1-CP processes payment data under PCI DSS and personal data under the GDPR.

You assign access yourself, per business unit. Every data delivery to your systems is signed and verifiable. 1-CP is based in Frankfurt am Main.

Security foundationsBuilt into the platform
PCI DSS
Compliant
GDPR
Compliant
Access
Role-based
Events
HMAC-signed

Four foundations
for every purchase.

They apply on all four ways to buy: API, Corporate Checkout®, Corporate PayLink™ and Corporate Wallet® Agent.

  • PCI DSS compliant

    Payment handling built to the card industry’s data security standard, with encryption and fraud protection.

  • GDPR compliant

    Personal data is handled in line with the EU General Data Protection Regulation.

  • Role-based access

    Read, write and admin rights per business unit, assigned to people or inherited through groups.

  • Signed connections

    Events are delivered over HTTPS and signed with HMAC-SHA256, so your systems can verify every message.

Each party receives the data
it needs for the purchase.

The merchant does not see your cost centre, the payment provider does not see your policy, and your ERP does not see card numbers. Each party receives only its part.

  • Company & identity

    Name of the buyer, company, billing address and the applicable policy.

  • Purchase information

    Merchant, line items, amounts, status and invoice.

  • Payment information

    Only what the payment service needs to authorise, and the result it returns.

  • Connected systems

    Accounting, travel and reporting receive the fields they book or evaluate, nothing more.

Your company sets access rights
per business unit.

Finance may change everything, travel management may edit policies, controlling may only read. You set rights per business unit and per area: companies, payment methods, profile providers, transactions and reports.

  • Read, write and admin rights, set per business unit
  • Rights assigned to individuals or inherited through groups
  • Admin access limited to the people who need it
  • Company sign-in through your connected profile and identity providers

Data your systems
can verify.

Before your ERP posts a purchase, it can check that the data really comes from 1-CP and has not been changed on the way.

  • Every event is signed with a secret only you and 1-CP know
  • Timestamps protect against replayed messages
  • Unique event IDs prevent the same purchase being booked twice
  • API secrets stay on your server, never in the browser
  • A separate staging environment to test before going live

Who is responsible
for what in a purchase.

Your company controls access

Sign-in runs through your identity provider. If IT deactivates an account, that person can no longer buy on behalf of the company.

How the company setup works

Payment roles stay explicit

Banks, issuers and payment providers authorise and settle the payment. 1-CP is neither bank nor issuer; it adds the company details.

Payment partner responsibilities

Corporate Wallet® Agent works in the browser

The Agent reads the checkout page the buyer has open, fills in the company details and leaves the final click to the buyer.

What the Agent reads

Your security review,
well prepared.

Send us your security questionnaire. We answer it and provide the documents your IT, security and privacy teams need.

What you can request

  • Architecture and data-flow overview for your purchase flow
  • Data processing agreement and list of subprocessors
  • Hosting, retention and deletion details
  • Payment compliance evidence and card-data scope
  • Browser permissions and processing for Corporate Wallet® Agent
Is 1-CP PCI DSS compliant?

Yes. Payment handling on the 1-CP platform is PCI DSS compliant, with encryption and fraud protection. Request the compliance evidence for your review from security@one-cp.com.

How does 1-CP handle personal data?

In line with the GDPR. Each party receives only its part: the merchant the billing details, the payment service the payment data, your systems the booking fields.

Who in our company can see or change the setup?

Only the people you give access to. Rights are assigned as read, write or admin per business unit and per area, directly or through groups.

How do our systems know purchase data really comes from 1-CP?

Every event can be signed with HMAC-SHA256 using a secret you configure. Your system checks the signature and the timestamp before accepting the data.

Can we test the integration before going live?

Yes. A staging environment with test credentials is available for development and testing.

Does 1-CP become our bank or card issuer?

No. Your bank or card issuer keeps authorising and processing the payment. 1-CP adds buyer, company, cost centre and invoice to it.

Let’s talk about
security for your company.