Kayak · Trust Center

Kayak Trust Center

Trust center

Kayak maintains a public trust center documenting SOC 2 Type II, PCI DSS, GDPR, CCPA, and SOX compliance.

CompanyTravelMetasearchFlightsHotelsCar RentalTravel SearchPrice ComparisonBooking HoldingsAI
Trust center: https://www.kayak.com/c/security/

Certifications & Compliance

SOC 2 Type IIPCI DSSGDPRCCPASOX

Source

Trust Center

kayak-trust-center.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: false
source: https://www.kayak.com/c/security/
url: https://www.kayak.com/c/security/
summary: >-
  KAYAK publishes a public security page describing its security program:
  a HackerOne bug bounty and coordinated vulnerability disclosure, a 24/7
  Security Operations Center, alignment to the NIST Cybersecurity Framework,
  annual third-party audits, and a set of named compliance credentials.
certifications:
- SOC 2 Type II
- PCI DSS
- GDPR
- CCPA
- SOX
frameworks:
- NIST Cybersecurity Framework
programs:
- name: HackerOne bug bounty / coordinated vulnerability disclosure
  url: https://hackerone.com/kayak
- name: Security Operations Center (24/7)
- name: Annual third-party security audits
evidence:
- source: https://www.kayak.com/c/security/
  keywords:
  - soc 2 type ii
  - pci dss
  - gdpr
  - ccpa
  - sox
  - hackerone
  - nist cybersecurity framework
- source: well-known/kayak-security.txt
  keywords:
  - policy
  - contact