Trainline · Vulnerability Disclosure

Trainline Vulnerability Disclosure

Vulnerability disclosure

Trainline runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

TravelRailUnited KingdomEuropeBookingTicketingDistributionOTACorporate Travel
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security-external@thetrainline.com

Source

Vulnerability Disclosure

trainline-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
probe: true
source: https://www.thetrainline.com/terms/security
policy:
  - https://www.thetrainline.com/terms/security
contact:
  - security-external@thetrainline.com
bug_bounty:
  offered: false
  quote: "We don't currently offer payment for reporting vulnerabilities."
  platform: null
  note: >-
    hackerone.com/trainline exists but is a HackerOne community-curated "external / unclaimed"
    security page (HackerOne API reports the profile as an unclaimed team, about: null), not a
    Trainline-operated program. Do not treat it as an official Trainline bug bounty.
    bugcrowd.com/trainline returns 404.
disclosure:
  accepts_reports: true
  quote: >-
    If you believe you've identified a security vulnerability in one of our websites or apps,
    we thank you for reporting it as quickly as possible. We'll work with security researchers
    to investigate and fix any valid reports. Please send reports to security-external@thetrainline.com
  scope_stated: websites and apps
  safe_harbour_published: false
  response_sla_published: false
security_txt:
  published: false
  probed:
    - {url: 'https://www.thetrainline.com/.well-known/security.txt', status: 404}
    - {url: 'https://thetrainline.com/.well-known/security.txt', status: 404}
    - {url: 'https://tps.thetrainline.com/.well-known/security.txt', status: 404}
    - {url: 'https://api.thetrainline.com/.well-known/security.txt', status: 404}
    - {url: 'https://trainlinegroup.com/.well-known/security.txt', status: 404}
security_programme:
  penetration_testing: >-
    "All our production systems, services, websites and applications are subject to independent
    external penetration testing at least annually."
  vulnerability_scanning: >-
    "We also do regular internal and external vulnerability scans of our systems, as part of our
    PCI-DSS Level 1 compliance programme."
  secure_sdlc: >-
    Formal software security programme based on the Building Security in Maturity Model (BSIMM)
    framework; static and dynamic testing of all code before production rollout.
  soc: "24/7 Security Operations Centre (SOC)"
  personnel_screening: UK government BPSS standards, enhanced screening for sensitive-data roles
evidence:
  - source: https://www.thetrainline.com/terms/security
    kind: published security policy page
    status: 200
    keywords: [reporting suspected security issues, security researchers, vulnerability, penetration testing, bsimm]
  - source: https://hackerone.com/trainline
    kind: third-party community-curated page
    status: 200
    note: unclaimed HackerOne directory entry, not a Trainline-run program

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/trainline-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.