SingleComm
Platform

PCI compliance for phone payments — keeping agents, recordings, and your audit out of scope

DTMF masking, tokenized pay links, why descoping beats securing, what Level 1 certification actually covers, and the evidence your QSA will ask for. How to take card payments over the phone without turning the contact center into a cardholder data environment.

4 min readUpdated June 2026
On this page

The cheapest cardholder data to protect is the data you never touch

PCI-DSS has a blunt logic: every system, person, and process that stores, processes, or transmits cardholder data is in scope, and everything in scope must be secured, monitored, and audited. A contact center where agents hear card numbers read aloud puts the agents, their desktops, the phone system, the call recordings, and the QA team reviewing those recordings all inside the cardholder data environment. That's an enormous audit surface, and pausing the recorder doesn't fix it — the agent still heard the number, and the desktop they might type it into is still in scope.

The modern approach is descoping: design the payment flow so card data never reaches the agent, the recording, or the transcript in the first place. What's never there doesn't need to be protected.

DTMF masking on voice

DTMF masking is the core pattern for live phone payments. The customer stays on the call with the agent, but enters the card number on their phone keypad. The platform intercepts the keypad tones before they reach the agent's audio path or the recorder:

  • The agent hears flat tones or silence — not the distinct tones that could be decoded back into digits
  • The recording captures the conversation but no card data, so recordings stay out of scope
  • The agent's screen shows masked progress (digits entered, validation status), never the PAN
  • The conversation continues throughout — the customer is never dumped to an IVR and lost

The agent guides the payment without ever being able to see, hear, or write down the number. That removes agents, desktops, and recordings from PCI scope in one move.

Not every payment needs to happen in the call. The second pattern sends the customer a secure, tokenized payment link by SMS — the customer completes the card entry on their own device, in a hosted payment page, and the result posts back to the interaction:

  • Card data goes directly from the customer to the payment processor; the contact center platform handles a token, not a PAN
  • Works mid-call ("I've just texted you a secure link") or asynchronously for follow-ups and collections
  • The agent sees the outcome — paid, declined, abandoned — and the result is logged to the customer record

SingleComm packages both patterns as Silent Pay: DTMF masking on voice, tokenized SMS pay links, and integration with major merchant gateways including Stripe and Braintree, with no PAN data in recordings or transcripts.

What Level 1 certification covers — and what it doesn't

PCI-DSS Level 1 is the most stringent service-provider tier: an annual on-site assessment by a Qualified Security Assessor, not a self-completed questionnaire. When a vendor is Level 1 certified — as SingleComm is — it means their handling of payment flows has been independently assessed against the full standard.

What it does not mean: that you are automatically compliant. PCI responsibility is shared. The vendor's certification covers the platform's controls; your assessment still covers your processes, your policies, and any path where card data could enter your environment outside the platform (an agent writing down a number, a customer emailing a card photo, a legacy payment line). Descoping shrinks your side of the assessment dramatically — often from a full audit of the contact center to attesting that card data never enters it — but it doesn't shrink it to zero.

Ask the vendor for two things: their Attestation of Compliance (AOC) as a Level 1 service provider, and a responsibility matrix that says explicitly which PCI requirements they cover and which remain yours.

Audit evidence — what your QSA will ask for

When the assessment comes, "we use a compliant vendor" is a sentence, not evidence. Be ready to produce:

  • The vendor's current AOC and the shared-responsibility matrix
  • Architecture documentation showing the payment flow and where card data does and does not travel — the diagram that proves agents, recordings, and transcripts are out of the data path
  • Sample recordings and transcripts from payment calls, demonstrating no PAN is present
  • Access control evidence — who can configure payment workflows, with role-based access and MFA enforced
  • Audit logs for payment interactions: actor, action, timestamp, and data touched, exportable for the assessor
  • Agent process documentation — training and policy stating agents never accept card numbers verbally, and the script for redirecting customers who start reading one out

That last item is the human edge case every assessor probes. Customers will try to read their card number aloud. Agents need a practiced response that moves the customer to the secure flow — and your evidence file needs to show they're trained on it.

Don't trade compliance for conversion

A payment flow that's secure but clumsy costs you completed payments — customers abandon when they're transferred to a disembodied IVR and the line goes quiet. The advantage of agent-assisted patterns like DTMF masking and in-conversation pay links is that the agent stays present: they can answer questions, retry a declined card, and confirm success in the same call. Evaluate payment security and payment completion together; the right design improves both.

The short version

Don't try to secure card data inside the contact center — keep it out. DTMF masking keeps live phone payments flowing while agents, desktops, and recordings stay outside PCI scope; tokenized pay links do the same for SMS and asynchronous payments. Choose a platform that's Level 1 PCI-DSS certified, get the AOC and responsibility matrix in writing, and build your evidence file — architecture diagrams, clean recordings, access logs, and agent training — before the assessor asks. The result is a smaller audit, a calmer QSA, and payment calls where the only thing the agent handles is the conversation.

Back to

Platform

Return to the main platform page to see the full product family.

Related guides

See how the SingleComm platform can replace your stitched-together stack.

Schedule a demo