Website representations

Check what your public inquiry form invites visitors to share

The invitation includes every field label, instruction, attachment prompt and follow-up message a visitor sees. For a first consultation, ask for the website, relevant products and a concise question, with the contact details needed for a reply. Remove prompts that invite card data, passwords, identity documents or customer records into an ordinary inquiry. If further records may be needed, explain that the recipient and an authorized sharing process must be confirmed first. Do not claim a secure upload portal exists unless it actually does.

For: A research-only merchant or website owner reviewing the information requested by a public consultation or support inquiry form.

Updated 2026-10-01

Review the invitation from the visitor’s position

Open the public page and record what it asks for before any submission. Include the introductory paragraph, each label, required-field wording, message-box guidance, any attachment control, and the text explaining what happens next. A message field described as a place to send all supporting evidence can invite sensitive records even when there is no dedicated document field.

Connect each requested item to the decision the first inquiry is supposed to enable. A website URL lets someone locate the public pages. A concise product description establishes the topic. A short account of the problem explains what help is being requested. None of those purposes requires a card number, a password, a bank statement or an identity scan. If a prompt’s purpose is unclear, record the uncertainty instead of expanding what the visitor must provide.

This review concerns the words and controls that solicit information. It does not establish how the form’s backend stores messages, which staff can access them or what protections apply. Claims about those behaviors need separate evidence from the system owner.

State a useful boundary beside the request

Prism’s recorded contact page provides a bounded inquiry model: name, email, optional company, role and a message about the website, products and question. It tells visitors to leave out payment card details, passwords and customer records. Its preparation guidance asks people to identify known information and what remains unknown. An inquiry can therefore say that a provider requested records without attaching those records or inventing their contents.

Use field-specific guidance where broad wording creates ambiguity. Ask for the public page affected and a short description of the issue; ask whether a provider request exists and what question remains open. If the request concerns a private payment link or account page, describe its purpose without pasting access tokens. If a required field cannot be answered truthfully, flag the field for correction rather than encouraging a guess.

The PCI Security Standards Council’s FAQ 1085 specifically says unprotected primary account numbers must not be sent by email, instant messaging, SMS or chat. That is a card-number rule, not a blanket statement about every business document. It supports a clear card-data boundary; it does not certify this form or establish that all other sensitive records can be collected here.

A later document request needs an actual route

If the public form asks for verification papers, a processing statement or an order export, first identify why that material is needed at this stage. For an initial consultation, the fact that the document exists, its general type and the unresolved question may be enough to define the discussion. Keep the underlying file with the person authorized to hold it until a specific request and destination are established.

Record the intended recipient and the documented process for any later exchange. When neither has been confirmed, the correct form instruction is to wait for sharing instructions. An unverified route remains unresolved. Do not add a fictional portal, describe a normal message box as a secure vault or imply that email follow-up is permission to send every record by reply.

An attachment control, if present, deserves a separate decision. If it has no justified role in the first inquiry, identify it for removal or restriction by the site owner. If the business believes it is necessary, the owner must establish the actual purpose and handling process before the page invites use. Wording alone cannot establish protection for the files.

Make the next-step promise match the inquiry

Check the submit label and nearby promise against what the request actually does. Prism’s contact facts describe email follow-up and say the request does not book an appointment, purchase a service or submit a processing application. A message should not promise those outcomes merely because it asks for extensive business information. On your own site, retain only the next steps your real process supports.

For a Prism website-review consultation, supply the public form URL, research-only products and the exact invitation you want reviewed. Summarize any concern without sending real visitor messages or their attachments. The consultation sets the pages, questions, scope, fees and terms before work. A provider still decides its document requirements and whether any response meets them.

After an authorized copy or field change, compare the visible invitation with the worksheet: the unnecessary request should be gone, the remaining fields should have a clear purpose, and any sharing route should be one that actually exists. That closes the public-copy finding. It does not establish that past submissions were handled correctly or that the backend has been assessed.

Inquiry information boundary

Use the actual public form and repeat these checks for each requested field or prompt. Record labels and short findings, never the sensitive material a visitor might submit. An unresolved purpose or sharing route is a reason to revise the invitation before asking for records.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Inquiry information boundary. The last column is for temporary notes.
Requested field or promptBusiness purpose to establishSensitive category to excludeAuthorized route or form correctionYour finding
Website and relevant pageLocate the public storefront or page being discussed.Private account URLs, payment-link access tokens and credentials.Request public URLs; ask for a description when the affected page is private.
Product descriptionIdentify the research-only catalog relevant to the question.Customer lists and private supplier or buyer files unrelated to the initial question.Request product types and public catalog links; leave further evidence to an agreed request.
Message or problem descriptionState what happened, what is known and which question remains unanswered.Card numbers, authentication codes, passwords and copied customer records.Place the exclusion beside the message field and ask for a concise summary with unknowns identified.
Document or attachment requestEstablish why the initial inquiry needs a file rather than its type and purpose.Identity scans, full bank details, payment records and order exports.Identify the authorized recipient and actual handling process; if unconfirmed, remove the invitation and request a summary.
Reply contact and roleReach the person making the inquiry and understand their relationship to the business.Identity documents or account credentials offered as proof of authority.Use contact details appropriate to the reply; confirm any later authority check through its own authorized process.
Follow-up and submission wordingDescribe the next action the business actually performs.An invitation to send sensitive files by ordinary reply.Match the stated process; do not promise a booking, application or secure portal without evidence.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • This is a review of the public invitation. It does not assess form storage, access controls, past submissions or compliance with a privacy or security standard.
  • PCI SSC FAQ 1085 addresses unprotected primary account numbers in messaging; it does not impose a universal ban on discussing ordinary business documents by email.
  • Keep identity documents, bank records, payment details, credentials and customer records out of the public consultation inquiry.

Sources

  • PCI SSC FAQ 1085 — checked 2026-09-21. Unprotected primary account numbers must not be sent by email, instant messaging, SMS or chat. The FAQ concerns card numbers rather than every type of business document.
  • Prism resources — checked 2026-09-21. Preparation guidance asks for public links, products, claims and provider feedback, identifies known records and unknowns, and keeps sensitive records out of the contact form.
  • Prism solutions — checked 2026-09-21. A consultation sets the pages and questions for review; scope, fees and terms are discussed before work. The provider decides whether a response meets its requirements.
  • Prism contact — checked 2026-09-21. The form requests name, email, optional company, role and a website/products/question message, excludes card details, passwords and customer records, and describes email follow-up rather than a booking, purchase or processing application.

Request a website review

Want a second look at your own storefront pages?