Regra

Know what gets you terminated.Before your processor does.

Regra reads your site like an underwriter would — card-network rules, Stripe's policy, the EU AI Act — and hands you the exact fix for every issue.

Early access — join the waitlist · no card required · every plan includes the full report.

◉ regra scancrawling yourdomain.com…
0 / 100
Scanning…
CRITRestricted-category businessStripe AUP
HIGHNo refund policy foundVisa · MC
MEDNo AI-content disclosureEU AI Act 50

Watch it work

This is what a scan looks like.

A replay of Regra scanning our demo property — the same crawl, the same 32 rules, and the same findings format you get on your own site. No signup to watch.

◉ regra scandemo.regra.appDemo site — representative contentready
GET demo.regra.app/ 200
GET demo.regra.app/create 200
GET demo.regra.app/pricing 200
GET demo.regra.app/terms 200
0 / 100
Scanning…
CRITICALFace-swap offered on third-party faces, no consent gateVisa GBPP · MC BRAM

Swap any face into any video in seconds.

HIGHFree trial converts without disclosed termsFTC Negative Option

Start your free trial today

HIGHNo age gate for adult-adjacent AI generationCard network
MEDIUMAI-generated content not disclosed to viewersEU AI Act Art. 50

A processor ban doesn't come with a warning.

We built Regra after watching a merchant get cut off. The account closed on a Tuesday — no call, no warning period. Stripe terminated, the MATCH listing went up under reason code 13, and the reserve was held for months. Shopify Payments followed under VIRP enforcement. Rebuilding payment rails took months and a separate entity; the MATCH listing kept them off mainstream processors for five years. None of it was unusual. That's the standard playbook.

It's in the agreements

Regra shows you what an underwriter would see — before they see it.

The public record

0public reports

Founders whose payment accounts were terminated or frozen in the past 6 months — and posted about it.

Payment processors publish no termination numbers. These are first-person reports on Hacker News and Reddit — every one linked, in the posters' own words. The real number is unknowable, and certainly higher.

Compiled 2026-07-30· dates from the public HN archive · each card quotes and links the original post; claims are the posters' own.

What a finding looks like

Every issue comes with the evidence and the fix.

No vague warnings. Regra quotes the exact copy on your page, explains why it puts your payments at risk, cites the rule, and tells you precisely what to change.

HighFree trial without disclosed termsBilling · FTC
Detection
Deterministic rule match — same input, same result, every scan.
Evidence
Start your 7-day free trial
Why it matters
Negative-option rules from the FTC and card networks require a trial offer to state, right next to it, exactly what the customer will be charged and when after the trial ends.
The fix
Everywhere "free trial" appears, state the post-trial price and cadence — e.g. "Free for 7 days, then $19/mo. Cancel anytime."

Representative example from Regra’s billing-transparency rules.

What Regra checks

Ruleset current as of July 29, 2026

Every rule that gets merchants cut off.

31 rules across 5 frameworks. Every rule links to the document it comes from — verify any finding yourself.

Card networks (Visa / Mastercard)

9 rules

Prohibited and high-risk content under the Visa Global Brand Protection Program and Mastercard BRAM — the rules that get merchants MATCH-listed.

Stripe & processor AUP

5 rules

Restricted-business and acceptable-use screening for the categories mainstream processors terminate without warning.

EU AI Act

5 rules

Article 50 transparency duties — AI-content, chatbot, and synthetic-media disclosure obligations.

TAKE IT DOWN Act

2 rules

Content notice-and-removal duties for platforms that host user- or AI-generated media.

Billing transparency

6 rules

Pricing visibility, free-trial conversion terms, auto-renewal and cancellation disclosure under FTC and card-network rules.

The rules keep moving

AI compliance is a moving target.

Regra tracks the rulebooks. When they change, your next scan shows exactly what's newly required.

  • Aug 2, 2026

    EU AI Act Article 50 disclosure duties become applicable — AI content, chatbots, synthetic media.

    Implementation timeline
  • May 19, 2026

    TAKE IT DOWN Act notice-and-removal process now mandatory for covered platforms.

    PL 119-12 §3
  • Ongoing

    Visa and Mastercard revise brand-protection standards throughout the year.

    Mastercard SPME

Get an email when the rules move

Free digest — only sent when a rulebook actually changes. No marketing.

Methodology

What actually happens when we scan.

No black box. Six steps, each one inspectable — and every finding links to the rule and the page that produced it.

  1. 01

    Crawl your public pages

    We read your site the way an underwriter would — landing, product, pricing, and legal pages, exactly as they're served to visitors. Nothing behind logins, nothing you haven't published.

  2. 02

    Classify every page

    Each page is typed — landing, product, checkout, legal — so rules only run where they belong. A refund-policy check has no business judging your blog.

  3. 03

    Deterministic rules, cited

    31 pattern and missing-element checks against the rules that actually get merchants terminated — Visa and Mastercard's registries, Stripe's Restricted Businesses list, the EU AI Act, the TAKE IT DOWN Act. Same input, same result, every scan. Safety language is recognized: a page saying you block explicit content is never counted as selling it.

  4. 04

    AI judgment, labeled as judgment

    Claude reads every page against the rules that need context — like whether a deepfake tool discloses its labeling. Every finding carries a verbatim quote, the exact page, and a confidence score, and judgment calls are labeled so you never mistake them for hard matches.

  5. 05

    Byte-level provenance verification

    Bytes, not claims

    We download samples of the output media on your pages and inspect the actual file bytes for C2PA Content Credentials and IPTC AI markers — verifying your EU AI Act Art. 50(2) implementation, not just what your policy claims. Nobody else checks the bytes.

  6. 06

    Score, exact fixes, artifacts

    Findings weigh into a 0–100 score with the exact fix for each issue, and each scan becomes a frozen PDF report you can hand to your processor. Dismiss a finding with a reason and Regra won't raise it again.

We're measuring precision on real scans now, and we'll publish the numbers when the sample is big enough to mean something. Until then, every finding links to its source rule — check our work.

Fixed isn't a feeling. It's a re-scan.

Compliance isn't a one-time audit — rules change and sites change. Regra closes the loop.

1

Scan

Paste your domain. Regra crawls your pages and evaluates them against every rule in scope for your business category.

2

Fix

Every finding comes with the exact quote, why it's a problem, and the specific change that resolves it.

3

Re-scan

Run it again. Findings you fixed are verified resolved — not assumed resolved.

4

Stay clean

Monitoring re-checks your site on schedule, so a new page or a new rule never becomes a silent violation.

We read only your public pages.

  • Regra fetches the same public HTML any visitor — or any underwriter — can see. No agents installed, no code access, no credentials.
  • We store the page text we scanned and the findings we raised so you can track fixes between scans. Nothing is shared or resold.

Details in our Privacy Policy and Security overview.

Pricing

Less than one chargeback.

Every plan includes the full report — evidence, the rule behind each finding, and the exact fix — across all frameworks.

Guard

Protect one site.

$49/mo

billed monthly

Join the early-access waitlist — we'll email you when your spot opens.

  • 1 site
  • Weekly monitoring
  • Full report + exact fixes
  • All frameworks
  • Email alerts (critical & high)
  • Fix verification
Most popular

Shield

Cover a portfolio.

$199/mo

billed monthly

Join the early-access waitlist — we'll email you when your spot opens.

  • 5 sites
  • Daily monitoring
  • Unlimited seats
  • Change alerts (all severities)
  • White-label reports
  • API access
  • Priority support

Enterprise

Screen your own merchants.

Custom

annual contract

Contact sales
  • Unlimited sites + bulk scanning
  • Custom rulesets
  • SSO / SAML + audit logs
  • Dedicated support + SLA

Early access — join the waitlist and we'll email you the moment your plan opens.

Questions

Is this legal advice?
No. Regra flags likely violations against published card-network and regulatory rules and shows you the source. It is not legal advice, and the final decision always rests with your processor. For high-stakes calls, confirm with counsel.
How current are the rules?
Regra tracks published card-network programs (Visa GBPP, Mastercard BRAM), Stripe's restricted-business list, the EU AI Act, and the TAKE IT DOWN Act. Each finding links to its source so you can verify it yourself.
What if a finding doesn't apply to me?
You can dismiss any finding with a reason, and Regra won't raise it again on future scans. Nuanced, judgment-based findings are labeled so you know to verify them before acting.

Find out before your processor does.

Three days is enough to see every warning on your site. The full report unlocks the moment you subscribe.