Traveller Readiness · Enterprise Travel
Duty-of-care readiness for business travel, without holding travellers' sensitive data.
Third Rail Systems gives employers a Ready, Review or Not_Ready answer before a trip is booked. Sensitive details are assessed without being stored or linked to the traveller's identity, and the employer never receives them.
Keep your people safer when they travel.

Destination risk: low. Traveller context: additional document checks are more likely for this traveller at transit hubs, so guidance is adjusted accordingly.
Carry passport, visa printout, and employer letter
Keep digital copies of documents on device
District advisory · updated 14 min ago
Escalation route confirmed
Held on device · sent encrypted and identity-stripped, never stored
Trip TRS-4471 · 12 Aug
Guidance issued & acknowledged
Personal attributes stored: none
Why the example matters
A destination can be safe. The traveller may still face risk.
Traditional travel-risk systems begin with the destination. But the same trip can be experienced differently by different travellers.
Understanding those differences can require sensitive personal information that an enterprise should not need to possess.
Left unaddressed, that gap is usually where the liability sits, not in the destination, in what the enterprise ends up holding to explain a decision after the fact.
The trade-off
Duty of care has a data problem.
Companies need enough information to protect their people when they travel. But collecting sensitive information about those people can create a new privacy, security and compliance risk.
Know too little
and you may fail to protect someone.
Know too much
and you create another liability.
Third Rail breaks that trade-off.
What you get
One assessment. Three outcomes.
Guidance that reflects who they actually are.
Personalised safety intelligence delivered privately to the traveller.
A safety decision without private details.
Managers can act when a trip requires attention without being told sensitive personal circumstances.
Proof the step ran, without the sensitive dataset.
The enterprise receives evidence that the pre-travel duty-of-care step took place, without holding the personal information that would turn that evidence into a liability.
The category
Traveller Readiness
Is this traveller ready for this trip, in this context, right now?
Third Rail Systems performs the Traveller Readiness Assessment, the traveller completes the Readiness Check, and the resulting Readiness State — Ready, Review, or Not_Ready — can be consumed by the traveller, a manager, an existing workflow, or an AI travel agent.
A trip is proposed in the systems you already use — TMC, OBT, or an internal request flow.
Third Rail assesses this traveller against this specific trip. The assessment runs privately: identity is stripped and the request travels over Oblivious HTTP, so no one can link it back to the traveller.
The traveller receives guidance built around their own circumstances, and acknowledges it.
A single actionable output — Ready, Review, or Not_Ready — with an Assessment Receipt that the step took place.
Your existing workflow acts on the state — book, proceed, or intervene before exposure.
Where it sits
Third Rail owns the readiness state, not the booking interface.
Third Rail sits upstream of your existing TMC, OBT, travel-risk or assistance workflow. It determines readiness and hands that state to whatever system manages the next step — before booking, before exposure.
How it is possible
The sensitive context stays private.
A minimum-disclosure architecture designed so special-category inputs are not retained beyond the assessment boundary. The enterprise receives the decision, not the underlying personal context.
Traveller context
Sensitive personal circumstances, held on the traveller's device.
Private synthesis
Minimum-disclosure assessment behind a strict data boundary.
Readiness state
Evidence and an API handoff your workflow can act on.
On-Device Profile
In plain terms: the assessment sees the context, never the person, and nothing is kept afterwards.
The traveller's device holds and encrypts the profile, and the assessment interprets the trip's context server-side without knowing who the traveller is. Personal signals are never stored and never reach the employer.
Special-category dataStateless Threat Synthesis
In plain terms: risk guidance is generated fresh each time and never stored.
Adaptive safety intelligence is synthesised without creating an enterprise-held profile of sensitive personal data.
Architecture paperThe Split Output
Travellers receive actionable guidance. The enterprise receives a readiness state and a sanitised record that the pre-travel step took place.
The Catch-22Evidence for security, privacy, legal and procurement
Built for Global Mobility, Security, Privacy and Travel Operations.
Identity verification and acknowledgement signing via IdentiGateFit
This isn't for you if
- You want to see your travellers' health, faith or identity data. We're built so you never hold it, and that won't change.
- You need a booking tool or a new TMC. We sit before the booking and hand a Ready, Review or Not_Ready answer to the tools you already use.
- Nobody in your organisation owns travel risk policy. The thresholds are yours to set, and we won't set them for you.
- You want software to make the final call on a person. Review means a human decides.
- You need it live across the whole company in two weeks. We start with an eight-week pilot on one programme.
If that's you, we're happy to point you to travel risk and TMC partners who are a better fit.
Initiate a Pilot Assessment
Request a 20-minute architecture fit-call. Our 8-week paid enterprise pilots run with no HRIS integration, and at most a lightweight webhook.
- 20-minute architecture fit-call
- Zero HRIS API integration required
- EU-sovereign data flows throughout