The Vault

Compliance run for you, not by you.

KYC, OFAC/sanctions screening, PCI DSS controls, and an immutable audit trail — operated by Pulse on every sub-merchant so adding payments never creates a compliance burden for your platform.

Acme Coffee Co. · MID 482910

Pending KYC
  • KYC

    Smarty + ID.me · direct API

    passed
  • Bank verification

    Plaid · direct API

    queued
  • OFAC screen

    Sovos · direct API

    queued
  • PCI scan

    SAQ-A controls · direct API

    queued
  • 1099 generated

    Sovos · direct API

    queued

Continuous screening · re-runs on schedule · every event logged immutably & exportable

Why a built-in vault

Payments without the compliance weight.

Embedding payments means taking on sub-merchant compliance — KYC, sanctions screening, PCI controls, document management — unless your PayFac provider handles it for you. Pulse makes compliance continuous and invisible — pulled into onboarding, underwriting, and ongoing monitoring so the audit trail builds itself without your team lifting a finger.

What's inside

Built for the regulated world your platform operates in.

PCI DSS controls

Pulse tracks SAQ status, vulnerability scans, and renewal deadlines across every merchant on your platform — no PCI burden lands on your engineering team.

Document collection

Required documents are defined per merchant type and processor. Pulse auto-requests, versions, and stores every file so your team never chases paper.

KYC + sanctions screening

Identity verification and OFAC screening run inline via Sovos and Smarty + ID.me at onboarding, then re-screen on a schedule so the audit trail stays current.

Immutable audit trail

Every signature, document upload, decision, and status change is logged immutably. Exportable to CSV or piped via webhook for card-brand reviews.

Renewal & deadline alerts

Pulse watches every PCI renewal, license expiration, and document refresh across your merchant portfolio and routes alerts before deadlines hit.

Regulator-ready reporting

AML/KYC summaries, document status, and incident logs available on demand. When a card brand or auditor asks, the export is one click — not a two-week scramble.

The evidence binder

Every document and decision, sealed and exportable.

Documents file themselves into a per-merchant binder while an append-only, hash-chained event log records who did what and when — so a card-brand review is an export, not an excavation.

Evidence binder · Acme Coffee Co.

Sealed · append-only

Documents on file

  • KYC + identityVerified
  • OFAC screeningClear
  • PCI SAQ-AOn file
  • Business licenseTracked
  • Signed agreements3 docs

Immutable event log

  1. OFAC re-screen — clear

    0x9f3a…c1

    Sovos · system · Nov 1 · 02:14

  2. PCI SAQ-A attested

    0x4b7e…2d

    Sarah Kestler · Oct 28 · 09:41

  3. Merchant agreement e-signed

    0x1c08…a7

    Documenso · Acme Coffee Co. · Oct 12 · 14:08

  4. KYC verified — boarded

    0xe27d…90

    Smarty + ID.me · Oct 12 · 13:59

Hash-chained · tamper-evidentExport for review

Coverage

What Pulse operates on your behalf.

PCI DSS Self-Assessment Questionnaires
Quarterly vulnerability scan monitoring
AML / KYC verification status
OFAC sanctions screening (Sovos)
Business license + registration tracking
Insurance certificate management
Processor-specific compliance rules
Annual renewal reminders
Exception tracking + resolution
PCI DSS · SAQ-A3 / 4 current
  • SAQ-A questionnaire attested
  • Quarterly vulnerability scan
  • Cardholder data scope review
  • Annual renewal · due in 41 days

PCI controls tracked, not chased.

Pulse maps each sub-merchant to the right SAQ level, watches quarterly scans, and surfaces renewals long before they lapse — so SAQ-A coverage for Acme Coffee Co. stays current without anyone on your team owning a PCI checklist.

OFAC re-screen · SovosMID 482910
Boarding
30d
60d
90d

Every re-screen result appended to the immutable log

Sanctions screening that never goes stale.

OFAC screening via Sovos runs at boarding and then re-runs on a schedule for the life of the account. Every pass lands in the immutable log, so your audit trail reflects today's reality — not a one-time check from boarding day.

How it works

From boarding to audit export — fully automated.

  1. Step 1

    Merchant boards

    At onboarding, Pulse runs KYC via Smarty + ID.me and OFAC screening via Sovos inline — before the first transaction clears.

  2. Step 2

    Documents collected

    Pulse requests, validates, and versions required documents per merchant type and processor via Documenso e-sign portals.

  3. Step 3

    Continuous monitoring

    Sanctions re-screening, PCI SAQ tracking, and deadline watchers run automatically — your platform stays current without manual effort.

  4. Step 4

    Alert + resolve

    When a deadline approaches, a document expires, or a status changes, Pulse routes an alert to the right person before it becomes a violation.

  5. Step 5

    Export on demand

    Full event history, document trails, and decisions are exportable to CSV or via API — ready for card-brand reviews the moment they are requested.

Outcomes

Your platform ships faster. Pulse handles the rest.

Ship payments without compliance overhead

Pulse operates KYC, OFAC screening, and PCI controls on your behalf — your engineers build features, not compliance tooling.

Audits become exports

Centralized documentation and an immutable event log mean card-brand reviews and audits are answered with a single export, not weeks of digging.

Continuous coverage, not annual fire drills

Ongoing screening and deadline tracking catch compliance drift before it becomes a processor relationship problem.

Protect your platform standing

Consistent compliance across every sub-merchant protects your sponsor bank relationship and processor agreements.

0 min

Boarded to Fiserv + NMI, fully screened

0%

Sub-merchants under continuous screening

0

Click to a card-brand-ready export

0

Compliance engineers you have to hire

Who it's for

Built for platforms that can't afford a compliance team.

  • Vertical SaaS platforms embedding payments without inheriting a compliance team
  • ISVs whose sponsor bank or processor requires auditable KYC and OFAC documentation
  • Product teams that need PCI DSS coverage without restructuring their infrastructure
  • Operations teams managing document-heavy merchant portfolios at scale
  • Founders who want card-brand-ready exports on demand without adding compliance headcount

Now onboarding software partners

Turn your software into a payments business.

We sell it, board it, underwrite it, and run it. You add a revenue line to your platform without adding headcount.

Built for vertical SaaS platforms ready to monetize payments.

PCI DSS compliantSOC 2 Type II99.9% uptimeMulti-processor