Payments / Underwriting / Content Scan

Your Payment Processor Scans Your Site Before Your First Sale

LegitScript says card network standards effective January 2026 make your acquirer scan your site before your first transaction, then keep looking behind your login.

Builds Shopify, WordPress, Webflow, landing pages, product pages, checkout flows, subscriptions, and intake paths.
Growth Meta, Google, TikTok, Reddit, SEO structure, Klaviyo, SMS, analytics, tracking, and campaign-ready pages.
Health HIPAA-conscious workflows, LegitScript-focused cleanup, telehealth forms, pharmacy disclosures, and compliance-aware site structure.
ToolBX Field Guide / Updated October 2026

Somebody reads your website before you are allowed to sell.

Most clinics think about website review in two places. The ad platforms, which disapprove an ad and tell you so, and LegitScript Healthcare Certification, which you apply for and hear back on. Both are reviews you take part in.

There is a third one you are not party to. Before your merchant account goes live, the bank or payment company sponsoring it has its own obligation to look at your site. You submit nothing and you get no report. The first sign of it is usually a question from your processor about a page you had half forgotten was public.

Who is doing the scanning?

On October 6, 2026, LegitScript announced new capabilities for its Merchant Underwriting solution, built on workflow and decision automation technology from Kompliant, now a LegitScript company. The audience is not subtle: LegitScript describes the suite as helping "sponsor banks, ISOs, and PayFacs identify and manage risk across the merchant lifecycle". The customer is your processor.

Three of the capabilities are proprietary risk signals pushed into the verification result an underwriter sees:

  • Merchant Category Detection, which compares a merchant's self-reported Merchant Category Code against LegitScript's own detected classification, "surfacing mismatches, related MCCs, and potential risk indicators that might otherwise require manual review".
  • Merchant Match, which compares merchant details against LegitScript's risk universe "to uncover potential ties to known bad actors".
  • Content Scan, which "Analyzes merchant websites in real time for prohibited content and BRAM and VIRP card-network rule violations, adding website risk visibility directly into the underwriting process".

The release attributes all three to "20 years of proprietary merchant risk intelligence", and names alongside them Mastercard MATCH Pro scoring and re-underwriting on demand, which "Enables acquirers to reassess approved merchants as their businesses and risk profiles evolve".

None of this is a product a telehealth clinic buys. It is a product the company holding your merchant account buys, which is exactly why it matters to you.

What is the rule behind the scan?

This is the part worth getting precise about, because it has a date on it.

LegitScript states that Mastercard's Merchant Monitoring Program requires acquirers to screen merchants for Brand Reputation and Misuse violations and transaction laundering, both before onboarding and continuously afterward. In its words, "Under the standards effective January 1, 2026, acquirers must complete an initial website scan before a merchant's first transaction, then maintain ongoing monitoring that extends into restricted, members-only areas." Elsewhere on the same page it puts the obligation in three parts: pre-transaction scans, monitoring of password-protected areas, and proof of continuous oversight across the merchant lifecycle.

Two honest qualifications on that.

First, that is LegitScript describing a card network standard, not a quotation from Mastercard's own rule text. LegitScript is a registered provider under the program and has a commercial interest in the requirement being understood. That does not make the description wrong, but the authority on how the rule applies to your account is your processor. Ask them directly.

Second, the ongoing watching of merchants who are already approved is not new. LegitScript draws that line itself: "Underwriting is a point-in-time decision made before a merchant is initially approved. Persistent monitoring picks up where underwriting ends." Monitoring is an existing product. What the January 2026 standards change is the timing, which is a scan before the first transaction rather than after the first bad month.

The pre-transaction scan is the part to plan for. By the time anybody tells you your site was read, it has already been read.

Is this the same review as Healthcare Certification?

No, and conflating the two is the most expensive mistake available here.

LegitScript Healthcare Certification is a review of your business against the nine certification standards published on its own site: licensure and business registration, legal compliance, prior discipline and history, affiliates and partners, patient services, privacy, validity of prescription, transparency, and advertising. It looks at the operating business, not only the website, and it asks for licenses, registration documents, a privacy policy and the compliance status of your partner pharmacies.

A content scan in merchant underwriting is narrower and faster, with a different question behind it. In LegitScript's own description it looks for prohibited content and card network rule violations, in real time, and keeps the review audit-ready with downloadable screenshots.

Nothing here changes the certification standards, and no published source says it does. What it changes is how many parties read the site and on what schedule. Certification is a review you prepare for. The underwriting scan is a review that happens to you.

What is sitting behind your login?

This is the detail you can act on today, because you can check it yourself. Ask one question: what does a logged-in patient see that an unauthenticated visitor does not? On most telehealth and med spa builds the answer includes more than anybody remembers putting there.

  • Patient portal dashboards and treatment plan pages.
  • Post-checkout confirmation pages, upsell offers and refill screens.
  • Gated price lists and members-only program tiers.
  • Before and after galleries kept behind a login because somebody was nervous about them.
  • Downloadable intake forms, consent documents and program PDFs.
  • Legacy subdomains, old landing pages and staging sites still resolving in public.

That last one deserves its own sentence. LegitScript's fourth certification standard already requires an applicant to "provide all domain names and websites under its control", so a clinic that has been through certification was forced to inventory this once. If you never have, the underwriting scan is a less forgiving reason to, because nobody asks you for the list first.

The pattern that causes real trouble is a claim that exists only behind the login. A conservative public page plus a members page promising an outcome is not a smaller problem than one bad public page. It is the same problem with a login in front of it.

Does the category code on your application match your site?

Merchant Category Detection is the quietest item in the announcement and the one most likely to catch a legitimate business by surprise. It compares what you declared against what your website looks like it sells, and LegitScript states the point of it plainly, which is to "Catch miscoded or high-risk MCCs that require registration".

A clinic that applied as a general medical practice and now runs a GLP-1 program with a storefront can end up with an application and a website describing two different businesses. The fix is not clever wording. It is making the site and the application describe the same company, and telling your processor when the business changes shape rather than letting the next scan find out for you.

Does certification help with any of this?

It helps, and it does not decide.

LegitScript presents certification as enabling a merchant to "build trust with payment processing partners, advertising platforms, and the people you serve", and states on the same page that certification is trusted by a list including Visa and Mastercard. Visa puts the sequence plainly on its own site: "Before a merchant can accept Visa payments, their acquirer ... must conduct compliance checks to meet our standards."

What certification does not do is make the approval. That is decided by the acquirer, processor, bank, card network or platform under their own underwriting and policies, which is the answer we give in our 75 healthcare commerce questions and in the LegitScript and med spa FAQs. Certification is a signal those parties recognize. It is not a decision they handed over.

Being certified does not stop the scan. It changes what the scan finds.

An afternoon on your own site

  1. Log in as a patient and read every screen a patient can reach. Write down anything that makes a claim your public pages do not make.
  2. List every domain, subdomain and landing page you control, including the ones you stopped using, and load each one in a browser signed in to nothing.
  3. Compare the business your website appears to be against the category code on your merchant application.
  4. Check that each product and program page names who prescribes, who dispenses and where the service is available.
  5. Ask your processor which monitoring provider they use, and what the initial scan on your account returned.

What to fix once you have looked

Almost everything on that list is a disclosure problem rather than a design problem, which is good news, because disclosure problems are cheap to fix and expensive to leave. What makes them hard is that nobody reports them to you. The ad platform at least sends a disapproval. The underwriting scan goes into a file at your sponsor bank and stays there.

That inventory and repair work is the same pass as readiness for certification. It is the work in telehealth and GLP-1 website development, and in med spa website design when the program is aesthetics led. If you would rather somebody walked the public site and the logged-in pages with you before your processor does, that is a telehealth program fit review. The adjacent question, what an ad platform looks for, is in what a telehealth website needs before you run Google or Meta ads.

This is operational guidance, not legal advice, and not a statement of your card network obligations. The description of the Mastercard program quoted here is LegitScript's rather than Mastercard's own published text, and your acquirer is the party that can tell you what applies to your account. Have qualified counsel and your processor review your program, your public pages and the content behind your login.

Common questions

Does my payment processor read my website before approving my merchant account?

LegitScript states that under Mastercard's Merchant Monitoring Program, with standards effective January 1, 2026, acquirers must complete an initial website scan before a merchant's first transaction, then maintain ongoing monitoring that extends into restricted, members-only areas. That obligation sits on the acquirer, not the merchant, so a clinic never sees the scan happen. The practical consequence is that a page you considered internal or unfinished can be read as part of an underwriting decision.

Is a merchant underwriting website scan the same thing as LegitScript Healthcare Certification?

No. They are different reviews with different customers. Healthcare Certification is a review of an applicant business against LegitScript's nine certification standards, covering licensure, legal compliance, prior discipline, affiliates and partners, patient services, privacy, validity of prescription, transparency and advertising. A merchant underwriting content scan is sold to acquirers and analyzes a website for prohibited content and card network rule violations. Nothing published says the certification standards have changed.

What on a healthcare website sits behind a login that a scan would still reach?

More than most clinics expect. Patient portal dashboards, post-checkout confirmation and upsell pages, refill and treatment plan pages, gated price lists, members-only before and after galleries, downloadable intake or consent documents, and any staging or legacy subdomain still resolving in public. If the content makes a claim your public pages do not make, the login is not what decides whether it counts.

Can being LegitScript certified guarantee my merchant account is approved?

No. LegitScript presents certification as something that helps build trust with payment processing partners, and lists Visa and Mastercard among those that recognize it. Approval itself is decided by the relevant acquirer, processor, bank, card network or platform under their own underwriting and policies. Certification is a signal those parties recognize, not a decision they have delegated.

Why would a mismatch in my merchant category code matter?

LegitScript's Merchant Category Detection compares a merchant's self-reported Merchant Category Code against LegitScript's own independently detected classification and surfaces mismatches, related codes and potential risk indicators. In plain terms, the category you wrote on the application is compared against what your website appears to sell. If the two disagree, that disagreement is itself a finding, and the fix is usually to make the site and the application describe the same business.

What changed in LegitScript's merchant underwriting announcement on October 6, 2026?

LegitScript announced new capabilities for its Merchant Underwriting solution, powered by workflow and decision automation from Kompliant, a LegitScript company. The release names three proprietary risk signals brought into verification results, being Merchant Category Detection, Merchant Match and Content Scan, plus Kompliant-powered workflow automation, Mastercard MATCH Pro scoring and re-underwriting on demand. It is a product sold to sponsor banks, ISOs and PayFacs, not to merchants.

Sources

Want this costed for your build?

Tell us what you already have and what is not working, and we will come back with the shape of the work and what drives the number.

Talk to ToolBX Media
Discovery / Build Map / Next Step

Answer a few questions. We’ll find the cleanest path to launch or scale.

A stepped project quiz gets better answers than a blank contact form. Tell us what you are building, where the friction is, and what needs to happen next.

How we qualify the work

Not every project needs the same build path.

Some brands need a clean launch. Some need a conversion rebuild. Some need intake, checkout, tracking, and follow-up fixed before scaling ads. The quiz helps separate the real need from the surface request.

01

Offer

What are you selling, launching, or trying to make clearer?

02

Friction

Where is the current site, funnel, or backend slowing the business down?

03

Stack

Which tools, platforms, ads, checkout, intake, or email systems are involved?

04

Next move

We map whether this is a focused fix, full build, or ongoing growth system.

Project Type / Timeline / Scope

Map the build before we talk.

Five quick steps. No giant table form. Your answers get packaged into one project inquiry so we can reply with a clearer next step.

Step 1 / 5
Project type

What are we helping you build or improve?

Pick the closest fit. You can explain the details at the end.

Business stage

Where is the brand right now?

This helps us understand whether you need foundation, cleanup, or growth support.

What needs attention

Which parts need the most work?

Select all that apply. This gives us a better picture than one broad message.

Timing and scope

How urgent is this and what kind of scope are you expecting?

This does not lock you into anything. It helps us avoid wasting your time.

Contact details

Where should we send the next step?

Add the basics and anything important we should know before replying.