Trust / product boundaries

Transparency belongs in the product—not only the fine print.

D1 / DISCLAIMER

Guidance, not certification or legal advice

RUO Clear reviews stated public and connected coverage against a versioned ruleset and source library. It does not determine legal status, verify product identity or safety, or guarantee regulator, bank, provider, card-network, or platform outcomes.

P1 / PRIVACY

Collect progressively and explain the purpose

Identity, company, supplier, processor, domain, and evidence fields require documented purpose, access class, provenance, verification state, retention, and deletion behavior.

T1 / TERMS

Authorization and commercial terms remain explicit

Retained, deep, repeated, or connected scans require affirmative authority. Subscription and provider-facing actions require separate, versioned consent.

S1 / SECURITY

Tenant isolation and least privilege are release gates

Sensitive merchant, supplier, provider, and evidence records require scoped access, encryption, audit history, secure secret handling, incident response, and verified deletion behavior.

A1 / ACCESSIBILITY

Core journeys must work without a mouse

Navigation, scan setup, findings, evidence, account lifecycle, and payment-readiness states require keyboard, screen-reader, focus, contrast, zoom, mobile, loading, error, and permission testing.

C1 / CORRECTIONS

Challenge the record without erasing history

Authorized users can dispute a finding, evidence excerpt, source record, or account context. Corrections preserve the original, reviewer, rationale, superseding version, and downstream notice.

Open support routes

N1 / CHANGE NOTICE

Material changes are versioned

Rules, sources, plans, policies, disclaimers, retention, and provider-role changes require an owner, approval, effective date, impact analysis, and customer notice appropriate to the change.