AirGateway
Germany · www.airgateway.com · 17 vendors
AirGateway GmbH is a Berlin-based B2B travel technology company that provides an airline distribution platform. It specializes in New Distribution Capability (NDC) aggregation, enabling travel agencies and travel management companies to access and manage airline content, dynamic pricing, and ancillary services directly from various airlines. The company offers both API solutions and an agent desktop tool called BookingPad.
Resilience scores
- Digital Sovereignty: 24
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Mandrill (an Intuit company) — United States
- Netlify, Inc. — Technology — United States
- and 14 more
Services catalogue
1 service in catalogue across 1 category; runs on 17 sub-vendors.
- NDC Aggregation
Insights
Last updated 2026-07-30 · revision 2
17 direct vendors, 211 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- Spain: 1
- India: 2
Subvendors by controlling owner country (sample)
- Sweden: 4
- Poland: 2
- Denmark: 3
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
AirGateway exhibits high migration readiness due to its modern, cloud-native technology stack, with a strong foundation on Google Cloud Platform (GCP). The extensive use of modern programming languages (Go, Elixir, TypeScript, Python, Ruby) and Infrastructure as Code (HCL/Terraform) ensures a highly adaptable and portable codebase and infrastructure, significantly simplifying environment replication and potential migration efforts. The company's API-first product strategy, exemplified by the AirGateway API, and its expertise in various data formats (JSON, XML, EDIFACT) suggest a modular architecture that is inherently easier to move and re-integrate. The presence of numerous distinct SaaS vendors (e.g., Stripe, Mailgun, Zoho, GitHub) within its internal tech stack indicates a comfort and capability in integrating and managing external services, which is beneficial for handling dependencies during a migration. Key challenges and opportunities for migration are primarily linked to unknown factors: specific data residency requirements and the regulatory environment are not detailed, which could introduce complexities or constraints. Furthermore, the absence of financial stability data makes it difficult to assess the company's capacity to fund a significant migration project. While vendor diversity is present, the specific degree of lock-in with critical cloud providers (GCP) or specialized airline content vendors is not fully detailed, which could pose challenges if a migration away from these specific platforms were considered. The contradictory 'Total Vendors: 0' in the vendor relationships section has been disregarded.
Compliance
8 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 certification is not legally mandated but is a globally recognized best-practice standard for information security management. For AirGateway, as a cloud-based API provider handling sensitive traveler PII, airline credentials (6,598+ NDC credentials), and payment-adjacent data, ISO 27001 is highly relevant. The risk is Medium because: (1) no ISO 27001 certificate has been publicly disclosed; (2) the absence of certification may be a barrier in enterprise sales cycles with large TMCs or airlines that require vendor security certifications; (3) AirGateway's NIS2 obligations (if applicable) would be significantly easier to demonstrate with ISO 27001 certification; (4) the company's PCI DSS engagement suggests security awareness, but ISO 27001 provides a broader ISMS framework. The risk is not High because ISO 27001 is voluntary and non-compliance carries no direct regulatory penalty.
Evidence: https://airgateway.com/compliances/sub-processors/, https://airgateway.com/compliances/pci-dss
IATA NDC Standard & Accreditation — Compliant
AirGateway explicitly displays the IATA NDC Level 4 badge on their website and markets itself as a certified NDC aggregator. IATA NDC certification is a core commercial and operational requirement for AirGateway's business model — without it, they cannot legally operate as an NDC aggregator connecting airlines and travel agencies. The risk is Low because the company has demonstrated active certification and their entire business is built around this standard. Non-compliance would be immediately commercially disruptive and is therefore highly unlikely.
Evidence: https://airgateway.com, https://airgateway.com/articles/arpc-2026, https://airgateway.com/providers
PCI DSS (source) — Partially Compliant
AirGateway explicitly displays a PCI DSS badge on their website, indicating active engagement with the standard. The company processes payment card transactions through Stripe, Inc. and GoCardless Ltd. as sub-processors, and their platform handles booking and payment flows for travel agencies. PCI DSS is directly applicable as AirGateway stores, processes, or transmits cardholder data (or operates systems that interact with payment flows). The risk is rated High because: (1) the PCI DSS badge is displayed but no formal Attestation of Compliance (AoC), Report on Compliance (RoC), or SAQ (Self-Assessment Questionnaire) level has been publicly disclosed; (2) the travel industry is a high-value target for payment fraud; (3) AirGateway's platform handles payment data for thousands of travel consultants across 489+ IATAs globally; (4) PCI DSS v4.0 introduced new requirements (effective March 2025) that require updated compliance assessments. Without a publicly verifiable AoC or RoC, the actual compliance level cannot be confirmed.
Evidence: https://airgateway.com/compliances/pci-dss, https://airgateway.com/compliances/sub-processors/, https://airgateway.com
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
AirGateway GmbH benefits from a strong structural tailwind as major airlines (Lufthansa Group, IAG, Air France-KLM) push NDC adoption and impose GDS surcharges of ~€20/ticket, making aggregators like AirGateway increasingly valuable. The company has validated commercial standing via Premium Partner status with Lufthansa (2026), broad content coverage (35+ NDC airlines, 489 IATAs, 45+ countries), and a capital-light SaaS-style model with recurring subscription revenue from BookingPad and transaction-based fees from its API. Diversification across geographies and customers reduces concentration risk. However, resilience is constrained by several factors: as a small private German GmbH, AirGateway likely files only abridged balance sheets under HGB §§ 267/267a, so revenue, EBIT, and equity are not publicly disclosed, limiting transparency on runway and profitability. The company faces competition from well-funded rivals (Duffel, Travelfusion, Verteil, Kyte) and from GDSs (Amadeus, Sabre, Travelport) integrating NDC natively. Airline bargaining power over credentials and commercial terms creates margin compression risk, and any slowdown in NDC adoption would materially affect growth. Capital cushion likely depends on VC funding rounds with limited public visibility.
Key strengths: Structural tailwind from airline NDC adoption and GDS surcharges (~€20/ticket), Premium Partner status with Lufthansa (2026), Broad content coverage: 35+ NDC airlines, 489 IATAs, 45+ countries, Recurring/subscription SaaS revenue model with high switching costs, Diversified customer base across 500+ agencies globally, Capital-light software-only operating model
Risk factors: Concentration on airline NDC ecosystem; slowdown or reversal would hit growth, Airline bargaining power over credentials and margins, Competition from Duffel, Travelfusion, Verteil, Kyte and native GDS NDC offerings, Small-company capital cushion likely dependent on VC funding rounds, FX and cross-border collection risk across 45+ countries, Regulatory/data-security exposure (PCI-DSS payment card handling), Limited financial transparency due to abridged HGB filings
Revenue by geography
- Rest of World: 0%
- Europe (Germany, Iberia, France, Benelux, Italy, UK): 0%
Revenue by product/service
- Partnership/integration fees: 0%
- BookingPad (agency subscriptions/transaction fees): 0%
- AirGateway API (OTA/TMC/OBT/CBT license and transaction fees): 0%
Workforce by country
- Spain: 0
- Germany: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.