Quick answer: The vertical compliance bundles announcement named four activated packs — healthcare (HIPAA), fintech (KYC), e-commerce, and payments (PCI) — but a buyer landing on the compliance pillar has had no single entry page that sequences them. This hub is that page: for each quadrant it states what one activation provisions, which existing walkthrough it deep-links, the tenant-owned controls statement for that vertical, and the go-live checklist back to the docs pillar pages. None of it promises compliance as a product property — the platform supplies draft provisioning and checklists; the determination and the posture are tenant-owned, exactly as the sibling walkthroughs each say in isolation.
The sequencing question this page answers is the one an evaluation committee asks after the announcement: given four packs and half a dozen standalone explainers, where do we start and what does each pack owe us? Read top to bottom and the answer resolves.
1. Healthcare quadrant — the HIPAA pack
What an activation provisions. Per the activation announcement, one activation creates a draft compliance profile, appointment-reminder / prescription-refill / post-visit follow-up campaign drafts that keep PHI out of plain SMS, a patient-intake assistant, and a double-opt-in flow. Nothing sends until your checklist clears.
The walkthrough it deep-links. The BAA lifecycle walkthrough is the operations half: PHI attestation, owner-only e-signature, the one-year not_required → pending → executed → expired term, the PHI access-log rows that roll into your DPA processing records. The HIPAA buyer checklist is the evaluation half, if procurement is still open.
Tenant-owned controls for this vertical. HIPAA mode is a workspace-owner toggle that only opens after an in-term BAA executes. PHI-adjacent audience designation, retention windows, minimum-necessary access, and log export are all your determinations — the platform enforces them on your behalf and never declares your organization compliant.
Go-live checklist back to the docs. The BAA flow states step through BAA flow → HIPAA compliance controls → PHI-adjacent audience designations. Then work the pack's checklist in Vertical compliance bundles: attach documents, submit the profile, and clear the healthcare-specific step — the executed BAA — before any patient message schedules.
2. Fintech quadrant — the KYC pack
What an activation provisions. Five draft campaigns covering verification, onboarding, and transaction alerts, plus an onboarding-support assistant, an opt-in flow, and the usual draft profile.
The walkthrough it deep-links. The fintech verification explainer covers the OTP-onboarding entry point and the wider account leg — SIM-swap fraud monitoring, pay-by-link, wallet passes, and voice biometrics on the same account. The KYC sender-ID compliance loop documents the manual registration loop the bundle compresses.
Tenant-owned controls for this vertical. You register Verify before any traffic, pick channels per market, and set the fraud-monitoring policy — block, challenge, or pass on each signal — as a configurable posture, not a platform guarantee. The checklist's vertical step makes you confirm the transactional-versus-marketing consent split before anything promotional sends.
Go-live checklist back to the docs. Start from Vertical compliance bundles, then the Verify overview for the request contract and the fraud-signal levers. If your verification traffic carries payment prompts, read the PCI row below before launch.
3. E-commerce quadrant — the order-lifecycle pack
What an activation provisions. Five draft campaigns for order, shipping, and re-engagement messaging, plus an order-support assistant and the usual draft profile and opt-in flow.
The walkthrough it deep-links. The retail and e-commerce buyer explainer maps the order-notifications, cart-recovery, renewal, and loyalty problem end to end — the channel-fallback chain you configure once and the store-platform flows that recover carts.
Tenant-owned controls for this vertical. The pack's vertical step separates marketing consent from order updates: promotional sends only target contacts who opted in to marketing, and the consent record, quiet-hours window, and opt-out list are your configuration in every pack.
Go-live checklist back to the docs. Vertical compliance bundles carries the shared tail — attach documents, submit the profile, confirm quiet hours, review campaign copy — plus the e-commerce-specific marketing-consent split step.
4. Payments quadrant — the PCI pack
What an activation provisions. Invoice, payment-link, and dunning drafts that never carry card data, plus a billing-support assistant and the double-opt-in flow.
The walkthrough it deep-links. The PCI-DSS buyer checklist runs the scope-separation review: which channel surfaces can carry a PAN, the transport facts to verify, and when self-assessment ends and a QSA has to confirm. A fintech tenant collecting repayment inside a conversation crosses into this quadrant the moment a payment link ships.
Tenant-owned controls for this vertical. The pack's vertical step asks you to confirm your payment links route to a PCI-compliant hosted payment page — a full card number, CVV, or expiry never travels over SMS or chat. The scope decision per channel is yours: Orbit is the conduit, and the messaging store is not a cardholder data environment, so the senders in your organization are the control.
Go-live checklist back to the docs. The PCI DSS posture page documents the SAQ A posture and the exclusion list, and Vertical compliance bundles carries the pack checklist with the hosted-payment-page step.
How the quadrants compose
The packs compose rather than compete: a healthcare tenant running a payments arm activates both packs into separate draft compliance profiles and runs two checklists against the same consent record and quiet-hours policy, exactly as the activation announcement lays out. The hot-path checklists post walks the activation-response checklist mechanics — automatic versus manual steps and the resume path — once the sequencing above has picked your quadrants.
Frequently asked questions
Does this hub replace the announcement post?
No — it is the next-cadence installment. The announcement names the shipped packs and the provisioning semantics; this hub sequences the quadrants for a buyer who needs the whole pillar in one page before splitting the work across a compliance lead and an operator.
Is any quadrant a compliance shortcut?
No. Activation creates drafts behind the same verification gates a hand-built setup faces, and every vertical-specific step — the BAA, the transactional-versus-marketing split, the marketing-consent separation, the hosted-payment-page confirmation — is a tenant-owned remainder on the checklist, not a step the platform completes for you.
Which quadrant does an insurance or other adjacent vertical start from?
The insurance buyer explainer maps renewals, claims status, and premium collection onto the same account: policy communications start from the e-commerce-style notification patterns, and premium collection reads the payments quadrant.