All documentation

Security & Compliance

PCI DSS & Card Payments

The controls we implement for card payments taken over the phone.

We describe Silux Call as built for PCI DSS, not as PCI compliant. We hold no QSA certification, and claiming compliance we cannot evidence is exactly what your auditor will ask us to produce. What follows is the set of controls we actually implement.

The controls

  • Card numbers are keyed on the phone keypad and never spoken to an agent
  • The digits are suppressed so the agent neither hears nor sees them
  • Call recording is paused automatically before collection starts
  • If recording cannot be paused, the payment is refused rather than recorded
  • Transcription redacts card-number patterns

Why the refusal behaviour matters

A system that carries on when the pause fails will eventually write a card number into a recording. Refusing the payment is disruptive but it is the only behaviour that cannot silently produce a breach.

What remains your responsibility

  • Your own PCI scope, assessment and evidence
  • Agent training and clean-desk handling
  • Your payment provider relationship and merchant obligations
  • Retention policy for recordings that surround a payment

Still stuck?

If this page did not answer your question, our UK support team will.

Contact support