PCI DSS 4.0.1 · Cyber Essentials Plus

Take fees and repayments. Keep card data out of your business.

Lenders handle card payments at every step — application and arrangement fees, scheduled repayments, ad-hoc and settlement payments. Paytia captures each one on its PCI DSS 4.0.1 platform, so the borrower's card never reaches your agents, systems or call recordings.

Where card data gets into a lending business

The moment a card number is spoken to an agent, typed into a CRM, or passed through a chat, it drags your business into PCI DSS scope and puts sensitive data where it can be intercepted.

Fees taken at the point of sale

Arrangement and broker fees are often collected on the call that closes the loan. That is the moment a card number is most likely to be read aloud, written down, or typed into a system that was never built to hold it.

Repayment schedules that outlive the call

A repayment plan runs for months or years. If the card details behind it are stored in your systems, so is the risk — for the whole term, across every record you hold.

Collections moving to chat and AI

More borrower contact now starts in chat or with an automated assistant. Card details entered there can land in a transcript, a log or a model's context unless capture is handed off properly.

Regulated records, higher stakes

Lending files already hold affordability data, credit history and personal detail. Combine that with payment data and a single breach exposes both — which is a conduct problem, not only an IT one.

Fees in. Repayments in. Settlements in.

Whether a borrower is paying an upfront fee or a monthly instalment, the risk is identical — and so is the fix. Paytia removes the card from that path entirely.

01

Application & arrangement fees

Take upfront and broker-taken fees over the phone, by payment link, or on a hosted checkout. No card digits reach the agent or your CRM.

02

Scheduled repayments & instalments

Collect monthly repayments across web, chat, IVR or an AI assistant. Tokenise once and reuse it for the schedule — the raw card is never stored by you.

03

Ad-hoc & settlement payments

Handle early settlements, catch-up payments and one-off amounts through whichever channel suits the borrower.

Five ways to collect, each secure by default

Secure telephone payments are the foundation. Everything else layers on through the same central API, so every channel a borrower uses carries the same protection — nothing to bolt on.

01

Advanced payment links

A branded, single-use link by SMS, email or QR for a fee or a repayment. The borrower pays on a Paytia-hosted page — nothing sensitive touches your systems.

Tokenised · logged

02

Advanced web checkout

A hosted, embeddable checkout for repayments and settlements on your borrower portal. Brandable fields, no cardholder data in your page or servers.

Hosted capture · alerting

03

Agent capture assist

On a call, the borrower keys their card on their own phone or a hosted form. The agent stays on the line and guides them, but never sees or hears the digits.

Descoped agents · full call audit trail

04

AI-bot payment handling

Let a voice or chat assistant run collections at scale. Capture is handed to Paytia at the payment step, so card data never enters the model, transcript or logs.

Isolated from the AI network

05

Secure capture in chat

Take payment inside a live chat or messaging session with a secure in-session capture step. The borrower stays in the conversation; the card stays out of it.

No card number in the transcript

06

One central common API

Every product above shares a single integration and tokenised result. Add channels without new contracts, new certifications or a new attack surface.

One integration · one security posture

On by default, not an add-on

The same protections apply to every product on the platform, whichever channel the borrower pays through.

PCI DSS 4.0.1 capture

Card data is captured and processed on Paytia's certified platform, keeping your agents, systems and portals out of scope across every channel.

Man-in-the-middle prevention

Hosted capture, integrity checks and secure transport stop card data being intercepted, injected or replayed between the borrower and Paytia.

Logging & alerting

Every transaction and capture event is logged with real-time alerting — a full audit trail for compliance, disputes and monitoring.

Is this you?

Answer yes to any one of these and card data is entering your business today.

?Do you take card payments over the phone?
?Do borrowers read card details aloud to your agents?
?Do you collect through live chat, messaging or an AI assistant?
?Do you send payment requests by SMS, email or QR code?
?Do you record calls that might capture spoken card numbers?
?Do you want to shrink your PCI DSS scope and audit burden?

Frequently asked questions

Can borrowers pay an arrangement fee without reading their card to an agent?+

Yes. The borrower keys their card into their own phone keypad while your agent stays on the line. The tones are masked, so the agent never hears or sees the digits — they just see whether the payment went through. It works the same way whether the fee is taken by your own team or by a broker. See DTMF masking for how it works on the call.

How do scheduled repayments work if we never store the card?+

The card is captured once and swapped for a token — a reference that is useless to anyone who intercepts it. The schedule runs against that token, so monthly instalments collect without the raw card number ever being stored by you. If a borrower wants to change the card, they re-enter it themselves and a new token replaces the old one. More on tokenisation.

Does this cover early settlements and catch-up payments?+

Yes. Ad-hoc amounts are the same mechanism as any other payment — a settlement figure, a missed instalment, or a one-off charge can be taken on the phone, by payment link, or through a hosted checkout, whichever suits the borrower. Nothing about the amount or the timing changes how the card is captured.

We use a broker network. Can they take fees without pulling us into scope?+

They can. Each party is scoped by their own store ID and API key, so a broker sees their own transactions and nothing else. The card data is captured by Paytia in every case, which means neither your systems nor the broker's are handling it.

What about payments taken in live chat or by an AI assistant?+

Capture is handed to Paytia at the payment step. The card data never enters the chat transcript, the model or the logs — the conversation carries on around it. That matters for collections, where a lot of contact now starts in chat. See conversational and AI payments.

Do we have to move everything at once?+

No, and most lenders don't. Secure telephone payments are the usual starting point because agent-taken calls carry the most risk. Payment links, web checkout, chat and AI capture sit on the same integration, so adding a channel later is configuration rather than a new project.

Lend with confidence. Stay out of scope.

Tell us how your borrowers pay today — on the phone, through a portal, in chat, or all three. We'll show you what changes and what doesn't.