Program Overview
Purpose
To confirm safeguards are in place to reduce the risk of unauthorized sharing of merchant data.
Program Overview
How It Works
- Submit request to join.
- You're added to the public directory as an Applicant.
- Receive access to the member portal: complete certification, upload evidence, track progress, message our team, connect with other members, and access program resources.
- Announce your commitment to your network — social media, newsletters, press. Contact us to collaborate.
- Upload evidence within 3 months — screenshots, screen recordings, documents.
- Extensions and support available.
- Certification — directory updated, digital badge, program announcement.
Requirement 01
Personnel Controls
Organizational policies to limit risk at the human layer.
Background Checks
Documentation confirming background checks are conducted for personnel with access to sensitive data.
- Blank copy of your background check authorization form.
- Screenshot from your provider showing active account or recent checks, with PII redacted.
Password Policy
A documented password policy or enforcement settings. At minimum, passwords should meet a required length and complexity standard.
- Copy of password policy or screenshot of admin panel showing enforcement settings.
Workstation & Screen Security
A policy or technical setting requiring workstations to lock when unattended.
- Screenshot of auto-lock timeout setting enabled in device management or admin panel.
Off-Boarding Process
A process for immediately revoking system access when employees leave or change roles.
- Offboarding checklist or policy.
Requirement 02
Email Security
If brokers or merchants email documents
Multi-Factor Authentication
MFA must be enabled on email accounts used to receive or handle submissions.
- Screenshot of MFA setting enabled in your email admin panel.
- Screen recording of a login showing MFA prompt triggering and being completed.
Submissions Email Inbox
Do brokers send documents via email? How do you prevent misuse?
- N/A. Brokers provide documents via API, form upload, portal, or equivalent.
- Attachments automatically route to CRM or equivalent (no manual inbox handling).
- Restrict email attachment downloads — check your email admin panel.
- Use managed devices — block USB access and access to personal email accounts.
- Email DLP controls — monitor, log, and audit events such as outbound emails to external domains with attachments.
- Aquamark's inbound email tool — watermark attachments before staff gain access.
Direct Sales Team
For funders with direct sales teams that receive merchant documents by email
- Attachments automatically route to CRM or equivalent (no manual inbox handling).
- Restrict email attachment downloads — check your email admin panel.
- Use managed devices — block USB access and access to personal email accounts.
- Email DLP controls — monitor, log, and audit events such as outbound emails to external domains with attachments.
- Aquamark's inbound email tool — watermark attachments before staff gain access.
Requirement 03
CRMs or Equivalent Systems
System-level controls to limit the ability to extract data and documents.
Multi-Factor Authentication
MFA must be enabled on CRM, portal, or equivalent system accounts.
- Screenshot of MFA setting enabled in your CRM admin panel.
- Screen recording of a login showing MFA prompt triggering and being completed.
Role-Based Access
Personnel should only be able to access accounts and information required for their role.
- Screenshot of your CRM's role list showing that separate roles exist.
- Screen recording logging in as two different roles showing information visible to one role and restricted for another.
Document Access Controls
If documents are accessible within your CRM, portal, or equivalent system, at least one document safeguard is required.
- View-only access, where documents cannot be downloaded.
- Document watermarking to deter sharing.
- If downloadable and unwatermarked, controls that stop it from leaving the company — e.g. DLP rules blocking outbound attachments, blocked personal cloud storage and personal email, blocked USB.
Requirement 04
Document Storage
Controls on secondary storage locations outside your main systems.
Storage Safeguards
If documents are stored in Google Drive, Dropbox, OneDrive, etc., at least one safeguard is required.
- View-only access, where documents cannot be downloaded.
- Document watermarking to deter sharing.
- If downloadable and unwatermarked, controls that stop it from leaving the company — e.g. DLP rules blocking outbound attachments, blocked personal cloud storage and personal email, blocked USB.
Requirement 05
Outsourcing
Safeguards for third-party access to merchant documents (e.g. BPO).
Third-Party Safeguards
If third-party personnel (e.g. BPO, onshore or offshore) have access to submission packages, at least one safeguard is required.
- View-only access, where third-party personnel cannot download files.
- Document watermarking to deter sharing.
- If downloadable and unwatermarked, controls that stop it from leaving the company — e.g. DLP rules blocking outbound attachments, blocked personal cloud storage and personal email, blocked USB.
Program Notice
Final Review
Evidence assessment, public records review, and continued listing.
Please allow up to five business days for final review, including assessment of your uploaded evidence, business registration verification, and limited public records checks.