Website representations

Review a report before publishing its private details

Compare the actual file with the claim beside its link. Identify the fields needed to connect that claim to the report, then flag unrelated personal, customer, payment or internal business information by category. Obtain an authorized publication copy whose omissions do not misrepresent the findings, and retain the unchanged original in restricted storage. If permission or a meaningful public copy is unresolved, hold publication and revise any claim that depends on the unavailable evidence.

For: A research-only merchant preparing a certificate of analysis or other product report for public access.

Updated 2026-10-01

Review the file against one stated claim

Begin with the exact product-page sentence and the document it cites. Identify the report reference, issuer, product or sample identifier, relevant batch or lot, dates, findings and qualifications that let a reader understand that sentence. Treat this as a comparison of your own records. A report's availability does not establish authenticity, analytical validity or a broader claim about the whole catalog.

Next, inspect the remaining material for information that has no role in that public explanation. Flag categories rather than copying the contents: private contact details, customer identifiers, purchasing information, payment data or internal correspondence. A field can have both evidentiary and privacy significance. Do not automatically strip every identifier or issuer detail; removing the information that ties the report to the product can make the public copy misleading or unusable.

Resolve publication authority before editing

Record who supplied the report, who owns or controls its release, and what permission you actually have. Possessing a supplier's file is not a reason to assume unrestricted publication authority. If the permission does not cover a public website or an edited copy, ask the owner or issuer for an approved version and retain the answer. A missing permission remains unresolved; the worksheet does not grant one.

Prefer a publication copy supplied or expressly approved by the responsible owner or issuer. Keep an internal description of the omitted field categories, the reason for each omission and the approval reference. Do not silently change measurements, units, dates, sample identity, conclusions or limiting statements. If a finding itself needs correction, obtain the issuer's correction and follow a version-replacement process instead of treating it as privacy editing.

Where a public copy cannot retain enough context to support the claim, narrow or remove the claim until suitable evidence is available. Do not leave an assurance that visitors can verify a finding when the linked version no longer contains the necessary context.

Keep the original and inspect the deliverable

Retain the unchanged original in storage limited to authorized people, and record its internal location without placing a download token or access credential in the worksheet. Give the approved public version a distinguishable reference and preserve its relationship to the original. A filename alone should not be the only record of which copy was authorized.

Before release, inspect the actual publication file, including any selectable text, document properties, comments or attachments that it contains. Do not treat a visual cover placed over private information as proof that the information was removed. Have the person preparing the file confirm the result using the document tools appropriate to that file type. This is a release check, not a prescribed redaction technology or a certification that a file contains no hidden information.

After publication, open the public link and verify that it delivers the approved copy and that the surrounding claim still fits. If a sensitive original was already public, stop serving that copy and record the affected locations and responsible owner. Replacing the main link does not establish that all old downloads or externally retained copies have disappeared. Assess any further response with the people responsible for the information involved.

Use the right boundary for a document discussion

PCI SSC FAQ 1085 states that unprotected primary account numbers must not be sent through email, instant messaging, SMS or chat. That is a specific rule about card numbers. It does not decide whether every name, address or business field in a laboratory report is publishable. The publication decisions in this worksheet are editorial controls; legal permissions and obligations need advice appropriate to the information and jurisdiction.

A Prism website-review consultation can start with the website, research-only product categories and a description of the document concern. Do not attach the sensitive original or copy its private fields into the public inquiry. Prism's published review covers product descriptions, claims, policies and business disclosures within an agreed scope; findings are informational, not certification. Scope, fees and terms are discussed before work, and the provider retains account decisions. The contact request leads to email follow-up and is not a booking, purchase or processing application.

Publication-copy review

Complete this for one real report before release. Use references and field categories, never the sensitive values themselves. A copy is ready for publication only when its authority, meaningful claim support and actual delivered version have been resolved. Preserve the original privately; this worksheet does not validate laboratory findings.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Publication-copy review. The last column is for temporary notes.
Release checkRecord to inspectHow to interpret itYour finding
Document ownerIssuer or owner and the recorded permission for website publication and any permitted editing.Unclear authority means release is unresolved, even if the supplier sent the file.
Claim-supported fieldsExact claim location and the report identifiers, findings and qualifications it needs.Retain enough authorized context for the claim to remain accurate and traceable.
Sensitive field categoryCategory and location of unrelated private information, without copying its value.Resolve each category with the responsible owner; privacy editing must not change the analytical meaning.
Approved public versionPublic-copy reference, approval record and description of authorized omissions.An altered draft is not an approved copy. A correction to a finding needs a separate issuer correction.
Original locationRestricted internal archive reference and the role authorized to retrieve the unchanged original.Preserves provenance without publishing the original or embedding access credentials.
Delivered-file inspectionActual public download, surrounding claim and dated inspection of its contents.Close the release check only for the version that visitors receive; flag any old exposed copies separately.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • This publication workflow does not authenticate a report, validate analytical results or establish legal permission to publish it.
  • Do not silently alter analytical findings, obscure limitations or present an edited copy as an unchanged original.
  • The PCI source addresses unprotected card account numbers in messaging. It is not a general privacy law or a redaction standard for laboratory reports.
  • Keep private originals, identity documents, card data, passwords and customer records out of worksheets and the public consultation form. A website review does not establish processing eligibility.

Sources

  • Prism features — checked 2026-09-28. An agreed website review can cover product descriptions, claims, policies and business disclosures. Findings are informational, not legal advice or certification, and do not guarantee approval or continued processing.
  • PCI SSC FAQ 1085 — checked 2026-09-21. Unprotected primary account numbers must not be sent through email, instant messaging, SMS or chat. This supports the card-data messaging boundary, not a general publication or report-redaction rule.
  • Prism solutions — checked 2026-09-21. Storefront review and provider website questions are published support areas; scope, fees and terms are discussed before work. Account eligibility remains the provider's decision.
  • Prism contact — checked 2026-09-21. The inquiry asks for website, products and question without payment-card details, passwords or customer records. Email follow-up does not make the request a booking, purchase or processing application.

Request a website review

Want a second look at your own storefront pages?