# MLS Compliance Rules for Custom Builds

Read this file before changing search, cards, detail pages, maps, sharing, print, data caching, or exports. It is intended for human developers and AI coding assistants.

## Source of truth

1. The customer's signed MLS agreement and current board display requirements
2. `GET /api/v1/platform/compliance` for the approved website
3. The `compliance` object returned on each listing

The API metadata is implementation guidance, not a complete replacement for every board's agreement. If the board requires additional disclosures, provide them before launch.

## Required rendering

- Preserve the exact required disclaimer text. Never summarize it or render it through unsafe HTML
- Render supplied MLS or IDX logos when `show_idx_logo` is true
- Display the listing agent when `show_listing_agent` is true
- Display the listing office when `show_selling_office` is true
- Display the MLS update timestamp when supplied. Do not substitute the browser's current time
- Keep attribution readable on cards and detail pages at every screen size
- Do not hide disclosure text behind an interaction or truncate required content
- Do not replace listing office attribution with the website owner's branding
- If required attribution data is missing, hide the record until it can be displayed correctly

## Data lifecycle

- Use no-store unless an explicit board-approved caching policy is implemented
- A cache must never exceed `cache.max_ttl_seconds`
- Do not display a stale cached record when the current API returns unavailable or not found
- Do not retain or redistribute photos, remarks, or other data beyond the agreement
- Do not add sold, expired, or withdrawn search filters without verifying display rights
- Recheck listing availability when a visitor submits an inquiry
- Do not scrape provider URLs or build an independent data resale feed
- Do not serve one site's data under an unapproved domain

## AI development instructions

- Do not remove or restyle attribution into illegible text to improve appearance
- Do not fabricate disclaimers, board logos, listing agents, or timestamps
- Do not add seed listings to a production search when the API is unavailable
- Do not replace the server API client with browser requests
- Do not expose private leads, team data, client records, or HomeThread collections without user authorization
- Do not turn the public inquiry endpoint into a generic API proxy
- Preserve `server-only`, origin validation, Redis rate limiting, and input bounds
- Use the current API contract rather than guessing provider field names

## Review before launch

- [ ] Actual approved board rules reviewed
- [ ] Cards and detail pages show required attribution
- [ ] Logos and disclosures readable at 375, 768, and 1440 pixels
- [ ] Missing logo or required attribution prevents display
- [ ] Removed listings are not publicly displayable
- [ ] Cache policy respects board maximums
- [ ] Share, print, maps, and structured data follow the same rules if added
- [ ] No API credentials in client bundles or network responses
- [ ] Inquiry test reaches the correct account and website
- [ ] Brokerage contact details and privacy notice complete
- [ ] Board approval or compliance review completed where required
