BCD

BCD

Search the Trust Center...
Ctrl +K

BCD | Security Center

Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence. Our Trust Center is regularly updated to reflect the latest audit results, and subprocessor disclosures.


Welcome to BCD's Information Security Trust Center

BCD Travel relies on information and information technology (IT) to provide services and information to users and customers around the globe. As the use of technology increases, so do the risks associated with technology, including the unauthorized disclosure of sensitive information and the unscheduled downtime of IT services and applications.

We mitigate security risks and protect client data by following international security standards, such as the ISO 27001, and data privacy laws, as well as input from our clients. We have established enterprise-wide policies and standards, a chief information security officer (CISO), a dedicated Information Security department, a Cyber Security operations team, and an internal audit department.

Explore our Trust Center to uncover our robust security measures and request exclusive access to our detailed information security documentation.

BCD Travel Information Security

New Trust Center Experience

We’re making our Information Security Trust Center easier, faster, and more intuitive to use.


BCD Travel Information Security Overview

One or more annual third-party audit(s)

Has a formal mobile device management (MDM) program

Annual third-party penetration testing

Has a disaster recovery plan

Has cyber insurance

Has an AI policy


Special Announcements

BCD Response to React2Shell (CVE-2025-55182 / CVE-2025-66478)

In December 2025, BCD became aware of two vulnerabilities for React2Shell related to React Server Components (React2Shell – Remote Code Execution).
A prompt assessment was conducted by BCD and no instances of these vulnerabilities were found within the BCD environment.
We continue to actively monitor our systems and have detected no signs of compromise.


BCD's Response to F5 Security Incident

On October 15th, 2025, F5 notified some of its customers and BCD that a highly sophisticated nation-state threat actor maintained long-term, persistent access to, and downloaded files from, certain F5 systems, and that they have taken extensive actions to contain the threat actor and have not seen any new unauthorized activity, and have taken proactive measures to protect its customers and strengthen the security posture of its enterprise and product environments.
A prompt assessment was conducted by BCD following the disclosure, and all affected systems have since been upgraded and verified.


BCD's Response to Cisco ASA & FTD Zero Days

Cisco disclosed three critical vulnerabilities (CVE-2025-20333, -20362, and -20363) in ASA and FTD software on September 25, 2025, two of which are actively exploited.
While our environment includes affected devices, VPN web services are not enabled, and all relevant patches have been applied.
We are actively monitoring and have detected no signs of compromise.


BCD's Response to Citrix NetScaler (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424)

On August 26, 2025, Citrix published security advisories for critical vulnerabilities, CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424, affecting the following products:
• NetScaler ADC and NetScaler Gateway 14.1 – versions prior to 14.1-47.48
• NetScaler ADC and NetScaler Gateway 13.1 – versions prior to 13.1-59.22
• NetScaler ADC 13.1-FIPS and NDcPP – versions prior to 13.1-37.241-FIPS and NDcPP
• NetScaler ADC 12.1-FIPS and NDcPP – versions prior to 12.1-55.330-FIPS and NDcPP

As part of our proactive security posture, BCD continuously monitors and scans its environments for vulnerabilities. We do not currently use Citrix NetScaler within our environment, and we have confirmed the Citrix NetScaler vulnerabilities are not present within the BCD Network.


BCD's Response to Salesloft Drift breach on Cloudflare.

On August 23rd, 2025, Salesloft, notified some of its customers, of a potential security issue in Salesloft's Drift application. whereby Salesloft Drift OAuth integration flow with Salesforce had been compromised, exposing some of its customer’s information.
Proactively, BCD began scanning its environment to determine if its Salesforce application was impacted. No instance of Salesloft Drift was identified and importantly, no compromise was detected.


BCD Travel's Response to MS zero day Sharepoint exploitation

On July 19, 2025, Microsoft disclosed a critical zero-day vulnerability (CVE-2025-53770) affecting on-premises SharePoint Server installations. Our environment includes two on-premises SharePoint servers, which were not publicly exposed and were immediately assessed upon disclosure. We have applied the official Microsoft patch (KB5002760), rebooted the systems, updated machine keys, and verified full functionality. Importantly, no client data is hosted or processed on these servers, and no compromise was detected.


TISAX renewal

Renewal of the TISAX certification for the locations Bremen, Düsseldorf, Berlin (all Germany), as well as London and Singapore visible in the ENX portal.


BCD Travel's Response to CrowdStrike issue

BCD is aware of Crowdstrike technical issue/mis configuration. We do not use any CrowdStrike product in our environment and thereby not affected or impacted by this outage.


BCD Travel's Response to Sisense Data Breach

BCD is aware of Sisense's breach disclosure. We do not use any SiSense product in our environment and thereby not affected or impacted by this threat.



Compliance and Certifications

tisax
TISAX
pci
PCI
soc1-type-2
SOC 1 Type II
gdpr
GDPR
sig
SIG
cmmc-level-2
CMMC Level 2
nist-800-171
NIST 800-171

Featured Documents


Documents & Knowledge Base FAQs

Powered by Conveyor, the first end-to-end customer trust platform.
Learn more