The Traveller Readiness layer for enterprise travel.
Third Rail Systems provides Traveller Readiness: a privacy-preserving pre-booking layer for enterprise travel risk. A Traveller Readiness Assessment evaluates whether a proposed trip is Ready, Needs Review, or Not Ready for that particular traveller, while the personal context behind the assessment stays unavailable to the enterprise. The organisation receives a Readiness State and an Assessment Receipt evidencing its ISO 31030 duty-of-care step, not the special-category data the assessment used. It works alongside existing TMC, OBT and travel risk management systems rather than replacing them.
The same minimum-disclosure architecture serves civil-society organisations, IGOs, and human rights institutions that protect activists, defenders, and field staff in higher-risk environments. Different scale, identical operational tension between duty-of-care and identity protection.
- Avoid Jalan Alor 23:00–04:00
- Verified lodging cluster: KLCC / Bangsar
- Local counsel hotline attached
Illustrative operator view · sanitised Assessment Receipt
The ISO 31030 vs. GDPR Catch-22
Two compliance regimes pulling in opposite directions. Most programmes pick one risk and inherit the other.
The Duty-of-Care Mandate
Enterprises must demonstrate reasonable steps to provide localised mitigations for marginalised employees (LGBTQ+, disabled, neurodivergent).
The Privacy Liability
Centrally collecting demographic identities creates a toxic, regulated data lake, exposing the enterprise to structural GDPR Article 9 violations.
The "Shadow HR" Risk
Well-intentioned teams track vulnerable travellers on informal spreadsheets, creating an un-audited legal nightmare for Data Protection Officers.
Why every multinational with a diverse workforce is exposed to the same regulatory pattern, and the architectural alternative that resolves it. Read the brief.
Long-form pieces from the founder. Start with the newest, on AI agents and mandates, or pick the lens that matches your concern: agency, data, platform, or human.
Minimum-Disclosure Architecture
In plain terms: we're built to collect the least data possible, by design, not by policy.
We materially decouple risk intelligence from human identity.
On-Device Processing
The traveller’s profile is encrypted locally. Special-category data never enters your HRIS.
Stateless Threat Synthesis
The system cross-references the destination against local penal codes without centrally logging demographic inputs.
The Assessment Receipt
Your Global Travel Risk team receives a sanitised, actionable Assessment Receipt. You get the audit trail; your DPO avoids the data.
Three dimensions. One minimum-disclosure boundary.
A Traveller Readiness Assessment considers how a specific journey lands on a specific person. The personal context stays with the traveller; the enterprise receives a Readiness State and a sanitised Assessment Receipt.
Sensory and neurodivergence
- Sensory load across airports, transit and accommodation
- Predictability, routine and recovery time
- Guidance the traveller can actually use on the day
Physical accessibility
- Mobility, equipment and assistance requirements
- Built-environment and transport realities at the destination
- Mitigations arranged before departure, not on arrival
Intersectional identity
- Overlapping characteristics that change exposure
- Local conditions and how they land on this traveller
- Personal guidance without an enterprise-held profile
The architecture is designed so the personal context used during an assessment is not carried forward past the point the receipt is issued, and does not cross into the enterprise record. What crosses is the Readiness State and the evidence that the process occurred. See the minimum-disclosure data boundary.
Safety intelligence without centralised storage of special-category data.
Human-in-the-loop oversight with logged data provenance.
Auditable evidence that an individualised readiness step occurred prior to travel.
Bridging Security, Privacy, and Inclusion
Three mandates. One architecture. Each function keeps its own remit intact.
- Eliminate "Shadow HR" tracking.
- Generate auditable Assessment Receipts.
- Procure securely with flat Total Travel Volume (TTV) pricing.
- Enforce strict data decentralisation for special-category traits.
- Utilise an AI architecture designed to EU AI Act high-risk obligations, documented for scrutiny.
- Maintain full EU-sovereign data flows.
- Provide enterprise-grade protection for underrepresented cohorts.
- Partner strategically with Security to unlock safe global mobility.
- Protect human rights defenders, activists, and field staff without creating internal demographic registers.
- Deploy intersectional safety assessments aligned with donor compliance frameworks (USAID 2 CFR 200, EU AI Act, GDPR).
- Pilot pricing for design partners; pro-bono deployment available for qualifying mission-aligned organisations.
Outcome · Mission-aligned safety infrastructure that withstands donor audit and protects the people you serve.
Who buys, and who uses
The buyer and the user are different, and the user is not always human.
Buyers carry the liability and sign: the Chief Security Officer, the Data Protection Officer, the travel-risk function.
Users consume the output. The traveller reviews and signs their own assessment. Whoever owns the booking workflow, a travel manager or the agent running it, reads the Readiness State as a gate.
Engineered for the Modern Regulatory Landscape
Every architectural decision maps to a defensible compliance artefact.
We do not centralise “special-category data”. The enterprise remains the Controller of standard itineraries; Third Rail acts as a Processor.
Built to meet EU AI Act high-risk obligations, with mandatory human-in-the-loop oversight and logged data provenance. Final classification under review with counsel.
Verifiable, date-stamped evidence that the organisation assessed intersectional threats prior to deployment.
KTH Innovation Readiness Level (IRL) · Evidence Report
Third Rail Systems OÜ assessed its readiness under KTH Royal Institute of Technology's Deeptech Startup Network IRL framework: six structured dimensions of readiness, scored against the international standard, with the evidence documented. The assessment is our own, performed against KTH's published methodology. We state that plainly because the distinction between a framework and a validator matters.
- TRLTechnologyL5
System validated in relevant environment with integrated components operating end-to-end.
- CRLCustomerL4
Customer segmentation with initial basic customer profiles in place.
- BRLBusinessL5
Validated calculations of main costs and revenues; pricing model and unit economics documented.
- IPRLIPL4
Confirmed possibilities for protection of key IPR through professional searches and analysis.
- TMRLTeamL5
Initial founding team working together, all spending significant time on the venture.
- FRLFundingL4
Documented 12-month development plan with costs and activities; identified funding sources and pre-seed strategy in place.
The evidence report is public and describes its own methodology. Patent protection is in progress.
Built on Earned Secrets
Third Rail Systems was founded on a singular operational truth: institutional safety requires deep visibility, but human privacy requires absolute discretion. We built the minimum-disclosure compliance layer to resolve this paradox. Today, that architecture is expressed as Traveller Readiness: Third Rail Systems' pre-booking layer for enterprise travel risk, which assesses whether a proposed trip is Ready, Needs Review, or Not Ready for a particular traveller and returns that Readiness State to the enterprise without requiring it to receive the underlying sensitive personal context.
Follow Third Rail Systems on F6SIdentity verification and acknowledgement signing via IdentiGate20-year US Navy combat veteran with lived experience under "Don't Ask, Don't Tell." Operational authority on discretion under institutional scrutiny. Primary architect and builder of the company's proprietary assessment infrastructure.
Founded Third Rail Systems to build the infrastructure that did not exist when he served, for enterprises managing duty-of-care obligations, and for civil-society organisations protecting the activists who do the most exposed work.
Cybersecurity analyst with national-security research depth (RAND), HIPAA-grade healthcare GRC experience (Cedars-Sinai, UCLA), and German multinational GDPR experience (Karl Storz). Co-engineer of the stateless synthesis layer, the decoupled audit trail, and the human-in-the-loop oversight design.
Proudly registered in Tallinn, Estonia, ensuring a strict European corporate footprint outside direct US jurisdiction.
The power is in the margins
A word about our logo: nothing in it is decorative. Every element is the company, architected.
The mark is a letter T built as a structure, and it carries the whole of what we are. Three vertical rails form the stem. They are our three modules, and each one holds a different kind of person the world tends to overlook: one for neurodivergent people, who experience the world differently and deserve environments built with that in mind; one for disabled people, where accessibility is treated as a right, not an afterthought; and one for the full intersection of identity, holding space for the queer and trans people whose safety can depend entirely on where they are standing.
The metallic bar across the top is the intersection itself. It is the place where these identities overlap, where a person is never only one thing, and where the crossbar holds everything together rather than forcing anyone to choose which part of themselves to bring.
The surface of the rails is iridescent, and the spectrum shifting across it is deliberate. It is the rainbow, kept subtle, the way so many people have had to keep it. It is also the wider spectrum of human difference: minds that think differently, bodies that move differently, and lives lived at the margins.
And the line down the centre, the one that glows, is the third rail. We made it the light blue of the transgender flag on purpose. The word “third” is on purpose too. A third rail. A third gender. The presence of people the binary was never built to hold.
In a rail network, the third rail carries the live current. It is the source of power, and the line you are warned never to touch. That is the point. The power in this picture does not belong to those who police the margins. It belongs to the people at them. Their presence, their refusal to disappear, is the live wire.
Third Rail Systems. The power is in the margins.
From the founder's desk
- Founder noteJun 2026
What twenty years under "Don't Ask, Don't Tell" taught me about building Third Rail Systems.
The lived-experience operational thesis behind a minimum-disclosure architecture: why discretion under institutional scrutiny is the founding constraint, not a feature.
- Liability briefMay 2026
The duty-of-care vs. data-privacy Catch-22: a multi-billion-euro liability hiding in EU enterprise HR.
The five enforcement vectors EU general counsel and CISOs are quietly under-pricing right now, and the architectural pattern that resolves them.
Initiate a Pilot Assessment
Request a 20-minute architecture fit-call. Our 4-to-6 week paid enterprise pilots require zero API integration with your HRIS.
- 20-minute architecture fit-call
- Zero HRIS API integration required
- EU-sovereign data flows throughout