Payment HSMs and key management
Target architecture with device selection and migration plan
More on thisIndustries / Financial
Secure payment processing and connect core banking systems to digital services.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We integrate payment HSMs and key management under PCI DSS, connect core banking systems through controlled interfaces to digital channels and the third-party access required by PSD2, and build data platforms for real-time fraud detection.
Target architecture with device selection and migration plan
More on thisReal-time data platform connected to payment and customer systems
More on thisIdentity architecture with authentication flows
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
Payment HSMs are certified devices that hold cryptographic keys tamper-resistant and execute PIN verification, card data encryption and tokenization. We advise vendor-neutrally on payment HSMs from Thales, Utimaco, Entrust, IBM and Futurex and plan key ceremonies with roles, quorums and records. We integrate the devices into card processing, acquiring and tokenization. The requirements of PCI DSS and the PCI PIN Security Standard shape architecture, operating procedures and audit files from the first day.
A payment processor replaces end-of-support payment HSMs with a redundant pair across two sites; the key migration runs under a documented ceremony with a planned cutover window for the terminal hosts.
Our approach
Core banking systems manage accounts, bookings and products and must not stand still during any change. We place an integration layer with controlled interfaces between the core and the channels. These are online banking, mobile apps, payment platforms and the third-party access that PSD2 requires. New products are built outside the core, while the core stays stable and auditable. Every interface is versioned, tested automatically and equipped with permissions and logging.
A regional bank launches a mobile product outside its core banking system; the app reaches accounts and bookings only through a versioned integration layer with full request logging.
Our approach
Fraud patterns change faster than static rule sets. We build data platforms that merge transaction, customer and device data in real time. On this data we train models that score each transaction before the payment is executed. Rules and models work together so that known patterns are caught reliably and new ones surface early. Every decision is explainable and logged so that customer service, compliance and the supervisor can follow it.
A card issuer scores a payment from a new country in milliseconds by device, merchant category and prior behavior instead of blocking it outright; every decision carries a reason for customer service.
Our approach
DORA obliges financial entities to run ICT risk management with incident reporting, resilience testing and contractual control of every ICT provider. We record your ICT risks and document systems and providers in the register of information. Reporting processes, threat-led penetration tests, security monitoring and recovery are set up to match the regulation. For our own services we deliver contracts with audit rights, service levels and exit plans, as DORA requires for third parties.
An insurer consolidates its provider contracts into a register of information and adds audit rights and exit plans before the supervisor's first DORA review.
Our approach
PSD2 requires strong customer authentication for account access and payments, and the card schemes require EMV 3-D Secure for online purchases. We integrate identity providers, passkeys and 3-D Secure into online banking, apps and checkout. Customers authenticate with two independent factors without abandoning the process. Employee access to core systems and HSM consoles gets the same treatment with multi-factor authentication, role models and session logging.
A direct bank replaces its SMS TAN with app-based approval and passkeys; the login for PSD2 third parties runs through the same identity provider with consent records.
Our approach
Quantum computers will break RSA and elliptic-curve cryptography, which today protects card keys, TLS connections and every certificate in a bank's PKI. We inventory the cryptography in payment systems, PKI and interfaces and rate each use by lifetime and exposure. The migration to ML-KEM and ML-DSA then follows the order the risk demands. HSMs are selected or upgraded so that the new algorithms run in certified hardware. Hybrid modes keep today's card and terminal fleets compatible during the transition.
A payment provider inventories the cryptography of its terminals, HSMs and PKI and starts the migration with a hybrid root CA in certified hardware, while the terminal fleet keeps its current keys until replacement.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Financial
Payment HSMs reach end of support, key ceremony records are incomplete and the PCI assessor has flagged the gap.
Target architecture with redundant payment HSMs, documented key ceremonies, TR-31 key blocks and a staged migration per host application.
Certified devices in operation, complete key records for the PCI PIN assessment, cutover in planned windows outside peak hours.
02 / Financial
Instant payments go live, the static rule set blocks legitimate transfers and lets new fraud patterns through.
Streaming platform with transaction events, scoring model combined with rules, explanation per decision for customer service.
Scoring before execution, fewer false alarms in manual review, decision logs for compliance and the supervisor.
03 / Financial
The supervisor announces a DORA review, provider contracts predate the regulation and no register of information exists.
ICT risk framework mapped to the ISMS, register of information with criticality and exit plans, incident reporting workflow, resilience test program.
Complete register, contracts with audit rights, first threat-led penetration test documented before the review.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Prioritized list of gaps and measures
Target architecture, security measures, operating model
HSMs, interfaces and data platform in stages
Monitoring, audits, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six modules from payment HSMs to post-quantum readiness, delivered and operated by OTOKO®. The entire solution runs in German data centers, documented for DORA, PCI DSS and PSD2 audits.
IT solutions for banks and financial services secure payments cryptographically, keep core banking systems running through every change and prove each change to the supervisor. OTOKO® covers six modules: payment HSMs and key management, core banking integration and PSD2 interfaces, fraud detection with data and AI, DORA resilience and third-party management, identity and customer authentication, and post-quantum readiness for payment and PKI.
The difference lies in the evidence. Every HSM, interface and model comes with the documentation that DORA, PCI DSS and PSD2 auditors ask for, from key ceremony records to change logs. Cryptography and hardware security modules are our core competence. Payment keys, PINs and certificates are protected accordingly.
Cryptography and hardware security modules are our core competence. Payment keys, PINs and certificates are handled with the care that PCI PIN and the card schemes demand.
The entire solution runs in German data centers, from the payment HSM to the fraud platform, with the location evidence your DORA register needs.
We work with operators of critical infrastructure and regulated industries. We know what information security officers, compliance and auditors expect from a provider.
One team accompanies you from consulting to operations. Cryptography specialists, integration developers and data engineers stay on without handover to third parties.
Most institutions do not fail on technology but on the evidence and the dependencies around it.
01
Payment keys were loaded years ago, ceremony records are incomplete and nobody knows which key block format the terminals use.
02
Every new channel connects directly to the core banking system, so each release puts the nightly batch and the booking run at risk.
03
Static rule sets catch known patterns, while new fraud schemes only show up weeks later in chargebacks and customer complaints.
04
DORA requires audit rights, exit plans and a register of information, but the provider contracts predate the regulation.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your data center, your HSMs | Data centers in Germany, operated under ISO 27001 | Azure, AWS or Google Cloud, region selectable |
| Operation | Your team or OTOKO® as managed service | OTOKO®, with audit rights for your institution | Shared, platform services by the provider |
| Tools | Payment HSMs and key managers on site | Hosted HSMs and key management in Germany | Cloud HSM services, payShield Cloud HSM |
| Suited for | Card processing, PIN handling, PCI PIN scope | Regulated institutions with a need for sovereignty | Digital channels, analytics, fast pilots |
| Compliance | Full control, evidence from your ISMS | Processing agreement under GDPR, DORA register entry, location Germany | Processing agreement, standard contractual clauses per service, DORA subcontractor chain |
Collaboration
Project
Clearly scoped module with a defined result, milestones and acceptance.
Team reinforcement
Cryptography specialists, integration developers or data engineers work in your teams, with your tools and in your sprints.
Managed service
OTOKO® operates HSMs, interfaces or data platforms with agreed service levels, reports and the contract terms DORA requires.
What each regulation requires and what OTOKO® delivers for it.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| DORA | ICT risk management, incident reporting, resilience testing, register of information and contractual control of ICT third-party providers | Risk framework, register of information, reporting workflow, test program and contracts with audit rights and exit plans for our own services |
| PCI DSS | Protection of cardholder data with network segmentation, encryption, access control, logging and annual assessment | Scope definition, HSM-based encryption and tokenization, key management procedures, evidence for the assessor |
| PCI PIN Security | PIN processing in PCI-approved HSMs, dual control and split knowledge for keys, documented key ceremonies and key blocks | Approved payment HSMs, key ceremony records, TR-31 key block migration, operating procedures for the PIN assessment |
| PSD2 | Strong customer authentication with dynamic linking and access interfaces for licensed third-party providers | Authentication integration with passkeys and 3-D Secure, PSD2 interfaces with consent management and fallback evidence |
| GDPR | Legal basis, data minimization, data subject rights, processing agreements and data protection impact assessment | Data protection concept for fraud models, pseudonymization, deletion concept, processing agreement with location Germany |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers payment HSMs and key management under PCI DSS and PCI PIN. It includes core banking integration with PSD2 interfaces and fraud detection with data platforms and models. It also covers DORA resilience, customer authentication and post-quantum readiness. Each module can be commissioned on its own or as a package. Operation runs in your data center, in German data centers or on a hyperscaler.
We record your ICT risks, document systems and providers in the register of information and set up incident reporting and resilience testing. For our own services we deliver contracts with audit rights, service levels and exit plans, as DORA requires for ICT third-party providers. Your institution stays able to answer the supervisor at any time.
Usually yes. We check firmware levels, certifications and vendor support. A replacement is planned only where devices reach end of support or miss requirements such as PCI PTS HSM v3 or post-quantum cryptography. Migrations run with documented key ceremonies and planned cutover windows, as we are used to with operators of critical infrastructure and regulated industries.
Every score is stored with the features that drove it, the rule that fired and the model version that produced it. Customer service sees the reason in plain terms and compliance gets the full log. The model card documents training data, quality and limits under the EU AI Act.
Yes. Payment HSMs, key management, interfaces and the fraud platform can run in your data center or in German data centers operated under ISO 27001. Hyperscaler regions in Germany are an option for channels and analytics where the data classification allows it.
Now, with the inventory. Card keys, root certificates and archived data have lifetimes that exceed the expected arrival of capable quantum computers, and HSM refresh cycles take years. The inventory decides which systems migrate first and which can wait for the next hardware cycle.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
Cryptography architect: HSM architecture, key management, PCI evidence. Integration architect: Interface catalog, data contracts, core banking integration. Data engineer: Streaming platform, feature store, model operations. Security architect: DORA framework, identity, monitoring. Compliance lead: Register of information, audit files, supervisor communication. Project lead: Milestones, acceptance, reporting.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Prioritized list of gaps and measures Inventory of payment processes, core systems, interfaces and regulatory gaps, prioritized measures
Project: Clearly scoped module with a defined result, milestones and acceptance. Team reinforcement: Cryptography specialists, integration developers or data engineers work in your teams, with your tools and in your sprints. Managed service: OTOKO® operates HSMs, interfaces or data platforms with agreed service levels, reports and the contract terms DORA requires.
Monitoring, audits, knowledge transfer Monitoring, key rotation, audit support, stepwise handover to your teams
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Financial
Let us explore together how payment security, core system integration and fraud detection can work together in your institution.
Book a first consultation