> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usefini.com/llms.txt
> Use this file to discover all available pages before exploring further.

# PCI DSS

> Fini is PCI DSS Level 1 certified, masks card numbers automatically in stored conversation data, and keeps card actions in your payment provider's systems through Actions.

export const ScenarioChecker = ({title = "Try it", question, scenarios = [], labels = {
  yes: "Yes",
  no: "No",
  depends: "It depends"
}}) => {
  const FV = {
    lime: "#C3EE5E",
    ink: "#131415",
    line: "rgba(127,127,127,0.28)",
    soft: "rgba(127,127,127,0.07)",
    softer: "rgba(127,127,127,0.04)",
    muted: "rgba(127,127,127,0.95)",
    pass: "#C3EE5E",
    warn: "#FFB020",
    fail: "#FF4D4D",
    radius: 14
  };
  const fvCard = {
    border: `1px solid ${FV.line}`,
    borderRadius: FV.radius,
    padding: 18,
    margin: "20px 0",
    background: FV.softer
  };
  const fvChip = active => ({
    border: `1px solid ${active ? FV.lime : FV.line}`,
    background: active ? FV.lime : "transparent",
    color: active ? FV.ink : "inherit",
    borderRadius: 999,
    padding: "6px 12px",
    fontSize: 13,
    fontWeight: 600,
    cursor: "pointer",
    lineHeight: 1.2
  });
  const fvBtn = primary => ({
    border: `1px solid ${primary ? FV.lime : FV.line}`,
    background: primary ? FV.lime : "transparent",
    color: primary ? FV.ink : "inherit",
    borderRadius: 10,
    padding: "7px 14px",
    fontSize: 13,
    fontWeight: 600,
    cursor: "pointer"
  });
  const fvLabel = {
    fontSize: 11,
    fontWeight: 700,
    letterSpacing: "0.08em",
    textTransform: "uppercase",
    opacity: 0.6,
    marginBottom: 8
  };
  const [k, setK] = useState(null);
  const s = k === null ? null : scenarios[k];
  const col = {
    yes: FV.pass,
    no: FV.fail,
    depends: FV.warn
  };
  return <div style={fvCard}>
      <div style={fvLabel}>{title}</div>
      {question && <div style={{
    fontSize: 16,
    fontWeight: 700,
    marginBottom: 12
  }}>{question}</div>}
      <div style={{
    display: "grid",
    gridTemplateColumns: "repeat(auto-fill, minmax(220px, 1fr))",
    gap: 8
  }}>
        {scenarios.map((sc, i) => <button key={i} onClick={() => setK(i)} style={{
    textAlign: "left",
    padding: "10px 12px",
    borderRadius: 10,
    cursor: "pointer",
    fontSize: 13.5,
    lineHeight: 1.4,
    color: "inherit",
    border: `1px solid ${k === i ? FV.lime : FV.line}`,
    background: k === i ? "rgba(195,238,94,0.14)" : "transparent"
  }}>{sc.label}</button>)}
      </div>
      <div style={{
    marginTop: 14,
    minHeight: 64,
    padding: "12px 14px",
    borderRadius: 10,
    border: `1px solid ${s ? col[s.verdict] : FV.line}`,
    background: FV.soft,
    transition: "border-color .25s"
  }}>
        {s ? <div>
            <b>{labels[s.verdict]}</b>{s.title ? <b>{`: ${s.title}`}</b> : null}
            <div style={{
    fontSize: 14,
    marginTop: 4,
    lineHeight: 1.55
  }}>{s.why}</div>
          </div> : <span style={{
    fontSize: 13.5,
    opacity: 0.6
  }}>Pick a scenario to see the answer.</span>}
      </div>
    </div>;
};

Fini (usefini.com) is PCI DSS Level 1 certified, the highest level of the Payment Card Industry Data Security Standard. Fini automatically masks card numbers and other sensitive data everywhere it stores conversation data, so raw cardholder data doesn't sit in transcripts, Inbox or AI Steps traces.

Certification covers how Fini runs its platform. How your agent handles card topics depends on your configuration: route card actions (freezes, replacements, refunds) through your payment provider with [Actions](/en/api-reference/actions), and never ask customers for full card numbers or CVVs in a conversation. This page explains both sides and how to set them up.

## Fini's PCI DSS posture

| Topic | Fini position |
| - | - |
| Certification | PCI DSS Level 1 certified |
| Card data in stored conversations | Masked automatically in transcripts, Inbox and AI Steps traces. Fields you hide from the AI are also redacted in AI Steps. |
| Card actions | Run in your payment provider's systems through Actions, called from Rulebook **Tool** nodes |
| Attestation of Compliance (AOC) | Available to customers on request through your Fini account team |
| Other certifications | SOC 2 Type II, ISO/IEC 27001:2022, HIPAA-compliant and BAA-eligible, GDPR, CCPA. See [Security overview](/en/security/overview). |

## How card data moves in a Fini conversation

Customers sometimes type a card number into chat even when nobody asked. Fini masks it before the conversation is stored, and any card operation runs against your payment provider, which holds the card data. The conversation only carries references such as a card token or the last four digits.

```mermaid theme={null}
---
title: Card data in a Fini conversation
---
flowchart LR
    PAN["Customer types a<br/>card number into chat"] --> MASK["Fini masks it<br/>automatically"]
    MASK --> STORE["Stored conversation data<br/>transcripts · Inbox · AI Steps"]
    TOOL["Rulebook Tool node<br/>card token, not the number"] --> PSP["Your payment provider<br/>freeze · replace · refund"]

    classDef source fill:#F7F7F7,color:#131415,stroke:#E8E8E8
    classDef agent fill:#131415,color:#FFFFFF,stroke:#131415,stroke-width:3px
    classDef surface fill:#FFFFFF,color:#131415,stroke:#131415
    classDef human fill:#C3EE5E,color:#131415,stroke:#131415,stroke-width:2px

    class PAN source
    class MASK,TOOL agent
    class STORE surface
    class PSP human
```

Masking is a backstop, not a reason to collect card data. Your helpdesk and email threads are outside Fini, so design your flows so customers never need to type card details at all:

| Data | Recommendation |
| - | - |
| Full primary account number (PAN) | Never request it in chat, email or voice. Identify the card another way (see below). |
| Card verification code (CVV, CVC) | Never request it. PCI DSS prohibits storing it after authorization. |
| PIN, full magnetic stripe or chip data | Never request it. |
| Last four digits, card nickname, card type | Acceptable identifiers for most support flows, subject to your own policy. |
| Card tokens or internal card IDs | Preferred. Load them from your systems through User Attributes or Actions; the customer never types them. |

<ScenarioChecker
  title="Try it"
  question="Should this card data be in a Fini conversation?"
  scenarios={[
{ label: "The agent asks for the full card number to find the card", verdict: "no", title: "Never request the PAN", why: "Identify the card another way. Load the customer's cards from your systems through a User Attribute or lookup Action and ask them to pick one by last four or nickname." },
{ label: "The agent asks for the CVV to confirm the card", verdict: "no", title: "Never request it", why: "PCI DSS prohibits storing the card verification code after authorization. There is no support flow that needs it." },
{ label: "The agent asks for the card PIN", verdict: "no", title: "Never request it", why: "PINs, full magnetic stripe data and chip data never belong in chat, email or voice." },
{ label: "The customer confirms which card by its last four digits", verdict: "depends", title: "Acceptable for most flows", why: "Last four digits, card nickname and card type are acceptable identifiers for most support flows, subject to your own policy." },
{ label: "A Tool node freezes the card using a token from your systems", verdict: "yes", title: "Preferred pattern", why: "Card tokens loaded through User Attributes or Actions are preferred. The customer never types them, and the Action runs in your payment provider's systems." },
{ label: "A customer pastes their full card number without being asked", verdict: "no", title: "Fini masks it; don't echo it", why: "Fini masks the number in stored conversation data automatically. Add an Escalation Topics trigger for sensitive data shared in-channel, and a Banned terms guardrail so a reply never repeats the number back." },
{ label: "A customer needs to add a new card", verdict: "no", title: "Use your hosted payment flow", why: "Send them to your own hosted payment page or in-app flow with a Reply node, rather than collecting the number in the conversation." }
]}
  labels={{ yes: "Fine in the conversation", no: "Keep it out", depends: "Depends" }}
/>

## How to configure Fini

### 1. Identify cards without asking for them

Let the authenticated session identify the customer, and load their cards from your systems. A User Attribute or a lookup Action returns the customer's cards with tokens and last-four digits; the Rulebook asks the customer to pick one by last four or nickname. The [card replacement walkthrough](/en/walkthroughs/card-replacement) builds exactly this pattern: list the customer's cards, confirm which one, freeze it, order a replacement, without the customer typing a card number.

### 2. Run card operations through Actions in your systems

Freezing a card, ordering a replacement, disputing a charge or updating a payment method should be an [Action](/en/api-reference/actions) that calls your payment provider's card-management or payments API with a token, not something the agent does by handling card details. Actions run only when a Rulebook **Tool** node invokes them, so the call happens in a deterministic flow you built and tested. If your firewall restricts inbound traffic, allowlist Fini's [static IP addresses](/en/api-reference/static-ip).

When a customer genuinely needs to enter a new card, send them to your own hosted payment page or in-app flow with a Reply node, rather than collecting the number in the conversation.

### 3. Tell the agent never to ask, and escalate when a customer volunteers

* In the Planning Prompt, add an **Escalation Topics** trigger for sensitive data shared in-channel, as the prompt guidance suggests for "last 4 of card, SSN" and similar. See [Prompts](/en/configuration/prompts#controlling-when-the-agent-escalates).
* In your Main Guidelines, state that the agent never requests a full card number, security code or PIN, and directs customers to the secure flow instead.

### 4. Add guardrails on replies

* **Confidential attributes**: select any attribute keys that carry card details (for example a full card number your attributes endpoint should not return in the first place). If a reply contains one of those values, Fini attempts a rewrite and, if that fails, escalates instead of sending it.
* **Banned terms**: add a regular expression that matches 13 to 19 digit sequences, including ones separated by spaces or hyphens, so a reply does not echo a card number back.
* **Custom rule**: fail any reply that asks the customer for a card number, CVV or PIN.

<Warning>
  Guardrails check the agent's replies, not the customer's messages, and they are not a fail-closed boundary: a check error can let the original reply through. Use them as an extra layer on top of Fini's automatic masking and the design above. See [Guardrails](/en/configuration/guardrails).
</Warning>

### 5. Use Reply Rules for card-sensitive topics

If your helpdesk policy is that card disputes or payment-method changes always go to a person, add a condition on the **Internal Comment** or **No Reply** card, for example *Type of Issue In disputes, chargebacks*. See [Reply Rules](/en/automations/reply-behavior).

### 6. Test it

Create [Test Suite](/en/testing/test-suite) test cases from conversations where a customer pastes a card number, asks the agent to "just take my card details", or offers a CVV. Create those conversations in Inbox with test card numbers, never real ones. Add an AI judgement that the agent declines, points to the secure flow, and escalates where your policy requires, and mark it **Required to pass**.

## What this means for your PCI scope

Your QSA decides your scope. Fini's PCI DSS Level 1 certification and automatic masking cover the Fini side. The configuration above keeps cardholder data out of normal support conversations, so card operations happen only in your payment provider's systems. Document that design, Fini's attestation (AOC) and your Test Suite results in your scoping evidence.

To request Fini's AOC, contact your Fini account team.

## Related

<CardGroup cols={2}>
  <Card title="End-to-end: card replacement" icon="credit-card" href="/en/walkthroughs/card-replacement">
    A deterministic lost-or-stolen card flow with no card numbers in chat.
  </Card>

  <Card title="Guardrails" icon="shield-check" href="/en/configuration/guardrails">
    Confidential attributes, banned terms and custom rules.
  </Card>

  <Card title="Fintech setup" icon="building-columns" href="/en/industry-setup/fintech">
    Recommended configuration for banking and fintech support.
  </Card>

  <Card title="Security overview" icon="shield-halved" href="/en/security/overview">
    Fini's certifications and how to request reports.
  </Card>

  <Card title="Data handling" icon="database" href="/en/security/data-handling#masking-sensitive-data">
    How automatic masking works across stored conversation data.
  </Card>
</CardGroup>


## Related topics

- [Fini FAQ](/en/faq.md)
- [Data handling, residency and model training](/en/security/data-handling.md)
- [SOC 2 Type II and ISO 27001](/en/security/soc2-iso27001.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.