Security & Trust Statement
Download PDF1. Security model
The platform uses layered application, hosting and operational controls designed to reduce confidentiality, integrity and availability risks.
2. Application controls
Controls include HTTPS-only production access, secure sessions, CSRF/origin validation, input validation, prepared database queries, role-based access, rate limiting and restricted administrative functions.
3. Document security
Restricted travel documents are encrypted before storage and kept outside the public web-document path. Access is tied to authorised users and trips.
4. Logging and evidence
Sensitive actions such as authentication and protected-document access are logged. Audit records are intended to support investigation, accountability and service recovery.
5. Payments
Raw card numbers and CVV information are excluded from the application boundary; hosted/tokenised payment processing is required when card payments are enabled.
6. Cryptographic agility
The architecture maintains a cryptographic-inventory and migration mindset so algorithms and key-management choices can evolve as standards change. No live post-quantum protection claim is made unless the deployed end-to-end path is verified.
7. Certifications
See The World Travel does not claim ISO, PCI, FIPS, SOC or other independent certification unless an applicable certificate or attestation has actually been obtained.
Trust Centre