Carver Agents · demo
Compliance review of Mastercard SPME → Halyard Pay policy updates
This site presents an AI agent's analysis of 5 Mastercard SPME releases spanning Jun 2022 to May 2025, with proposed updates to 8 Halyard Pay policies.
01 · How it works
What the agent did
A three-stage agent reads each Mastercard SPME release, identifies what changed since the previous version, and proposes corresponding edits to Halyard Pay's internal compliance policies.
Detect
Extract text from each SPME PDF, identify every numbered section, and compare consecutive versions to surface added, removed, and modified sections.
Classify & map
For each detected change, an LLM assigns a materiality grade (breaking → cosmetic) and identifies which Halyard Pay policy areas are affected by the new Mastercard text.
Propose
Draft updated rules.yaml and policy.md for each affected policy, emit a change record with side-by-side redlines, and link back to the cited SPME section.
02 · Inputs
Mastercard input documents
The SPME (Security Rules and Procedures — Merchant Edition) is Mastercard's primary compliance publication for acquirers and merchants. Mastercard refreshes it roughly every 6–12 months. The following published versions were reviewed:
- Mastercard SPME · Jun 2022 PDF
- Mastercard SPME · May 2023 PDF
- Mastercard SPME · Sep 2023 PDF
- Mastercard SPME · Feb 2024 PDF
- Mastercard SPME · Sep 2024 PDF
- Mastercard SPME · May 2025 PDF
Source: archived from Mastercard's public publications via the Internet Archive Wayback Machine. PDFs are bundled with this demo for offline review.
03 · Outputs
Halyard Pay policies evaluated
These represent the eight policy areas a hypothetical Halyard Pay compliance program would maintain to satisfy Mastercard's published rules. These are synthetic v1 baseline policies — they do not reflect any production Halyard Pay policy and exist solely to demonstrate how the agent surfaces and proposes edits.
04 · Vocabulary
Glossary
Acronyms used throughout the site, plus the four materiality grades the classifier assigns.
- SPME
- Security Rules and Procedures — Merchant Edition. Mastercard's primary B2B compliance document for acquirers and merchants.
- BRAM
- Business Risk Assessment and Mitigation. A Mastercard investigation process triggered when a merchant is suspected of brand-damaging activity.
- ECP
- Excessive Chargeback Program. Mastercard's framework for monitoring merchants whose chargeback rate exceeds defined thresholds.
- KYB
- Know Your Business. The acquirer's obligation to verify and document the identity and legitimacy of merchants it onboards.
- ATO
- Account Takeover. Fraud pattern where an attacker gains unauthorized control of a cardholder's account.
- MATCH
- Member Alert To Control High-Risk Merchants. Mastercard's shared registry of terminated merchants used by acquirers during onboarding.
- PCI DSS
- Payment Card Industry Data Security Standard. The cross-network security baseline that acquirers and merchants must satisfy.
- Materiality grades
- Breaking
- Alters an obligation, threshold, or required behavior. A policy revision is required to remain compliant.
- Substantive
- Adds meaningful new context, references, or examples without altering an obligation. A policy update is recommended.
- Restates an existing rule in different language. No policy change required, but cross-references may need updating.
- Cosmetic
- Formatting, typo, or section reordering with no semantic impact. No action required.
05 · Navigation
How to read this demo
There are two complementary ways to navigate.
06 · Disclaimers
What this is not
- The Halyard Pay policies shown here are synthetic v1 baselines built for this demo. They do not reflect any production policy.
- All proposed edits are agent-generated and have not been reviewed or approved by Halyard Pay Compliance.
- This site is for review feedback; nothing here is binding, legal advice, or a recommended course of action.
- Mastercard publications are republished here under fair-use review purposes from publicly archived versions. Always consult the current authoritative Mastercard publication for compliance decisions.