Secure phone payment handling
Card payments taken through controls designed so agents never hold card data.
Outsourced service
Handling card details on a call is the fastest way to drag your entire contact centre into PCI DSS scope. The work is arranging things so that never happens.
Discuss pci-compliant call center
What we handle
Choose the tasks you need now and expand the scope when the workload changes.
Card payments taken through controls designed so agents never hold card data.
Customers key card details directly; agents stay on the line but never see or hear them.
Recording suspended around payment capture so card data never enters the recording store.
Structure the flow so the smallest possible part of your estate falls inside PCI scope.
Clean-desk rules, device restrictions, and access controls written down and enforced.
Documentation and logs prepared so an assessment is a review rather than an investigation.
Designed around you
We adapt to your tools, communication rhythm, approvals, brand standards, and escalation process.
Where this runs
Free consultation
Tell us what your team is spending time on and we will scope the pci-compliant call center coverage, team size, and reporting that fits.
FAQ
Common questions about outsourcing pci-compliant call center.
The aim is that agents never see, hear, or write down card details. Instead of reading a card number aloud, the customer keys it on their phone keypad while the agent stays on the line. The tones are masked, and the digits go to the payment processor without passing through the agent's screen or the call recording. Where that is not available, recording is paused around the payment step. Around those controls sit written agent rules: clean desks, restricted devices, and limited system access. PCI DSS governs cardholder data, and the design goal is to keep that data out of as many places as possible.
Scope follows the card data. The systems, networks, and people that store, process, or transmit cardholder data fall inside your PCI DSS assessment, and so can anything connected to them. If agents hear card numbers and recordings capture them, your phone system, recording store, and agent desktops can all come into scope. Keypad entry with masked tones sends the data to the payment processor and takes those pieces out of the path. Scope reduction is a design exercise, mapped flow by flow. Your acquiring bank or a Qualified Security Assessor confirms what ends up in scope for you. We cannot declare that on their behalf.
Ask any provider, including us, for the current Attestation of Compliance for the services in question, and read which services and locations it covers. Ask for a responsibility matrix showing which PCI DSS requirements the provider meets, which you meet, and which are shared. Ask for a data flow diagram of the payment step, the call recording policy, and the written agent controls. Ask how agents are screened and trained and how incidents are reported to you. Do not rely on the word compliant on a web page, ours included. What applies to your program is documented during scoping, before any payment is taken.
You remain the merchant. Your merchant account, your payment processor or gateway, your own PCI DSS validation with your acquiring bank, and your refund and chargeback policies stay with you. Outsourcing the calls does not outsource your accountability for cardholder data, and you should keep track of which requirements each service provider covers. Our agents take the payment inside the flow you approve, follow your refund rules, and escalate disputes to your team. If you use a hosted payment page or a processor's phone payment tool, agents work inside that instead of a system of ours.
After the discovery call, a project manager maps your payment flow step by step: when the agent introduces the payment, how the customer enters card details, what the agent sees on screen, and what happens when a payment fails. Agents are trained on that flow and on the written controls, including what to do when a customer starts reading a card number aloud despite being asked not to. That situation comes up often, and the response has to be scripted. Agents also learn your refund and cancellation rules. Access to payment tools is granted by role and removed when an agent leaves the program.
Yes, with one condition: the payment controls have to apply to every agent on every shift, including temporary peak staff and overnight cover. A surge team that takes card numbers by voice because the secure tool was not set up for them undoes the scope work. For planned peaks, tell us early so added agents are trained on the payment flow and given access before the rush. After-hours payment lines use the same flow as daytime ones. If your payment tool has an outage, agents follow the fallback you approved in advance, which is usually a callback, not a handwritten card number.
Quality review still covers the whole call except the card entry itself. Reviewers check that the agent introduced the payment step correctly, did not ask the customer to read card details aloud, confirmed the amount, and handled a failed payment according to your rules. Separate checks look at the controls: whether any recording captured card data, whether desk and device rules are followed, and whether access lists are current. Results go into your regular reporting on the rhythm agreed at launch. A suspected exposure of card data is an incident, and it is escalated to your named contact under the procedure written during scoping.
If customers can pay through a link sent by text or email, or through your website, agents may never need to take a card by phone, and that is the simplest scope reduction of all. A dedicated phone payment setup is also hard to justify for a handful of phone payments a month. And it is the wrong fix if the real problem is elsewhere, such as card numbers stored in order notes or spreadsheets in your own office. Outsourcing the calls will not clean that up. Start with where card data lives today, then decide what the phone channel needs.
Related services