generated: '2026-07-28' method: searched probe: true source: https://www.thetrainline.com/terms/security policy: - https://www.thetrainline.com/terms/security contact: - security-external@thetrainline.com bug_bounty: offered: false quote: "We don't currently offer payment for reporting vulnerabilities." platform: null note: >- hackerone.com/trainline exists but is a HackerOne community-curated "external / unclaimed" security page (HackerOne API reports the profile as an unclaimed team, about: null), not a Trainline-operated program. Do not treat it as an official Trainline bug bounty. bugcrowd.com/trainline returns 404. disclosure: accepts_reports: true quote: >- If you believe you've identified a security vulnerability in one of our websites or apps, we thank you for reporting it as quickly as possible. We'll work with security researchers to investigate and fix any valid reports. Please send reports to security-external@thetrainline.com scope_stated: websites and apps safe_harbour_published: false response_sla_published: false security_txt: published: false probed: - {url: 'https://www.thetrainline.com/.well-known/security.txt', status: 404} - {url: 'https://thetrainline.com/.well-known/security.txt', status: 404} - {url: 'https://tps.thetrainline.com/.well-known/security.txt', status: 404} - {url: 'https://api.thetrainline.com/.well-known/security.txt', status: 404} - {url: 'https://trainlinegroup.com/.well-known/security.txt', status: 404} security_programme: penetration_testing: >- "All our production systems, services, websites and applications are subject to independent external penetration testing at least annually." vulnerability_scanning: >- "We also do regular internal and external vulnerability scans of our systems, as part of our PCI-DSS Level 1 compliance programme." secure_sdlc: >- Formal software security programme based on the Building Security in Maturity Model (BSIMM) framework; static and dynamic testing of all code before production rollout. soc: "24/7 Security Operations Centre (SOC)" personnel_screening: UK government BPSS standards, enhanced screening for sensitive-data roles evidence: - source: https://www.thetrainline.com/terms/security kind: published security policy page status: 200 keywords: [reporting suspected security issues, security researchers, vulnerability, penetration testing, bsimm] - source: https://hackerone.com/trainline kind: third-party community-curated page status: 200 note: unclaimed HackerOne directory entry, not a Trainline-run program