Skip to main content
OnArrival

All of travel, embedded under one contract.

Property platforms, marketplaces and HR suites can add travel under one commercial agreement. Policy is enforced by the API for every booking surface.

Why enterprises pick us

One commercial agreement across travel products.

01
Single relationship
One commercial agreement covers flights, stays, ground, experiences, insurance and payments.
02
Policy as code
Per-traveller, per-cost-centre policy enforced server-side, at the API, not as bypassable client-side checks.
03
Procurement-ready
SOC 2 Type II, DPA, vendor risk pack, and customer-managed keys on the Enterprise tier.
Capabilities

Controls product can ship, and security can verify.

Identity
  • SSO + SCIM
  • Per-tenant isolation
  • Role-based access
  • Audit log streaming
  • Session controls
Policy
  • Approval workflows
  • Cost-center routing
  • Spend caps and alerts
  • Per-traveller policy
  • Pre-trip approval
Data
  • Webhooks + streams
  • Warehouse sync
  • Reverse ETL friendly
  • Per-event PII tags
  • Custom retention
Trust
  • SOC 2 Type II
  • GDPR + CCPA aligned
  • Customer-managed keys
  • Penetration testing
  • BAA on request
The console

What the review board actually sees.

Tenants isolated with their own customer-managed keys, SSO and SCIM live, policy enforced as code, and every booking signed into an immutable audit trail: the answers your CISO asks for, in one screen.

The governance surface

One console for every tenant.

Per-tenant isolation, SSO and SCIM status, the policy rules in force and the live audit stream. The governance surface enterprises actually buy, in one view instead of four dashboards.

Tenants, isolated

Data and keys scoped per tenant: no shared blast radius, no cross-tenant leak path to explain in review.

Policy you can read

Server-side rules shown as config, not buried in code: spend, cabin and cost-centre limits the product team can see and the auditor can verify.

Audit you can stream

Every event to your SIEM or warehouse in real time, so detection and retention live in your stack, not ours.
For the security review

Built to pass the review.

SOC 2 Type II, a DPA, a vendor risk pack and customer-managed keys: the answers your CISO asks for, ready before the first call.

Audited, annually

SOC 2 Type II report shared under NDA during procurement.

Data stays yours

Per-tenant isolation, customer-managed keys, per-event PII tags.

Policy server-side

Spend, cabin and cost-centre rules enforced at the API, not in the UI.
From pilot to rollout

One security review, then every team.

Clear the security review, ship a pilot in a single product surface, then add products and teams without a second procurement cycle.

  1. Scope

    Security sign-off

    Vendor risk pack, DPA and SOC 2 report clear review before a line of code ships.

  2. Integrate

    Wire SSO, drop in the SDK

    Wire SSO/SCIM and drop in components or APIs themed to your product.

  3. Govern

    Set policy as code

    Per-traveller, per-cost-centre rules and approval routing, enforced server-side.

  4. Expand

    Roll out wide

    Add products and teams under one contract. Every event streamed to your warehouse.

At enterprise scale

What review boards sign off on.

Get started
Clear the review once. Expand without reopening it.
Related

Pairs well with

Most of our customers use two or three of these together.

Related reading

All field notes →