Business cards aren't on your roadmap. They're on your ticket queue.

Onboarding ticket loop

New hire's first week. They ping IT asking where their business cards are. IT pings HR, HR pings the local office manager. Three days later, you're chasing a print shop in Warsaw - for cards.

Offboarding blind spot

An employee leaves. Offboarding checklist runs cleanly - accounts deactivated, devices retrieved, badges revoked. Business cards aren't on the list. They keep circulating for months. When a customer mentions it, the question lands with IT.

Compliance audit gap

An auditor asks where employee personal data is stored. You map your systems: HRIS, IdP, payroll, the usual stack. Then you realize: every business card with a phone number is a data exposure point. There's no central registry. You can't even count them.

Vendor sprawl

Procurement asks for the vendor list. You provide it. Three months later, finance discovers business cards billed to four different vendors across three departments. None of them are in your vendor management system. Now you're being asked to consolidate something IT never bought.

Business cards aren't an IT problem. But until something owns them, they become one.

Identity in. Cards out. Nothing for IT to administer in between.

DBC1 doesn't store your employee directory. It subscribes to it. Cards are created, updated, and deactivated as a side effect of identity events in the systems you already run.

Architecture diagram: Identity sources flow into DBC1, then out to card manifestations

Identity as source

Your HR system or identity directory stays the source of truth. DBC1 mirrors the org chart from whichever system you nominate, and our team keeps that mirror current. When an employee record changes - joins, promotion, transfer, departure - you tell us once and the card state follows.

Card as derivative

A card in DBC1 isn't a stored artefact. It's rendered on request from the current employee record, the company's brand configuration, and the format requested. Update a title once and every format reflects it the next time the card is opened - no reissue, no stale copies in circulation.

IT observability

Every administrative action - provisioning, deprovisioning, card generation, configuration change - is logged with actor, timestamp and target. Logs are exportable on request. Retention and tamper-resistance are being formalised as part of our ISO 27001 programme.

HRIS sync. That's the entire integration surface today.

No agents, no new tools, no data warehouse. DBC1 reads from your existing systems and writes nothing back.

Identity & Authentication

There is nothing for your team to build. You nominate the system that holds your employee records, and DBC1 runs the sync. SAML 2.0 single sign-on and SCIM 2.0 provisioning are planned for the Enterprise tier and are not available today. If you want cards on your own subdomain, one CNAME record completes the setup.

Identity ProviderStatus
OktaTestedVERIFY
Microsoft Entra IDTestedVERIFY
Google WorkspaceTestedVERIFY
OneLoginSupported
JumpCloudSupported
Any SAML 2.0 IdPSupported
HR System of Record

If your HR system isn't your identity provider - which is usually the case - DBC1 works from the HR record instead. Employment status, department hierarchy and custom fields that don't exist in an IdP are still available for card generation and access decisions, because our team maintains that record with you rather than relying on a connector.

HRISStatusMethod
BambooHRTestedVERIFYNative API
RipplingTestedVERIFYNative API
WorkdayTestedVERIFYSCIM 2.0
HiBobTestedVERIFYNative API
SAP SuccessFactorsSupportedSCIM 2.0
ADPSupportedSCIM 2.0
OtherSupportedSCIM 2.0
What you don't need
  • Your prospects don't need to install anything to scan a card. Tap, scan, or open the link - the experience is browser-based.
  • Your employees don't need to install anything to have a card. Cards work via web links and Apple/Google Wallet - both already on every modern phone.
  • You don't need to expose internal APIs. DBC1 reads from your IdP and HRIS via standard protocols (SAML, SCIM). No firewall changes required.
  • You don't need to set up VPN access for DBC1. All integration is through public, authenticated endpoints on your existing systems.

Three phases. Two weeks. No engineering work.

Most customers go from contract signed to first cards in pockets within two weeks. Our team handles the setup. Your team makes decisions and authorizes access. The work happens on our side of the line.

01Setup
Days 1-3
What DBC1 does
  • Provision your tenant
  • Configure your brand based on assets you provide
  • Set up IdP and HRIS connections (with your authorization)
  • Map user attributes to card fields
  • Run end-to-end tests
What you do
  • Authorize SAML app in your IdP (one-time, takes minutes)
  • Grant DBC1 read access to your HRIS (one-time)
  • Provide brand assets (logo, fonts, colors)
  • Add CNAME record if using a custom subdomain (optional)
  • Approve the configuration before we go live
02Pilot
Days 4-7
What DBC1 does
  • Generate card designs for review
  • Produce test prints of physical formats
  • Provision pilot group cards
  • Walk you through the admin view (optional - most customers never log in)
  • Adjust based on your feedback
What you do
  • Identify pilot group (typically 10-20 employees)
  • Review card designs, approve or request changes
  • Test end-to-end employee experience with your pilot group
03Rollout
Day 8+
What DBC1 does
  • Enable provisioning across your organization
  • Process initial physical card orders
  • Handle ongoing changes (brand updates, new fields, regional adjustments) as you request them
  • Monitor system, alert you to anomalies
What you do
  • Communicate launch to employees
  • Reach out to us when you need anything changed
  • Employees access cards on day one
Your concierge team
You don't log in to a portal - you write an email.

You have a named contact at DBC1 who knows your configuration. Changes to templates, brand rules, fields or fulfilment go to that person and are handled for you - there is no ticket queue and no self-service configuration to learn.

From day 8 the system is yours - and we keep running it. New hires get cards. Departing employees are deactivated. When something needs to change, you tell us. We handle the rest.

Configuration is delegated. Control is not.

Operational work happens on our side. Decisions about access, brand, scope, and enforcement happen on yours. The admin portal is available if you want to use it - most customers don't.

AreaDBC1IT
Who gets a cardapplies criteriasets criteria
Card contentrendersdefines fields
Brand standardpropagatesgoverns
Access controlimplementsconfigures roles
Audit logsmaintainsreviews
Physical fulfillmentexecutes(not involved)
Who gets a card

Provisioning criteria and triggers.

Cards can be issued to all employees, specific roles, specific departments, or specific markets. You set the criteria; we apply them - automatically, from your HRIS data.

What's on the card

Fields, layouts, and role-specific variants.

The standard fields (name, title, email, phone) are baseline. Beyond that, you decide: do field offices show their local address, or HQ's? Do certain roles show direct phone, or main switchboard?

Brand and visual standard

Where cards live and what they look like.

Logos, colors, typography, banner imagery, custom subdomain. Defined once, applied to every card and every landing page. When the brand evolves, the change is propagated - by us, on your signal.

Access and audit

Roles, permissions, and audit trail.

Roles in DBC1 are Super Admin, Company Manager, Group Manager and Reseller. Custom roles are not available today. Audit logs record every change with actor, timestamp and target, exportable on request.

The admin portal exists.

If you'd rather click than email, the admin portal lets you do everything your concierge does - provisioning rules, brand updates, role assignments, audit log exports. We'll walk you through it during onboarding. Most customers prefer to delegate; some prefer to drive. Both are supported.

However you use DBC1 - concierge or hands-on - the territory is the same. We operationalize. You govern.

The IT work that was never IT's job in the first place.

Business cards have always created work for IT - even though business cards aren't an IT system. New hires chase you. Departures slip through. Marketing escalates inconsistencies. DBC1 takes that entire category of work off your plate and runs it for you.

Onboarding tickets

You no longer chase down business cards for new hires. They appear in the employee record we maintain with you, their card is provisioned, and the physical version ships to their desk or address — without IT ever opening a ticket.

Offboarding gaps

You no longer wonder whether a departing employee's cards are still circulating. Tell us they've left — or we pick it up from the employee record we maintain with you — and their card stops working. The physical version becomes an unscannable piece of plastic.

Portal administration

You no longer train your team on a new admin tool. Configuration, brand updates, and ongoing changes are handled by your DBC1 concierge - you send a request, we do the work. The portal is available if your team prefers to drive it themselves; most don't.

Compliance audit prep

You no longer scramble when an auditor asks where employee PII is stored. Business cards are now a centralized, governed system with audit logs, access controls, and a documented data flow - searchable, exportable, defensible.

What's left for IT to do? Decide policy. Authorize access. Let DBC1 run it.

Built to pass your security review.

EU-only data residency, encryption, role-based access and audit logging — plus a straight account of what we have not built yet. Highlights below, full detail on /security.

Hosting & data residency

Google Cloud, three EU regions: Belgium, Poland and Germany. Customer data stays inside the EU. We do not offer non-EU regions, on request or otherwise.

Identity & access

Role-based admin access with least-privilege defaults. Audit logs for every administrative action. SAML 2.0 SSO, SCIM 2.0 provisioning and administrator MFA are on the Enterprise roadmap and are not available today.

Encryption

TLS 1.3 in transit. AES-256 at rest, applied at the platform layer by our hosting and database providers.

Compliance

GDPR compliant. Standard DPA with EU Standard Contractual Clauses available. DPO designated. SOC 2 Type II and ISO 27001 are in preparation — no certificate has been issued yet.

Incident response

Confirmed personal data breaches are notified to your designated contact without undue delay and no later than 72 hours, as committed in the DPA. High-severity operational incidents are reported directly to your named contact.

Want the full picture?

Our security page documents the controls in place, the certifications in preparation, the sub-processor categories, and what we have not built yet — written for the depth your review team needs. Completed security questionnaires, architecture detail and our internal security test summary are available to reviewers under NDA.

Full security details →

If your security team has questions before we book a call, send them to security@dbc1.com - we'll respond before the demo.

Talk to engineering, not to sales.

Initial calls are with our CTO. Thirty minutes. No demo script - just the product and your questions.

Wojciech Kwiatek, CTO of DBC1



Wojciech Kwiatek
CTO, DBC1

Designs and operates the systems behind DBC1. Will be on your call.

Or:
  • Email Wojciech directly - cto@dbc1.com
  • Send questions to our security team - security@dbc1.com - we'll respond before any call
What to expect on the call
  1. A walkthrough of how DBC1 plugs into your specific stack - bring your IdP and HRIS names.
  2. Architecture questions, data flow questions, security questions - answered by the person who designed them.
  3. Honest discussion of what we don't do yet, and what's on the roadmap.

DBC1 isn't built for every IT team. It's built for the ones who'd rather decide than configure. If that's you, the next step is short - thirty minutes with our CTO.

×
Book a technical demo
Thirty minutes with our CTO. We reply within a few working hours.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We use these details only to prepare and arrange the call. Your data stays in the EU.