Skip to content

Legal

Security

How the platform is secured, and what we have not yet done.

Identity and access

OAuth 2.0 client credentials with short-lived, scoped bearer tokens. Role-based access control in the admin surfaces. Multi-factor authentication for administrative accounts.

Isolation

Tenancy is enforced at the data layer rather than filtered in application code, so a query that fails to scope by tenant fails rather than leaking across customers.

Secrets and payment data

Supplier credentials and API secrets are held in a secrets manager and referenced, never stored in application databases. Client secrets are shown once at creation.

Payment card data is tokenised at a PCI-compliant provider. TravelCore does not receive, process or store raw card numbers.

Operational security

Encryption in transit and at rest. Audit logging of configuration and pricing changes with actor and before/after state. Rate limiting and request validation at the gateway. Automated backups with periodic restore verification.

What we have not done yet

TravelCore does not hold SOC 2 or ISO 27001. An independent penetration test is scheduled before the first production customer goes live and has not yet been completed.

We state this plainly because a security page that lists only strengths is not a security page. If you need a certification we do not hold, that is a legitimate reason to choose someone else, and we would rather you know now.

Reporting a vulnerability

Send findings to platform@travelcore.tech. We will acknowledge within two working days, and we will not pursue action against researchers who act in good faith and avoid harming users or data.

Status of this document

This document is a plain-language draft describing intended practice. It has not been reviewed by counsel and is not yet an executed agreement. Before any commercial engagement, a reviewed version will be issued and will govern. If you need the binding text now, ask and we will tell you honestly that it is in preparation.