- Reference
Traveller Readiness
The pre-booking layer where individual travel risk readiness is assessed before departure, producing a Readiness State — Ready, Needs Review, or Not Ready — an organisation can act on without accessing the underlying personal data.
Open - Reference
The Minimum-Disclosure Data Boundary
What Third Rail receives, processes and retains, and what the enterprise receives instead of the traveller's personal context.
Open - Reference
The Assessment Receipt
The sanitised record that a Traveller Readiness Assessment took place: what it records, what it proves, and what it deliberately does not contain.
Open - Reference
Direct Collection vs Minimum Disclosure
Why asking travellers to self-disclose directly, though the simplest option, creates the most centralised and exposed record.
Open - Reference
Why Not Deterministic Rules?
Why the readiness assessment runs as a structured multi-model debate rather than a fixed rules engine, and where rules genuinely are the right tool.
Open - Reference
Special category data in employee travel
What GDPR Article 9 prohibits, what ISO 31030 requires, and why most travel risk programmes are caught between the two. A reference for DPOs and security leads.
Open - Reference
Does travel risk management require a DPIA?
Article 35, the criteria supervisory authorities apply, and what an honest DPIA of a travel risk programme usually finds. A working reference for DPOs.
Open - Reference
Prescription medication at borders: the employer problem
Lawful prescriptions are controlled substances in some jurisdictions. Why medication is a travel risk, why asking about it is an Article 9 problem, and the architecture that resolves both.
Open - Reference
What airline assistance codes disclose
Requesting assistance transmits a standardised disability category through the reservation ecosystem. Who sees an SSR code, why it is special category data, and what employers should not hold.
Open - Reference
Duty of care for human rights defenders: the file problem
Monitoring and evacuation protect people in the field. Almost nothing protects them from the file built to qualify them for protection. A reference for casework and security leads.
Open - Reference
Glossary
The vocabulary of minimum-disclosure architecture, defined once and citable by stable anchor. Terms coined elsewhere are credited to their authors.
Open - Reference
Hard questions, answered honestly
The questions evaluators ask about minimum-disclosure architecture, answered plainly with limits stated. Offline decay, re-identification, validation.
Open - Reference
Full platform overview
A single-page summary of the Traveller Readiness architecture, for readers who want the whole model in one pass rather than the reference-by-reference breakdown.
Open - Reference
Third-party delegation vs minimum disclosure
Outsourcing sensitive travel-risk data to a medical or assistance vendor is a common compliance pattern. What it actually resolves, and what it only relocates.
Open