Diligence package, on day one.
Public pricing. Standard MSA. SOC 2 Type II. DPA, security questionnaire, sub-processor list, insurance certificates — all available before the first call. Procurement timelines measured in weeks, not quarters.
Procurement shouldn't be the gating step.
Mid-market procurement teams face a structural problem with travel platforms: most enterprise vendors won't share pricing without a sales call. Implementation timelines stretch 3–6 months. Custom contract negotiation eats legal hours. Diligence questionnaires take 4–6 weeks because the vendor's security team is gated behind a partner. By the time the contract is signed, your stakeholders have moved on.
The other extreme — fast-onboarding consumer-grade vendors — lacks the diligence rigor procurement teams need. No SOC 2. No DPA. No standard MSA. The contract redlines drag on because the vendor doesn't have a baseline.
Travel Code is built to be procurement-friendly without being light on diligence. Public pricing on the website. Standard MSA, DPA, SOC 2 Type II — all packaged and downloadable on day one. Implementation in days, not quarters. The work that procurement should be doing — risk assessment, supplier evaluation — gets done in weeks.
Typical procurement timeline for legacy enterprise travel platforms.
Typical security questionnaire turnaround with most enterprise vendors.
Avg. legal hours on custom contract negotiation per major travel platform.
Built for procurement evaluation.
Public, fixed-price plans.
Pricing is published on our website: $0 / $100 / $290 per company per month for travel; Free or $12.99/user/month for expense+cards. No per-seat fees on travel. No volume tiers to negotiate. Annual contracts available with standard discount. Quote-to-contract: 48 hours.
SOC 2 Type II and GDPR.
SOC 2 Type II audited annually by a Big-4 firm. Full audit report shareable under NDA. GDPR Art. 28 DPA standard. Multi-region data residency (US/EU/MENA). Pen-test summary refreshed quarterly.
Standard MSA, redline-friendly.
Standard MSA available before the first call. Most clauses negotiable; standard redlines turn around in 5 business days. DPA standard. SLA standard (99.95% uptime). Insurance: $5M cyber liability + $5M professional liability + $2M general liability.
Implementation measured in days.
Standard onboarding: 5–10 business days for SCIM integration, policy configuration, payment setup, supplier rate loading. Pro-plan implementations include named onboarding manager. No professional services fees on Free or Premium plans.
RFP to live in 4 weeks.
A typical mid-market procurement engagement, end-to-end. Times are P50 across deals closed in the last 12 months. Faster paths exist when a customer has pre-approved standard SaaS terms.
Diligence + initial review.
Diligence pack downloaded by procurement. Security questionnaire (SIG Lite) filled in by our team in 3 business days. SOC 2 review by your CISO. Standard MSA review by your legal.
Redlines + commercial.
Legal redlines exchanged. Most clauses negotiable; standard turn-around 5 business days. Pricing locked from public sheet. Annual term, payment terms, success criteria agreed.
Sign + implementation kickoff.
MSA + DPA + Order Form executed. Implementation manager assigned (Pro plan). SCIM integration with your IdP, supplier rate loading, policy configuration, GL coding mapped from your ERP.
Go-live + parallel run.
First travelers onboarded. 2-week parallel run alongside legacy platform if requested. Quarterly business review scheduled. Standard 99.95% SLA in effect from go-live.
Common Procurement questions.
Is your pricing really fixed, or is there a hidden enterprise tier?
Pricing is fixed and published. $0 / $100 / $290 per company per month for travel; Free or $12.99/user/month for expense+cards. There is no separate enterprise tier with negotiated pricing. Pro plan includes everything; volume discounts on annual contracts are standard (10–15%) and published.
What's included in the diligence package?
SOC 2 Type II report (under NDA), pen-test summary, SIG Lite questionnaire, sub-processor list, standard MSA, DPA (GDPR Art. 28), standard SLA, insurance certificates, public price sheet, reference customer list, implementation plan template. Available as a single ZIP within 1 business day of request.
What clauses in the MSA are negotiable?
Most are. Liability caps, indemnity scope, IP ownership, termination triggers, audit rights, data return, payment terms — all negotiable within reason. Non-negotiable: our security/compliance baseline (SOC 2, GDPR), our use of standard sub-processors. Standard redline turn-around: 5 business days.
What's the cancellation / data return process?
30-day notice for monthly contracts; standard renewal terms for annuals (60-day notice). Full data export in standard formats (CSV, JSON, PDF audit logs) within 14 days of termination. Data deletion certified within 30 days post-export. Per-region retention of audit logs honored according to your data retention configuration.
Get the diligence pack.
Single ZIP, signable in 48 hours. SOC 2 + DPA + MSA + SLA + insurance certificates + reference list. No sales call required to receive it.