D1 / DISCLAIMER
Guidance, not certification or legal advice
RUO Clear reviews stated public and connected coverage against a versioned ruleset and source library. It does not determine legal status, verify product identity or safety, or guarantee regulator, bank, provider, card-network, or platform outcomes.
P1 / PRIVACY
Collect progressively and explain the purpose
Identity, company, supplier, processor, domain, and evidence fields require documented purpose, access class, provenance, verification state, retention, and deletion behavior.
T1 / TERMS
Authorization and commercial terms remain explicit
Retained, deep, repeated, or connected scans require affirmative authority. Subscription and provider-facing actions require separate, versioned consent.
S1 / SECURITY
Tenant isolation and least privilege are release gates
Sensitive merchant, supplier, provider, and evidence records require scoped access, encryption, audit history, secure secret handling, incident response, and verified deletion behavior.
A1 / ACCESSIBILITY
Core journeys must work without a mouse
Navigation, scan setup, findings, evidence, account lifecycle, and payment-readiness states require keyboard, screen-reader, focus, contrast, zoom, mobile, loading, error, and permission testing.
C1 / CORRECTIONS
Challenge the record without erasing history
Authorized users can dispute a finding, evidence excerpt, source record, or account context. Corrections preserve the original, reviewer, rationale, superseding version, and downstream notice.
N1 / CHANGE NOTICE
Material changes are versioned
Rules, sources, plans, policies, disclaimers, retention, and provider-role changes require an owner, approval, effective date, impact analysis, and customer notice appropriate to the change.