Appendix D — MANAGED PCI DSS

This Appendix describes the scope and features of the MANAGED PCI DSS services offered by Intech Hawaii. This Appendix is incorporated by reference into the Services Guide and is subject to all terms and conditions of the Services Guide and the Master Services Agreement ("MSA"). Only the specific services listed in your Quote will be provided; all other services described in this Appendix are available but not included unless expressly added to your Quote. Intech Hawaii reserves the right to update this Appendix from time to time to reflect changes in available services; material changes that negatively impact services already included in your Quote will be communicated to you by email.

MANAGED PCI DSS

This service supports businesses handling cardholder data in achieving and maintaining PCI DSS compliance. Intech Hawaii supports clients operating under SAQ A, SAQ A-EP, SAQ B, SAQ B-IP, SAQ C, and SAQ C-VT. SAQ D compliance requires a Qualified Security Assessor (QSA) and is outside the scope of this service.

Assessment and Gap Analysis
Initial review of your security posture against PCI DSS requirements; gap analysis with prioritized remediation action plan. (Remediation projects such as network segmentation or encryption setup are billed separately.)

Policy Development and Review
Development and ongoing maintenance of PCI DSS-aligned policies covering data protection, access controls, and incident response.

Vulnerability Management
Monthly internal and external vulnerability scans; annual penetration testing.

Network Security and Monitoring
Firewall configuration and maintenance; intrusion detection/prevention monitoring; log collection, review, and storage for critical systems; continuous monitoring of network and system activity.

Encryption and Tokenization
Coordination with your third-party payment processor to ensure cardholder data is encrypted in transit and at rest, and that tokenization is properly implemented.

Incident Response
Development of a PCI DSS-aligned Incident Response Plan and breach notification guidance. (Incident response and remediation services are billed separately — see Breach/Cybersecurity Incident Recovery section.)

Training and Awareness
Regular staff training on PCI DSS requirements and security best practices.

Reporting, Audits, and Third-Party Management
Preparation of required quarterly and annual compliance reports; audit preparation and assessor support; monitoring of third-party vendor PCI DSS compliance; maintenance of audit-ready compliance documentation.

Client Responsibility and Attestation
Client is solely responsible for achieving and maintaining its own PCI DSS compliance. Intech Hawaii's role is limited to the security controls, vulnerability management, and documentation support described in this Appendix and is scoped to the SAQ levels identified herein. Client acknowledges and agrees that Intech Hawaii's provision of Managed PCI DSS services does not constitute PCI DSS compliance, certification, or validation, and does not relieve Client of any obligation under PCI DSS requirements or Client's agreements with payment card brands or acquiring banks. Client represents that it will independently satisfy, attest to, and maintain all PCI DSS requirements applicable to its cardholder data environment. Intech Hawaii shall have no liability for Client's failure to achieve or maintain PCI DSS compliance or for any fines, penalties, or assessments imposed by payment card brands, acquiring banks, or regulators.

 

Last Updated: April 7, 2026