Secure phone payments: PCI DSS compliant call handling
How DTMF masking and dual-tone suppression let you take card payments by phone without PCI scope creep.
By the Telappliant team

Taking card payments by phone without proper controls is one of the fastest ways to fail a PCI DSS assessment and expose customers to fraud. Secure phone payment technology solves this by keeping card data out of your systems and your staff's hands entirely.
The problem with the traditional approach
An agent asking a customer to read out their card number, typing it into a terminal or writing it on a note, creates cardholder data everywhere: in call recordings, in browser history, on paper, in emails. Every one of those is now in PCI DSS scope and a potential breach point.
How DTMF masking works
The customer enters their card number, expiry and CVV using their phone keypad while still talking to the agent. The tones are intercepted and masked before they reach the agent's headset or any recording, and sent directly and securely to the payment processor. The agent hears silence or a flat tone instead of the digits, so they never see or hear the card data at all.
What PCI DSS v4.x requires around telephone payments
- Cardholder data must not be stored unless absolutely necessary, and never in plain text
- Call recordings that could capture spoken card numbers must be prevented or the recording paused
- Access to any system that does handle card data must be logged and restricted
- Multi-factor authentication is required for administrative access to payment systems
- Regular vulnerability scanning and penetration testing apply to any in-scope systems
Business benefits beyond compliance
- Dramatically reduced PCI DSS scope, often removing the need for card data controls across most of the business
- Lower fraud risk, since agents and recordings never hold card details to be stolen
- Customer confidence, particularly for higher-value or repeat transactions
- Faster PCI assessments and lower annual compliance costs
Choosing a solution
Look for DTMF masking that integrates with your existing cloud phone system rather than a separate parallel process, confirm it is certified against current PCI DSS requirements, and check it works across mobile and remote agents, not just office desk phones.



