VendorLens

    Welcome offer: 50% off your first 3 months

    New customers only. Applied automatically at checkout.

    06d:06h:46m:23s
    See pricing

    Payments

    A trust center for payments, PSPs and acquirers

    Payments companies face the heaviest disclosure burden in B2B: PCI DSS, SOC 2, AML/KYC, cyber insurance, regulator correspondence. VendorLens gives you a single, audit-logged portal to release them under NDA per merchant, partner or scheme.

    Who's asking

    Acquirers, schemes, sponsor banks, large merchants and partner PSPs running risk reviews.

    Documents typically shared in Payments

    PCI DSS AOC + ROC summary
    SOC 2 Type 2 report
    AML / KYC policy
    Sanctions screening summary
    Pen test report
    Cyber insurance certificate
    Business continuity plan
    Vendor management policy

    What slows down deals today

    Acquirer onboarding asks for everything

    A self-serve trust portal moves most of the document collection out of email and into a controlled flow.

    Annual scheme reviews repeat

    Visa, Mastercard and sponsor banks run annual reviews. Same docs, different cover letter.

    PCI evidence is highly sensitive

    AOC and ROC content needs NDA, watermark and time-limited access — not email.

    The payments disclosure set, and who asks for what

    Payments companies field requests from several directions at once, and each direction wants a different slice. Sponsor banks and acquirers want the outsourcing pack: SOC 2, BCP and DR evidence, cyber insurance, information security and vendor management policies, AML/KYC and sanctions screening summaries. Schemes and larger merchants concentrate on card-data scope: the PCI DSS Attestation of Compliance, a ROC summary or SAQ as applicable, network segmentation evidence and the current penetration test. Partner PSPs and platforms usually sit between the two and want the DPA, subprocessor list and a security overview they can attach to their own review.

    Mapping documents to audiences up front is what makes a portal useful rather than another folder. Public layer: certificate, DPA, subprocessor list, security overview, redacted pen test summary. NDA layer: AOC and ROC content, full pen test report, regulator correspondence, detailed BCP test results.

    PCI evidence needs controlled release, not email

    AOC and ROC material describes exactly how cardholder data flows through your environment, which is precisely why it should never be a permanent attachment in a shared mailbox. Gate it behind an NDA request that issues a watermarked, expiring download to a named individual, and keep the audit trail: who requested it, when the NDA was accepted, when the file was viewed and downloaded. When an acquirer asks how you control distribution of PCI evidence, that log is the answer.

    Because compliance dates move, the file matters less than the pointer. One canonical URL per document means the annual AOC refresh reaches everyone who has your trust page, and stale copies stop circulating with last year's validity date on them.

    Annual scheme and sponsor reviews as a repeatable cycle

    Scheme and sponsor reviews land on a calendar, and the effort is dominated by re-collection rather than analysis. Treating the review pack as a maintained surface — documents with effective and last-reviewed dates, a standing set of security answers, a current subprocessor list — turns the annual exercise into a diff: what changed since last year, and what evidence proves it.

    The same rhythm applies to your own supply chain, which reviewers will ask about: the processors, hosting providers, KYC and fraud vendors in your flow should each have an exposure rating, a questionnaire on file, evidence and a decision with a next review date, so the answer to "when did you last assess this provider" is a record instead of a recollection.

    Frequently asked

    Can I host PCI evidence here?

    Yes — typically the AOC, ROC summary and SAQ. Mark them NDA-required so they only release after a signed NDA.

    Does VendorLens support multi-entity payments groups?

    Not within a single account — each account has one trust page and one custom domain. Groups with several regulated entities run a separate VendorLens account per entity.

    Ready for a payments trust portal?

    Free to start. Custom domain on Pro and Business.