How to Take Payments on Avaya: PCI-Compliant Contact Centre Payments

By Shuttle Team, February 28, 2026

Where Card Payments Fit in an Avaya Contact Centre

Avaya has been the backbone of enterprise contact centres for decades. Avaya Aura, Avaya OneCloud CCaaS, and the Communication Manager platform handle millions of calls daily across some of the largest contact centre operations in the world.

Avaya is not a payment processor, though. If your Avaya deployment has no secure capture step, taking a card during a live call exposes your agents, recordings, and infrastructure to PCI scope.

That matters most in heavily regulated industries (financial services, insurance, utilities, government), where PCI compliance is not optional and audit scrutiny is intense.


The Payment Gap in Avaya

Avaya environments range from fully on-premises Aura deployments to hybrid architectures mixing on-prem and cloud, to the newer Avaya Cloud Office and OneCloud CCaaS platforms. Where a deployment has no secure capture step, the same needs come up across all of them:

A secure capture step. Avaya can route calls, queue them, record them, and provide IVR menus. Without a secure capture step, card digits a customer keys in during a call reach the agent's audio and the call recording.

Recording infrastructure. Whether you record through Avaya Workforce Engagement or a third-party recorder like Verint or NICE, the capture step has to keep card data out of the recorded audio.

Legacy infrastructure complicates payments. Many Avaya deployments run on older infrastructure: Session Border Controllers, Avaya Media Servers, proprietary SIP implementations. Bolting card capture directly onto this stack is not trivial and varies significantly between deployments.

Platform changes. If you move platforms later, whether to Avaya's cloud offerings or to another contact centre platform, a deeply coupled, Avaya-specific payment integration has to be rebuilt. A payment approach that sits outside the contact centre platform travels with you.


How Shuttle Adds Payments to Avaya

Shuttle adds PCI-compliant card capture to your Avaya payment flows. When the customer is ready to pay, the card is captured through Twilio Pay and passed to Shuttle's PCI DSS Level 1 environment, and the card data never reaches your Avaya recordings, transcription, or your agents.

The setup is light. It runs on Twilio Pay, so you need to be a Twilio customer, and you build a small integration on your side. Shuttle ships the secure PCI capture, payment links, IVR, and the payment APIs; what it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call wired for Avaya specifically. So the part you build is small: pass the payment amount to Shuttle through its API (the minimum data we need), connect the secure capture into your Avaya call flow over Twilio, and add your own agent screen if your workflow needs one. If that fits, book a call and we will scope your exact setup. There is practical detail in the "What to Expect" section further down.

Secure card capture (voice)

When it is time to pay, the card is captured in a secure, PCI DSS Level 1 call via Twilio Pay. The customer enters their card details on their phone keypad, and the digits pass from Twilio Pay to Shuttle's PCI DSS Level 1 environment. They never reach your Avaya recordings, your recorder (Verint, NICE, or Avaya Workforce Engagement), or your agents. See the Twilio IVR & Agent Assist payment docs for the technical flow.

This is the most turnkey path. Shuttle generates payment links and sends them via SMS or email, including mid-call to a customer who is still on the line. The customer completes payment on a secure hosted page, and confirmation is returned in real time. Shuttle provides the link interfaces via its API, and links work even with gateways that don't support voice capture. See the Payment Links docs.

Agent experience

For voice, the agent triggers the capture and sees the result without ever handling card data. Shuttle does not ship a pre-built agent screen or input UX for Avaya, so you build that minimal piece against Shuttle's APIs: trigger the capture, pass the amount, and show the result in your own agent screen if your workflow needs one. There is more in the "What to Expect" section below.


How a voice payment works

  1. Call is handled normally. The customer calls in, is routed through Avaya, and speaks with an agent. The conversation proceeds as usual.

  1. Payment is needed. The agent identifies that payment is required (a bill, a premium, a balance, a booking) and triggers payment from your agent interface.

  1. Card is captured securely. The card is captured in a PCI DSS Level 1 call via Twilio Pay. The customer enters their card number, expiry, and CVV on the keypad, and the digits pass from Twilio Pay to Shuttle's PCI DSS Level 1 environment, never your Avaya recordings.

  1. Transaction is processed. Shuttle routes the payment to the appropriate PSP (Stripe, Adyen, Worldpay, Checkout.com, or any of 30+ supported gateways). Provider selection is configured per merchant and payment type.

  1. Agent sees the result. The transaction result (approved, declined, error) is returned in real time via webhook. A tokenised reference is available for CRM logging.

  1. Call continues. The agent confirms payment to the customer and continues the conversation.


Multi-PSP Support

Large enterprises and regulated industries typically have existing, long-standing PSP relationships, and migrating to a new payment gateway is rarely an option.

Shuttle supports 30+ PSPs for voice and allows provider selection to be configured per merchant or per business unit. This is critical for Avaya environments that serve multiple brands or divisions.

Typical routing configurations for Avaya deployments:

  • Different business divisions use different PSPs based on existing contracts

  • Backup gateway: if the primary gateway returns errors, you can move the affected payment types to another connected gateway. There is no automatic failover, and saved cards stay with the gateway that stored them, so repeat payments on stored cards will not run through the second one

Your existing payment relationships stay intact. Switching processors later is configuration, not a re-integration, though saved cards stay with the gateway that stored them. One caveat for voice specifically: a small number of gateways (for example Braintree) don't permit the raw card data to be passed to them, so they don't work for voice capture, though they do work for payment links.


PCI Compliance

Shuttle is a PCI DSS Level 1 certified Service Provider.

For Avaya contact centres, this changes the compliance picture fundamentally:

Without Shuttle: Card data passes through your Avaya infrastructure, telephony, recording, agent desktops, and network. Your entire environment is in PCI scope. You face SAQ-D, penetration testing, and significant ongoing compliance costs. For on-premises Avaya deployments with complex infrastructure, this is particularly burdensome.

With Shuttle: Because the card is captured in the secure Twilio Pay call, card data never enters your Avaya environment. Recordings contain no card data. Agents never hear card numbers. Merchants complete SAQ-A, the lightest PCI self-assessment, and platforms complete SAQ-D; your acquirer confirms which form applies to you. Full compliance documentation is in the security docs.

This is especially important for Avaya customers in regulated industries where compliance audits are frequent and thorough. The annual cost difference between SAQ-A and SAQ-D is substantial.

Voice payments cost $49 per live instance per month, plus from $0.20 per transaction, falling with volume, billed through your Twilio account, with no per-seat fees. See pricing.


For Solution Providers and Avaya Implementation Partners

If your team deploys Avaya for clients, as a partner or a system integrator, Shuttle is the payment layer you deliver alongside the rest of the implementation. Each client keeps their own merchant account and their own gateway, and your side integrates once, so payments are not rebuilt for every engagement and client money never lands in yours.

Shuttle's voice capture runs on Twilio Pay, where Shuttle is Twilio's chosen provider to enable Twilio Pay for many payment gateways. Shuttle is not a pre-packaged Avaya plugin, so your team builds a small integration between Avaya and Shuttle, and voice deployments need a Twilio account. For partnership conversations, book a discovery call.

Use Cases

Financial Services

Banks and building societies running Avaya handle card payments for loan repayments, account top-ups, and service fees. PCI compliance in financial services is subject to FCA oversight, and regulators increasingly scrutinise how card data is handled in contact centres. Shuttle keeps card data out of the contact centre.

Insurance

Premium collection, policy renewals, and claims payments happen over the phone daily. Shuttle allows agents to collect payments mid-call while limiting PCI scope, without breaking the conversation, which is critical for maintaining retention during renewal calls.

Utilities

Utility companies processing bill payments through Avaya contact centres need high-volume, reliable payment capture. Shuttle handles automated IVR payments for self-service callers and agent-assisted payments for more complex interactions, all via the same Twilio Pay capture.

Government and Public Sector

Local councils, NHS trusts, and government agencies running Avaya can add secure payment collection for council tax, parking fines, prescription charges, and service fees. This simplifies the procurement and audit process significantly.


What to Expect

Shuttle is a payment layer you connect to your stack, not a pre-packaged Avaya plugin. Here is the honest detail so there are no surprises on the call:

  • It runs on Twilio Pay today. Shuttle's voice capture uses Twilio Pay, where Shuttle is Twilio's chosen provider to enable Twilio Pay for many payment gateways, so you need to be a Twilio customer. Shuttle works with Twilio today, and any carrier coming soon.

  • You build a small integration, not a payment system. Shuttle ships the secure PCI capture, IVR, payment links, and payment APIs. What it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call for Avaya specifically. So you build that minimal glue: pass the amount to Shuttle via its API (the minimum data we need), connect the capture into your Avaya call flow over Twilio, and add your own agent screen if your workflow needs one. It is light.

  • Point-of-payment capture is what is live. Securely capturing the card at the moment of payment works today. Shuttle staying present across the entire conversation is not available today, and Shuttle does not ship call hand-back after payment out of the box. What happens to the caller after payment is part of the call flow you build in Twilio. Works with Twilio today, and any carrier coming soon.

Payment links are the most turnkey path and need the least build. Many teams start there and add voice capture later.


Frequently Asked Questions

Does Shuttle have a native Avaya integration?

Not today. Shuttle's voice capture runs on Twilio Pay, and you invoke that setup rather than installing a Shuttle app in your Avaya stack. You'll need to be a Twilio customer and to build a small integration on your side (pass the amount to Shuttle's API and wire the secure capture into your call flow over Twilio). Shuttle works with Twilio today, and any carrier coming soon.

Does this require Twilio?

Yes, today. The secure card capture runs via Twilio Pay, where Shuttle is Twilio's chosen provider to enable Twilio Pay for many payment gateways. Shuttle works with Twilio today, and any carrier coming soon.

What if we are migrating away from Avaya?

The payment leg runs through Twilio Pay, not coupled into your Avaya infrastructure, so the approach is independent of your telephony platform. If you are migrating from Avaya to Genesys, Five9, Amazon Connect, or another CCaaS platform, your Shuttle setup is not Avaya-specific and travels with you (provided you remain a Twilio customer for voice capture).

How does Shuttle keep card data out of Avaya's call recording?

The card is captured in a separate, secure Twilio Pay call rather than in the Avaya-recorded audio, so your recording platform (Avaya Workforce Engagement, Verint, NICE, or another solution) never receives card data. No pause-and-resume configuration is needed.

Yes. Many teams use links only, sent via SMS or email, including mid-call. Links are the most turnkey part of Shuttle and work with gateways that don't support voice capture.

Can we try it before committing?

Yes. You can build a proof of concept against Shuttle's sandbox gateway and demo app to see the IVR flow, then move to a compatible production gateway when you're ready.

What is the cost?

Voice costs $49 per live instance per month, plus from $0.20 per transaction, falling with volume, billed through your Twilio account, with no per-seat fees. See pricing.



Get Started

If you are a merchant taking payments on Avaya rather than building for clients, talk to us about your deployment, or see how Voice Checkout works.

Talk to us

See how Shuttle can power payments for your platform: multi-PSP, multi-channel, white-label.

Book a Call