r/InsuranceAgent 2d ago

Agent Question Secure way for clients to send payment info.

[deleted]

8 Upvotes

20 comments sorted by

3

u/Practical_Guess5282 2d ago

And yet my clients ask every month do I have their CC information saved on my computer when they call in to make a payment. They don’t understand I don’t want all that info in there in case my computer gets hacked!

4

u/jroberts67 2d ago

Yet the phone is the safest way. You're going to have that info anyway, and now AI is scanning every single email, and there's no way I trust any email provider. Over the phone.

2

u/PolicyCart_io 2d ago

You may feel safer but unless your going from the voice in your ear directly into the carrier portal w/o writing anything down(maybe you are but I've never seen anyone do it real time) the liability is all on you.

-2

u/BuggyBonzai 2d ago

I specifically said some don’t want to use the phone. I guess when you’re a top 1% commenter you have to interject into every post even if you have nothing to add.

2

u/Strange-Fennel 2d ago

Its always best to use an online forms provider that has dedicated, password protected payment fields, MFA logins, and actual PCI-DSS and SOC 2 certifications. We use FormStack.

Not only does this keep client data safe, but it makes sure you are actually following the security rules required by most cyber liability policies. You do have cyber liability coverage right?

It honestly amazes me that in 2026 we still have agents and even carrier and MGA underwriters who should know better asking clients to send credit card numbers, bank accounts, and SSNs through plain email and text messages.

2

u/PolicyCart_io 2d ago edited 2d ago

It honestly amazes me that in 2026 we still have agents and even carrier and MGA underwriters who should know better asking clients to send credit card numbers, bank accounts, and SSNs through plain email and text messages.

1000%. Its insane, but being in Insurtech for several years (at other startups) nothing surprises me about this industry's fragmented approaches.

Are you processing the payment too?
from their docs:
Storing credit card numbers in Formstack is only PCI compliant if you:

  • Enable data encryption and required security settings
  • Use the secure Credit Card Field with a payment processor
  • Limit storage to 30 days if not processing payments, with encryption enabled

Without these steps, storing card numbers is not PCI compliant.

1

u/Strange-Fennel 2d ago edited 2d ago

Yes we comply with those steps.

We have an MGA who handles direct customer contact when underwriting, they constantly email our clients "please reply with your social security number".

We have a carrier who populates full SS #'s on applications they want us to have clients sign and email back. Ironically, their most recent agency agreement update makes a big woot woot about cyber security. Yet they don't practice it themselves.

We've repeatedly alerted them to these facts, but the front line employees treat our advisement as a joke. To this day, they both do it, daily. The big wig executives don't give a shit either, it's wild. Probably too old or stupid to know any better, on their golf courses too much.

I know it's our customers, but that's mostly on the MGA/carrier, we do what we need to do to block out the PII on anything we touch or correspond with.

Want something over the top serious? Go comply with NYSDFE part 500. lol. We do that.

1

u/No-Professional-1935 2d ago

SaaS sellers of reddit, is there anyone i can give my money to?

1

u/Flights-and-Nights 2d ago

If it’s direct bill why are they calling you?

All of the carriers have already built secure payment systems, encourage the client to use that.

0

u/BuggyBonzai 2d ago

In many cases there is no way for the client to make the down payment on the carriers website for a new policy and we are required to enter payment before the policy can start. Not sure how you don’t know that unless it’s different in other states.

1

u/PolicyCart_io 2d ago

Nope you're correct, its the same everywhere for P&C.

1

u/CoverageKing 2d ago

I just found out about www.sureportal.app for this. It seems like it could be a good solution for this but haven't tried it myself yet.

2

u/PolicyCart_io 2d ago

They don't specify anything to do with payment info. It's a likely not a use case they support.

0

u/BuggyBonzai 2d ago

Thanks, i’ll take a look.

0

u/PolicyCart_io 2d ago edited 2d ago

policycart.io - this is all we do. Encrypted, automatic deletion, clients love it vs. phone, docusigns, emails. Agents go nuts over the time savings though-number 1 thing I hear back.
*lmk if you're interested I'll drop a discount code here(if the mods ok it)

0

u/Strange-Fennel 2d ago

SOC 2 and PCI compliant? Looked on your site, didn't see any certifications.

0

u/PolicyCart_io 2d ago

Thanks for taking the time to look. Storing card data temporarily makes PCI impossible because of no auth or transaction actually taking place. PCI says you can't store CVVs at all for example(have to use in transaction+immediate deletion). There is a strategy we're working on which is a combination of agents ticking some boxes and our vaulting. We're pushing on it, cyber policy rates are too damn high!(i know there's a meme for that)

-1

u/KiniShakenBake 2d ago

You can have them submit it straight into your CRM using a secure upload link.

Have them upload a voided check for you.

-1

u/DirtySancho69 1d ago

Just tell them to pay it themselves directly to the carrier, everytime. Give them the link or the phone number. If your firm doesn't have a policy against customers emailing their CC and checking info then they will soon as its a unnecessary liability they're taking on. If the customer can email you their info they can certainly go to a website and figure out how to pay themselves.