json →Structured data
Organization + SoftwareApplication + Offers + FAQPage embedded in every page <head>. Google AI Overview + Perplexity extraction ready.