boost.ai builds conversational AI for the enterprise, with a particularly strong footprint across banking, insurance, financial services, and public sector. Founded in Norway and widely deployed across the Nordics and beyond, boost.ai powers virtual agents that handle everything from account queries and loan applications to insurance renewals and public service requests. Its compliance posture is serious: SOC 2 Type II, ISO 27001, ISO 27701, and ISAE 3402 certifications make it a credible choice in regulated industries where audit requirements are non-negotiable.
Payment capability is a different matter. boost.ai handles the conversation exceptionally well but has no native payment product of its own. For PCI-compliant payment capture, boost.ai relies on third-party integrations, including an established contact-centre payments partner and a Vipps connector for Nordic markets. That works in many contexts, but banks and insurers running contact centres at scale often need more flexibility: a broader choice of payment gateways, per-client gateway setup across a multi-tenant portfolio, the ability to bring their own acquirer, and a consistent compliance posture across channels.
This guide is for regulated-sector teams running boost.ai virtual agents who need to add payment capture, and it explains exactly what that involves with Shuttle today. If your compliance team needs to minimise PCI scope while your operations team needs multi-PSP flexibility, this is the pattern that achieves both.
How Shuttle Adds Payments to boost.ai
Shuttle adds PCI-compliant card capture to your boost.ai payment flows. When the customer is ready to pay, the card is captured through Twilio Pay and passed to Shuttle's PCI DSS Level 1 environment, and the card data never reaches your boost.ai recordings, transcription, or your agents.
The setup is light. It runs on Twilio Pay, so you need to be a Twilio customer, and you build a small integration on your side. Shuttle ships the secure PCI capture, payment links, IVR, and the payment APIs; what it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call wired for boost.ai specifically. So the part you build is small: pass the payment amount to Shuttle through its API (the minimum data we need), connect the secure capture into your boost.ai call flow over Twilio, and add your own agent screen if your workflow needs one. If that fits, book a call and we will scope your exact setup. There is practical detail in the "What to Expect" section further down.
Secure card capture (voice)
When it is time to pay, the card is captured in a secure, PCI DSS Level 1 call via Twilio Pay. The customer enters their card details on their phone keypad, and the digits pass from Twilio Pay to Shuttle's PCI DSS Level 1 environment. They never reach your boost.ai deployment, your call recordings, your CRM, your agents, or the conversational LLM. See the Twilio IVR & Agent Assist payment docs for the technical flow.
Payment Links
This is the most turnkey path. Shuttle generates payment links and sends them via SMS or email, including mid-conversation. The customer taps the link, enters card details on a secure hosted page served from Shuttle's PCI-certified environment, and confirmation is returned in real time. Shuttle provides the link interfaces out of the box, and links work even with gateways that do not support voice capture. See the Payment Links docs.
Agent experience
For voice, the agent triggers the capture and sees the result without ever handling card data. Shuttle does not ship a pre-built agent screen or input UX for boost.ai, so you build that minimal piece against Shuttle's APIs: trigger the capture, pass the amount, and show the result in your own agent screen if your workflow needs one. There is more in the "What to Expect" section below.
The Payment Challenge for boost.ai Agents
boost.ai's architecture separates conversation intelligence from back-end execution cleanly, which is one of its strengths. That same separation means payment capture has to be handled by an external layer rather than natively within the platform. For many deployments this is not a problem: the partner integration handles the transaction, and the agent continues the conversation once payment is confirmed.
The friction appears when requirements get more specific. A bank with an existing acquirer relationship needs to settle through their mandated processor, not through a capture tool's built-in flow. An insurer running across multiple brands or subsidiaries needs per-client gateway setup so that each premium payment runs on the correct merchant account. A financial services firm running both voice and chat channels needs a consistent compliance behaviour and the same card-data isolation, regardless of which channel the customer used.
PCI DSS Level 1 compliance for a service provider is a significant undertaking, and it is not part of boost.ai's current certification set. boost.ai's certifications are strong for data protection and information security, but card data handling requires a separate compliance layer. The question for regulated-sector teams is how to add that layer without complicating the boost.ai deployment or expanding cardholder data scope across systems that should not be in scope at all.
How a voice payment works
The boost.ai agent runs the conversation: it identifies the customer, confirms the payment amount, and collects intent.
Payment is triggered from your agent interface, via API or webhook, at the point where card details are needed.
Card captured securely. The card is captured in a PCI DSS Level 1 call via Twilio Pay. The customer enters their card on the keypad, and the digits pass from Twilio Pay to Shuttle's PCI DSS Level 1 environment.
Transaction is processed. Shuttle sends it to the configured PSP, one of 30+ supported gateways.
Result returned to the boost.ai agent and your systems via webhook, so the conversation continues accordingly.
No card data in boost.ai. The card digits never touch your boost.ai deployment, your call recordings, your CRM, or the conversational LLM.
Multi-PSP Support
Shuttle connects to 30+ gateways through a single integration. That list includes Stripe, Adyen, Worldpay, Checkout.com, and many others across Europe, North America, and APAC. You can bring your own acquirer rather than being channelled through a capture tool's preferred processor.
For organisations running boost.ai across multiple clients, brands, or subsidiaries, Shuttle supports per-client and per-tenant gateway setup. Each conversation flow can use a different merchant account and gateway configuration. This is particularly relevant for insurers managing multiple underwriting entities, for banks with distinct product divisions, and for system integrators delivering white-label contact centre deployments at scale.
The contrast with a single third-party capture tool tied to its own processing flow is straightforward. If your organisation has an existing gateway relationship or is bound by a procurement decision to use a specific acquirer, a gateway-neutral layer like Shuttle accommodates that from the start. Switching processors later is configuration, not a re-integration, though saved cards stay with the gateway that stored them. One caveat for voice specifically: a small number of gateways (for example Braintree) don't permit the raw card data to be passed to them, so they don't work for voice capture, though they do work for payment links.
Shuttle also takes payments in multiple currencies, and each client or business entity can run on its own gateway, which matters for boost.ai deployments spanning the Nordics, broader Europe, and international markets.
PCI Compliance
Shuttle is a PCI DSS Level 1 certified service provider, the highest level of certification available. Card data is captured through Twilio Pay and processed through Shuttle's PCI DSS Level 1 environment, and is never transmitted to boost.ai, your call recordings, your CRM, or any other system in your stack.
This matters for your compliance posture in two ways. First, it means card data never reaches your boost.ai deployment, which limits its PCI scope. The conversation platform stays exactly where it is in your architecture, with the same certifications and the same audit perimeter. Second, it can move your contact centre environment from the more demanding SAQ-D scope toward SAQ-A, the lightest possible assessment, because card data capture happens outside your systems entirely.
boost.ai's own compliance certifications (SOC 2 Type II, ISO 27001, ISO 27701, ISAE 3402) are strong and appropriate for a platform handling sensitive customer data in regulated industries. Shuttle's PCI DSS Level 1 status complements rather than duplicates that posture: it addresses the one compliance requirement that boost.ai's certifications do not cover, without requiring any change to how boost.ai itself is deployed or audited. Full compliance documentation, including the AOC scope, is in the security docs.
Beyond Voice: Payment Links
boost.ai supports both voice and chat channels, and the most turnkey path with Shuttle works across both. On voice, the card is captured securely via Twilio Pay. On chat, SMS, and WhatsApp, Shuttle generates hosted payment links: secure, single-use URLs served from Shuttle's PCI-certified environment, returned inline to the conversation for the customer to complete.
This means a customer can start a query in the boost.ai chat widget, receive a payment link, complete the transaction in a browser tab, and return to the chat for confirmation, with no card data crossing the chat session at any point. The same applies to outbound SMS flows where boost.ai triggers a follow-up message after a conversation: the payment link opens to a Shuttle-hosted form, completing the PCI scope isolation in that channel too.
Use Cases
Bill-Pay and Account Payments
Customers contacting a bank or utility through a boost.ai virtual agent can make account payments, settle outstanding balances, or set up payment arrangements without being transferred to a human agent. Shuttle handles card capture, with the result returned to the agent to confirm and update the account.
Insurance Premiums and Renewals
Insurers using boost.ai for renewal conversations can collect premium payments at the point of renewal confirmation, within the same interaction. Per-client gateway setup means each underwriting entity or brand can run on its own merchant account, with a consistent compliance posture across the portfolio.
Collections and Payment Plans
For collections workflows, Shuttle supports instalment arrangements and recurring card authorisations alongside one-off capture. The boost.ai agent negotiates the plan; Shuttle captures the card, which is tokenised with your gateway.
Customer Support Payments
Banks and financial services firms using boost.ai for general customer support can offer fee payments, top-ups, and charges within the support conversation rather than redirecting customers to a separate payment journey.
What to Expect
Shuttle is a payment layer you connect to your stack, not a pre-packaged boost.ai plugin. Here is the honest detail so there are no surprises on the call:
It runs on Twilio Pay today. Shuttle's voice capture uses Twilio Pay, where Shuttle is Twilio's chosen provider to enable Twilio Pay for many payment gateways, so you need to be a Twilio customer. Shuttle works with Twilio today, and any carrier coming soon.
You build a small integration, not a payment system. Shuttle ships the secure PCI capture, IVR, payment links, and payment APIs. What it does not ship is an out-of-the-box agent screen, the input UX, or the amount-passing API call for boost.ai specifically. So you build that minimal glue: pass the amount to Shuttle via its API (the minimum data we need), connect the capture into your boost.ai call flow over Twilio, and add your own agent screen if your workflow needs one. It is light.
Point-of-payment capture is what is live. Securely capturing the card at the moment of payment works today. Shuttle staying present across the entire conversation, or handing the caller back to the same agent afterwards, is part of the fuller call control coming with the carrier-agnostic version.
Payment links are the most turnkey path and need the least build. Many teams start there and add voice capture later.
FAQ
Does Shuttle have a native boost.ai integration? Not today. Shuttle's voice capture runs on Twilio Pay, and you invoke that setup rather than installing a Shuttle app in boost.ai. You'll need to be a Twilio customer and to build a small integration on your side (pass the amount to Shuttle's API and wire the secure capture into your call flow over Twilio). Shuttle works with Twilio today, and any carrier coming soon.
Does this require Twilio? Yes, today. The secure card capture runs via Twilio Pay, where Shuttle is Twilio's chosen provider to enable Twilio Pay for many payment gateways. Shuttle works with Twilio today, and any carrier coming soon.
Does boost.ai process payments natively? No. boost.ai has no native payment product. For PCI-compliant card capture it partners with third parties, including a specialist contact-centre payments provider and Vipps for Nordic markets. A gateway-neutral layer like Shuttle is the alternative for teams needing broader PSP coverage or per-client gateway setup.
How is Shuttle different from boost.ai's partner payment integrations? boost.ai's payment partners are capable within their own approaches. Shuttle's difference is gateway neutrality and per-client gateway setup: 30+ PSPs on a single integration, per-client configuration for multi-tenant deployments, and BYO acquirer support. If you want to compare options, see Voice Checkout for how Shuttle's approach works.
Which gateways does Shuttle support? Shuttle connects to 30+ gateways including Stripe, Adyen, Worldpay, Checkout.com, and many regional processors. You can use your existing acquirer relationship and configure a gateway per client or per payment method. Switching gateways later is configuration, not re-integration, though saved cards stay with the gateway that stored them.
Does this limit our bank or contact centre's PCI scope? Yes. Card data is captured through Twilio Pay and processed through Shuttle's PCI DSS Level 1 environment, and is never transmitted to boost.ai, your call recordings, or your CRM. That limits those systems' PCI scope and can move your contact centre assessment from SAQ-D toward SAQ-A. You still validate your own compliance.
Related Reading
The Payment Layer for AI Agents: how a gateway-neutral payment layer fits across any conversational AI platform
AI Voice Agent PCI Payments: technical guide to secure voice capture, PCI scope reduction, and SAQ-A qualification for voice agents
Voice Payments: end-to-end guide to taking card payments over voice channels
Cognigy Payments: same pattern applied to Cognigy.AI virtual agents, including contact centre and voice use cases
Kore.ai Payments: multi-PSP payment capture for Kore.ai virtual agent deployments
Add Payments to Your boost.ai Agents
Shuttle is a PCI DSS Level 1 service provider offering payment capture across 30+ gateways via Twilio, at $49 per live instance per month, plus $0.20 per transaction billed through your Twilio account, with no per-seat fees. We'll walk you through what's live today and the path for your setup. See pricing.
See Voice Checkout | Book a discovery call