For Brokers Publications Sign In

Funder certification guidelines

Join, then complete certification through our self-guided member portal. No specific software or tools required. Guidelines public for transparency.

Join
Program Overview

Purpose

To confirm safeguards are in place to reduce the risk of unauthorized sharing of merchant data.

Program Overview

How It Works

  • Submit request to join.
  • You're added to the public directory as an Applicant.
  • Receive access to the member portal: complete certification, upload evidence, track progress, message our team, connect with other members, and access program resources.
  • Announce your commitment to your network — social media, newsletters, press. Contact us to collaborate.
  • Upload evidence within 3 months — screenshots, screen recordings, documents.
  • Extensions and support available.
  • Certification — directory updated, digital badge, program announcement.
Requirement 01

Personnel Controls

Organizational policies to limit risk at the human layer.

Background Checks

Documentation confirming background checks are conducted for personnel with access to sensitive data.

Example pathways
  • Blank copy of your background check authorization form.
  • Screenshot from your provider showing active account or recent checks, with PII redacted.

Password Policy

A documented password policy or enforcement settings. At minimum, passwords should meet a required length and complexity standard.

Example pathways
  • Copy of password policy or screenshot of admin panel showing enforcement settings.

Workstation & Screen Security

A policy or technical setting requiring workstations to lock when unattended.

Example pathways
  • Screenshot of auto-lock timeout setting enabled in device management or admin panel.

Off-Boarding Process

A process for immediately revoking system access when employees leave or change roles.

Example pathways
  • Offboarding checklist or policy.
Requirement 02

Email Security

If brokers or merchants email documents

Multi-Factor Authentication

MFA must be enabled on email accounts used to receive or handle submissions.

Example pathways
  • Screenshot of MFA setting enabled in your email admin panel.
  • Screen recording of a login showing MFA prompt triggering and being completed.

Submissions Email Inbox

Do brokers send documents via email? How do you prevent misuse?

Example pathways
  • N/A. Brokers provide documents via API, form upload, portal, or equivalent.
  • Attachments automatically route to CRM or equivalent (no manual inbox handling).
  • Restrict email attachment downloads — check your email admin panel.
  • Use managed devices — block USB access and access to personal email accounts.
  • Email DLP controls — monitor, log, and audit events such as outbound emails to external domains with attachments.
  • Aquamark's inbound email tool — watermark attachments before staff gain access.
Sample/test data is acceptable in any screen recordings, or redact PII.

Direct Sales Team

For funders with direct sales teams that receive merchant documents by email

Example pathways
  • Attachments automatically route to CRM or equivalent (no manual inbox handling).
  • Restrict email attachment downloads — check your email admin panel.
  • Use managed devices — block USB access and access to personal email accounts.
  • Email DLP controls — monitor, log, and audit events such as outbound emails to external domains with attachments.
  • Aquamark's inbound email tool — watermark attachments before staff gain access.
Sample/test data is acceptable in any screen recordings, or redact PII.
Requirement 03

CRMs or Equivalent Systems

System-level controls to limit the ability to extract data and documents.

Multi-Factor Authentication

MFA must be enabled on CRM, portal, or equivalent system accounts.

Example pathways
  • Screenshot of MFA setting enabled in your CRM admin panel.
  • Screen recording of a login showing MFA prompt triggering and being completed.

Role-Based Access

Personnel should only be able to access accounts and information required for their role.

Example pathways
  • Screenshot of your CRM's role list showing that separate roles exist.
  • Screen recording logging in as two different roles showing information visible to one role and restricted for another.
Sample/test data is acceptable in any screen recordings, or redact PII.

Document Access Controls

If documents are accessible within your CRM, portal, or equivalent system, at least one document safeguard is required.

Example pathways
  • View-only access, where documents cannot be downloaded.
  • Document watermarking to deter sharing.
  • If downloadable and unwatermarked, controls that stop it from leaving the company — e.g. DLP rules blocking outbound attachments, blocked personal cloud storage and personal email, blocked USB.
Sample/test data is acceptable in any screen recordings, or redact PII.
Requirement 04

Document Storage

Controls on secondary storage locations outside your main systems.

Storage Safeguards

If documents are stored in Google Drive, Dropbox, OneDrive, etc., at least one safeguard is required.

Example pathways
  • View-only access, where documents cannot be downloaded.
  • Document watermarking to deter sharing.
  • If downloadable and unwatermarked, controls that stop it from leaving the company — e.g. DLP rules blocking outbound attachments, blocked personal cloud storage and personal email, blocked USB.
Sample/test data is acceptable in any screen recordings, or redact PII.
Requirement 05

Outsourcing

Safeguards for third-party access to merchant documents (e.g. BPO).

Third-Party Safeguards

If third-party personnel (e.g. BPO, onshore or offshore) have access to submission packages, at least one safeguard is required.

Example pathways
  • View-only access, where third-party personnel cannot download files.
  • Document watermarking to deter sharing.
  • If downloadable and unwatermarked, controls that stop it from leaving the company — e.g. DLP rules blocking outbound attachments, blocked personal cloud storage and personal email, blocked USB.
Sample/test data is acceptable in any screen recordings, or redact PII.
Program Notice

Final Review

Evidence assessment, public records review, and continued listing.

Please allow up to five business days for final review, including assessment of your uploaded evidence, business registration verification, and limited public records checks.