Delivering Risk Mitigation to Merchant Service Providers

The SecureTrust Web Risk Monitoring solution offers merchant service providers such as acquiring banks, payment processors, payment gateways and independent sales organizations (ISOs) a full suite of protection for merchant monitoring and reducing risk. SecureTrust Web Risk Monitoring delivers industry-leading card brand monitoring capabilities and much more. It is designed for 360° risk mitigation to help you address risks beyond card brand requirements and provide additional opportunities for you to protect and expand your business.


  • Designed for 360° Risk Mitigation

    SecureTrust Web Risk Monitoring helps you ensure that merchants are selling the goods they say they are – and that online sites have the right foundation of data security practices in place. A cloud-based, managed service, SecureTrust Web Risk Monitoring helps you address your internal and proprietary standards in addition to compliance with regulatory and industry mandates.

    Five key services are offered independently or as a set, according to your requirements:

    • Content Monitoring for card brand monitoring and onboarding requirements such as Mastercard Business Risk Assessment and Mitigation (BRAM)
    • Merchant Intelligence to validate business operations, identify third-party relationships and conduct URL discovery
    • Malware Monitoring that allows you to deliver a Merchant Malware Report to your merchants as well as reviewing merchant website security
    • Custom Monitoring for your specific requirements such as counterfeit merchandise, terms of service violations and searches for false claims
    • Transaction Laundering Detection for scalable and reliable identification and reporting of previously unknown illicit websites associated with a merchant

    Web Risk Monitoring


  • SecureTrust Web Risk Monitoring helps you:

    • Efficiently satisfy card brand monitoring requirements
    • Identify violations with current and prospective merchants
    • Reduce onboarding risks
    • Reduce costs of manual web content reviews
    • Eliminate non-compliance penalties
    • Reduce risks of malware threats to your merchants
    • Drive additional revenues with merchant services

    SecureTrust has close ties with law enforcement and investigative agencies, and SecureTrust Web Risk Monitoring processes work within commonly used computer forensic frameworks. SecureTrust Web Risk Monitoring has an ongoing adaptive release cycle to monitor ever-changing illegal, unethical and fraudulent practices taking place online. Additionally, SpiderLabs at Trustwave is continuously researching the latest threats in malware and creating detection methods for the monitoring services.

    SecureTrust Web Risk Monitoring solution offers you a high-level of flexibility and the ability to customize your monitoring capabilities for your specific requirements.

How It Works

  • You manage your Web Risk Monitoring (WRM) services through the secure TrustKeeper® web portal, setting parameters for the identification of questionable and illegal content and malware scanning.

    Results are presented in an easy-to-read and customizable dashboard that showcases critical management elements for valuable insight on merchant activity, including a statistical reviews, drill-downs and hierarchical views.


    WRM offers an easy-to-read dashboard with critical management elements available for immediate analysis.

    Content Monitoring

    Highly Scalable, High Quality Card Brand Monitoring

    The Content Monitoring service delivers both broad automated and deep expert analysis to help you take action to head off offensive or illegal activity and threats to your business. Content Monitoring has been specifically tuned to meet the needs of standard card brand reporting. SecureTrust Content Monitoring supports specific standards, such as the Visa Global Brand Protection Program (GBPP) and the Mastercard Merchant Monitoring Program (MMP).

    SecureTrust Content Monitoring scans, detects, inventories and analyzes website content in a fraction of the time required to perform the same functions manually. It identifies a variety of violations and illegal activity prohibited by leading card brands and processors, including illegal pharmaceutical sales, gaming, tobacco and other categories. You can combine it with the Custom Monitoring service to search for your specific requirements.

    The Content Monitoring process features a multi-tier analysis workflow that creates a special queue for any sites suspected of containing sensitive data. These sites are isolated for real-time review by Trustwave’s senior analysts. From there, the sites undergo detailed review and escalation for Quality Assurance (QA) of the results along with reporting back to you when necessary. This helps eliminate false positives and expedites timely alerts to you. You can also specify direct reporting to the card brand if you like for satisfaction of MMP and other programs.

    Merchant Intelligence

    A Fuller View of Merchants’ Online presence


    The WRM Merchant Scorecard provides an overview of the risk state for the e-commerce URL being monitored.

    The Merchant Intelligence service helps address your requirements for a fuller view of your merchants’ online presence. This service includes:

    • Merchant Policy Monitoring - Track merchants’ policies published on the web for changes over time. Published policies include privacy policy, return policy, shipping policy, terms of service, and more.
    • Third-Party Detection - A service delivered by the elite SpiderLabs team at Trustwave to help you identify service providers that your merchants employ, including the payment service provider, merchant web host and merchant shopping cart provider.
    • Merchant Discovery - A service to help you identify all of the websites associated with your merchants. This is important to identify new websites that may have been added since onboarding and to uncover websites that were not disclosed.
    • Geolocation and IP Analysis - This service combines physical address confirmation and IP analysis to provide a spotlight into a merchant’s web presence. It automatically identifies and confirms a merchant’s physical address with a record provided via Google Street View. It performs IP analysis to understand where the merchant is hosting websites and how many other websites are associated with the IP address.

    Malware Monitoring

    Benefits Both You and Your Merchants

    In addition to merchant monitoring capabilities so vital to your business, the Malware Monitoring service provides you with the opportunity to deliver services to the merchant that you can monetize. You can offer merchants malware scanning and SSL verification as a means of adding value to them or to drive additional revenue. This can be delivered to your merchants as a Merchant Malware Report.

    The Malware Monitoring service delivers real-time risk checks for onboarding new merchants into a portfolio. It includes bulk onboarding scans for new account additions, including SSL validation and malware detection, powered by the Trustwave Secure Web Gateway.

    You benefit from an in-depth merchant scorecard to help augment your underwriting efforts and help you ensure only those merchants conducting commerce in a secure and ethical manner are signed in to your portfolio.

    Custom Monitoring

    Define Your Own Monitoring Parameters

    The Custom Monitoring service scans for content that you deem objectionable and/or prohibited beyond card brand program restrictions. It searches for the specific requirements you define, such as counterfeit merchandise, terms of service violations and searches for false claims. An alert is provided to you when such specified activity has been identified and confirmed by a Trustwave auditor.


    Custom Monitoring identifies violations to your specifics, beyond card brand compliance requirements.

    Transaction Laundering Detection

    Highly Scalable and Highly Reliable

    SecureTrust Transaction Laundering Detection (TLD) delivers large-scale analysis, combined with rigorous testing and evidence collection unmatched by any other TLD vendor. You receive a broad and substantiated view of merchant violations to help you reduce your risks and costs.

    You are presented with a report of sites found in connection with each merchant and a separate report with the found websites that are violating a card brand policy. The Web Risk Monitoring Reporting Tool for Mastercard MMP allows you to easily review and send the monthly report to Mastercard for both BRAM monitoring and transaction laundering.

    Related Products and Services

    Merchant PCI Compliance and Security

    Merchant Risk Management Program