Protect sensitive records during merchant onboarding
Do not put the file in Prism's contact form or in an ordinary email just because someone asked. First write down who asked, what decision the file is for, the smallest record that answers that request, and the destination that requester's own instructions name. Prism's contact page tells you to leave out payment card details, passwords, and customer records. The PCI Security Standards Council's FAQ says unprotected primary account numbers must not be sent by email, instant message, SMS, or chat. Stripe's verification-document page says Stripe accepts those documents through the Dashboard and says not to send them by email. A different provider's destination is not Stripe's, and this page does not collect the records.
For: An owner or authorized representative preparing a processing conversation for a research-use-only peptide business who has been asked for business or identity records.
Updated 2026-09-21
An inquiry form is not a document channel
Prism's contact form asks for your name, email, an optional company, your role, and a message about the website, the research-only products, and the question. It says the team reviews the inquiry and follows up by email. It says a request does not book an appointment, purchase a service, or submit a processing application. On the form itself, the instruction is to leave out payment card details, passwords, and customer records.
That limit is the point of this page. The application you send a provider, and the records inside it, are a different job from describing the problem. This page does not check whether the application is consistent. It checks the channel. If a row would require you to paste a document, an account number, or a password into the worksheet, leave the row as a pointer to where the file is kept. Do not paste the file.
Verify the requester before you choose a destination
A document request names a person or a company, a purpose, and a place to send the file. Those three have to match. A message that says it is from your provider, but tells you to email a scan to an address you have never used inside that provider's account, is not yet a verified destination. Look for the request inside the provider account you already log in to, or in instructions on that provider's own site. Write the purpose in ordinary words, such as identity verification or a question about the legal entity. Do not add a purpose the request did not state.
Send the smallest record that answers the stated purpose. A request for the legal name does not need a customer list. A request for a formation document does not need a card number that happens to be in a bank download. If the file contains more than the request, do not invent a redaction method. Ask the requester how they want the extra information removed, and use the destination they document. This worksheet records that you asked. It does not store the image.
Card numbers have a narrower rule than ordinary business papers
The PCI Security Standards Council's FAQ number 1085, dated August 2025 on the page, answers whether unprotected primary account numbers can be sent by email, instant message, SMS, or chat. The answer on that page is no. It cites PCI DSS Requirement 4.2.2 for those end-user messaging technologies, whether the message is internal or crosses a public network, and Requirement 4.2.1 for strong cryptography when cardholder data is sent over open, public networks.
That FAQ is about primary account numbers, not about every PDF a processor might request. Do not treat it as a rule that formation documents can never be discussed by email. Do treat it as a rule against placing a card number in the inquiry form, in chat, or in an unprotected message. If a file you were asked for contains a card number, stop and use the channel the requester documents for that file. This page does not teach a homemade way to mask a card number.
Use the destination the requester publishes
Stripe's acceptable-verification-documents page says that, because the documents are sensitive, Stripe can only accept them when they are uploaded through the Dashboard, and it says not to send them by email. The upload path it names is Settings, then Business, then Account status. The same page says the account status screen is where that account can see what Stripe still needs, and that acceptable document types depend on the country and the request. It also says some country instructions call for specified numbers to be removed before upload. Follow the instruction for the country on that page. Do not reuse one country's instruction for another country, and do not email the scan to Prism.
If the requester is not Stripe, Stripe's Dashboard is not the destination. Write the destination only after you have opened that provider's current instructions. Until then the destination row stays blank. A blank is safer than a guessed portal.
After you send a file through the verified destination, keep a receipt that says what type of document went, the date, and the destination name. The receipt is not a second copy of the identity document. You do not need to attach the file to the consultation message. Prism's public form is still only the place to describe the question.
What you can close, and what you cannot
You can decide not to use the public form for records, which file answers the request you actually received, and whether the destination is the one in the provider's own instructions. You can tell Prism, in ordinary language, that a provider asked for documents and that you have not attached them.
You cannot decide from this page which documents a provider will eventually require, whether the copies you have will be accepted, or how a provider protects a file after it arrives. Stripe's page is Stripe's. The PCI FAQ is about unprotected primary account numbers in end-user messaging. Neither one is a checklist for every processor.
A Prism consultation can help you organize the processing question. Scope, fees, and terms are discussed before work. The provider decides what it will accept and whether an account is opened. The review is not a legal opinion or a certificate. What remains unknown is any request you have not matched to a published destination.
Document-channel worksheet
Record the request, not the document. Do not type a card number, a password, a government identifier, or a customer list. If a cell would contain the sensitive record itself, name the folder where you keep it instead. Worksheet entries are not submitted by this worksheet or saved by this site. Use only non-sensitive summaries; do not enter credentials, government identifiers, card or bank-account numbers, private receipt links, or customer details.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Document-channel worksheet. The last column is for temporary notes.
Check
Why it is part of the channel
Where to confirm it
Your note
Who asked, and where that request appeared
Why it is part of the channelA request that arrives only as an unexpected email is not yet the provider's own channel.
Where to confirm itThe provider account you already use, or the provider's current documentation. Leave blank if you cannot find it there.
The purpose they stated
Why it is part of the channelThe purpose limits the file. A broader upload is not a more complete answer.
Where to confirm itThe request text, with account numbers removed.
The smallest record that answers that purpose
Why it is part of the channelCustomer lists, passwords, and card numbers are not a substitute for the document that was named.
Where to confirm itYour own file index. Write the document type, not the document.
The destination that requester tells you to use
Why it is part of the channelStripe's verification page names the Dashboard and says not to email those documents. Another provider must name its own destination.
Where to confirm itThat provider's upload instructions. Leave blank until you have opened them.
Whether a card number would be included
Why it is part of the channelPCI SSC FAQ 1085 says unprotected primary account numbers are not to be sent by email, instant message, SMS, or chat.
Where to confirm itThe file itself, reviewed before sending. If the answer is yes, stop and ask the requester. Do not type the number here.
The receipt you kept after sending
Why it is part of the channelA later question should be answerable without placing the identity document in an inquiry form.
Where to confirm itYour sent record: document type, date, and destination name only.
These are temporary notes. Leaving or reloading this page may clear them. The consultation form does not include these entries.
Limits
A Prism consultation can help you organize the facts and discuss the website or processing question. The payment provider decides eligibility, pricing, reserves, and whether an account is opened or closed.
Do not attach identity documents, bank records, card numbers, passwords, or customer lists to the public consultation form.
Stripe's Dashboard instruction applies to Stripe verification documents. It is not a universal upload portal.
This worksheet is not a determination that your business is eligible for an account.
Prism contact — checked 2026-09-21. The form collects name, email, optional company, role, and a message about the website, products, and question. It says to leave out payment card details, passwords, and customer records. Follow-up is by email. A request does not book an appointment, purchase a service, or submit a processing application.
PCI SSC FAQ 1085 — checked 2026-09-21. Unprotected primary account numbers are not to be sent by email, instant message, SMS, or chat. The FAQ cites PCI DSS Requirements 4.2.2 and 4.2.1 and is dated August 2025 on the page.
Stripe acceptable verification documents — checked 2026-09-21. Stripe says verification documents are accepted through the Dashboard, at Settings, Business, Account status, and says not to send them by email. Required documents depend on the country and the request.
Prism solutions — checked 2026-09-21. A consultation can help organize a processing question. Scope, fees, and terms are discussed before work. The provider decides eligibility and what documents it wants.
Prism features — checked 2026-09-21. A review is informational. It is not a legal opinion or a compliance certification.
Request a consultation
Describe the business and this specific question. Prism follows up by email to discuss fit and scope. An inquiry is not a processing application or an approval.