VELARU MANDATE EXHIBIT PACK — PAYMENTS / PCI DSS Jurisdiction: Brazil (br) Modality: Text / Chat Program: Velaru Payments / PCI DSS · Brazil (galactic_payments_br) Product ID: payments:br:bundle:text Vertical: payments Generated: 2026-08-22T19:20:18.137352Z Authority: Brazil LGPD ADM Pack — Payment AI Fraud Decision Pack Deadline: PCI DSS v4.0 continuous compliance Velaru verify: https://velaru-erra.onrender.com/verify EXHIBIT A — AI INVENTORY [] EXHIBIT B — GOVERNANCE FRAMEWORK { "framework": "Velaru Mandate Registry \u2014 Payments / PCI DSS", "exhibit_authority": "Brazil LGPD ADM Pack \u2014 Payment AI Fraud Decision Pack", "regulatory_frameworks": [ "PCI DSS v4.0", "Reg E", "EU PSD2", "LGPD Art 20", "ANPD AI resolution", "CVM AI guidance", "Marco Civil" ], "standards_alignment": [ "POSS-2", "DRP-1", "TCB", "FRE 707 pre-compliance", "ISO 42001" ], "human_oversight": "authorize payment", "third_party_verification": "https://velaru-erra.onrender.com/verify (operator-independent)", "data_lineage": "Hash-chained Ed25519 receipts; optional RFC3161 + external anchor", "mirror_trap": "Issuer declines AI-authorized transaction \u2014 merchant needs receipt proving agent mandate existed. \u00b7 LGPD Art 20 review of automated decisions \u2014 receipt enables review request response.", "chain_integrity": { "depth": 6, "invariant_holds": true } } EXHIBIT D — DATA INPUTS & VALIDATION { "data_validation_method": "Cryptographic receipt per AI decision; public verify without trusting deployer, vendor, or Velaru operator", "bias_testing_proxy": "Asymmetry score from live chain signals", "model_change_control": "Policy lock registry \u2014 criteria hash frozen pre-dispute", "logging_retention": "90-day pre-dispute window minimum; permanent verify permalinks", "external_validator": "Nisaba LLC / Velaru", "validator_independence": "Client-side Ed25519 verify; BYOK tri-receipt optional", "headline_stat": "Reg E unauthorized transaction \u2014 prove customer authorized AI agent payment", "global_leaders_addressed": [ "Visa", "Mastercard", "Stripe", "PayPal", "Federal Reserve", "ANPD", "Nubank", "BCB" ] } MIRROR TRAP (regulatory insight) Issuer declines AI-authorized transaction — merchant needs receipt proving agent mandate existed. · LGPD Art 20 review of automated decisions — receipt enables review request response. NERVE CARDS — WHY GLOBAL LEADERS CARE [ { "title": "PCI 4.0", "body": "Customized approach requires documented risk analysis \u2014 AI fraud model changes trigger re-assessment.", "source": "vertical" }, { "title": "PSD2 EU", "body": "Strong customer authentication + AI agent = SCA exemption documentation required.", "source": "vertical" }, { "title": "Chargeback", "body": "Reason code 10.4 \u2014 merchant proves authorization with cryptographic receipt chain.", "source": "vertical" }, { "title": "[Brazil] LatAm hub", "body": "Brazil sets pattern for LATAM \u2014 receipt architecture scales to Mexico, Colombia.", "source": "jurisdiction" }, { "title": "[Brazil] Fintech", "body": "Nubank, Mercado Libre AI \u2014 BCB expects credit decision explainability.", "source": "jurisdiction" }, { "title": "[Text / Chat] Modality hook", "body": "Baseline \u2014 all frameworks apply to text decisions.", "source": "modality" } ] BOOK SUMMARY: { "total_insureds": 0, "compliant": 0, "grace_period": 0, "non_compliant": 0, "expired": 0, "not_enrolled": 0, "compliant_pct": 0.0 } TAM / EXPOSURE: $10T+ card volume · AI fraud detection universal INSURANCE LINES: Cyber, Crime, E&O DISCLAIMER: External validation evidence pack — not legal advice, not filed rate approval.