Skip to content
Coverwright
For online and retail stores that take cards

The security documentation your payment processor and insurer both want

Card payments bring PCI DSS obligations most small retailers have never seen written down, on top of what a cyber insurance renewal now asks for. What each actually requires, and how to produce the paperwork without a security team.

Usually a payment processor’s annual self-assessment questionnaire (SAQ), a cyber insurance renewal, or a chargeback dispute that asks how card data is protected.

5
documents
82
clauses
6
gaps flagged

What the engine actually produced for one real business of this kind — including the gaps, which it states with a remediation clause rather than leaving out.

What tends to be true of firms like yours.

PCI DSS applies the moment you take a card

Accepting card payments carries obligations from the card brands, administered through your payment provider or acquiring bank — an annual self-assessment questionnaire matched to how you accept cards, and in some cases a quarterly external scan. Using a payment provider narrows which questionnaire applies; it does not remove the obligation.

A hosted checkout doesn’t cover everything

Routing payment through a processor keeps card numbers off your own servers, but the checkout page itself — and everything around it — stays your responsibility even when the payment is processed elsewhere. Your documents state what is outsourced and what you still own, so a reviewer can see the actual boundary.

Admin access is the highest-value target here

For an online store, the storefront and payment-dashboard logins are worth more to an attacker than any single card number. Multi-factor authentication and a password manager on those accounts are the two controls worth getting right first — your documents record honestly which ones are and aren’t in place.

Reusable across your processor and your insurer

The same written program answers your processor’s SAQ questions and your cyber insurance renewal — re-answer what changed a year later and regenerate, rather than filling out each form from a blank page.

Where this stops

Whether your PCI DSS obligations call for a particular self-assessment questionnaire, or something beyond it, depends on transaction volume and your processor’s own determination — that call sits with your processor and your counsel. Coverwright produces the written policies a merchant is asked to hold; holding them is not the same as PCI DSS compliance or certification, and your documents say so.

Worth reading first

Before you decide anything.

See your own set before you pay.

Answer 21 plain-English questions — about ten minutes — and read the first section of your real generated program before deciding. From $199, one time, renewed for $99 a year.

No account needed to see your documents · no sales call, ever