Skip to main content
OnArrival

Built to hold sensitive data.

Security controls for passenger data, payment tokens and supplier credentials. Review audits, architecture, access, incident response and resilience.

Illustration: an attendant at a bright left-luggage counter hands a traveller a small claim tag, a wall of closed lockers holding one case safely behind them.
Type II, audited annually
Level 1 service provider
Encryption at rest
Breach-disclosure window

Audits

SOC 2Type IIAudited annually
PCI DSSLevel 1Attested annually
ISO 27001Stage 2Scheduled · Q4 2026
GDPR + CCPADPA per customerAttested
Pen-testExternal, full-scopeAt least annually
  • SOC 2 Type II: audited annually by an independent firm; report available under NDA.
  • PCI DSS Level 1 service provider, attested annually. Card data is tokenised by our PSP in its PCI environment. Tokenisation can reduce PCI scope; confirm the scope of your integration with your QSA.
  • ISO 27001: Stage 2 audit scheduled; certification expected Q4 2026.
  • GDPR + CCPA: a DPA is executed per customer, with a published sub-processor registry and 30 days’ notice on changes.
  • Penetration testing: full-scope external test by an independent firm at least annually and after any material architecture change. Critical and high findings are remediated within 30 days; the executive summary is shared under NDA.

Architecture

Multi-region, multi-AZ. Customer data lives in the region of contracting unless an export is explicitly approved. Per-tenant logical isolation; per-customer encryption keys on Enterprise tier.

REGION · eu-westaz-aaz-baz-ctenant_atenant_btenant_cper-customer keysLogicalisolationlanes nevercross
Per-tenant isolation across AZs: separate lanes, separate keys
  • Encryption at rest: AES-256 (S3, RDS, vault).
  • Encryption in transit: TLS 1.2+ everywhere; mTLS for sensitive supplier links.
  • Secrets: AWS KMS + HashiCorp Vault, rotated quarterly.
  • Vault-isolated PII; only the booking service can read it, with audited request signatures.

Access

Least-privilege from day one. Engineers do not have routine access to production data; emergency access is JIT, signed, and reviewed within one business day.

  • SSO + SCIM on the customer dashboard. Provisioning and de-provisioning follow your directory, so an offboarded user loses access in minutes, not on a ticket queue.
  • Role-based access for our staff; sensitive roles are MFA-enforced with hardware keys, and standing production-data access is denied by default.
  • All access is logged; logs stream to a tamper-resistant, append-only audit store so every read is attributable after the fact.

PII handling

Traveller PII (name, DOB, passport, contact) is tagged at write-time and routed to a dedicated vault. Application services receive a reference token; only the booking service decrypts on demand, audit-logged per call.

Incoming PIIname · DOB · passporttag @ writeAES-256 · PII VAULTtok_••• (reference only)App servicestoken onlysigned decrypt · on demandBooking servicedecrypts on callaudit-log stamped
Tagged at write · only the booking service decrypts · every call is stamped

Each authorised decrypt request is signed and logged for investigation.

Sub-processors & vendor management

Each sub-processor completes a security review covering certifications, data handling, incident history and operating regions. Access is scoped to the data needed for its contracted purpose.

  • Security review before onboarding: every prospective sub-processor is assessed against the same control framework we hold ourselves to, and high-risk gaps must be remediated before any production data flows.
  • Flow-down obligations: each sub-processor is contractually bound to terms no less protective than the ones in your DPA. Confidentiality, security measures, breach notification and audit rights flow all the way down the chain.
  • Published registry: the live registry lists every sub-processor by name, location, purpose and class, so your vendor file always reflects exactly who handles your data and why.
  • Change notice: material additions or changes are notified at least 30 days in advance, giving you time to review, and to object with reasonable cause, before the change takes effect.
Sub-processor details
The current sub-processor list, with each vendor’s name, location and purpose, is maintained under your agreement and referenced from our DPA.

Incidents

A documented incident-response plan defines on-call ownership, escalation and customer communication. Material incidents are disclosed to affected customers within 24 hours of confirmation.

Illustration: late at night in a quiet home study, an on-call engineer calmly takes a phone call at a small desk, one hand on an open laptop, under the single warm pool of a desk lamp while the city outside sleeps.
Detectt = 0Page on-callminutesCustomer comms< 1 hourBreach disclosure< 24 hoursPostmortemshared
Comms in the first hour · disclosure inside 24, not after the postmortem

Resilience

Booking-critical services run across availability zones. Stateless services scale across zones and stateful stores use automated failover.

async replicationRPO ≤ 5m · RTO ≤ 30mREGION APrimaryread/writereplicareplicasynchronous · in-regionREGION BWarm standbyready to take overPROMOTEDautomated · drilled quarterly
Fail over without a human in the loop: promotion is automated and drilled
  • Recovery targets: RPO ≤ 5 minutes and RTO ≤ 30 minutes for booking-critical services, contractually committed on Enterprise tier.
  • Multi-region, multi-AZ by default. Databases run with synchronous replicas in-region and asynchronous replication to a warm standby region; promotion is automated and drilled.
  • Backups: continuous point-in-time recovery on primary stores, plus encrypted snapshots every 6 hours retained for 35 days. Backups are AES-256 encrypted and stored in a separate account to contain blast radius.
  • Restore testing: backups are restored to an isolated environment and integrity-checked monthly; a full region-failover game day runs quarterly with timing measured against our RTO.
  • DDoS posture: edge anycast with always-on L3/L4 absorption, L7 rate-limiting and WAF rules, and traffic shaping that sheds abusive load before it reaches origin.

Reporting

Found something? We acknowledge every report within one business day. Coordinated disclosure is preferred, and we will never pursue good-faith researchers.

Report a vulnerability
Email security@onarrival.com with the details and steps to reproduce.
Illustration: late in the evening, a hotel concierge places a traveller's passport into one of a wall of small safe-deposit boxes behind the front desk while the traveller waits, relaxed, holding a room key.
Get started
Have a question we didn’t answer? Talk to us.

Related reading

All field notes →