How
It Works

Most businesses taking card payments over the phone assume they must complete SAQ D — over 300 PCI controls. Most shouldn't. If card data never enters your phone system and your agents cannot hear or see full PANs, you can typically qualify for SAQ A — just 22 controls. The difference? Months of work versus weeks. This is achieved through DTMF masking: customers enter card numbers via keypad while tones are securely masked. No card data touches your environment.

Instant Processing
Bank-Grade Security
Cost Effective

Solution Overview

Discover how our solution can help your business

Trusted by businesses of all sizes to protect their staff, customers and business brand

Online 4 Baby
/images/logos/customers/ophelos.png
/images/logos/customers/optoma.png
Osbourn Lesuire
Pinnacle Group
Ready Bus
Stephen James
Total Tiles
Trinity Hall College
We Power Your Car
Arcacia Learning
Believers Loveworld
Caths College Cambridge
CITB
Clinicians Choice Denmat
CMCCS
DPG Learn
Dunster House
Exclusive Holidays
Grouptyre Wholesale Ltd
Howard Kennedy
ICS Learn
IStructE
/images/logos/customers/panda.png
PHE Inc
Roundtable
Royal College of Radiologists
Stonebridge Insurance
The Nursery Store
University College School
Warby Parker
Worthing Homes
Archway Cards
Audio Technica
British American Tobacco
Clinnical Partners
Greeting Card Company
Online 4 Baby
/images/logos/customers/ophelos.png
/images/logos/customers/optoma.png
Osbourn Lesuire
Pinnacle Group
Ready Bus
Stephen James
Total Tiles
Trinity Hall College
We Power Your Car
Arcacia Learning
Believers Loveworld
Caths College Cambridge
CITB
Clinicians Choice Denmat
CMCCS
DPG Learn
Dunster House
Exclusive Holidays
Grouptyre Wholesale Ltd
Howard Kennedy
ICS Learn
IStructE
/images/logos/customers/panda.png
PHE Inc
Roundtable
Royal College of Radiologists
Stonebridge Insurance
The Nursery Store
University College School
Warby Parker
Worthing Homes
Archway Cards
Audio Technica
British American Tobacco
Clinnical Partners
Greeting Card Company

How It Works

SAQ A vs SAQ D · DTMF Masking · Fewer Controls, Lower Cost

Why Most Businesses Think They Need SAQ D

Under PCI DSS, if your staff hear, see, retype, or write down card data — or you use virtual terminals where card details are entered into your systems — your environment is in scope. The PCI Security Standards Council requires merchants in that situation to validate against the full set of controls. SAQ D (Self-Assessment Questionnaire D) for PCI DSS v4.0.1 has over 300 requirements for merchants. That means extensive security measures, documentation, training, and ongoing monitoring.

When You Can Qualify for SAQ A Instead

If cardholder data never enters your systems and your people never have access to full PANs (Primary Account Numbers), you may qualify for SAQ A — just 22 controls (the shortest self-assessment). Paytia achieves this by ensuring card data is captured via DTMF masking: the customer enters digits on their keypad, tones are masked, and only your payment processor receives the data. Your agents stay on the line to help but never hear or see the card number.

DTMF Masking in Practice

DTMF (Dual-Tone Multi-Frequency) masking means the keypad tones are replaced or suppressed so that call recordings and anyone on the call cannot recover the card number. The payment is still authorised in the normal way by your acquirer or payment provider. Because your business never possesses, processes, or stores card data, your PCI scope is dramatically reduced — and so is the cost and effort of compliance.

The Cost of Virtual Terminals and Staff Handling

Virtual terminals from banks and manual entry by staff put card data in your environment. That triggers the need for network segmentation, access controls, training programmes, secure disposal, logging, and annual assessments. The result is significant cost: security infrastructure, training, audits, and the risk of fraud and breach. Paytia removes that requirement — reducing compliance cost, fraud risk, training burden, and security red tape.

Less Work, Fewer Controls

With Paytia, card data does not touch your people, processes, or systems. You avoid the heavy lift of SAQ D: no need to prove hundreds of controls, maintain complex policies, or budget for evolving PCI DSS changes. Many customers achieve a substantial reduction in scope and move to a simpler validation path, with predictable annual cost and less operational overhead.

No Card Data, No Scope

Paytia is a PCI-DSS Level 1 certified payment capture provider. Our service is designed so that card data never enters your call recordings, databases, or agent workflows. That means you can focus on running your business instead of maintaining the security measures required when card data is present in your environment.

300+

SAQ D controls vs 22 for SAQ A

Level 1

PCI-DSS certified

Weeks

Not months — simpler validation

Frequently Asked Questions

SAQ D (Self-Assessment Questionnaire D) is the most comprehensive PCI DSS self-assessment. It applies when cardholder data is in your environment — for example when staff hear or see card numbers, use virtual terminals to key in card data, or when card data passes through or is stored on your systems. The PCI Security Standards Council publishes SAQ D with over 300 requirements for merchants (PCI DSS v4.0.1). Meeting them means significant security measures, documentation, and ongoing validation. See our PCI DSS compliance page for how Paytia reduces scope.
SAQ A is the shortest PCI DSS self-assessment. It applies when your organisation does not store, process, or transmit cardholder data and has outsourced all cardholder data functions to a compliant third party. If card data never enters your phone system and your agents cannot hear or see full PANs — for example because of DTMF masking — you may qualify for SAQ A — just 22 controls (vs over 300 for SAQ D).
DTMF masking means that when a customer enters their card number using their phone keypad, the tones are masked or suppressed so that they cannot be used to recover the card number on your systems or call recordings. The payment is still sent securely to your payment processor for authorisation. Because your environment never receives the card data, it stays out of PCI scope. Learn more in our DTMF suppression and keypad payments solution pages.
When staff hear, see, retype, or write down card data — or when you use a virtual terminal that requires card data to be entered into your systems — your business is in scope for PCI DSS. That typically means SAQ D: training, access controls, logging, secure disposal, network security, and annual assessments. The cost includes security infrastructure, audit fees, training programmes, and the risk of fraud or breach. Paytia removes card data from your environment so you can avoid that burden. See agent-assisted payments and PCI DSS compliance for how we help.
When card data never enters your environment, your staff cannot accidentally expose it, and there is nothing to steal from your systems. That reduces fraud risk and the need for PCI-specific staff training and monitoring. You also avoid the ongoing cost of maintaining the security controls required when card data is present. See our agent-assisted payments and support centre for how we support implementation.
The PCI Security Standards Council (pcisecuritystandards.org) publishes the PCI DSS standard and SAQ documents. SAQ eligibility and requirement counts are set by the Council; PCI DSS v4.0.1 and the related SAQ bulletins are the current reference for merchants. On our site, see PCI DSS compliance and PCI DSS (legal) for how Paytia helps reduce scope.

Paytia documentation and product pages

The services and topics mentioned on this page are described in detail across our product and documentation site. Use the links below to explore.

Product & solutions

Documentation & resources

When Card Data Is in Your Environment

Virtual terminals, staff hearing or seeing card numbers, and manual entry put you in scope for the full set of PCI DSS controls. With DTMF masking, card data never enters your systems.

With card data in your environment (SAQ D)

  • 300+ PCI DSS requirements to satisfy
  • Security policies, training, and access controls
  • Ongoing monitoring, logging, and reviews
  • Higher cost and more red tape

With Paytia — no card data (SAQ A eligible)

  • Just 22 controls; simplest self-assessment
  • No card data to train staff on or protect
  • Reduced fraud risk and compliance cost
  • Weeks of effort, not months