Compliance
Can an AI take a card over the phone and stay PCI compliant?
The short version
Yes, as long as the card never reaches the AI. With card-over-voice, the recording pauses, the customer types their card on their phone keypad, and the digits are tokenized and passed straight to your ServiceTitan payment gateway. The number never enters speech-to-text, the model, transcripts, or logs, which is what keeps it PCI compliant.
The risk: where card numbers usually leak
Taking a card over the phone sounds simple until you think about where the number goes. On a normal call the audio is recorded, and if an AI is on the line, that audio is also transcribed and fed to a model. Now the card number is sitting in a recording, a transcript, and a log, in three places it should never be. That is the PCI problem, and it is why a lot of teams refuse to take cards by phone at all.
The fix is not to be careful with the number. It is to make sure the system never receives it in the first place.
How card-over-voice works
Card-over-voice uses the phone keypad. When it is time to pay, the agent pauses, the customer types the card number on their keypad as tones, and those tones go straight to the payment processor. The customer never reads the number out loud, and the agent never hears it.
This is the same approach call centers have used for years to keep agents away from card data. Pairing it with an AI agent just means the AI steps aside for the payment the way a trained human agent would.
Why the recording has to pause
The detail that makes or breaks compliance is the pause. The moment card entry starts, recording and transcription stop. If the audio keeps rolling while the customer enters the number, you are back to storing card data, even if nobody meant to.
Done right, there is a clean gap in the recording where the payment happened, and nothing sensitive on either side of it.
Tokenization and your ServiceTitan gateway
The keypad tones are turned into a token at the payment processor, and that token, not the card number, is what flows through the rest of the system. The payment posts to your existing ServiceTitan payment gateway, against the right invoice, exactly like the rest of your receivables.
So the raw number exists for a few seconds at the processor and nowhere else. Your records show a payment and a token. The actual card never touches the AI, the transcript, or your logs.
What to ask any vendor who takes cards by phone
If a vendor says their AI can take payments on a call, ask one question: where does the card number live at each step? Walk it from the customer's mouth to the ledger. If the answer ever includes speech-to-text, the model, a transcript, or a log, that is a compliance gap.
Keypad entry, paused recording, and tokenization is the clean answer. That is how FrontDeskCollect takes payment.
Frequently asked
Does the AI ever hear or store the card number?+
No. The customer enters the digits on the keypad while recording is paused. The raw number is tokenized at the payment processor and never lands in the transcript, the model context, or any log.
Where does the payment actually go?+
Straight into your existing ServiceTitan payment gateway, posted against the right invoice, the same way the rest of your receivables already run.
What should I ask a vendor who says they take cards by phone?+
Ask exactly where the card number lives at each step. If it ever passes through speech-to-text, the model, or a log, that is a PCI problem. Keypad entry with tokenization is the clean answer.
See it run on your actual ServiceTitan data.
Book a demo
