Dashboard

Keyed-in MOTO Payments — PCI Compliance Guide

Brippo lets you take phone and mail orders (MOTO) by typing the customer's card number directly into the Brippo Dashboard, the Brippo iOS app or the Magento admin. This is the most flexible way to take a phone order — and the only Brippo payment flow that changes your PCI compliance level. Read this page before enabling it.

Three ways to take a phone order

Not every phone order needs keyed-in entry. Brippo supports three MOTO flows, and two of them require no extra compliance work at all:

Prefer the first two. Pay by Link and reader keyed entry cost you nothing in compliance. Only enable keyed-in MOTO if your volume of phone orders genuinely can't be handled by a link or a reader.
Brippo S700 terminal on its charging dock
No terminal yet?The Brippo S700 takes phone orders on its own certified keypad — keyed MOTO with zero extra PCI paperwork, plus tap, chip and swipe in person.

What keyed-in MOTO means for your business

Enabling keyed-in MOTO comes with two commitments. Neither is hidden in fine print — they are the deal:

Your SAQ C-VT obligations

To truthfully attest to SAQ C-VT, your day-to-day handling of phone orders must meet these conditions:

!
Attest truthfully or not at all. Ticking the boxes while keying cards into a shared, everyday computer is worse than having no attestation — if a card-data incident is ever investigated, an untruthful SAQ works against you. If you can't meet the conditions, use Pay by Link or the terminal reader instead.

Generating your SAQ C-VT in the Brippo Dashboard

Brippo generates the completed SAQ C-VT document for you, the same way it does for your e-commerce and terminal assessments.

  1. 1

    Open Compliance and Documents

    • Log in to the Brippo Dashboard.
    • Go to Settings → Compliance and Documents and choose Generate PCI assessment.
  2. 2

    Pick the virtual terminal option

    • In the assessment type selector, choose the option for card details keyed into the Brippo Dashboard or Brippo apps (the virtual terminal assessment). The e-commerce and terminal options remain separate documents — generate those too if you use those channels.
    • Fill in your company details (name, contact, address). These are printed onto the official PCI document.
  3. 3

    Tick the eligibility confirmations

    The generator will not produce the document until you confirm each eligibility statement. You are asserting, on your company's behalf, that:

    • Card numbers are keyed on a dedicated device used for payment entry.
    • Payments are keyed one transaction at a time.
    • You never store card data electronically in any form.
    • Any paper holding a card number is destroyed as soon as the payment is entered.
  4. 4

    Generate, sign and file

    • Click Generate — the Dashboard produces your completed SAQ C-VT as a PDF, pre-filled with your details and the correct payment-channel descriptions.
    • Have an executive officer sign the attestation page, and keep the document on file. Your acquirer or bank may request it.
    • Repeat annually — the document carries its completion date.

Enabling the payment methods

Keyed-in MOTO is off by default everywhere, and generating the SAQ C-VT is part of switching it on:

i
Reader MOTO is unaffected. The existing Terminal MO/TO flow — keying the number on the terminal's own keypad — needs none of this. It stays covered by your terminal (SAQ P2PE) document, including its MOTO wording.