PCI DSS controls
Pulse tracks SAQ status, vulnerability scans, and renewal deadlines across every merchant on your platform — no PCI burden lands on your engineering team.
The Vault
KYC, OFAC/sanctions screening, PCI DSS controls, and an immutable audit trail — operated by Pulse on every sub-merchant so adding payments never creates a compliance burden for your platform.
Acme Coffee Co. · MID 482910
KYC
Smarty + ID.me · direct API
Bank verification
Plaid · direct API
OFAC screen
Sovos · direct API
PCI scan
SAQ-A controls · direct API
1099 generated
Sovos · direct API
Continuous screening · re-runs on schedule · every event logged immutably & exportable
Why a built-in vault
Embedding payments means taking on sub-merchant compliance — KYC, sanctions screening, PCI controls, document management — unless your PayFac provider handles it for you. Pulse makes compliance continuous and invisible — pulled into onboarding, underwriting, and ongoing monitoring so the audit trail builds itself without your team lifting a finger.
What's inside
Pulse tracks SAQ status, vulnerability scans, and renewal deadlines across every merchant on your platform — no PCI burden lands on your engineering team.
Required documents are defined per merchant type and processor. Pulse auto-requests, versions, and stores every file so your team never chases paper.
Identity verification and OFAC screening run inline via Sovos and Smarty + ID.me at onboarding, then re-screen on a schedule so the audit trail stays current.
Every signature, document upload, decision, and status change is logged immutably. Exportable to CSV or piped via webhook for card-brand reviews.
Pulse watches every PCI renewal, license expiration, and document refresh across your merchant portfolio and routes alerts before deadlines hit.
AML/KYC summaries, document status, and incident logs available on demand. When a card brand or auditor asks, the export is one click — not a two-week scramble.
The evidence binder
Documents file themselves into a per-merchant binder while an append-only, hash-chained event log records who did what and when — so a card-brand review is an export, not an excavation.
Evidence binder · Acme Coffee Co.
Sealed · append-onlyDocuments on file
Immutable event log
OFAC re-screen — clear
0x9f3a…c1Sovos · system · Nov 1 · 02:14
PCI SAQ-A attested
0x4b7e…2dSarah Kestler · Oct 28 · 09:41
Merchant agreement e-signed
0x1c08…a7Documenso · Acme Coffee Co. · Oct 12 · 14:08
KYC verified — boarded
0xe27d…90Smarty + ID.me · Oct 12 · 13:59
Coverage
Pulse maps each sub-merchant to the right SAQ level, watches quarterly scans, and surfaces renewals long before they lapse — so SAQ-A coverage for Acme Coffee Co. stays current without anyone on your team owning a PCI checklist.
Every re-screen result appended to the immutable log
OFAC screening via Sovos runs at boarding and then re-runs on a schedule for the life of the account. Every pass lands in the immutable log, so your audit trail reflects today's reality — not a one-time check from boarding day.
How it works
At onboarding, Pulse runs KYC via Smarty + ID.me and OFAC screening via Sovos inline — before the first transaction clears.
Pulse requests, validates, and versions required documents per merchant type and processor via Documenso e-sign portals.
Sanctions re-screening, PCI SAQ tracking, and deadline watchers run automatically — your platform stays current without manual effort.
When a deadline approaches, a document expires, or a status changes, Pulse routes an alert to the right person before it becomes a violation.
Full event history, document trails, and decisions are exportable to CSV or via API — ready for card-brand reviews the moment they are requested.
Outcomes
Pulse operates KYC, OFAC screening, and PCI controls on your behalf — your engineers build features, not compliance tooling.
Centralized documentation and an immutable event log mean card-brand reviews and audits are answered with a single export, not weeks of digging.
Ongoing screening and deadline tracking catch compliance drift before it becomes a processor relationship problem.
Consistent compliance across every sub-merchant protects your sponsor bank relationship and processor agreements.
0 min
Boarded to Fiserv + NMI, fully screened
0%
Sub-merchants under continuous screening
0
Click to a card-brand-ready export
0
Compliance engineers you have to hire
Who it's for
Related
Now onboarding software partners
We sell it, board it, underwrite it, and run it. You add a revenue line to your platform without adding headcount.
Built for vertical SaaS platforms ready to monetize payments.