Payment security with HSMs and point-to-point encryption
Payment flow analysis with defined PCI scope
More on thisIndustries / Commercials
Secure payments, protect customer data and connect digital sales channels.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We secure card payments with encryption and hardware security modules in line with PCI DSS.
Payment flow analysis with defined PCI scope
More on thisData protection concept with record of processing and deletion concept
More on thisData platform connected to shop, checkout and customer systems
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
Card data stays encrypted from the terminal to the payment service provider when terminal keys, decryption and tokenization reside in certified hardware security modules. We plan point-to-point encryption under PCI P2PE, load terminal keys under control and replace card numbers in checkout, shop and merchandise management with tokens. For merchants with their own payment platform we advise vendor-neutrally on payShield 10K, Atalla AT1000 and Futurex Excrypt and set up key ceremonies with roles and records. The PCI scope shrinks to the systems that actually see plaintext.
A retail chain switches its terminals to point-to-point encryption and tokenizes card numbers in checkout and merchandise management; the next PCI assessment covers only the decryption environment.
Our approach
Omnichannel only works when checkout, online shop, app, marketplaces and merchandise management see the same stock, prices and customer profiles. We place an integration layer with versioned interfaces and event processing between point-of-sale system, ERP, shop platform and inventory management, so that store pickup, returns in the branch and orders placed in the store run without nightly file reconciliation. Existing checkouts and ERP systems remain in place and are connected through adapters, including the technical security device required by the KassenSichV.
A multi-store retailer connects checkout, Shopware and SAP through an event platform; stock levels in store and online shop match within seconds and returns from the shop are accepted at every checkout.
Our approach
Loyalty programs, gift cards and customer accounts collect purchase histories and contact data and therefore fall fully under the GDPR. We develop and operate customer apps, customer portals and rewards systems with consent management, roles and deletion rules anchored in the data model from the start. Card programs with physical loyalty or gift cards get card keys and balance verification in the HSM, so that cards cannot be copied and balances cannot be manipulated.
A restaurant group introduces a rewards program with app and gift card; consents, deletion periods and balance verification are documented before launch, and balances are signed in the HSM.
Our approach
Store networks and businesses with several properties benefit when checkout back end, merchandise management and customer portals run centrally and locations only need terminals and network. We migrate these applications to Microsoft Azure, AWS, Google Cloud or German data centers, build site connectivity, identities and monitoring centrally and provide an offline mode for the checkout so that sales continue during a line outage.
A hotel group moves the reservation and point-of-sale systems of all its properties to German data centers; updates reach every property on the same day and the front desk keeps booking offline during a line outage.
Our approach
Fraud in retail shows up as account takeover in the online shop, return fraud, misuse of loyalty points and vouchers, and suspicious voids at the checkout. We merge transaction, account and device data in a data platform and train models that score orders, returns and redemptions before they are approved. The same platform delivers sales and demand forecasts for replenishment and staff planning. Every decision is explainable and logged so that customer service and data protection can follow it.
An online retailer scores returns by account age, device and return history instead of refunding across the board; suspected misuse is reviewed, honest customers get their money immediately.
Our approach
Stores, shop platform and back office form a large attack surface with checkout terminals, guest Wi-Fi, supplier access and publicly reachable interfaces. We segment site networks, harden checkouts and shop servers, protect interfaces with a web application firewall and monitor all locations centrally with intrusion detection and incident response. For businesses that fall under NIS2 as important entities, such as food retailers or online marketplaces, we deliver risk management, reporting processes and evidence under ISO 27001.
A food retailer separates checkout, guest and building technology networks in every store and reports incidents centrally; the NIS2 gap analysis shows the reporting channels as the only open item.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Commercials
Card numbers pass in plaintext through checkout software and merchandise management, and the acquirer demands full PCI DSS evidence.
Payment flow analysis, point-to-point encryption from the terminal, tokenization in checkout and merchandise management, key ceremonies with records.
Scope limited to the decryption environment, complete files for the QSA assessment, operations manual for the in-house team.
02 / Commercials
Store, online shop and marketplaces keep their own stock, reconciliation runs at night, and returns from the shop are refused at the checkout.
Integration layer with event platform, interface catalog for checkout, shop and ERP, order management for store pickup and returns.
Stock reconciled within seconds, returns accepted at every checkout, releases without checkout downtime.
03 / Commercials
A rewards program with app and gift card is about to launch, consents and deletion periods are unclear, and balances sit in a spreadsheet.
Data protection concept with record of processing, customer app with consent management, stored-value system with keys and signatures in the HSM.
Program launched with a documented legal basis, balances protected against tampering, access and deletion requests in regular operation.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Payment flows, checkout and shop landscape, customer data and locations
Target architecture, encryption, interfaces, operating model
HSMs, integration layer, applications and cloud in stages per store group
Monitoring, audits, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six modules from payment encryption to fraud detection, planned, integrated and operated by OTOKO® for stores, online shops, restaurants and venues. Every card payment stays encrypted from the terminal to settlement. The entire solution runs in German data centers.
IT solutions for retail and commerce connect checkout, online shop, merchandise management and customer accounts into one platform while protecting card payments and personal data. OTOKO® covers six modules: payment security with HSMs under PCI DSS, omnichannel integration from checkout to ERP, customer accounts and loyalty programs under GDPR, cloud operations for many locations, fraud detection and sales forecasting with AI, and cybersecurity for store networks and e-commerce.
The difference from a systems integrator lies in cryptography and evidence. Card data is encrypted from the terminal to settlement, keys sit in certified devices, and every interface, deletion rule and change is documented for PCI assessors and data protection officers. Cryptography and hardware security modules are our core competence. That is why we reduce the PCI scope instead of only describing it.
Cryptography and hardware security modules are our core competence. Terminal keys, tokenization and balance signatures sit in certified devices, as PCI DSS and PCI P2PE require.
The entire solution runs in German data centers, from the payment HSM through the event platform to customer app and data platform.
We work with operators of critical infrastructure and regulated industries. We know what PCI assessors, data protection officers and card schemes expect from the financial sector and apply it to retail and hospitality.
One team accompanies you from consulting to operations. Integration developers, cryptography specialists and cloud engineers stay with you, without handover to third parties.
Most businesses do not fail on missing technology but on grown checkout landscapes, distributed locations and evidence gaps toward card schemes and data protection.
01
Terminals, checkout software and shop back end process card numbers unencrypted, so the PCI scope covers almost the entire network.
02
Checkout, online shop and marketplaces maintain their own stock and prices, reconciliation runs at night by file and returns end up in the wrong system.
03
Customer accounts collect purchase histories without documented consent, deletion periods are not implemented and access requests take weeks.
04
Every location runs its own checkout servers and network equipment, security updates arrive late and nobody sees attacks across all stores.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your data center, your checkout servers and HSMs | Data centers in Germany, operated under ISO 27001 | Azure, AWS or Google Cloud, region selectable |
| Operation | Your team or OTOKO® as managed service | OTOKO®, with reports for your PCI and data protection audits | Shared, platform services by the provider |
| Tools | payShield or Atalla on site, Kafka, Kubernetes | Hosted HSMs, event and data platform in Germany | Cloud HSM services, payShield Cloud HSM, managed data services |
| Suited for | Own payment platform, checkout back end with high requirements | Merchants who need data storage in Germany | Shop platform, analytics, promotion days with load peaks |
| Compliance | Full control, evidence from your ISMS and PCI scope | Processing agreement under GDPR, location Germany | Processing agreement, standard contractual clauses, PCI responsibility matrix per service |
Collaboration
Project
Clearly scoped undertaking such as a checkout migration, a P2PE rollout or a new online shop with a defined result, milestones and acceptance.
Team reinforcement
Integration developers, cloud engineers or security specialists work in your teams, tools and release cycles.
Managed service
OTOKO® operates payment platform, integration layer, customer app or cloud environment with agreed service levels, reports and evidence for PCI and data protection audits.
What each requirement in retail and commerce demands and what OTOKO® delivers for it.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| PCI DSS | Protection of cardholder data through network segmentation, encryption, access control, logging and annual assessment by a QSA or self-assessment | Scope definition, encryption and tokenization in the HSM, segmentation of store networks, files for QSA assessment and SAQ |
| PCI P2PE | Encryption of card data in the terminal, decryption only in an assessed environment with HSM, controlled key injection and device management | P2PE architecture with a listed solution or your own decryption environment, key injection with records, device inventory and operating processes |
| GDPR | Legal basis, consent for profiling, data minimization, data subject rights, processing agreements and data protection impact assessment | Data protection concept for loyalty program and customer app, consent management, deletion concept, access request process, processing agreement |
| ISO 27001 | Information security management system with risk analysis, control catalog, supplier management and regular internal and external audits | ISMS setup or extension to stores and shop platform, risk register, action plan, operation of the platform under ISO 27001 |
| NIS2 | Risk management, reporting of significant incidents, supply chain security and management accountability for important entities such as food retail and online marketplaces | Applicability check, gap analysis, reporting processes, supplier requirements and evidence for registration with the BSI |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers payment security with HSMs and point-to-point encryption under PCI DSS, omnichannel integration of checkout, shop and ERP, customer accounts and loyalty programs under GDPR, cloud operations for many locations, fraud detection and forecasting with AI, and cybersecurity for store networks and e-commerce. Each module can be commissioned on its own or as a package, with operation in German data centers.
The scope depends on where card data appears in plaintext. Point-to-point encryption from the terminal and tokenization in checkout, shop and merchandise management take these systems out of the plaintext path, and network segmentation separates the rest. What remains is a small decryption environment with HSM for which evidence can be maintained with reasonable effort.
Usually yes. We connect existing point-of-sale systems, ERP and shop platforms to the integration layer through adapters and replace only components that offer no interfaces or reach end of support. The technical security device under the KassenSichV stays connected unchanged.
A legal basis for every processing activity, documented consent for profiling and personalized offers, deletion periods, an access request process and, for extensive profiling, a data protection impact assessment. We anchor these rules in the data model and in consent management so that access and deletion work in regular operation and not as a special case.
That depends on sector and size. Food retail, online marketplaces and providers of certain digital services can qualify as important entities, while classic retail and hospitality usually do not. We check applicability against the German implementation act and, where needed, deliver risk management, reporting processes and registration with the BSI. We work with operators of critical infrastructure and regulated industries. That is why these requirements are routine for us.
Yes, if the checkout is designed for it. We provide an offline mode in which checkout and terminal buffer sales locally and keep accepting card payments under the rules of the payment service provider. Once the connection returns, the checkout automatically synchronizes receipts, stock and payments.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
Security architect: Target architecture, segmentation, PCI scope. Cryptography specialist: HSMs, P2PE, tokenization, key ceremonies. Integration developer: Interfaces, event platform, checkout and ERP adapters. Cloud engineer: Landing zone, migration, site connectivity. Data engineer: Data platform, fraud models, forecasts. Project lead: Milestones, store rollout, acceptance.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Payment flows, checkout and shop landscape, customer data and locations Prioritized list of measures, PCI scope, gap analysis for GDPR and NIS2
Project: Clearly scoped undertaking such as a checkout migration, a P2PE rollout or a new online shop with a defined result, milestones and acceptance. Team reinforcement: Integration developers, cloud engineers or security specialists work in your teams, tools and release cycles. Managed service: OTOKO® operates payment platform, integration layer, customer app or cloud environment with agreed service levels, reports and evidence for PCI and data protection audits.
Monitoring, audits, knowledge transfer Monitoring, key rotation, audit support, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Commercials
Let us discuss how payments, customer data, and sales channels can work together securely in your business.
Book a first consultation