Trainline · Trust Center
Trainline Trust Center
Trust center
Trainline maintains a public trust center documenting PCI DSS Level 1, ISO/IEC 27001, and ISO 22301 compliance.
TravelRailUnited KingdomEuropeBookingTicketingDistributionOTACorporate Travel
Trust center: https://www.thetrainline.com/terms/security
Certifications & Compliance
PCI DSS Level 1ISO/IEC 27001ISO 22301
Source
Trust Center
generated: '2026-07-28'
method: searched
probe: true
url: https://www.thetrainline.com/terms/security
title: Trainline Security Overview
note: >-
Trainline runs no vendor trust portal (no trust.thetrainline.com, no Vanta/Drata/SafeBase
page, no security.thetrainline.com). Its published trust surface is a single consumer-facing
"Trainline Security Overview" page under the terms tree. It is unusually substantive for that
format — it names certifications with certificate numbers, an uptime commitment, the hosting
provider and data residency, and a vulnerability reporting address — so it is captured here as
the trust-centre equivalent. There is no partner/API-specific trust pack published, and no
downloadable evidence (no SOC 2 report, no ISO certificate PDF, no CAIQ/SIG, no subprocessor list).
certifications:
- name: PCI DSS Level 1
scope: both as a merchant and as a service provider
quote: "Trainline are PCI Level 1 compliant both as a merchant and as a service provider"
certificate_number: null
- name: ISO/IEC 27001
scope: Information Security Management Systems
certificate_number: IS 775108
- name: ISO 22301
scope: Business Continuity Management Systems
certificate_number: BCMS 763415
regulatory:
- name: UK GDPR / EU GDPR
posture: >-
"We're strong advocates of the GDPR and believe that the transparency it delivers around
the management and use of personal data is great for our customers, partners and our staff."
privacy_policy: https://www.thetrainline.com/terms/privacy
data_subject_contact: DPO@thetrainline.com
- name: Modern Slavery Act (UK)
posture: statement published in the site footer
not_published:
- SOC 2 Type I / Type II
- ISO 27017 / ISO 27018
- Cyber Essentials / Cyber Essentials Plus
- HIPAA
- FedRAMP
- CSA STAR / CAIQ
- subprocessor list
- downloadable audit evidence or NDA-gated evidence portal
infrastructure:
hosting: Amazon Web Services (AWS)
data_residency: European Economic Area (EEA)
quote: >-
"We protect our systems and your data within industry-leading, accredited data centres,
operated by Amazon Web Services (AWS), which are located in the European Economic Area (EEA)."
resilience: >-
"Our systems are mirrored across multiple sites (AWS availability zones), each of which have
backup power supplies and networks."
availability_commitment:
uptime_target: 99.9%
quote: >-
"We provide a commitment to our customers that our services will achieve at least 99.9%
operational uptime."
scope: consumer services as described on the security overview page; no API-specific SLA is published
contractual: false
controls:
governance: dedicated Information Security team
personnel: BPSS security screening for all staff, contractors and temporary workers
training: regular security and privacy training for all staff; annual secure code training for engineers
supply_chain: Supplier Security team; compliance screening and contractual security/data-privacy obligations
operational: Advanced Web Application Firewall, DDoS protection, bot management, anti-virus/anti-malware, IDS/IPS, 24/7 SOC
secure_sdlc: BSIMM-based software security programme; static and dynamic code analysis
evidence:
- source: https://www.thetrainline.com/terms/security
status: 200
keywords: [pci level 1, iso 27001, iso 22301, gdpr, information security, penetration testing, soc]
- source: https://trust.thetrainline.com
status: 000
note: does not resolve
- source: https://www.trainlinegroup.com/security
status: 404