PCI Pal® Automated Secure Payments
PCI Pal® Automated Secure Payments,(IVR, Chatbots, AI): Offer 24/7 secure self-service payments with PCI Pal. Whether using DTMF, voice recognition, or secure digital links, customers are guided through a simple,
compliant process that mirrors agent-led support.
Features
- De-scope for Contact Centre from PCI DSS Requirements
- Multiple payment options to meet accessibility requirements
- Automated Payments enables customers to make secure, PCI-compliant payments
- Works with chatbots, voice bots, IVRs, and virtual agents
- Gateway Agnostic: Use your existing payment gateway
- Compatible with all leading UCaaS and CCaaS vendors
Benefits
- Full PCI DSS Compliance: No cardholder data enters your systems.
- Provide peace of mind for your customers
- Improve efficiency: Reduces agent workload by automating routine payment interactions
- Increased Payment Completion Rates: Support more first-time payment success
- "Always on" payment options are fast, convenient, improving customer satisfaction
- Boosts payment completion rates by offering frictionless self-service journey
- Improve customer experience, enabling them to utilise channel they prefer
- Increase revenue by offering more payment options to customers
- Intuitive for customers with easy-to-follow instructions
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 6 7 3 0 4 0 1 4 3 3 0 4 6 4
Contact
PCI-PAL (U.K.) LIMITED
David Swift
Telephone: +44 (0)330 131 0340
Email: ccs@pcipal.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Contact centre
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Can be integrated with payment and CRM applications
Can be integrated as part of a contact centre or telecoms offering - Cloud deployment model
- Private cloud
- Service constraints
- The service is agnostic to all connecting components: Telephony, Applications and Payment Gateway.
- System requirements
-
- Optional Access to Browser / Interfacing Desktop Application
- Customer environment requires TLS 1.2 to connect to PCI Pal
- Browsers should adhere to supported list
User support
- Email or online ticketing support
- Yes
- Support response times
- As per standard SLA
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
Priority 1 (Critical)
Contact Channel: Telephone
Response Time: 1 hour
Definition: Complete loss of the Service to all users within one or more sites or business units.
Priority 2 (High)
Response Time: 4 hours
Definition: Significant degradation of the Service affecting more than 30% of users, calls or payment attempts within one or more sites or business units.
Priority 3 (Medium)
Response Time: 24 hours
Definition: Degradation of the Service affecting less than 30% of users, calls or payments within one or more sites or business units OR widespread loss of ancillary functionality that does not prevent processing of payments, such as post transaction logic.
Priority 4 (Low)
Response Time: 48 hours
Definition: Localised technical issues affecting single users.
Priority 5 (Very low)
Response Time: 72 hours
Definition: Transient faults that have been ameliorated prior to being reported to PCI Pal or non-functional issues such as UI defects.
Dedicated Customer Success Managers (Technical Account Managers ) are assigned to deployments exceeding 150 agents
Custom SLA's may be agreed for enterprise customers (>1000 seats) - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
The service is very simple for a user to use and the standard train-the-trainer and User Acceptance Testing can be completed in a single day. We are able to provide both remote, on-site and on-line learning packages. We can work alongside Training Departments for larger organisations or where more custom integrations have been created, to help build internal training programs for users.
The project will also include either on-site or remote go live support. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- No data is collected or held by PCI Pal.
- End-of-contract process
- PCI Pal will contact the user at the end of the contract to determine their requirements and agree a new term or exit process if required
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation can be provided in various format to aid accessibility.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Page elements are resized accordingly to work with mobile devices
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Services are configured to capture card data and additional fields required for payment processing. Solution and service interface will be subject to scoping.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- NVDA, Dragon, Read/Write Gold, JAWS, Zoom Text.
- API
- Yes
- What users can and can't do using the API
-
By integrating a Billing System or Application via the API, the user experience can be enhanced by passing necessary data directly to PCI Pal without the need for manual input.
Administrative Users have the ability to configure the service including integration points and configuration of the User Interface. This setup is usually performed by PCI Pal in the initial deployment of the service but full training is available should the customer wish.
Changes are made via the Administration web-based environment and not directly through the API. The API allows interfacing between a customer Desktop Environment and PCI Pal via RESTful Web Services. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
User interface can be customised to accommodate specific user requirements. This work is carried out by the PCI Pal professional services team and can be included within the standard deployment process.
Following suitable training and accreditation from PCI Pal, it is possible to enable a customer's development team to access and administer changes to the service.
Scaling
- Independence of resources
- For each User (end customer), PCI Pal sets a limit for accessing each component (Web and Telephony) into PCI Pal. An example of this is the number of simultaneous telephone calls allowed for each user. This is not the number of licences, but a maximum peak above the number of licences to allow some burst scenarios. Alerting is used within the platform and the nature of the Cloud service architecture means that additional capacity can be very quickly added when capacity thresholds are reached. Where required and deemed warranted (> 1000 seats), dedicated infrastructure (SBCs and CAPs) can be deployed.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Both standard and customised usage reports are available to show volumes, transactions attempted based on different criteria.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- All data at rest is encrypted using AES-256 at a minimum
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Service request to PCI Pal, although by design no data is collected or held by PCI Pal
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- HTML
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Network Availability
PCI Pal offers a target service uptime availability to the Customer as follows: PCI Pal Platform Availability 99.99% average uptime per month.
Service Credits will be calculated as a percentage of the Customer’s monthly licenses cost as indicated below. Where licenses are paid annually this will be the annual cost divided by 12.
99.90% - 100% Uptime - Service Commitment met, no credit due.
99.50% - 99.89% - Minor downtime, 3% credit due.
99.00% - 99.49% - Moderate downtime, 6% credit due.
98.99% or less – Major downtime, 10% credit due.
Custom SLA's may apply to enterprise level contracts (> 1000 seats) - Approach to resilience
- Available on Request
- Outage reporting
- PCI Pal has a system status dashboard that authorised users can login to to access system status, incident updates and planned maintenance. Notifications for all system status events will also be delivered by email to users who have registered to receive such notifications.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Platform is tenanted in the web environment and only allows Admin-level users to have access to the management interfaces of their specific tenant. Admin-Level users can also create sub-tenants within their own tenant and grant sub-tenant admin access to users. Standard Users (Agents) access the system to simply conduct payments for end customers. They are not able to view any of the administrative areas of the system or change or modify the functionality of their payment screens.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- ISO 27001, ISO 22301, SOC2, CE+ and PCI DSS compliant. PCI Pal adopts automatic and manual monitoring of systems to adhere to these policies.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration and change requests are logged via our ticketing system (CR).
The CR must include a deployment plan, a rollback plan, a test plan and detail potential risks and impact to service, during the change window.
The CR is peer assessed before being passed for Change Manager and CAB approval.
A CAB is formed to assess and approve CRs on a daily basis.
Once released, the change is tested and signed off. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We have a comprehensive Patch Management Policy that provides guidance on patching and is reviewed periodically. This details the patch management even after a system has been initially hardened and secured, with high or critical risk items to be remediated and patched within 30 days of identification. Additionally, our processes for identifying and managing security vulnerabilities include maintaining an inventory of software components and installing critical or high-security patches within one month of release.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Constant monitoring by ASV.
Centralised logging server is monitored.
Incident Response plan in place with response deadlines within 8 hours. Any service-affecting incidents adhere to the defined Priority Level SLAs for customer communication on top of the Incident Response plan mentioned above. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Incidents can be raised reactively by a customer or proactively via our monitoring tools.
All incidents are logged via our ticketing system (INC).
Incidents are triaged and assessed for impact then prioritised correctly.
Once resolved, the customer is contacted to confirm satisfactory resolution.
Problem tickets (PR) are raised for any necessary follow up investigations (root cause analysis etc) following a high priority incident.
For all high priority incidents, a full fault summary is provided once the investigation is complete. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo Group Limited T/A British Assessment Bureau Ltd
- ISO/IEC 27001 accreditation date
- Friday 20 March 2020
- What the ISO/IEC 27001 doesn’t cover
- Not applicable : Scope covers The Provision of Network Telecommunications Platforms and PCI DSS Telephony Based Solutions to clients globally.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Tuesday 14 March 2017
- What the ISO 9001 doesn’t cover
-
Not applicable : The scope of the Management System applies to the following:-
THE PROVISION OF NETWORK TELECOMMUNICATIONS PLATFORMS AND PCI DSS TELEPHONY BASED SOLUTIONS - Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- 1 Sequence Cyber Limited
- PCI DSS accreditation date
- Monday 13 October 2025
- What the PCI DSS doesn’t cover
- Not applicable : We are a level 1 certified service provider and have been since 2011
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 0a09702f-debb-44b8-9ab3-c6829470ce84
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- A1705147-9f7c-410b-a101-848d67af45e8
- Other security certifications
- Yes
- Any other security certifications
-
- SOC 2 Type 1
- ISO 14001:2015
- ISO 22301
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-