Navigation

Get in touch
Logo
News

Industries / Commercials

Connected commerce. Reliable systems.

Secure payments, protect customer data and connect digital sales channels.

Consulting. Integration. Operations.

A grocery store aisle with shelves stocked with cereal boxes and milk cartons — illustrative image

Built around your industry.

  • Retail chains and multi-store retailers
  • Restaurants and hotels
  • Venues and leisure operators
  • Online retailers and marketplaces

Your priorities

Understand the challenge. Shape the solution.

We secure card payments with encryption and hardware security modules in line with PCI DSS.

01

Payment security with HSMs and point-to-point encryption

Payment flow analysis with defined PCI scope

More on this
02

Customer accounts, loyalty and card programs under GDPR

Data protection concept with record of processing and deletion concept

More on this
03

Fraud detection and sales forecasting with AI

Data platform connected to shop, checkout and customer systems

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01Payment security with HSMs and point-to-point encryptionThales payShield 10K · Utimaco Atalla AT1000 · Futurex Excrypt

Our approach

Card data stays encrypted from the terminal to the payment service provider when terminal keys, decryption and tokenization reside in certified hardware security modules. We plan point-to-point encryption under PCI P2PE, load terminal keys under control and replace card numbers in checkout, shop and merchandise management with tokens. For merchants with their own payment platform we advise vendor-neutrally on payShield 10K, Atalla AT1000 and Futurex Excrypt and set up key ceremonies with roles and records. The PCI scope shrinks to the systems that actually see plaintext.

Full scope
  • Payment flow analysis across terminals, checkouts, online shop, vending machines and back office with definition of the PCI scope
  • Point-to-point encryption under PCI P2PE with a listed solution or your own decryption environment in the HSM
  • Terminal key injection and remote key loading with KeyBRIDGE POI or Futurex SKI Series 3, key blocks under TR-31
  • Tokenization of card numbers for customer accounts, subscriptions and returns with a token vault in the HSM
  • Operations manual for key rotation, firmware levels, monitoring and evidence for QSA assessment or SAQ

A retail chain switches its terminals to point-to-point encryption and tokenizes card numbers in checkout and merchandise management; the next PCI assessment covers only the decryption environment.

What you get

  • Payment flow analysis with defined PCI scope
  • Encryption and tokenization concept with HSM architecture
  • Operations manual with ceremony records and audit files
Discuss this topic
02Omnichannel integration from checkout to ERPSAP S/4HANA · Shopware · commercetools

Our approach

Omnichannel only works when checkout, online shop, app, marketplaces and merchandise management see the same stock, prices and customer profiles. We place an integration layer with versioned interfaces and event processing between point-of-sale system, ERP, shop platform and inventory management, so that store pickup, returns in the branch and orders placed in the store run without nightly file reconciliation. Existing checkouts and ERP systems remain in place and are connected through adapters, including the technical security device required by the KassenSichV.

Full scope
  • Interface catalog across checkout, ERP, shop platform, inventory management, order management and marketplaces with data contracts
  • Event processing with Apache Kafka for sales, stock and prices in real time instead of batch reconciliation
  • Integration of shop platforms such as Shopware or commercetools and ERP systems such as SAP S/4HANA through an API gateway
  • Order management for store pickup, shipping from the store and returns across all channels
  • Automated tests, versioning and release process per interface, changes without checkout downtime

A multi-store retailer connects checkout, Shopware and SAP through an event platform; stock levels in store and online shop match within seconds and returns from the shop are accepted at every checkout.

What you get

  • Integration architecture with interface catalog and data contracts
  • Event platform with connected checkout, shop and ERP systems
  • Test concept with release process per interface
Discuss this topic
03Customer accounts, loyalty and card programs under GDPRKeycloak · OpenID Connect · FIDO2 and passkeys

Our approach

Loyalty programs, gift cards and customer accounts collect purchase histories and contact data and therefore fall fully under the GDPR. We develop and operate customer apps, customer portals and rewards systems with consent management, roles and deletion rules anchored in the data model from the start. Card programs with physical loyalty or gift cards get card keys and balance verification in the HSM, so that cards cannot be copied and balances cannot be manipulated.

Full scope
  • Data protection concept with legal bases, record of processing activities and data protection impact assessment for profiling
  • Customer app and customer portal with login via OpenID Connect, passkeys and consent management
  • Rewards and stored-value system with card keys, balance signatures and verification in the HSM
  • Deletion concept, access request process and pseudonymization for analytics
  • Operation of the applications with monitoring, updates and support in German data centers

A restaurant group introduces a rewards program with app and gift card; consents, deletion periods and balance verification are documented before launch, and balances are signed in the HSM.

What you get

  • Data protection concept with record of processing and deletion concept
  • Customer app or customer portal with consent management
  • Rewards and stored-value system with HSM-protected card keys
Discuss this topic
04Cloud operations for many locationsMicrosoft Azure · AWS · Google Cloud

Our approach

Store networks and businesses with several properties benefit when checkout back end, merchandise management and customer portals run centrally and locations only need terminals and network. We migrate these applications to Microsoft Azure, AWS, Google Cloud or German data centers, build site connectivity, identities and monitoring centrally and provide an offline mode for the checkout so that sales continue during a line outage.

Full scope
  • Target architecture with landing zone, network segmentation and site connectivity via SD-WAN or VPN
  • Migration of checkout back end, merchandise management and customer portal with infrastructure as code in Terraform
  • Offline capability of the checkout with local buffering and later synchronization
  • Central monitoring, patch management and backup for all locations
  • Cost control and scaling for promotion days and seasonal peaks

A hotel group moves the reservation and point-of-sale systems of all its properties to German data centers; updates reach every property on the same day and the front desk keeps booking offline during a line outage.

What you get

  • Cloud target architecture with site connectivity
  • Migrated applications with infrastructure as code
  • Operations manual with monitoring, backup and offline concept
Discuss this topic
05Fraud detection and sales forecasting with AIApache Kafka · Apache Flink · XGBoost

Our approach

Fraud in retail shows up as account takeover in the online shop, return fraud, misuse of loyalty points and vouchers, and suspicious voids at the checkout. We merge transaction, account and device data in a data platform and train models that score orders, returns and redemptions before they are approved. The same platform delivers sales and demand forecasts for replenishment and staff planning. Every decision is explainable and logged so that customer service and data protection can follow it.

Full scope
  • Data platform with streaming connections to shop, checkout, customer accounts, payment service providers and device data
  • Scoring model for orders, returns and redemptions, validated against historical fraud cases and false alarms
  • Sales and demand forecast per location and item for replenishment and staff scheduling
  • Explainability per decision for customer service, complaints and data protection
  • Model operations with versioning, drift monitoring and documentation under GDPR and the EU AI Act

An online retailer scores returns by account age, device and return history instead of refunding across the board; suspected misuse is reviewed, honest customers get their money immediately.

What you get

  • Data platform connected to shop, checkout and customer systems
  • Versioned scoring model with rule set and model card
  • Forecasting model with decision log per transaction
Discuss this topic
06Cybersecurity for store networks and e-commerceMicrosoft Sentinel · Microsoft Defender for Endpoint · OPSWAT MetaDefender

Our approach

Stores, shop platform and back office form a large attack surface with checkout terminals, guest Wi-Fi, supplier access and publicly reachable interfaces. We segment site networks, harden checkouts and shop servers, protect interfaces with a web application firewall and monitor all locations centrally with intrusion detection and incident response. For businesses that fall under NIS2 as important entities, such as food retailers or online marketplaces, we deliver risk management, reporting processes and evidence under ISO 27001.

Full scope
  • Security architecture with network segmentation per location, separated for checkout, guest Wi-Fi, back office and building technology
  • Hardening of checkouts, terminals and shop servers, protection of interfaces with web application firewall and bot defense
  • Security monitoring with SIEM and endpoint detection across all locations, incident response with reporting channels
  • Penetration tests for online shop, customer app and store network, supplier access under the four-eyes principle
  • ISMS under ISO 27001 and gap analysis for NIS2 for businesses in scope

A food retailer separates checkout, guest and building technology networks in every store and reports incidents centrally; the NIS2 gap analysis shows the reporting channels as the only open item.

What you get

  • Security architecture with segmentation concept per location
  • Monitoring and incident response operations with reporting channels
  • Test reports, ISMS documents and NIS2 gap analysis
Discuss this topic
A woman in a rust-colored sweater paying with a card at a salon counter — illustrative image
Commercials

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Commercials

P2PE rollout at a retail chain

Card numbers pass in plaintext through checkout software and merchandise management, and the acquirer demands full PCI DSS evidence.

Solution

Payment flow analysis, point-to-point encryption from the terminal, tokenization in checkout and merchandise management, key ceremonies with records.

Scope limited to the decryption environment, complete files for the QSA assessment, operations manual for the in-house team.

Discuss this topic

02 / Commercials

Omnichannel at a fashion retailer

Store, online shop and marketplaces keep their own stock, reconciliation runs at night, and returns from the shop are refused at the checkout.

Solution

Integration layer with event platform, interface catalog for checkout, shop and ERP, order management for store pickup and returns.

Stock reconciled within seconds, returns accepted at every checkout, releases without checkout downtime.

Discuss this topic

03 / Commercials

Rewards program at a restaurant group

A rewards program with app and gift card is about to launch, consents and deletion periods are unclear, and balances sit in a spreadsheet.

Solution

Data protection concept with record of processing, customer app with consent management, stored-value system with keys and signatures in the HSM.

Program launched with a documented legal basis, balances protected against tampering, access and deletion requests in regular operation.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Payment flows, checkout and shop landscape, customer data and locations

    Prioritized list of measures, PCI scope, gap analysis for GDPR and NIS2
  2. 02

    Concept

    Target architecture, encryption, interfaces, operating model

    Target architecture, interface catalog, data protection concept, operating model, audit concept
  3. 03

    Implementation

    HSMs, integration layer, applications and cloud in stages per store group

    Integrated systems, pilot stores, tests, documentation, approval per stage
  4. 04

    Operations

    Monitoring, audits, knowledge transfer

    Monitoring, key rotation, audit support, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What are IT solutions for retail and commerce?

Six modules from payment encryption to fraud detection, planned, integrated and operated by OTOKO® for stores, online shops, restaurants and venues. Every card payment stays encrypted from the terminal to settlement. The entire solution runs in German data centers.

IT solutions for retail and commerce connect checkout, online shop, merchandise management and customer accounts into one platform while protecting card payments and personal data. OTOKO® covers six modules: payment security with HSMs under PCI DSS, omnichannel integration from checkout to ERP, customer accounts and loyalty programs under GDPR, cloud operations for many locations, fraud detection and sales forecasting with AI, and cybersecurity for store networks and e-commerce.

The difference from a systems integrator lies in cryptography and evidence. Card data is encrypted from the terminal to settlement, keys sit in certified devices, and every interface, deletion rule and change is documented for PCI assessors and data protection officers. Cryptography and hardware security modules are our core competence. That is why we reduce the PCI scope instead of only describing it.

Why OTOKO® for retail and commerce

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. Terminal keys, tokenization and balance signatures sit in certified devices, as PCI DSS and PCI P2PE require.

  • German data centers

    The entire solution runs in German data centers, from the payment HSM through the event platform to customer app and data platform.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what PCI assessors, data protection officers and card schemes expect from the financial sector and apply it to retail and hospitality.

  • One team through to operations

    One team accompanies you from consulting to operations. Integration developers, cryptography specialists and cloud engineers stay with you, without handover to third parties.

Delivery and details

Most businesses do not fail on missing technology but on grown checkout landscapes, distributed locations and evidence gaps toward card schemes and data protection.

Card data in plaintext

Terminals, checkout software and shop back end process card numbers unencrypted, so the PCI scope covers almost the entire network.

Channels without shared data

Checkout, online shop and marketplaces maintain their own stock and prices, reconciliation runs at night by file and returns end up in the wrong system.

Loyalty program without a data protection concept

Customer accounts collect purchase histories without documented consent, deletion periods are not implemented and access requests take weeks.

One server per store

Every location runs its own checkout servers and network equipment, security updates arrive late and nobody sees attacks across all stores.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour data center, your checkout servers and HSMsData centers in Germany, operated under ISO 27001Azure, AWS or Google Cloud, region selectable
OperationYour team or OTOKO® as managed serviceOTOKO®, with reports for your PCI and data protection auditsShared, platform services by the provider
ToolspayShield or Atalla on site, Kafka, KubernetesHosted HSMs, event and data platform in GermanyCloud HSM services, payShield Cloud HSM, managed data services
Suited forOwn payment platform, checkout back end with high requirementsMerchants who need data storage in GermanyShop platform, analytics, promotion days with load peaks
ComplianceFull control, evidence from your ISMS and PCI scopeProcessing agreement under GDPR, location GermanyProcessing agreement, standard contractual clauses, PCI responsibility matrix per service

Collaboration

Project

Clearly scoped undertaking such as a checkout migration, a P2PE rollout or a new online shop with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for checkout replacement, shop relaunch and PCI preparation

Team reinforcement

Integration developers, cloud engineers or security specialists work in your teams, tools and release cycles.

  • Onboarding into your checkout, shop and ERP landscape
  • Scalable by season and project progress
  • Suited for merchants with in-house IT and capacity gaps

Managed service

OTOKO® operates payment platform, integration layer, customer app or cloud environment with agreed service levels, reports and evidence for PCI and data protection audits.

  • Monitoring, updates, key rotation and support
  • Standby on promotion days and at events
  • Suited for businesses without their own operations team

What each requirement in retail and commerce demands and what OTOKO® delivers for it.

Standards and evidence
RequirementDemandsOTOKO® delivers
PCI DSSProtection of cardholder data through network segmentation, encryption, access control, logging and annual assessment by a QSA or self-assessmentScope definition, encryption and tokenization in the HSM, segmentation of store networks, files for QSA assessment and SAQ
PCI P2PEEncryption of card data in the terminal, decryption only in an assessed environment with HSM, controlled key injection and device managementP2PE architecture with a listed solution or your own decryption environment, key injection with records, device inventory and operating processes
GDPRLegal basis, consent for profiling, data minimization, data subject rights, processing agreements and data protection impact assessmentData protection concept for loyalty program and customer app, consent management, deletion concept, access request process, processing agreement
ISO 27001Information security management system with risk analysis, control catalog, supplier management and regular internal and external auditsISMS setup or extension to stores and shop platform, risk register, action plan, operation of the platform under ISO 27001
NIS2Risk management, reporting of significant incidents, supply chain security and management accountability for important entities such as food retail and online marketplacesApplicability check, gap analysis, reporting processes, supplier requirements and evidence for registration with the BSI

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which IT solutions for retail and commerce does OTOKO® offer?

The portfolio covers payment security with HSMs and point-to-point encryption under PCI DSS, omnichannel integration of checkout, shop and ERP, customer accounts and loyalty programs under GDPR, cloud operations for many locations, fraud detection and forecasting with AI, and cybersecurity for store networks and e-commerce. Each module can be commissioned on its own or as a package, with operation in German data centers.

How do we reduce the scope of PCI DSS?

The scope depends on where card data appears in plaintext. Point-to-point encryption from the terminal and tokenization in checkout, shop and merchandise management take these systems out of the plaintext path, and network segmentation separates the rest. What remains is a small decryption environment with HSM for which evidence can be maintained with reasonable effort.

Do our existing checkouts and merchandise management stay in place?

Usually yes. We connect existing point-of-sale systems, ERP and shop platforms to the integration layer through adapters and replace only components that offer no interfaces or reach end of support. The technical security device under the KassenSichV stays connected unchanged.

What does the GDPR require of a loyalty program?

A legal basis for every processing activity, documented consent for profiling and personalized offers, deletion periods, an access request process and, for extensive profiling, a data protection impact assessment. We anchor these rules in the data model and in consent management so that access and deletion work in regular operation and not as a special case.

Does our business fall under NIS2?

That depends on sector and size. Food retail, online marketplaces and providers of certain digital services can qualify as important entities, while classic retail and hospitality usually do not. We check applicability against the German implementation act and, where needed, deliver risk management, reporting processes and registration with the BSI. We work with operators of critical infrastructure and regulated industries. That is why these requirements are routine for us.

Do sales continue if the cloud connection fails?

Yes, if the checkout is designed for it. We provide an offline mode in which checkout and terminal buffer sales locally and keep accepting card payments under the rules of the payment service provider. Once the connection returns, the checkout automatically synchronizes receipts, stock and payments.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

Security architect: Target architecture, segmentation, PCI scope. Cryptography specialist: HSMs, P2PE, tokenization, key ceremonies. Integration developer: Interfaces, event platform, checkout and ERP adapters. Cloud engineer: Landing zone, migration, site connectivity. Data engineer: Data platform, fraud models, forecasts. Project lead: Milestones, store rollout, acceptance.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Payment flows, checkout and shop landscape, customer data and locations Prioritized list of measures, PCI scope, gap analysis for GDPR and NIS2

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as a checkout migration, a P2PE rollout or a new online shop with a defined result, milestones and acceptance. Team reinforcement: Integration developers, cloud engineers or security specialists work in your teams, tools and release cycles. Managed service: OTOKO® operates payment platform, integration layer, customer app or cloud environment with agreed service levels, reports and evidence for PCI and data protection audits.

What happens at handover to operations?

Monitoring, audits, knowledge transfer Monitoring, key rotation, audit support, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Commercials

Let's discuss your next step.

Let us discuss how payments, customer data, and sales channels can work together securely in your business.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.