Any business – from travel startups to financial enterprises - can build with Duffel to search and book flights, stays, add ancillaries, charge customers, manage orders and more.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
PCI DSS
Payment card industry standard for handling cardholder data securely.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Duffel discloses on its trust center. Linked entries have their own profile in the Trust Index.
52% chain trust: 14 of 27 disclosed subprocessors are themselves in the Trust Index.
- Active Campaign LLC Marketing email and automation
- Anthropic AI assistance (e.g. Notion connector)
- Cloudflare Platform security
- Evervault Limited Payment processing
- Fareladder Consulting Services LLC Traveller support
- Google Cloud Platform Processing and storage (cloud infrastructure)
- Hybrid Travel LLC d.b.a. Air1 Aggregator providing access to Suppliers
- IGT Technologies Inc. Traveller support
- InTouch CX Inc. Traveller support
- Linear Customer support communications
- Mailgun Technologies, Inc. Transactional emails e.g. password reset
- Meili Travel Technology Limited Aggregator for Cars Orders
- Notion Knowledge hub
- OpenAI OpCo LLC AI assistance
- PEGASUS BUSINESS INTELLIGENCE LP D.B.A ONYX CENTRE SOURCE Payment collections
- Plain Customer support communications
- Posthog Inc. User analytics
- Segment.io, Inc. User analytics
- Sentry (Functional Software, Inc.) Error reporting and application monitoring (including IP addresses)
- Seon Fraud detection
- Slack Customer support communications
- Stream.IO Inc Customer / Traveller support
- Stripe Payment processing (Duffel Payments)
- Travelfusion Limited Aggregator for Flights Orders
- Very Good Security Storage and encryption of cardholder data
- Zendesk, Inc. Customer / Traveller support
- Zoom Video conferencing
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.