PCI DSS · SAQ-A
self-assessment
Filed Sep 12 · valid 12 mo
The Vault
KYC, OFAC/sanctions screening, PCI DSS controls, and an immutable audit trail — operated by Pulse on every sub-merchant so adding payments never creates a compliance burden for your platform.
Compliance vault · Acme Coffee Co.
CompliantPCI DSS · SAQ-A
self-assessment
Filed Sep 12 · valid 12 mo
SOC 2 · Type II
audit · in progress
Q1 attestation
KYC · Owner ID
Smarty + ID.me
Re-screened daily
W-9 · ACH auth
Documenso · e-signed
Aug 04
OFAC · sanctions
Sovos · auto-screen
Last hit · 0
Audit log · 2yr
immutable storage
12.4M events
12.4M events captured · exportable to CSV / API · immutable storage
Why a built-in vault
Embedding payments means taking on sub-merchant compliance — KYC, sanctions screening, PCI controls, document management — unless your PayFac provider handles it for you. Pulse makes compliance continuous and invisible — pulled into onboarding, underwriting, and ongoing monitoring so the audit trail builds itself without your team lifting a finger.
What's inside
Pulse tracks SAQ status, vulnerability scans, and renewal deadlines across every merchant on your platform — no PCI burden lands on your engineering team.
Required documents are defined per merchant type and processor. Pulse auto-requests, versions, and stores every file so your team never chases paper.
Identity verification and OFAC screening run inline via Sovos and Smarty + ID.me at onboarding, then re-screen on a schedule so the audit trail stays current.
Every signature, document upload, decision, and status change is logged immutably. Exportable to CSV or piped via webhook for card-brand reviews.
Pulse watches every PCI renewal, license expiration, and document refresh across your merchant portfolio and routes alerts before deadlines hit.
AML/KYC summaries, document status, and incident logs available on demand. When a card brand or auditor asks, the export is one click — not a two-week scramble.
Coverage
How it works
At onboarding, Pulse runs KYC via Smarty + ID.me and OFAC screening via Sovos inline — before the first transaction clears.
Pulse requests, validates, and versions required documents per merchant type and processor via Documenso e-sign portals.
Sanctions re-screening, PCI SAQ tracking, and deadline watchers run automatically — your platform stays current without manual effort.
When a deadline approaches, a document expires, or a status changes, Pulse routes an alert to the right person before it becomes a violation.
Full event history, document trails, and decisions are exportable to CSV or via API — ready for card-brand reviews the moment they are requested.
Outcomes
Pulse operates KYC, OFAC screening, and PCI controls on your behalf — your engineers build features, not compliance tooling.
Centralized documentation and an immutable event log mean card-brand reviews and audits are answered with a single export, not weeks of digging.
Ongoing screening and deadline tracking catch compliance drift before it becomes a processor relationship problem.
Consistent compliance across every sub-merchant protects your sponsor bank relationship and processor agreements.
Who it's for
Related
Now onboarding software partners
We sell it, board it, underwrite it, and run it. You add a revenue line to your platform without adding headcount.
Built for vertical SaaS platforms ready to monetize payments.