Fini’s PCI DSS posture
How card data moves in a Fini conversation
Customers sometimes type a card number into chat even when nobody asked. Fini masks it before the conversation is stored, and any card operation runs against your payment provider, which holds the card data. The conversation only carries references such as a card token or the last four digits. Masking is a backstop, not a reason to collect card data. Your helpdesk and email threads are outside Fini, so design your flows so customers never need to type card details at all:How to configure Fini
1. Identify cards without asking for them
Let the authenticated session identify the customer, and load their cards from your systems. A User Attribute or a lookup Action returns the customer’s cards with tokens and last-four digits; the Rulebook asks the customer to pick one by last four or nickname. The card replacement walkthrough builds exactly this pattern: list the customer’s cards, confirm which one, freeze it, order a replacement, without the customer typing a card number.2. Run card operations through Actions in your systems
Freezing a card, ordering a replacement, disputing a charge or updating a payment method should be an Action that calls your payment provider’s card-management or payments API with a token, not something the agent does by handling card details. Actions run only when a Rulebook Tool node invokes them, so the call happens in a deterministic flow you built and tested. If your firewall restricts inbound traffic, allowlist Fini’s static IP addresses. When a customer genuinely needs to enter a new card, send them to your own hosted payment page or in-app flow with a Reply node, rather than collecting the number in the conversation.3. Tell the agent never to ask, and escalate when a customer volunteers
- In the Planning Prompt, add an Escalation Topics trigger for sensitive data shared in-channel, as the prompt guidance suggests for “last 4 of card, SSN” and similar. See Prompts.
- In your Main Guidelines, state that the agent never requests a full card number, security code or PIN, and directs customers to the secure flow instead.
4. Add guardrails on replies
- Confidential attributes: select any attribute keys that carry card details (for example a full card number your attributes endpoint should not return in the first place). If a reply contains one of those values, Fini attempts a rewrite and, if that fails, escalates instead of sending it.
- Banned terms: add a regular expression that matches 13 to 19 digit sequences, including ones separated by spaces or hyphens, so a reply does not echo a card number back.
- Custom rule: fail any reply that asks the customer for a card number, CVV or PIN.
5. Use Reply Rules for card-sensitive topics
If your helpdesk policy is that card disputes or payment-method changes always go to a person, add a condition on the Internal Comment or No Reply card, for example Type of Issue In disputes, chargebacks. See Reply Rules.6. Test it
Create Test Suite test cases from conversations where a customer pastes a card number, asks the agent to “just take my card details”, or offers a CVV. Create those conversations in Inbox with test card numbers, never real ones. Add an AI judgement that the agent declines, points to the secure flow, and escalates where your policy requires, and mark it Required to pass.What this means for your PCI scope
Your QSA decides your scope. Fini’s PCI DSS Level 1 certification and automatic masking cover the Fini side. The configuration above keeps cardholder data out of normal support conversations, so card operations happen only in your payment provider’s systems. Document that design, Fini’s attestation (AOC) and your Test Suite results in your scoping evidence. To request Fini’s AOC, contact your Fini account team.Related
End-to-end: card replacement
A deterministic lost-or-stolen card flow with no card numbers in chat.
Guardrails
Confidential attributes, banned terms and custom rules.
Fintech setup
Recommended configuration for banking and fintech support.
Security overview
Fini’s certifications and how to request reports.
Data handling
How automatic masking works across stored conversation data.

