The capability underneath both verticals

The agent asks for the money. It never sees the card.

Most voice AI resolves a payment conversation by texting a link and hoping. VoicePay takes the payment on the call — with card entry handled by the telephony layer, so the number never reaches the model, the transcript, the recording, or your staff.

The call path

The caller types. The carrier handles it. The agent never hears it.

The payment node hands the call to the telephony provider's payment session, and takes back a token and a result — not a card number.

Keypad · DTMF
Vault
•••• 4291
Masked
Card numbers are keyed in as DTMF tones and captured inside a separate vault — never reaching your agent.

In detail

HOW IT WORKS

Digits go to the carrier, not the model.

When the flow reaches a payment node, the call hands to the telephony provider's payment session. The caller enters their card on the keypad. Recording pauses for the duration. What comes back to the workflow is a token and a result — never a number. The agent resumes the conversation on the same call with the outcome already known.

WHERE THE DATA GOES

Card data doesn't traverse the systems you operate.

Because the digits go to the payment session rather than the agent, they never land on an agent desktop, in a call recording, or in your application logs — the places that would otherwise pull those systems into scope. What your own assessment concludes depends on your wider environment; we'll walk your assessor through the call path rather than hand you a badge.

GATING

Regulated flows refuse to ask before they're allowed to.

The payment node sits behind branch conditions. In a collections flow that means required disclosures must have fired on that call before the graph can reach capture — and the execution trace records which node ran, in what order, with what result. Compliance review reads a graph, not a prompt.

BEYOND CAPTURE

Tokens, plans, retries, refunds, voids.

Save a card for an arrangement and schedule the installments. Retry a failed charge on a follow-up call. Issue a refund or void a capture inside a returns flow. The payment primitive is a connector like any other, which means it composes with the rest of the workflow instead of living in a separate tool.

Security

Security by architecture, not by promise.

There's no code path in Voicent that can read a card number, because the number is never sent to us. The parties that do touch it are certified for exactly that leg — and we name which.

Card data never enters our systems

Digits are captured inside Twilio's PCI DSS Level 1 environment and passed straight to the payment connector. Voicent sees a masked number, brand, expiry and status — nothing more.

Your application stays outside the boundary

Because capture happens before any of your systems, neither your app nor ours forms part of the cardholder data environment. Confirm your specific SAQ with your acquirer or QSA — it depends on your whole payment estate.

The right party holds each certification

Twilio holds PCI DSS Level 1 for the capture leg; the payment connector holds Level 1, SOC 2 Type 2 and ISO 27001 for the submission leg. Voicent holds none of these, and doesn't need to — it never handles the card.

Read the full detail

Where it runs

A workflow that asks for money·Reselling this to clients?