CollectInHouse

Security & Data Handling

Last updated: August 2026

This page summarizes security and data-handling practices for the CollectInHouse service. Contract documents, implementation scope, and the current Attestation of Compliance control where they are more specific.

PCI DSS scope

Advanced Cash Management LLC is validated as a PCI DSS v4.0.1 Level 1 Service Provider for the services and systems included in its current Attestation of Compliance.

That validation is limited to the services, people, processes, and systems within the assessed environment. It does not mean that every CollectInHouse feature, integration, client environment, or client process has been independently assessed. Clients remain responsible for their own PCI DSS obligations and for using the service in accordance with the agreed implementation.

Access and data exchange

Available controls may include role-based access, user-specific credentials, and logging appropriate to the contracted configuration. Account data may be exchanged through approved file transfer or API methods, including SFTP where supported by the implementation.

Encryption is used for supported transmissions and storage within the service environment. Exact retention, integration, authentication, and data-flow requirements are confirmed during implementation and in applicable agreements.

Client-controlled workflows

Clients define eligible accounts, users, approved scripts, communication channels, consent and suppression data, payment options, escalation paths, and other operating rules. CollectInHouse provides configurable tools and records that support those workflows; it does not replace the client's legal, security, privacy, or compliance program.

SOC 2 statement

Security controls are informed by relevant SOC 2 Trust Services Criteria; no SOC 2 report has been issued. CollectInHouse and Advanced Cash Management do not claim SOC 2 certification or SOC 2 compliance.

Health information and business associate terms

No service is “HIPAA certified,” because the HIPAA Rules do not establish a certification program for this purpose. Support for protected health information is available only for an approved use case, agreed safeguards, and an executed Business Associate Agreement when required. Do not submit health information through this public website.

Shared responsibility

Advanced Cash Management is responsible for the safeguards and operations assigned to it under the applicable agreement. Clients are responsible for their source data, legal authority, user access, endpoints, account eligibility, consent and preference records, workflow instructions, and the systems they connect to the service.

Security questions and requests for current supporting documentation may be sent to admin@advancedcashmanagement.com.