Trainline · Vulnerability Disclosure
Trainline Vulnerability Disclosure
Vulnerability disclosure
Trainline runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
TravelRailUnited KingdomEuropeBookingTicketingDistributionOTACorporate Travel
Program: Hackerone
Disclosure Policy
Security Contact
Contact
security-external@thetrainline.com
Source
Vulnerability Disclosure
generated: '2026-07-28'
method: searched
probe: true
source: https://www.thetrainline.com/terms/security
policy:
- https://www.thetrainline.com/terms/security
contact:
- security-external@thetrainline.com
bug_bounty:
offered: false
quote: "We don't currently offer payment for reporting vulnerabilities."
platform: null
note: >-
hackerone.com/trainline exists but is a HackerOne community-curated "external / unclaimed"
security page (HackerOne API reports the profile as an unclaimed team, about: null), not a
Trainline-operated program. Do not treat it as an official Trainline bug bounty.
bugcrowd.com/trainline returns 404.
disclosure:
accepts_reports: true
quote: >-
If you believe you've identified a security vulnerability in one of our websites or apps,
we thank you for reporting it as quickly as possible. We'll work with security researchers
to investigate and fix any valid reports. Please send reports to security-external@thetrainline.com
scope_stated: websites and apps
safe_harbour_published: false
response_sla_published: false
security_txt:
published: false
probed:
- {url: 'https://www.thetrainline.com/.well-known/security.txt', status: 404}
- {url: 'https://thetrainline.com/.well-known/security.txt', status: 404}
- {url: 'https://tps.thetrainline.com/.well-known/security.txt', status: 404}
- {url: 'https://api.thetrainline.com/.well-known/security.txt', status: 404}
- {url: 'https://trainlinegroup.com/.well-known/security.txt', status: 404}
security_programme:
penetration_testing: >-
"All our production systems, services, websites and applications are subject to independent
external penetration testing at least annually."
vulnerability_scanning: >-
"We also do regular internal and external vulnerability scans of our systems, as part of our
PCI-DSS Level 1 compliance programme."
secure_sdlc: >-
Formal software security programme based on the Building Security in Maturity Model (BSIMM)
framework; static and dynamic testing of all code before production rollout.
soc: "24/7 Security Operations Centre (SOC)"
personnel_screening: UK government BPSS standards, enhanced screening for sensitive-data roles
evidence:
- source: https://www.thetrainline.com/terms/security
kind: published security policy page
status: 200
keywords: [reporting suspected security issues, security researchers, vulnerability, penetration testing, bsimm]
- source: https://hackerone.com/trainline
kind: third-party community-curated page
status: 200
note: unclaimed HackerOne directory entry, not a Trainline-run program
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/trainline-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.