Corporate Traveler logo
Corporate Traveler

Corporate Traveler

App description

When employees book travel through Corporate Traveler, trip details and invoices automatically flow into Ramp, reducing manual work and simplifying expense management. Travelers book within policy and gain access to exclusive rates, backed by a dedicated Travel Manager and 24/7 support team. The result is a more efficient travel program with greater compliance, visibility, and control.

Security and compliance

Access is granted strictly on a need-to-know, least-privilege basis. Only authorised production support personnel, and individuals specifically granted access to a given client's data as part of their role, may access it.

·     Direct database access is prohibited for all staff except database administrators, who access systems via controlled, audited pathways (e.g. Azure Bastion/jump host, with MFA enforced).

·     Identity and access management: Access is federated through Okta (OIDC) with MFA required; privileged accounts not integrated with central directory services (e.g. native database accounts) are managed separately with periodic — at minimum quarterly — access reviews.

·     Joiner/mover/leaver controls: Access provisioning and deprovisioning follows a formal process; departing staff have access revoked as part of offboarding, with any gaps closed at the next scheduled review.

·     Segregation of duties: Privileged access (e.g. DBA-level) requires dual approval before being granted and is logged for audit purposes.

·     Third-party/offshore access: Where managed service partners require access (e.g. offshore support teams), this is provided via controlled remote access pathways rather than direct network or database access.

Monitoring: Access activity is logged and subject to review as part of the broader observability and audit trail capability.

Personal data is retained in line with FCTG’s documented retention schedule (provided as supporting evidence — FCM Profile PII Elements and Retention Schedule): passport details are physically deleted six months after the last international trip where no future international travel is booked; first and last name are retained for seven years in line with financial-record legislation (held with the associated financial transactions such as invoices and payments); all other profile fields are deleted once the profile is marked inactive or the customer's contract is terminated.

https://www.corporatetraveller.com.au/en-au/privacy

SOC 2 TYPE 2, ISO 27001, PCI.

App information
Developer
Flight Centre Travel Group
Category
Receipt automation, Accounting, Productivity

Discover more integrations

Ramp integrates with all your existing software so you can manage your business with ease—from one place.

Time is money. Save both.