The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle cardholder information for the major debit, credit, prepaid and ATM cards. All merchants that process credit cards must be PCI compliant.
More information is available on the official PCI website.
http://www.pcicomplianceguide.org
Sigma Voice is a PCI Compliant merchant and can securely accept credit card payments for its services.
Applications built with Sigma Voice are not covered under Sigma Voice ’s compliant status as a merchant.
Sigma Voice recommends that customers seek guidance from their legal counsel for any compliance questions concerning their applications. See the questions below for further details.
According the official PCI website, if a customer application processes, transmits or stores credit, debit or prepaid card data, then they are responsible for ensuring that their application is PCI compliant. Merely using Sigma Voice for customer transactions does not exclude any company from PCI compliance regulations, as PCI compliance obligations apply to all organizations and merchants, regardless of size or number of transactions, that accept, transmit or store any cardholder data.
Many businesses have architected their applications in a PCI compliant manner, while still using Sigma Voice for part(s) of their workflow. The key is to avoid processing, storing and transmitting cardholder data on Sigma Voice. Some techniques that customers have used are as follows:
Verifying a customer’s account using only the last few digits of the PAN via voice, SMS (short messaging services) or DTMF (dual-tone multi-frequency) dialing.
Ensuring that the customer application never transmits entire cardholder data over unencrypted channels including voice, SMS or DTMF.
Not retaining sensitive authentication data after authorization
For telephone operations, “sensitive authentication data” means the CAV2/CVC2/CVV2/CID and/or PIN values that may be taken during a telephone call.
The Payment Application Data Security Standard (PA DSS) applies to payment processors. Sigma Voice recommends that customers familiarize themselves with the PA DSS requirements and security assessment procedures. Use of a PA DSS compliant application by itself does not make an entity PCI DSS compliant, because the application must be implemented in conformity with the overall PA-DSS Implementation Guide.
Also, the list above is not meant to be comprehensive or replace the PCI standards and guidelines described above. Customers will need to ensure that their applications meet those guidelines. As always, Sigma Voice recommends that customers seek guidance from their legal counsel if they have any compliance questions concerning their applications.
According to the PCI website, cardholder data is any personally identifiable data associated with a cardholder. This could be an account number, expiration date, name, address, social security number, etc. All personally identifiable information associated with the cardholder that is stored, processed, or transmitted is also considered cardholder data.
Cardholder Data is a Full magnetic stripe or the PAN plus any of the following items.
Primary Account Number (PAN)
Cardholder Name
Service Code
Expiration Date
What is considered Sensitive Authentication Data (SAD)?
Full Magnetic Stripe Data
CAV2/CVC2/CVV2/CID
PIN/PIN Block
Sigma Voice utilizes a third party to process all credit card payments (a tokenization service). Because of this, Sigma Voice does not store any customer Cardholder Data.
Get started with free personalized support. Create your own custom calling and texting strategy with a Sigma Voice expert.
Check out the Sigma Voice blog to learn about mass calling and texting best practices.
Discover the world of voice messaging as we delve into various types and applications of this innovative communication method. In this blog post, we explore the ins and outs of Sigma Voice's automated voice messaging system, voice messaging on iPhone and Android devices, and WhatsApp voice messaging. Learn how these platforms are revolutionizing the way we connect, share information, and engage with one another, making communication more efficient, personal, and dynamic than ever before.
Your important time-sensitive messages can now be heard with 'one-to-many' automated calling almost instantly by all your customers, employees or members fast.
A complete guide to voice broadcasting which is a technology that allows organizations to quickly and easily deliver important pre-recorded audio messages to 100's or even 1,000's of phones within minutes.