Now building · EU early access

The Control Plane for Autonomous Transactions.

AI agents are already moving money. mnnr is the policy layer banks, PSPs, and issuers use to make those actions safe to trust — with permissioning, real-time approvals, and immutable audit at every step.

Permissions Approvals Auditability
Request a demo Talk to enterprise

“AI is already acting. mnnr makes those actions safe to trust with money.”

PSD2 SCA eIDAS GDPR · EU data residency SOC 2 (Type I target) ISO 27001 (track)

What it is.

A regulated-fintech-grade control plane that sits between AI agents and the rails that move money. Three primitives, one verifiable record.

P

Permissions

Issue agent-scoped credentials with hard ceilings on amount, counterparty, MCC, geography, and time. Agents only spend the budget you give them — not the budget your customer's account holds.

A

Approvals

Step-up approval flows that route the right amount to the right human at the right moment. SCA-compliant by design. Webhook in milliseconds, decide in seconds.

L

Auditability

An append-only ledger of every agent intent, policy check, approval, and execution. Reconcile-ready exports for finance, dispute teams, and regulators.

Who it serves.

Built for the regulated counterparties already feeling the agentic-commerce wave hit their support queues, dispute desks, and compliance teams.

Issuers

Banks & card issuers

Give your retail and SMB customers an agent layer that doesn't ship liability back to your dispute desk.

PSPs

Payment service providers

Add agent-ready primitives to your gateway without rebuilding your risk engine.

Acquirers

Merchant acquirers

Help merchants accept agent-initiated payments with verifiable consent and clean chargeback posture.

Partners

AI platforms

Ship payment-aware agents into regulated jurisdictions without becoming a payment institution overnight.

Regulated by design.

European-first. We treat regulatory clarity as a feature, not a tax.

EU posture · first

  • PSD2 SCAStrong customer authentication baked into the approval primitive.
  • eIDASIdentity assurance level routing for Article 3 services.
  • GDPR data residencyCustomer-facing data stored in eu-central-1 (Frankfurt). Article 27 EU representative on file.
  • DORA awarenessICT third-party risk reporting hooks for in-scope financial entities.

Security posture · in flight

  • SOC 2 Type ITargeting Q4 2026 audit window.
  • ISO 27001Controls mapping in build. Track-to-certification in 2027.
  • EncryptionAt-rest AES-256, in-transit TLS 1.3, optional CMEK for enterprise tier.
  • Append-only ledgerCryptographically signed events. Exportable to BigQuery / Snowflake / Postgres.

Design partners wanted.

We're opening early access to ten European banks, PSPs, and issuers building toward agentic commerce in 2026–2027. If that's you, we'd like to talk.

No spam, no sales spam. One human reads each submission. Reply within two business days.