ATPCO
United States · www.atpco.net · 32 vendors
ATPCO is a privately held corporation that serves as the airline industry's leading source for airline merchandising and pricing data. It collects and distributes fare and fare-related data, providing solutions, data, and standards that enable airlines to manage fares, implement dynamic pricing, and distribute offerings globally.
Resilience scores
- Digital Sovereignty: 78
- Digital Resilience: 8
Technology vendors
- Anthropic, PBC — Technology — United States
- Demandware — Technology — United States
- Livemesh — Technology — India
- and 29 more
Services catalogue
2 services in catalogue across 1 category; runs on 32 sub-vendors.
- Airline Fare Data
- Pricing and Retailing Solutions
Insights
Last updated 2026-03-13 · revision 2
32 direct vendors, 345 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 1
- United Kingdom: 1
- India: 1
Subvendors by controlling owner country (sample)
- Germany: 6
- Moldova: 1
- Norway: 6
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
ATPCO exhibits high migration readiness, primarily driven by its modern and cloud-oriented technology stack. The use of AWS and Amazon CloudFront, coupled with key technologies such as "Cloud-native," "API-Based Data Distribution," "NDC (New Distribution Capability)," and "Dynamic Offers," indicates an architecture well-suited for cloud migration, potentially leveraging microservices and containerization. The absence of specified data residency requirements further simplifies potential migration efforts. While the "Total Vendors: 0" data point is inconsistent with other vendor information, the high geographic diversity of vendor HQs (9 unique countries) suggests a distributed vendor ecosystem, which can be beneficial in avoiding concentrated vendor lock-in from a geographic perspective. However, the total number of vendors for the 70 services is unknown, making a precise assessment of vendor lock-in risk challenging. Additionally, the assessment lacks data on ATPCO's financial stability to fund a significant migration initiative and details on its regulatory environment, which could introduce unforeseen compliance complexities during migration.
Compliance
4 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
ATPCO has demonstrated compliance through ISO 27701 certification, appointed Data Protection Officer, and EU-US Data Privacy Framework certification. However, ongoing compliance requires continuous monitoring due to the complexity of international data transfers and evolving regulatory requirements. The company processes personal data of EU/EEA residents through its global operations, making GDPR fully applicable.
Evidence: https://atpco.net/compliance, https://atpco.net/privacy-policy, https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt00000008SLoAAM&status=Active
ISO 27001 (source) — Compliant
ATPCO has achieved ISO 27001 certification, demonstrating implementation of comprehensive information security management system. Risk is low as the company has demonstrated compliance through third-party certification. Ongoing risk is limited to maintaining certification through regular audits and continuous improvement.
Evidence: https://atpco.net/compliance
SOC 2 (source) — Assessment Required
ATPCO provides cloud-based data services to airlines and processes sensitive business data, making SOC2 highly relevant for demonstrating security controls to customers. While the company has ISO 27001 certification (which covers similar security domains), SOC2 is often specifically required by US-based customers for cloud service providers. The risk is medium as lack of SOC2 could impact customer acquisition and retention in the US market.
Evidence: https://atpco.net/compliance, https://atpco.net/api
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.