1-CP processes payment data under PCI DSS and personal data under the GDPR.
You assign access yourself, per business unit. Every data delivery to your systems is signed and verifiable.
- PCI DSS
- Compliant
- GDPR
- Compliant
- Access
- Role-based
- Events
- HMAC-signed
Four foundations
for every purchase.
They apply on all four ways to buy: API, Corporate Checkout®, Corporate PayLink™ and Corporate Wallet® Agent.
PCI DSS compliant
Payment handling built to the card industry’s data security standard, with encryption and fraud protection.
GDPR compliant
Personal data is handled in line with the EU General Data Protection Regulation.
Role-based access
Read, write and admin rights per business unit, assigned to people or inherited through groups.
Signed connections
Events are delivered over HTTPS and signed with
HMAC-SHA256 , so your systems can verify every message.
Each party receives the data
it needs for the purchase.
The merchant does not see your cost centre, the payment provider does not see your policy, and your ERP does not see card numbers. Each party receives only its part.
Company & identity
Name of the buyer, company, billing address and the applicable policy.
Purchase information
Merchant, line items, amounts, status and invoice.
Payment information
Only what the payment service needs to authorise, and the result it returns.
Connected systems
Accounting, travel and reporting receive the fields they book or evaluate, nothing more.
Your company sets access rights
per business unit.
Finance may change everything, travel management may edit policies, controlling may only read. You set rights per business unit and per area: companies, payment methods, profile providers, transactions and reports.
- Read, write and admin rights, set per business unit
- Rights assigned to individuals or inherited through groups
- Admin access limited to the people who need it
- Company
sign-in through your connected profile and identity providers
Data your systems
can verify.
Before your ERP posts a purchase, it can check that the data really comes from
- Every event is signed with a secret only you and
1-CP know - Timestamps protect against replayed messages
- Unique event IDs prevent the same purchase being booked twice
- API secrets stay on your server, never in the browser
- A separate staging environment to test before going live
Who is responsible
for what in a purchase.
Payment roles stay explicit
Banks, issuers and payment providers authorise and settle the payment.
Corporate Wallet® Agent works in the browser
The Agent reads the checkout page the buyer has open, fills in the company details and leaves the final click to the buyer.
What the Agent readsYour security review,
well prepared.
Send us your security questionnaire. We answer it and provide the documents your IT, security and privacy teams need.
What you can request
- Architecture and data-flow overview for your purchase flow
- Data processing agreement and list of subprocessors
- Hosting, retention and deletion details
- Payment compliance evidence and card-data scope
- Browser permissions and processing for Corporate Wallet® Agent
Security questions, answered.
Talk to theIs 1-CP PCI DSS compliant?
Yes. Payment handling on the
How does 1-CP handle personal data?
In line with the GDPR. Each party receives only its part: the merchant the billing details, the payment service the payment data, your systems the booking fields.
Who in our company can see or change the setup?
Only the people you give access to. Rights are assigned as read, write or admin per business unit and per area, directly or through groups.
How do our systems know purchase data really comes from 1-CP ?
Every event can be signed with
Can we test the integration before going live?
Yes. A staging environment with test credentials is available for development and testing.
Does 1-CP become our bank or card issuer?
No. Your bank or card issuer keeps authorising and processing the payment.



