Check what your public inquiry form invites visitors to share
The invitation includes every field label, instruction, attachment prompt and follow-up message a visitor sees. For a first consultation, ask for the website, relevant products and a concise question, with the contact details needed for a reply. Remove prompts that invite card data, passwords, identity documents or customer records into an ordinary inquiry. If further records may be needed, explain that the recipient and an authorized sharing process must be confirmed first. Do not claim a secure upload portal exists unless it actually does.
For: A research-only merchant or website owner reviewing the information requested by a public consultation or support inquiry form.
Open the public page and record what it asks for before any submission. Include the introductory paragraph, each label, required-field wording, message-box guidance, any attachment control, and the text explaining what happens next. A message field described as a place to send all supporting evidence can invite sensitive records even when there is no dedicated document field.
Connect each requested item to the decision the first inquiry is supposed to enable. A website URL lets someone locate the public pages. A concise product description establishes the topic. A short account of the problem explains what help is being requested. None of those purposes requires a card number, a password, a bank statement or an identity scan. If a prompt’s purpose is unclear, record the uncertainty instead of expanding what the visitor must provide.
This review concerns the words and controls that solicit information. It does not establish how the form’s backend stores messages, which staff can access them or what protections apply. Claims about those behaviors need separate evidence from the system owner.
State a useful boundary beside the request
Prism’s recorded contact page provides a bounded inquiry model: name, email, optional company, role and a message about the website, products and question. It tells visitors to leave out payment card details, passwords and customer records. Its preparation guidance asks people to identify known information and what remains unknown. An inquiry can therefore say that a provider requested records without attaching those records or inventing their contents.
Use field-specific guidance where broad wording creates ambiguity. Ask for the public page affected and a short description of the issue; ask whether a provider request exists and what question remains open. If the request concerns a private payment link or account page, describe its purpose without pasting access tokens. If a required field cannot be answered truthfully, flag the field for correction rather than encouraging a guess.
The PCI Security Standards Council’s FAQ 1085 specifically says unprotected primary account numbers must not be sent by email, instant messaging, SMS or chat. That is a card-number rule, not a blanket statement about every business document. It supports a clear card-data boundary; it does not certify this form or establish that all other sensitive records can be collected here.
A later document request needs an actual route
If the public form asks for verification papers, a processing statement or an order export, first identify why that material is needed at this stage. For an initial consultation, the fact that the document exists, its general type and the unresolved question may be enough to define the discussion. Keep the underlying file with the person authorized to hold it until a specific request and destination are established.
Record the intended recipient and the documented process for any later exchange. When neither has been confirmed, the correct form instruction is to wait for sharing instructions. An unverified route remains unresolved. Do not add a fictional portal, describe a normal message box as a secure vault or imply that email follow-up is permission to send every record by reply.
An attachment control, if present, deserves a separate decision. If it has no justified role in the first inquiry, identify it for removal or restriction by the site owner. If the business believes it is necessary, the owner must establish the actual purpose and handling process before the page invites use. Wording alone cannot establish protection for the files.
Make the next-step promise match the inquiry
Check the submit label and nearby promise against what the request actually does. Prism’s contact facts describe email follow-up and say the request does not book an appointment, purchase a service or submit a processing application. A message should not promise those outcomes merely because it asks for extensive business information. On your own site, retain only the next steps your real process supports.
For a Prism website-review consultation, supply the public form URL, research-only products and the exact invitation you want reviewed. Summarize any concern without sending real visitor messages or their attachments. The consultation sets the pages, questions, scope, fees and terms before work. A provider still decides its document requirements and whether any response meets them.
After an authorized copy or field change, compare the visible invitation with the worksheet: the unnecessary request should be gone, the remaining fields should have a clear purpose, and any sharing route should be one that actually exists. That closes the public-copy finding. It does not establish that past submissions were handled correctly or that the backend has been assessed.
Inquiry information boundary
Use the actual public form and repeat these checks for each requested field or prompt. Record labels and short findings, never the sensitive material a visitor might submit. An unresolved purpose or sharing route is a reason to revise the invitation before asking for records.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Inquiry information boundary. The last column is for temporary notes.
Requested field or prompt
Business purpose to establish
Sensitive category to exclude
Authorized route or form correction
Your finding
Website and relevant page
Business purpose to establishLocate the public storefront or page being discussed.
Sensitive category to excludePrivate account URLs, payment-link access tokens and credentials.
Authorized route or form correctionRequest public URLs; ask for a description when the affected page is private.
Product description
Business purpose to establishIdentify the research-only catalog relevant to the question.
Sensitive category to excludeCustomer lists and private supplier or buyer files unrelated to the initial question.
Authorized route or form correctionRequest product types and public catalog links; leave further evidence to an agreed request.
Message or problem description
Business purpose to establishState what happened, what is known and which question remains unanswered.
Sensitive category to excludeCard numbers, authentication codes, passwords and copied customer records.
Authorized route or form correctionPlace the exclusion beside the message field and ask for a concise summary with unknowns identified.
Document or attachment request
Business purpose to establishEstablish why the initial inquiry needs a file rather than its type and purpose.
Sensitive category to excludeIdentity scans, full bank details, payment records and order exports.
Authorized route or form correctionIdentify the authorized recipient and actual handling process; if unconfirmed, remove the invitation and request a summary.
Reply contact and role
Business purpose to establishReach the person making the inquiry and understand their relationship to the business.
Sensitive category to excludeIdentity documents or account credentials offered as proof of authority.
Authorized route or form correctionUse contact details appropriate to the reply; confirm any later authority check through its own authorized process.
Follow-up and submission wording
Business purpose to establishDescribe the next action the business actually performs.
Sensitive category to excludeAn invitation to send sensitive files by ordinary reply.
Authorized route or form correctionMatch the stated process; do not promise a booking, application or secure portal without evidence.
These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.
Limits
This is a review of the public invitation. It does not assess form storage, access controls, past submissions or compliance with a privacy or security standard.
PCI SSC FAQ 1085 addresses unprotected primary account numbers in messaging; it does not impose a universal ban on discussing ordinary business documents by email.
Keep identity documents, bank records, payment details, credentials and customer records out of the public consultation inquiry.
PCI SSC FAQ 1085 — checked 2026-09-21. Unprotected primary account numbers must not be sent by email, instant messaging, SMS or chat. The FAQ concerns card numbers rather than every type of business document.
Prism resources — checked 2026-09-21. Preparation guidance asks for public links, products, claims and provider feedback, identifies known records and unknowns, and keeps sensitive records out of the contact form.
Prism solutions — checked 2026-09-21. A consultation sets the pages and questions for review; scope, fees and terms are discussed before work. The provider decides whether a response meets its requirements.
Prism contact — checked 2026-09-21. The form requests name, email, optional company, role and a website/products/question message, excludes card details, passwords and customer records, and describes email follow-up rather than a booking, purchase or processing application.