Nestack Agent Care
Industries / Retail & E-commerce / Attestation agent

Retail AI agent · PCI attestation

PCI Attestation Evidence AI Agent

Read the acceptance channels back to the tier they imply, hold the evidence and its currency behind each requirement, and put the open gaps in front of the officer before they sign.

4–6 weeksTypical delivery
Your stackDeployment
Before signingOfficer signs
Agent CareAfter launch

What this agent does

Works the evidence, never the attestation

In
01

A payment page changes, and the change is logged against the acceptance channel it sits on and the tier that implies.

02

A channel is inventoried with what it sends, where it sends it and which systems touch it.

Reason
03

An iframe stays an iframe: FAQ 1588 of 28 February 2025 holds the processor route to embedded forms.

04

A processor confirmation is filed, and the solution it names is matched to the page as deployed.

05

A requirement is answered, and the evidence and the date it was gathered ride with the answer.

Decide
06

A quarterly ASV scan lands, and the failures and the rescans are kept too.

07

An attestation falls due on the date your acquirer set; in Nevada NRS 603A.215 also makes it a duty.

Out
08

A gap stays open, and it is carried on the pack as an open gap rather than closed by inference.

09

Execute write actions only inside the approval boundaries agreed during implementation.

Product statement

The agent assembles the pack; a named executive officer signs. It never attests, never determines compliance, and never confirms the scope boundary.

Example workflow

One attestation year, channel to signature

AgentHuman
1Acceptance channels receivedPayment stack, gateway config, checkout release notes or scope inventory
2Evidence gatheredRequirement evidence, scans, tests, third-party AOCs and the rationale behind each entry
3Pack draftedTier position, per-requirement evidence, open gaps and confidence
4Controls appliedEvidence-binding checks, eligibility-criterion checks, currency checks and confidence threshold
No human action required

Stages 1 to 4 run unaided, and nothing is attested at any of them — the agent is assembling, and the officer's lane opens at the confidence gate.

5DecisionBranches at the confidence threshold
High confidence

Goes to the executive officer to review.

Low confidence

Adds a QSA read first.

Officer approval

The pack is held with its open gaps, its evidence dates and the confidence.

Approve · Amend · Send to QSA
Approved — released to sign
6Compliance records updatedOnly where write access and approval policy allow it
7Outcome evaluatedEvidence coverage, gaps closed, acquirer acceptance and post-submission queries
Amendments

Officer amendments are counted in the evaluation.

What should not run autonomously

Human approval stays in control

Outside the boundary — human approval required8 items
Signing the attestation of compliance.
Determining that the entity is compliant.
Confirming the cardholder data environment scope.
Deciding which questionnaire the merchant may use.
Automation boundaryAgent acts unaided
Map acceptance channels to the criteria each questionnaire sets.
Carry each requirement with the evidence and date behind it.
Track scan, penetration-test and third-party AOC currency.
Report the requirements still open, and what each one is still missing.
The officer signs. After a breach, Washington's shield needs an assessment under a year old.
Marking a requirement not applicable.
Accepting a compensating control as adequate.
Submitting the pack to the acquirer.
Changes to tier, scope or approval rules.

Example output

One requirement, annotated

What the agent records is attached to the evidence it came from.

Attestation output · single requirementIllustrative example
Requirement
What the evidence shows
Currency
Source on file
Confidence
Disposition
PCI DSS v4.0.1 · 11.3.2
Quarterly ASV scan passing; the failing scan it replaced and the rescan are both on file
Within the quarter
ASV scan report
88%
Held for the executive officer
As receivedTaken from the scan reports and the change record as filed — nothing on this side is asserted by the agent.
Evidence used ASV scan report Rescan and remediation Change-record entry
Why this is heldThe officer is promising controls will be maintained, not only that they were.
ActionApproveAmendSend to QSA
What the score decidesBelow the configured threshold the pack adds a QSA read before it reaches the officer.

Value

Where AI adds value

The same four claims, placed at the point in the workflow where each one applies.

Where the value landsValue 01 – 04
Every acceptance channelFrom the payment stack
03Assembly

Build the pack from the evidence

Draw on the scans, tests, AOCs and change records on file. The Council's note of 30 January 2025 replaced SAQ A Requirements 6.4.3, 11.6.1 and 12.3.1 with an eligibility criterion, in force 31 March 2025.

01Approved path

The tier is a consequence

Which questionnaire you may use follows from how the channels actually accept cards, and that criterion is met only by an implementation record or a written processor confirmation covering the solution as deployed.

02Human review

Not the transaction, the environment

The payment-fraud agent scores one transaction and leaves declines above the threshold to the fraud analyst. This one works an annual attestation about an environment, and a checkout change is a scope event it has to be told about.

04Build an evidence trail

The channel, the requirement it pulls in and the officer who signed stay on the attestation.

Integrations

Typical integrations

Five system groups connect to the same agent. Which of them are in scope is decided in discovery.

Gateways and processorsStripe · Adyen
Worldpay · Checkout.com
Commerce and checkoutShopify · BigCommerce
Salesforce · custom checkout
Scanning and testingQualys · Tenable
ASV portals · test reports

Agent

PCI attestation evidence

Reads the channels
Assembles the pack
Holds for the officer

Evidence and GRC storesVanta · Drata
ServiceNow · Jira
Observability & evaluationOpenTelemetry · Langfuse
Supported monitoring/evaluation sources

Integration availability depends on the client's existing systems and API access.

Agent controls

Six layers between the model and the attestation

Six layers, each tighter than the last. What the whole stack misses is drawn in the map below.

L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeHold the pack at unattested when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, eligibility-rule and tier-configuration changes.Track
L4TraceabilityRecord the evidence, its date, the open gaps and what the officer was shown.Record
L3Officer approvalHold packs for the named officer; it governs release, not whether the position is right.Gate
L2Policy guardrailsTest each entry against the criterion as written and the evidence cited; a failure returns it.Restrict
L1Confidence thresholdsRoute low-confidence packs to a QSA read before the officer sees them.Require review
Model corePack assembled — tier position, per-requirement evidence, open gaps and confidence
L1 – L2Test whether an entry may stand
L3Puts the release in an officer's hands
L4 – L5Keep the channel and the requirement behind it
L6Holds the pack at unattested when signals degrade

How Nestack evaluates it

Evaluate the whole assembly — not only the finished pack.

Coverage runs the whole depth of the workflow, and every layer is cut by slice.

Surface — the pack the acquirer reads
Depth of coverage ▼
E1Final-output evaluationDid each requirement entry cite evidence that actually supports it?
E2Step-level evaluationDid the agent use the right criteria, scope inventory and change records?
E3Tool evaluationDid it read and write the correct requirement and the correct channel?
E4Confidence calibrationDo low-confidence entries actually attract more officer amendments?
E5Slice evaluationHow does performance change across acceptance channels and entity types?
E6Business outcomeHow many entries needed an amendment or a correction after the pack went in?
Floor — the outcome the officer answers for

Failure modes

Where each failure originates in the agent

Seven failure modes, each pinned at the stage where it first arises.

Agent lifecycleDirection of processing →
01 · Retrieval1 mode
HF-03

Stale channel inventory

A checkout change never reaches the scope record.

Stage gathersChannel inventory, evidence, scans and change records
02 · Reasoning2 modes
HF-04

Criterion read too widely

A processor letter is read as covering a solution it does not name.

HF-06

Rationale restates the answer

A not-applicable entry repeats its conclusion instead of the flow evidence.

Stage proposesTier position, evidence, gaps and confidence
03 · Tool / write2 modes
HF-02

Connected systems omitted

Systems that merely connect to the environment are left off.

HF-05

Passing scan kept alone

The failing scan and its remediation record are dropped.

Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
HF-01

Entry without evidence

A requirement entry cites nothing on file.

Stage returnsThe pack the executive officer reads before signing
05 · Change / Version1 mode
HF-07

Silent eligibility regression

A model or rule change loosens what counts as eligible.

Stage tracksModel, prompt, eligibility rules and tier config
Sev-1 · agent acts outside the boundary Sev-2 · a wrong entry reaches the pack Sev-3 · source degrades, pack goes to review

Affected slices

The estate reads clean until you split it by channel

An estate-level scope-boundary figure can look settled while one acceptance channel holds most of the unevidenced requirements. Nestack reports the gap rate by channel, not only in total.

Slice performance — reported separately, not only in aggregateIllustrative example
SliceFailure rateLift Lift vs. thresholdStatus
Embedded iframe checkout6.6%3.7× Review
Acquired-brand checkouts4.8%2.7× Review
Mail order and telephone order3.0%1.7× Watch
Fully outsourced storefronts1.5%0.8× Normal
Bar: unevidenced-requirement lift vs. fully-outsourced baseline · scale 0–4.0× · tick marks the 2.0× review threshold 2 of 4 slices over threshold

Evidence-linked improvement

A cycle is not closed until it is a test

A cycle closes when the wrong tier is a regression case. That suite is what the next attestation packed is measured against.

Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect

The unevidenced-requirement rate rises in one channel.

02Diagnose

The one page that stopped being an iframe in a sprint nobody logged is read back through its change record until the cause narrows to one.

03Improve

The change goes out with a number, and the channels behind it travel with it.

04Verify

Nothing signs while one touched channel case is still red.

05Learn

It is kept for good, and the eligibility rules are amended in the same commit.

Learn → DetectThe return edge. The next detection runs against a suite this one made longer.

Typical build scope

Twelve workstreams across six weeks

The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, pack assembly, evaluation, integration, then production validation and handover.

Workstream Week 1Week 2Week 3Week 4Week 5Week 6
01Attestation scope discovery and boundary definition.
02Payment-stack and evidence-source review.
03Tier eligibility and scope-boundary rule mapping.
04Channel inventory and evidence intake.
05Pack assembly and evidence binding.
06Confidence scoring and open-gap routing.
07Officer approval workflow.
08GRC and scan-portal integration.
09Eligibility and scope cases.
10Guardrails and attestation controls.
11Channel-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallel Final scope and sequence confirmed in discovery

Engagement tiers

What each tier includes

Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.

Capability✓ in scope · — not at this tier PilotOne channel, one entity ProductionProduction evidence systems AdvancedMultiple entities / brands
Introduced at Pilot
Assembly to your channels and rules
Officer approval
Scope-boundary baseline
Introduced at Production
Reporting by channel
Approval workflow in your systems
Approved write-back
Payment-stack integration
Introduced at Advanced
Multi-questionnaire tier rules
Multi-stage attestation approvals
High channel count
Multi-entity attestation controls
Build price From $5,000 From $8,000 Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.

What we need from you

What you bring, and what we build with it

Each input maps to a piece of build scope and a week in the delivery timeline.

You bringWe build with it
01Your acceptance channels and payment stack Channel inventory and evidence-record intakeWeek 1
02Representative evidence from last year Coverage baseline, evidence binding and gap handlingWeek 2
03Your tier, scope and eligibility rules Tier eligibility and scope-boundary rule mappingWeek 1
04Access to relevant APIs, feeds or exports Payment-stack and evidence-source review, then integration setupWeek 2
05Attestations you would not want tested Tier-eligibility cases and failure testingWeek 4
06What no attestation may promise Confidence scoring, gap routing, guardrails and approval controlsWeek 3
07A named executive officer to review packs Officer approval workflow, then pilot and production validationWeeks 5–6
Nothing else is required Deployment, documentation and Agent Care handover are ours.

Delivery timeline

Four phases across six weeks

The plan runs on the weeks that were genuinely worked, so the pair sitting in week five is honest.

Phase W1W2W3W4W5W6
Discovery W1
Build W2 – W3
Evaluate W4 – W5
Pilot & Launch W5 – W6
Week focus W1Attestation scope discovery, tier mapping and the automation boundary W2Payment-stack integration and the evidence baseline W3Pack assembly, currency logic and approval controls W4Evaluation suite, gap handling and failure-mode testing W5GRC integration, pilot requirements and targeted corrections W6One attestation year run under the executive signer, then Agent Care handover
Reading the bandEach bar spans the weeks its own work is named in, and no more. The week 5 overlap is real.
At the end of W6Validation closes on live channels, and Agent Care picks up monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.

Next step · Retail AI agent

Build an attestation-evidence agent around the pack your officer signs.

It does not attest, determine compliance or confirm your scope, and Minnesota is not the PCI state it is widely called — § 325E.64 bans retained security codes and mandates no standard. Show us your channels and who signs, and we hand your officer the gaps.

Nestack Agents · PCI attestation evidenceAGT-RT-22 · Agent Care available after launch