Skip to main content

Help us improve the Digital Marketplace - send your feedback

PCI-PAL (U.K.) LIMITED

PCI Pal® Automated Secure Payments

PCI Pal® Automated Secure Payments,(IVR, Chatbots, AI): Offer 24/7 secure self-service payments with PCI Pal. Whether using DTMF, voice recognition, or secure digital links, customers are guided through a simple,
compliant process that mirrors agent-led support.​

Features

  • De-scope for Contact Centre from PCI DSS Requirements
  • Multiple payment options to meet accessibility requirements
  • Automated Payments enables customers to make secure, PCI-compliant payments
  • Works with chatbots, voice bots, IVRs, and virtual agents
  • Gateway Agnostic: Use your existing payment gateway
  • Compatible with all leading UCaaS and CCaaS vendors

Benefits

  • Full PCI DSS Compliance: No cardholder data enters your systems.
  • Provide peace of mind for your customers
  • Improve efficiency: Reduces agent workload by automating routine payment interactions
  • Increased Payment Completion Rates: Support more first-time payment success
  • "Always on" payment options are fast, convenient, improving customer satisfaction​
  • Boosts payment completion rates by offering frictionless self-service journey
  • Improve customer experience, enabling them to utilise channel they prefer
  • Increase revenue by offering more payment options to customers
  • Intuitive for customers with easy-to-follow instructions

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ccs@pcipal.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 6 7 3 0 4 0 1 4 3 3 0 4 6 4

Contact

PCI-PAL (U.K.) LIMITED David Swift
Telephone: +44 (0)330 131 0340
Email: ccs@pcipal.com

About your service

Service categories

Applications

Customer relationship management

  • Customer service
  • Contact centre
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Can be integrated with payment and CRM applications
Can be integrated as part of a contact centre or telecoms offering
Cloud deployment model
Private cloud
Service constraints
The service is agnostic to all connecting components: Telephony, Applications and Payment Gateway.
System requirements
  • Optional Access to Browser / Interfacing Desktop Application
  • Customer environment requires TLS 1.2 to connect to PCI Pal
  • Browsers should adhere to supported list

User support

Email or online ticketing support
Yes
Support response times
As per standard SLA
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes
Support levels
Priority 1 (Critical)
Contact Channel: Telephone
Response Time: 1 hour
Definition: Complete loss of the Service to all users within one or more sites or business units.

Priority 2 (High)
Response Time: 4 hours
Definition: Significant degradation of the Service affecting more than 30% of users, calls or payment attempts within one or more sites or business units.

Priority 3 (Medium)
Response Time: 24 hours
Definition: Degradation of the Service affecting less than 30% of users, calls or payments within one or more sites or business units OR widespread loss of ancillary functionality that does not prevent processing of payments, such as post transaction logic.

Priority 4 (Low)
Response Time: 48 hours
Definition: Localised technical issues affecting single users.

Priority 5 (Very low)
Response Time: 72 hours
Definition: Transient faults that have been ameliorated prior to being reported to PCI Pal or non-functional issues such as UI defects.

Dedicated Customer Success Managers (Technical Account Managers ) are assigned to deployments exceeding 150 agents

Custom SLA's may be agreed for enterprise customers (>1000 seats)
Support available to third parties
Yes

Onboarding and offboarding

Getting started
The service is very simple for a user to use and the standard train-the-trainer and User Acceptance Testing can be completed in a single day. We are able to provide both remote, on-site and on-line learning packages. We can work alongside Training Departments for larger organisations or where more custom integrations have been created, to help build internal training programs for users.

The project will also include either on-site or remote go live support.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
No data is collected or held by PCI Pal.
End-of-contract process
PCI Pal will contact the user at the end of the contract to determine their requirements and agree a new term or exit process if required
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation can be provided in various format to aid accessibility.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Page elements are resized accordingly to work with mobile devices
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Services are configured to capture card data and additional fields required for payment processing. Solution and service interface will be subject to scoping.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
NVDA, Dragon, Read/Write Gold, JAWS, Zoom Text.
API
Yes
What users can and can't do using the API
By integrating a Billing System or Application via the API, the user experience can be enhanced by passing necessary data directly to PCI Pal without the need for manual input.

Administrative Users have the ability to configure the service including integration points and configuration of the User Interface. This setup is usually performed by PCI Pal in the initial deployment of the service but full training is available should the customer wish.

Changes are made via the Administration web-based environment and not directly through the API. The API allows interfacing between a customer Desktop Environment and PCI Pal via RESTful Web Services.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
User interface can be customised to accommodate specific user requirements. This work is carried out by the PCI Pal professional services team and can be included within the standard deployment process.

Following suitable training and accreditation from PCI Pal, it is possible to enable a customer's development team to access and administer changes to the service.

Scaling

Independence of resources
For each User (end customer), PCI Pal sets a limit for accessing each component (Web and Telephony) into PCI Pal. An example of this is the number of simultaneous telephone calls allowed for each user. This is not the number of licences, but a maximum peak above the number of licences to allow some burst scenarios. Alerting is used within the platform and the nature of the Cloud service architecture means that additional capacity can be very quickly added when capacity thresholds are reached. Where required and deemed warranted (> 1000 seats), dedicated infrastructure (SBCs and CAPs) can be deployed.

Analytics

Service usage metrics
Yes
Metrics types
Both standard and customised usage reports are available to show volumes, transactions attempted based on different criteria.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
All data at rest is encrypted using AES-256 at a minimum
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Service request to PCI Pal, although by design no data is collected or held by PCI Pal
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • HTML
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Network Availability

PCI Pal offers a target service uptime availability to the Customer as follows: PCI Pal Platform Availability 99.99% average uptime per month.

Service Credits will be calculated as a percentage of the Customer’s monthly licenses cost as indicated below. Where licenses are paid annually this will be the annual cost divided by 12.

99.90% - 100% Uptime - Service Commitment met, no credit due.
99.50% - 99.89% - Minor downtime, 3% credit due.
99.00% - 99.49% - Moderate downtime, 6% credit due.
98.99% or less – Major downtime, 10% credit due.

Custom SLA's may apply to enterprise level contracts (> 1000 seats)
Approach to resilience
Available on Request
Outage reporting
PCI Pal has a system status dashboard that authorised users can login to to access system status, incident updates and planned maintenance. Notifications for all system status events will also be delivered by email to users who have registered to receive such notifications.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Platform is tenanted in the web environment and only allows Admin-level users to have access to the management interfaces of their specific tenant. Admin-Level users can also create sub-tenants within their own tenant and grant sub-tenant admin access to users. Standard Users (Agents) access the system to simply conduct payments for end customers. They are not able to view any of the administrative areas of the system or change or modify the functionality of their payment screens.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ISO 27001, ISO 22301, SOC2, CE+ and PCI DSS compliant. PCI Pal adopts automatic and manual monitoring of systems to adhere to these policies.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration and change requests are logged via our ticketing system (CR).
The CR must include a deployment plan, a rollback plan, a test plan and detail potential risks and impact to service, during the change window.
The CR is peer assessed before being passed for Change Manager and CAB approval.
A CAB is formed to assess and approve CRs on a daily basis.
Once released, the change is tested and signed off.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We have a comprehensive Patch Management Policy that provides guidance on patching and is reviewed periodically. This details the patch management even after a system has been initially hardened and secured, with high or critical risk items to be remediated and patched within 30 days of identification. Additionally, our processes for identifying and managing security vulnerabilities include maintaining an inventory of software components and installing critical or high-security patches within one month of release.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Constant monitoring by ASV.
Centralised logging server is monitored.
Incident Response plan in place with response deadlines within 8 hours. Any service-affecting incidents adhere to the defined Priority Level SLAs for customer communication on top of the Incident Response plan mentioned above.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Incidents can be raised reactively by a customer or proactively via our monitoring tools.
All incidents are logged via our ticketing system (INC).
Incidents are triaged and assessed for impact then prioritised correctly.
Once resolved, the customer is contacted to confirm satisfactory resolution.
Problem tickets (PR) are raised for any necessary follow up investigations (root cause analysis etc) following a high priority incident.
For all high priority incidents, a full fault summary is provided once the investigation is complete.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Amtivo Group Limited T/A British Assessment Bureau Ltd
ISO/IEC 27001 accreditation date
Friday 20 March 2020
What the ISO/IEC 27001 doesn’t cover
Not applicable : Scope covers The Provision of Network Telecommunications Platforms and PCI DSS Telephony Based Solutions to clients globally.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation ISO Certification Limited
ISO 9001 accreditation date
Tuesday 14 March 2017
What the ISO 9001 doesn’t cover
Not applicable : The scope of the Management System applies to the following:-
THE PROVISION OF NETWORK TELECOMMUNICATIONS PLATFORMS AND PCI DSS TELEPHONY BASED SOLUTIONS
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
1 Sequence Cyber Limited
PCI DSS accreditation date
Monday 13 October 2025
What the PCI DSS doesn’t cover
Not applicable : We are a level 1 certified service provider and have been since 2011
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
0a09702f-debb-44b8-9ab3-c6829470ce84
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A1705147-9f7c-410b-a101-848d67af45e8
Other security certifications
Yes
Any other security certifications
  • SOC 2 Type 1
  • ISO 14001:2015
  • ISO 22301

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Plans for positive actions with community groups.
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ccs@pcipal.com. Tell them what format you need. It will help if you say what assistive technology you use.