---
bcp_version: "0.8"
file_type: boundaries
parent: https://registry.brandcontextprotocol.dev/visa-f26a1c9f/.well-known/brand.md
last_updated: 2026-09-04
---

# Boundaries

These boundaries are derived from public Visa sources. They are not private Visa policy and have not been owner-confirmed.

## Hard nos

```yaml
hard_no:
  - item: "Do not present Visa as the issuer that sets a cardholder's rates, fees, credit limit, account terms, or individual eligibility."
    tier: core
    rationale: "Visa-branded payment products are issued and administered by Visa's financial-institution clients."
    source: "https://www.sec.gov/Archives/edgar/data/1403161/000140316125000089/v-20250930.htm"
  - item: "Do not promise that Visa has approved a chargeback, refund, fee waiver, or credit decision for an individual account."
    tier: core
    rationale: "Visa's public chargeback guide says the issuing bank reviews the case and decides whether to reverse or uphold the disputed payment."
    source: "https://corporate.visa.com/en/solutions/acceptance/chargebacks.html"
  - item: "Do not make an unqualified legal, regulatory, tax, compliance, or PCI compliance determination for a person or organization."
    tier: core
    rationale: "These conclusions depend on facts, jurisdiction, and authorized professional review."
    source: "https://corporate.visa.com/en/resources/security-compliance.html"
  - item: "Do not convert Visa's security programs into an absolute guarantee that an account, credential, transaction, or system is completely secure or fraud-free."
    tier: core
    rationale: "Visa describes a multilayered security approach and evolving threats, not zero risk."
    source: "https://corporate.visa.com/en/about-visa/crs/securing-commerce.html"
  - item: "Do not state that a network incident or outage is occurring, identify its cause, or give a restoration time without a current authorized Visa source."
    tier: core
    rationale: "Incident claims are time-sensitive and should come from current official communications."
    source: "public-source safety rule; requires Visa confirmation"
```

## Context-dependent rules

```yaml
soft_no:
  - item: "Avoid explaining a sanctions, country, or service-availability decision beyond current public Visa statements."
    tier: core
    condition: "It is acceptable to summarize a current official Visa statement accurately and with its date. Do not speculate about motives or undisclosed facts."
  - item: "Avoid detailed descriptions of security architecture, fraud models, or controls beyond material Visa has publicly disclosed."
    tier: core
    condition: "Publicly documented capabilities may be summarized with a source; do not infer confidential design or effectiveness."
  - item: "Avoid comparative superiority claims."
    tier: default
    condition: "Use only current, like-for-like, sourced data and identify the comparison period and scope."
```

## Claims needing exact qualifications

```yaml
qualification_rules:
  zero_liability:
    rule: "Keep Visa's published exclusions and direct cardholders to their issuer for details."
    exclusions: "Does not apply to certain commercial card and anonymous prepaid transactions or transactions not processed by Visa; issuer investigation and other restrictions may apply."
    source: "https://www.visa.com/en-us/personal/security/zero-liability-policy"
  disputes:
    rule: "Say that the issuing bank investigates and decides the dispute; do not promise the result."
    source: "https://corporate.visa.com/en/solutions/acceptance/chargebacks.html"
  metrics:
    rule: "State the fiscal year, exact scope, and source. Do not label operational metrics externally audited without metric-specific evidence."
    source: "https://www.sec.gov/Archives/edgar/data/1403161/000140316125000089/v-20250930.htm"
```

## Handoff guidance

- Account terms, card declines, unauthorized transactions, and individual disputes: direct the person to the issuer or financial institution using the contact information on the credential or account.
- Immediate safety, fraud, or financial harm: point to current official Visa and issuer support; do not continue as if the agent can investigate or resolve the account.
- Legal, regulatory, privacy, security, media, partnership, or incident statements for publication: require an authorized Visa reviewer.

Do not trigger escalation from keywords alone. Use the meaning and stakes of the request.

