Trainline · Trust Center
Trainline Trust Center
Trust center
Trainline maintains a public trust center documenting PCI DSS Level 1, ISO/IEC 27001, and ISO 22301 compliance.
TravelRailUnited KingdomEuropeBookingTicketingDistributionOTACorporate Travel
Trust center: https://www.thetrainline.com/terms/security
Certifications & Compliance
PCI DSS Level 1ISO/IEC 27001ISO 22301
Source
Trust Center
generated: '2026-07-28'
method: searched
probe: true
url: https://www.thetrainline.com/terms/security
title: Trainline Security Overview
note: >-
Trainline runs no vendor trust portal (no trust.thetrainline.com, no Vanta/Drata/SafeBase
page, no security.thetrainline.com). Its published trust surface is a single consumer-facing
"Trainline Security Overview" page under the terms tree. It is unusually substantive for that
format — it names certifications with certificate numbers, an uptime commitment, the hosting
provider and data residency, and a vulnerability reporting address — so it is captured here as
the trust-centre equivalent. There is no partner/API-specific trust pack published, and no
downloadable evidence (no SOC 2 report, no ISO certificate PDF, no CAIQ/SIG, no subprocessor list).
certifications:
- name: PCI DSS Level 1
scope: both as a merchant and as a service provider
quote: "Trainline are PCI Level 1 compliant both as a merchant and as a service provider"
certificate_number: null
- name: ISO/IEC 27001
scope: Information Security Management Systems
certificate_number: IS 775108
- name: ISO 22301
scope: Business Continuity Management Systems
certificate_number: BCMS 763415
regulatory:
- name: UK GDPR / EU GDPR
posture: >-
"We're strong advocates of the GDPR and believe that the transparency it delivers around
the management and use of personal data is great for our customers, partners and our staff."
privacy_policy: https://www.thetrainline.com/terms/privacy
data_subject_contact: DPO@thetrainline.com
- name: Modern Slavery Act (UK)
posture: statement published in the site footer
not_published:
- SOC 2 Type I / Type II
- ISO 27017 / ISO 27018
- Cyber Essentials / Cyber Essentials Plus
- HIPAA
- FedRAMP
- CSA STAR / CAIQ
- subprocessor list
- downloadable audit evidence or NDA-gated evidence portal
infrastructure:
hosting: Amazon Web Services (AWS)
data_residency: European Economic Area (EEA)
quote: >-
"We protect our systems and your data within industry-leading, accredited data centres,
operated by Amazon Web Services (AWS), which are located in the European Economic Area (EEA)."
resilience: >-
"Our systems are mirrored across multiple sites (AWS availability zones), each of which have
backup power supplies and networks."
availability_commitment:
uptime_target: 99.9%
quote: >-
"We provide a commitment to our customers that our services will achieve at least 99.9%
operational uptime."
scope: consumer services as described on the security overview page; no API-specific SLA is published
contractual: false
controls:
governance: dedicated Information Security team
personnel: BPSS security screening for all staff, contractors and temporary workers
training: regular security and privacy training for all staff; annual secure code training for engineers
supply_chain: Supplier Security team; compliance screening and contractual security/data-privacy obligations
operational: Advanced Web Application Firewall, DDoS protection, bot management, anti-virus/anti-malware, IDS/IPS, 24/7 SOC
secure_sdlc: BSIMM-based software security programme; static and dynamic code analysis
evidence:
- source: https://www.thetrainline.com/terms/security
status: 200
keywords: [pci level 1, iso 27001, iso 22301, gdpr, information security, penetration testing, soc]
- source: https://trust.thetrainline.com
status: 000
note: does not resolve
- source: https://www.trainlinegroup.com/security
status: 404
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/trainline-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.