Private.
Transparent.
Secure.
Travelers worldwide trust us to protect their most sensitive documents and information.
Enterprise-grade security
Your data is protected by multiple layers of security, encryption, and compliance measures.
Data minimization
We collect only essential data required for visa processing and anonymize information wherever possible.
Reduces risk by minimizing sensitive data stored.
Secure payments
Industry-leading security measures including multi-factor authentication and advanced fraud detection.
Financial transactions protected from unauthorized access.
Encryption at rest
All user data stored on TravelDocx servers is encrypted using modern encryption standards.
Data protected even if physical storage is compromised.
End-to-end encryption
All data transmitted between you and our systems is encrypted to keep it unreadable to third parties.
Privacy and security maintained during transmission.
Industry compliance
We align with GDPR, CCPA, and PCI DSS practices to maintain strict privacy and security controls.
Meets stringent international security expectations.
Regular security audits
Continuous assessments and testing help identify and remediate vulnerabilities before they escalate.
Security measures stay current against evolving threats.
Secure access controls
Role-based access restrictions ensure only authorized personnel can access sensitive data.
Prevents unauthorized internal data access.
User education
Guides and resources help customers protect information and recognize common security threats.
Empowers users to actively protect their data.
Security researchers
Vulnerability disclosure program
We welcome reports of genuine security issues and appreciate responsible disclosure from the research community. Report vulnerabilities to security@traveldocx.com.
How to report a security issue+
Email security@traveldocx.com with a clear description of the issue, the affected endpoint or page, reproduction steps, and any proof-of-concept material. Please include a way for us to contact you for follow-up questions. We acknowledge reports within two business days.
Scope+
In scope: traveldocx.com and its subdomains, our public API, and the FlyLop iOS application. Out of scope: third-party services we do not operate, findings that require physical access to a device, social engineering of our staff, spam or best-practice reports without a demonstrable security impact, and automated scanner output without validation.
Responsible disclosure guidelines+
Give us reasonable time to remediate before any public disclosure. Do not access, modify, or delete data belonging to other users; use only test accounts you control. Do not degrade service availability, run denial-of-service or large-scale automated testing, and never exfiltrate personal data — a single record proving impact is enough.
Legal safe harbor+
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue legal action against you, and we will work with you if a third party does. If in doubt about whether an action is permitted, ask us first.
Rewards and bug bounty+
We do not currently operate a paid bug bounty programme. We do offer public acknowledgement for valid reports, with your permission, and we may provide service credit for high-impact findings at our discretion.
If you are unsure whether your research aligns with this policy, please contact us at security@traveldocx.com before proceeding.