Travelsoft Pay
France · www.travelsoft.com · 11 vendors
Resilience scores
- Digital Sovereignty: 9
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- ConsentPro — United States
- Google LLC — Technology — United States
- Mastercard Incorporated — Financial Services — United States
- and 9 more
Services catalogue
3 services in catalogue across 2 categories; runs on 11 sub-vendors.
- ConsentPro
- Issuing
- Payment Orchestration
Insights
Last updated 2026-08-15 · revision 2
11 direct vendors, 168 subvendors
Direct vendors by controlling owner country (sample)
- UK: 1
- Australia: 1
- United States: 8
Subvendors by controlling owner country (sample)
- Denmark: 4
- Canada: 5
- Sweden: 5
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Travelsoft Pay exhibits strong migration readiness due to its modern and flexible technology architecture. The "PSP-agnostic routing layer" and "Payment Orchestration" capabilities suggest a modular design that can facilitate easier integration with new systems or cloud environments. The use of secure tokenization and a PCI-aware architecture indicates adherence to modern security standards, which are often prerequisites for cloud migrations. Crucially, the stated "Total Vendors: 0" implies a very low vendor lock-in risk, which is a significant advantage for migration as it reduces dependencies and contractual complexities. The "Vendor Geographic Diversity: 4 unique countries" for the 14 services further suggests a distributed and adaptable underlying service landscape. The absence of specified data residency requirements also offers greater flexibility for choosing migration targets. A key limitation in assessing migration readiness is the lack of financial data (revenue concentration, growth history), which makes it impossible to evaluate the company's financial capacity to fund a significant migration effort. While the tech stack is modern, explicit confirmation of cloud-native, containerized, or microservices architecture is not provided, which would further enhance readiness. The inherent complexity of the payment regulatory environment, even with compliance, can still present challenges during migration.
Compliance
10 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
Travelsoft Pay provides cloud-based payment orchestration, virtual card issuing, and PSP connectivity services to travel businesses globally. As a B2B SaaS/platform provider handling sensitive financial and payment data, enterprise clients (OTAs, tour operators, airlines) will increasingly require SOC 2 Type II reports as part of vendor due diligence. The company's website explicitly references 'enterprise-grade security & governance,' 'compliance-first architecture,' and 'audit trail' capabilities, suggesting awareness of enterprise compliance requirements. However, no SOC 2 report or certification has been publicly disclosed. As a company founded in 2025, it may be in the process of obtaining its first SOC 2 report. Risk is medium because absence of SOC 2 may create commercial friction with enterprise clients and represents a gap in third-party assurance.
Evidence: https://www.travelsoftpay.com/, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
NIS2 (source) — Assessment Required
Travelsoft Pay operates as a payment orchestration and digital infrastructure provider within the EU. NIS2 covers 'digital providers' including online marketplaces, online search engines, and cloud computing services, as well as financial market infrastructure. As a payment hub processing billions in travel transactions and providing PSP connectivity, virtual card issuing, and payment orchestration, Travelsoft Pay may qualify as a digital provider or financial infrastructure entity under NIS2. The parent group (Travelsoft) reports €150M+ turnover and 700+ employees, which exceeds the NIS2 medium enterprise threshold (50+ employees or €10M+ turnover). However, Travelsoft Pay itself was founded in 2025 and its standalone size is unclear. If classified as an Important Entity, obligations include cybersecurity risk management measures, incident reporting to national authorities (ANSSI in France), and supply chain security. Risk is medium because sector classification requires formal assessment – payment orchestration is adjacent to but not explicitly listed as a core NIS2 sector, though financial market infrastructure is covered.
Evidence: https://www.travelsoftpay.com/, https://www.travelsoft.com/news-updates/travelsoft-pay-partners-with-checkout-com, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.ssi.gouv.fr/en/regulation/nis2/
ISAE 3000 (source) — Assessment Required
ISAE 3000 is relevant for companies providing assurance reports on non-financial information or controls to third parties. As a payment platform serving enterprise travel businesses, Travelsoft Pay may be subject to requests for ISAE 3000 assurance reports (e.g., ISAE 3402 for service organizations, which is the international equivalent of SOC 1). ISAE 3402 reports are commonly required by travel companies' auditors to assess controls at payment service providers that affect financial reporting. Risk is low-to-medium because while ISAE 3402 may be requested by enterprise clients' auditors, it is not a regulatory mandate and the company is newly established.
Evidence: https://www.travelsoftpay.com/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits-or
Financials
Three-year financials
- 2024: revenue €150M+
- 2023:
- 2022:
Financial Resilience Score: 7/10
Travelsoft Group demonstrates solid financial resilience underpinned by a SaaS/transactional revenue model with recurring revenue streams and high switching costs, given its platforms are deeply embedded in customers' reservation, mid-office and back-office operations. The group serves a blue-chip customer base including Lufthansa Group, IAG, TUI, easyJet Holidays, Disneyland Paris, and many others, providing revenue stability. Diversification across geographies (France, UK, Germany, Spain, Romania, Mexico), sub-segments (B2B distribution, back-office, media, connectivity, payments), and buyer profiles further strengthens resilience. The group benefits from strong PE backing through PSG Equity (majority since 2022), providing capital for continued M&A and organic investment. The recent launch of Travelsoft Pay unlocks a new revenue stream through virtual card interchange, FX margin, and orchestration fees on top of ~€50B in booking flows. However, resilience is tempered by the cyclicality of the travel industry (as demonstrated by COVID-19 and recent signals of 'summer 2026 departures significantly down'), acquisition-driven growth bringing integration risk and typically PE-style leverage, and limited public financial transparency with profitability, leverage and cash flow remaining opaque.
Key strengths: Recurring SaaS revenue model with high switching costs, Blue-chip customer base (Lufthansa, IAG, TUI, easyJet Holidays, Disneyland Paris), Geographic and product diversification across Europe and LatAm, PE backing from PSG Equity providing M&A capital, €150M+ turnover and €50B+ booking volume processed, New payments revenue stream via Travelsoft Pay, 700+ employees across 40+ nationalities
Risk factors: Cyclicality and demand shocks in the travel industry, Signs of weakening travel demand (summer 2026 departures down), Acquisition-driven growth carries integration and goodwill risk, Undisclosed PE-style leverage, Limited public financial transparency, Regulatory compliance risks for Travelsoft Pay (PSD2/PCI/EMD), Fraud, chargeback and FX exposure in payments, Customer concentration risk in certain regions
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.