Minimum-disclosure Traveller Readiness

Third Rail SystemsSovereign · Stateless · EU-Native
Traveller Readiness · Enterprise Travel

The Traveller Readiness layer for enterprise travel.

Third Rail Systems provides Traveller Readiness: a privacy-preserving pre-booking layer for enterprise travel risk. A Traveller Readiness Assessment evaluates whether a proposed trip is Ready, Needs Review, or Not Ready for that particular traveller, while the personal context behind the assessment stays unavailable to the enterprise. The organisation receives a Readiness State and an Assessment Receipt evidencing its ISO 31030 duty-of-care step, not the special-category data the assessment used. It works alongside existing TMC, OBT and travel risk management systems rather than replacing them.

The same minimum-disclosure architecture serves civil-society organisations, IGOs, and human rights institutions that protect activists, defenders, and field staff in higher-risk environments. Different scale, identical operational tension between duty-of-care and identity protection.

ISO 31030GDPR Article 9EU AI Act · Annex IV
Receipt / RCP-0342
Destination
Kuala Lumpur, MY
Threat Tier
Elevated
Data Class
On-device
Mitigations
  • Avoid Jalan Alor 23:00–04:00
  • Verified lodging cluster: KLCC / Bangsar
  • Local counsel hotline attached
GDPR Art. 9Designed to exclude special-category data

Illustrative operator view · sanitised Assessment Receipt

The Core Conflict

The ISO 31030 vs. GDPR Catch-22

Two compliance regimes pulling in opposite directions. Most programmes pick one risk and inherit the other.

01

The Duty-of-Care Mandate

Enterprises must demonstrate reasonable steps to provide localised mitigations for marginalised employees (LGBTQ+, disabled, neurodivergent).

02

The Privacy Liability

Centrally collecting demographic identities creates a toxic, regulated data lake, exposing the enterprise to structural GDPR Article 9 violations.

03

The "Shadow HR" Risk

Well-intentioned teams track vulnerable travellers on informal spreadsheets, creating an un-audited legal nightmare for Data Protection Officers.

The Shadow HR Liability · 8-min read
What H&M's €35.3 million fine looks like when it happens to your organisation.

Why every multinational with a diverse workforce is exposed to the same regulatory pattern, and the architectural alternative that resolves it. Read the brief.

Read the brief
Insights · the Exposure series
Essays on dependency, accumulation, and who holds the leverage.

Long-form pieces from the founder. Start with the newest, on AI agents and mandates, or pick the lens that matches your concern: agency, data, platform, or human.

Open the reading room
Platform

Minimum-Disclosure Architecture

In plain terms: we're built to collect the least data possible, by design, not by policy.

We materially decouple risk intelligence from human identity.

Data-flow contract
Identity inputsdevice-local
Output to enterprisesanitised Assessment Receipt
Feature 01

On-Device Processing

The traveller’s profile is encrypted locally. Special-category data never enters your HRIS.

Feature 02

Stateless Threat Synthesis

The system cross-references the destination against local penal codes without centrally logging demographic inputs.

Feature 03

The Assessment Receipt

Your Global Travel Risk team receives a sanitised, actionable Assessment Receipt. You get the audit trail; your DPO avoids the data.

How the assessment thinks

Three dimensions. One minimum-disclosure boundary.

A Traveller Readiness Assessment considers how a specific journey lands on a specific person. The personal context stays with the traveller; the enterprise receives a Readiness State and a sanitised Assessment Receipt.

01
Dimension

Sensory and neurodivergence

How a journey feels, not just where it goes
  • Sensory load across airports, transit and accommodation
  • Predictability, routine and recovery time
  • Guidance the traveller can actually use on the day
Grounded in the work of Temple Grandin
02
Dimension

Physical accessibility

Whether the journey is practically possible
  • Mobility, equipment and assistance requirements
  • Built-environment and transport realities at the destination
  • Mitigations arranged before departure, not on arrival
Grounded in the work of Judith Heumann
03
Dimension

Intersectional identity

Risk that only appears in combination
  • Overlapping characteristics that change exposure
  • Local conditions and how they land on this traveller
  • Personal guidance without an enterprise-held profile
Grounded in the work of Kimberlé Crenshaw
Minimum-disclosure boundary

The architecture is designed so the personal context used during an assessment is not carried forward past the point the receipt is issued, and does not cross into the enterprise record. What crosses is the Readiness State and the evidence that the process occurred. See the minimum-disclosure data boundary.

GDPR Article 9

Safety intelligence without centralised storage of special-category data.

EU AI Act · Annex IV

Human-in-the-loop oversight with logged data provenance.

ISO 31030

Auditable evidence that an individualised readiness step occurred prior to travel.

Third Rail Systems OÜ · Traveller Readiness
Read how it works
Solutions by persona

Bridging Security, Privacy, and Inclusion

Three mandates. One architecture. Each function keeps its own remit intact.

For CSOs
01
  • Eliminate "Shadow HR" tracking.
  • Generate auditable Assessment Receipts.
  • Procure securely with flat Total Travel Volume (TTV) pricing.
Outcome
For DPOs
02
  • Enforce strict data decentralisation for special-category traits.
  • Utilise an AI architecture designed to EU AI Act high-risk obligations, documented for scrutiny.
  • Maintain full EU-sovereign data flows.
Outcome
For ERGs
03
  • Provide enterprise-grade protection for underrepresented cohorts.
  • Partner strategically with Security to unlock safe global mobility.
Outcome
For Civil Society
04
  • Protect human rights defenders, activists, and field staff without creating internal demographic registers.
  • Deploy intersectional safety assessments aligned with donor compliance frameworks (USAID 2 CFR 200, EU AI Act, GDPR).
  • Pilot pricing for design partners; pro-bono deployment available for qualifying mission-aligned organisations.

Outcome · Mission-aligned safety infrastructure that withstands donor audit and protects the people you serve.

Next step
Audience

Who buys, and who uses

The buyer and the user are different, and the user is not always human.

Buyers

Buyers carry the liability and sign: the Chief Security Officer, the Data Protection Officer, the travel-risk function.

Users

Users consume the output. The traveller reviews and signs their own assessment. Whoever owns the booking workflow, a travel manager or the agent running it, reads the Readiness State as a gate.

Governance

Engineered for the Modern Regulatory Landscape

Every architectural decision maps to a defensible compliance artefact.

GDPR

We do not centralise “special-category data”. The enterprise remains the Controller of standard itineraries; Third Rail acts as a Processor.

EU AI Act

Built to meet EU AI Act high-risk obligations, with mandatory human-in-the-loop oversight and logged data provenance. Final classification under review with counsel.

ISO 31030

Verifiable, date-stamped evidence that the organisation assessed intersectional threats prior to deployment.

Readiness evidence

KTH Innovation Readiness Level (IRL) · Evidence Report

Third Rail Systems OÜ assessed its readiness under KTH Royal Institute of Technology's Deeptech Startup Network IRL framework: six structured dimensions of readiness, scored against the international standard, with the evidence documented. The assessment is our own, performed against KTH's published methodology. We state that plainly because the distinction between a framework and a validator matters.

KTH IRL Evidence Report
Deeptech Startup Network · six-dimension assessment
  • TRL
    Technology
    L5

    System validated in relevant environment with integrated components operating end-to-end.

  • CRL
    Customer
    L4

    Customer segmentation with initial basic customer profiles in place.

  • BRL
    Business
    L5

    Validated calculations of main costs and revenues; pricing model and unit economics documented.

  • IPRL
    IP
    L4

    Confirmed possibilities for protection of key IPR through professional searches and analysis.

  • TMRL
    Team
    L5

    Initial founding team working together, all spending significant time on the venture.

  • FRL
    Funding
    L4

    Documented 12-month development plan with costs and activities; identified funding sources and pre-seed strategy in place.

The evidence report is public and describes its own methodology. Patent protection is in progress.

View full IRL Evidence Report
About & origin

Built on Earned Secrets

Third Rail Systems was founded on a singular operational truth: institutional safety requires deep visibility, but human privacy requires absolute discretion. We built the minimum-disclosure compliance layer to resolve this paradox. Today, that architecture is expressed as Traveller Readiness: Third Rail Systems' pre-booking layer for enterprise travel risk, which assesses whether a proposed trip is Ready, Needs Review, or Not Ready for a particular traveller and returns that Readiness State to the enterprise without requiring it to receive the underlying sensitive personal context.

Follow Third Rail Systems on F6SIdentity verification and acknowledgement signing via IdentiGate
Registered
Tallinn, Estonia · European Union
CEO

Levi Hankins

Follow Levi Hankins on F6S

20-year US Navy combat veteran with lived experience under "Don't Ask, Don't Tell." Operational authority on discretion under institutional scrutiny. Primary architect and builder of the company's proprietary assessment infrastructure.

Founded Third Rail Systems to build the infrastructure that did not exist when he served, for enterprises managing duty-of-care obligations, and for civil-society organisations protecting the activists who do the most exposed work.

CTO

Jeremy Stabile

Follow Jeremy Stabile on F6S

Cybersecurity analyst with national-security research depth (RAND), HIPAA-grade healthcare GRC experience (Cedars-Sinai, UCLA), and German multinational GDPR experience (Karl Storz). Co-engineer of the stateless synthesis layer, the decoupled audit trail, and the human-in-the-loop oversight design.

The Estonia Advantage

Proudly registered in Tallinn, Estonia, ensuring a strict European corporate footprint outside direct US jurisdiction.

About the name

The power is in the margins

A word about our logo: nothing in it is decorative. Every element is the company, architected.

The mark is a letter T built as a structure, and it carries the whole of what we are. Three vertical rails form the stem. They are our three modules, and each one holds a different kind of person the world tends to overlook: one for neurodivergent people, who experience the world differently and deserve environments built with that in mind; one for disabled people, where accessibility is treated as a right, not an afterthought; and one for the full intersection of identity, holding space for the queer and trans people whose safety can depend entirely on where they are standing.

The metallic bar across the top is the intersection itself. It is the place where these identities overlap, where a person is never only one thing, and where the crossbar holds everything together rather than forcing anyone to choose which part of themselves to bring.

The surface of the rails is iridescent, and the spectrum shifting across it is deliberate. It is the rainbow, kept subtle, the way so many people have had to keep it. It is also the wider spectrum of human difference: minds that think differently, bodies that move differently, and lives lived at the margins.

And the line down the centre, the one that glows, is the third rail. We made it the light blue of the transgender flag on purpose. The word “third” is on purpose too. A third rail. A third gender. The presence of people the binary was never built to hold.

In a rail network, the third rail carries the live current. It is the source of power, and the line you are warned never to touch. That is the point. The power in this picture does not belong to those who police the margins. It belongs to the people at them. Their presence, their refusal to disappear, is the live wire.

Third Rail Systems. The power is in the margins.

Read the full Traveller Readiness definition →

Intake

Initiate a Pilot Assessment

Request a 20-minute architecture fit-call. Our 4-to-6 week paid enterprise pilots require zero API integration with your HRIS.

  • 20-minute architecture fit-call
  • Zero HRIS API integration required
  • EU-sovereign data flows throughout

By submitting, you consent to Third Rail Systems OÜ processing the information above solely to evaluate pilot fit. No special-category data is requested.