Trust · Compliance · Governance

Institutional review, verifiable.

Every artifact your procurement, risk, and InfoSec leads will ask for — published as a canonical URL, versioned on GitHub, and open source under Apache 2.0. Hand this page to your team.

Apache 2.0 open spec RFC 9116 security.txt SOC 2 planning GDPR + PSD3/PSR aligned NSPM-11 aligned

Open specification.

The MNNR Standard defines the schemas, adapter contracts, domain objects, and brand kit that mnnr implements. Every claim on this site is grounded in a versioned artifact in the spec repo.

Repository

mnnr-org/mnnr-standard

Latest release v0.1.2. Contracts, schemas, security posture, brand kit. Apache 2.0.

github.com/mnnr-org/mnnr-standard →
Domain objects

11 first-class objects

Agent Actor · Mandate · Merchant Acceptance Record · Transaction Intent · Transaction Envelope · Article 50 Disclosure · Post-Quantum Audit Entry · Reconciliation Event · Dispute Case · Compliance Attestation · Partner Integration Manifest.

Read the objects →
Rail adapters

Canonical adapter contract

One PaymentRailAdapter interface. Rail-specific specs for x402, AP2, UCP, ACP, MCP.

Read the adapters →
Reconciliation schema

mnnr.reconciliation.v1

JSON Schema draft-2020-12. Five validated example events. ML-DSA-65 audit receipts. Article 50 self-ID + PSD3 SCA metadata.

Inspect schema →

Security posture.

Threat model, data flows, sub-processors, incident response, disclosure policy, and SOC 2 readiness — all in the open. Reviewable before you sign anything.

Threat model

STRIDE across 6 surfaces

Agent API · rail adapters · persistence · audit trail · admin console · public spec repo. Risk register attached.

Download threat model (PDF) → · source
Data flow

Five Mermaid sequences

Transaction intent → envelope; settlement reconciliation; dispute open; compliance attestation; post-quantum audit chain. Trust boundaries + data classification.

Download data flow (PDF) → · source
Sub-processors

Nine vendors

Cloudflare · Netlify · Supabase · Stripe · Sentry · GitHub · Resend · Google Workspace · Cloudflare KMS. Regions + certifications + data classes.

Download sub-processor list (PDF) → · source
Incident response

5-phase IRP

SEV levels, GDPR Article 33 72-hour notification, holding-statement + 72h-notification templates.

Download IRP (PDF) → · source
Vulnerability disclosure

RFC 9116-aligned

Private advisories via GitHub Security. Safe harbor. Acknowledge in 3 business days.

Download VDP (PDF) → · source
SOC 2 readiness

TSC applicability + priorities

Type I readiness target Q4 2026. Formal engagement to follow.

Download SOC 2 tracker (PDF) → · source
security.txt

RFC 9116 endpoint

Machine-readable contact for vulnerability reporters and security researchers.

/.well-known/security.txt →
Platform status

Public surfaces + build state

Real-time posture of every published surface. Reference-implementation components labeled by build state per Claims Register.

View status →
Live PQC keys

ML-KEM-768 + ML-DSA-65

Published public keys with SHA-256 fingerprints and signed operational attestation. Verifiable at /crypto/.

Verify live keys →

Contract templates.

Publishable MSA, SOW, DPA, and AUP. Adapt to your counterparty; every artifact is drafted for institutional review with SCC Module 2 incorporation.

MSA

Master Services Agreement

EU / UK arbitration variant + US Delaware / JAMS variant. Confidentiality, IP, indemnity, LoL, DPA references.

Download MSA (PDF) → · source
SOW

Statement of Work

Deliverables, acceptance criteria, milestone payments. Adapts to A50 Emergency Retrofit and Full Pilot engagements.

Download SOW (PDF) → · source
DPA

Data Processing Addendum

GDPR + UK-GDPR + Swiss addendum. SCC Module 2 (Controller-to-Processor). Annexes: processing details, TOMs, sub-processors, SCC reference.

Download DPA (PDF) → · source
AUP

Acceptable Use Policy

Sanctions + AML + agent-actor requirements. Enforcement + reporting via security@mnnr.app.

Download AUP (PDF) → · source

Regulatory alignment.

Direct citations, no vendor talking points.

EU AI Act Art. 50

Transparency + self-ID

Applicability date 2026-08-02, subject to exceptions. MNNR implements Art. 50 self-ID at the transaction-envelope layer.

PSD3 / PSR

SCA delegation + mandate + dispute

Final implementation details pending legislative completion. MNNR implements controls designed to satisfy anticipated obligations.

eIDAS + EUDIW

Identity assurance level routing

Compatible with EUDI Wallet trajectory.

GDPR + Art. 27

Data residency + EU rep

EU-resident processing infrastructure available. Article 27 representative appointment under review.

DORA

ICT third-party risk

Hooks for in-scope financial-entity reporting.

NSPM-11 (US)

Federal agentic AI guardrails

Signed 2026-06-05. mnnr is the cross-vendor policy layer.

Positioning honesty.

Every claim on this site is a design specification. Some components have reference implementations; most are in build. External claim language uses "design specification," "target," or "in build." Real build state per component is published in the Claims Register — go there before signing anything.

Read the Claims Register →

Machine-readable capabilities.

For AI agents, RFP tools, and Gemini/Perplexity/ChatGPT extraction.

llms.txt

AI-crawler map

Value prop, buyer personas, pilot pricing, briefs, security, and canonical URLs.

/llms.txt →
Agent manifest

ai-agents-manifest.json

Actions, personas, rails, recognized agent user-agents. Machine-readable capability declaration.

/.well-known/ai-agents-manifest.json →
JSON-LD schema.org

Structured data

Organization + SoftwareApplication + Offers + FAQPage embedded in every page <head>. Google AI Overview + Perplexity extraction ready.