{{ quoteText }}
How it works
A disruption, step by step
An event arrives and is scored for severity and location immediately.
Your footprint is already known: devices reporting position, itineraries tracked passively, offices and operating sites on the map. Proximity does the rest.
Your own rules decide the response. Messages, notifications, and alerts distribute themselves to the people the event actually reaches.
Instant action, and instant accountability: who was told, on which channel, and who has answered.
Rules engine
Fire on a device, an intelligence alert, or an itinerary change. Escalate, start check-ins, publish an advisory, or change a tracker's settings mid-incident. Then let one rule's outcome trigger the next.
Packaging
Scoped by the modules you turn on and the people you cover, not by a fixed tier.
Your own tenant, run by your team.
Your brand on the portal and the app.
Bought and supported through a provider.
Partners and resellers
Security providers, travel managers, and intelligence firms run CI360 under their own brand, giving their clients tracking, intelligence, and operations management.
A working session with the team that builds it. Bring a route, a region, or a scenario you care about.
The operations center view: live positions, intelligence, and alerting in one console.
Planned travel, itinerary detail, and traveler records for the people who own duty of care.
The traveler's own record, plus the toolkit they carry in the field.
Reporting on footprint, exposure, and response, scheduled or on demand.
Every portal is role-based. You define what each role can see and what it can act on, so a regional manager, a duty officer, and a traveler open the same platform to different views and different permissions.
Security portal: traveler tracking
Operators watch traveler locations, physical assets, and planned travel on a single map. Global intelligence alerts flag security, medical, and travel disruption as it happens.
We don't replace your GSOC. We make it better.
Trip manager
Flights, accommodation, and ground transportation sit in one record, so updates and destination alerts reach the traveler before they need them.
Select a screen to enlarge it
Traveler portal and safety app
Travelers maintain their own trips, devices, personal details and emergency contacts — in the web portal before they go, and in the app once they are moving. Everything they need is one tap from the front page, and what they do there lands in the operations center immediately.
The app carries your own branding, and every tile below is switched on or off per client. Deploy the full set, or only the tools a given population should have.
Mass communications and alerting
The mass comms module reaches your entire staff, or a single group, office, or region, over SMS, email, in-app message, push, and interactive voice. Messages go out from the same screen as the live map, so notification happens where the response is already being run.
Send to
Compose once, deliver over every channel the recipient has.
Delivery and responses reported per message, down to each recipient.
Rules engine
A rule can fire on a device event, an intelligence alert, or a change to an itinerary. It can do far more than send a message: escalate to an on-call officer, start a check-in cadence, publish an advisory, open a workflow, or reach back into a tracker and change its settings mid-incident.
And rules stack. The outcome of one becomes the trigger for the next, which is how a single alert turns into a graduated response instead of a notification.
What starts a rule.
What narrows it.
Whichever ones you already have. CI360 integrates commercial intelligence feeds, and your own analysts can write and publish reporting through the same channels your travelers already read. We can also provide turn-key intelligence integrations from any of our intelligence partners.
When a critical intelligence alert lands within 25 km of a traveler, raise their tracker to five-minute reporting and send a check-in request.
When that check-in goes unanswered for fifteen minutes, notify the duty officer and the regional manager by SMS and voice.
When two or more people in the same city are unanswered, open a group incident and message everyone in the region.
Modules
Turn on what your program needs. Every module writes to the same person, site, and event record, so nothing has to be reconciled across tools later.
Risk-rated, located, filtered to your people
Position when it matters, on the terms you set
One press, with position attached
Scheduled contact, with a flag on every miss
Everyone, or exactly the right group
Offices, project sites, and residences on the same map
Planned movement, without manual entry
Footprint, exposure, and response, on demand
One view of people, sites, and events
Every module writes to the same console. Nothing has to be reconciled across tools later.
ISO 31030 evidence and compliance
ISO 31030 is the international standard for travel risk management, setting out how organizations identify, assess, treat and monitor the risks of sending people to work away from home. CI360 supports the framework across every stage: assessing risk, treating it, monitoring it, and reviewing what happened. Duty of care is judged after the fact, so the platform keeps the record that shows what you knew, who you told, and how quickly.
Briefings and destination advisories go out against the itinerary and its risk profile, with a record of who received and acknowledged them.
Position, check-ins, alerts served, and messages sent are timestamped against each person and each site.
Who was notified, on which channel, who answered, what was escalated, and when each of those happened.
Reports by destination, date, person, or severity, exportable for audit, insurer review, and board reporting.
Packaging
Your own tenant, your own rules, run by your team. Configuration, roles, and integrations are yours to set.
Your brand on the portal and the app, delivered to your own clients, with feature sets switched on per client.
Bought and supported through a security, travel, or intelligence provider who runs CI360 on your behalf.
In all three, access follows the role and modules are switched on per population. Pricing is scoped to the modules you turn on and the number of people covered, not to a fixed tier.
CI360 works on its own, or with the technology you already run.
GDS and TMC providers, including Sabre, Amadeus, and Concur, plus standalone email parsing for itineraries booked anywhere.
Device types, from satellite phones and personal trackers to vehicle and aircraft telemetry.
Notification channels out of the box: SMS, email, push, in-app message, and interactive voice, driven by your own rules.
What buyers, security teams, and procurement usually ask first.
CI360 gives security and travel-risk teams a real-time operational view of their people, travel activity, threats, and emerging situations. It brings travel data, intelligence, communications, and response tools together in one platform so teams can quickly understand who may be affected, reach the right people, and coordinate action.
No. CI360 is the technology platform that helps your GSOC operate more effectively. It provides the tools, data, visibility, communications, and workflows your team uses, but it does not replace your analysts, response capabilities, or human judgment—and it does not require you to purchase those services from us.
Whichever ones you already have. CI360 integrates commercial intelligence feeds, and your own analysts can write and publish reporting through the same channels your travelers already read.
Four ways, used together: booked itineraries from GDS and TMC integrations, app and device location where the traveler has enabled it, tracker and vehicle telemetry, and the offices and sites you have plotted.
Yes. The platform covers each stage of the framework and retains the record behind it: briefings delivered and acknowledged, alerts served, check-ins made or missed, and every communication sent.
Yes. The web portal and the mobile app can carry your branding, and each client deployment has its own feature set, so you decide which modules and app tiles a given population sees.
By your rules. Audiences resolve from live data — entire staff, a group, an office, or everyone inside an affected region — and messages go out over SMS, email, push, in-app message, or interactive voice.
CI360 is built entirely on a suite of well-documented APIs that let you pull data from the platform or push data into it. Virtually every record is available, so you stay in complete control of your data.
ISO 31030 is the international standard for travel risk management, published in 2021. It describes how an organization should identify travel risks, assess them against the trip and the traveler, treat them with controls such as briefings and monitoring, and review what happened afterwards. It is guidance rather than a certifiable standard, so organizations demonstrate alignment with it through evidence rather than a certificate.
It stays authoritative. CI360 reads from your existing systems rather than asking you to re-enter records, and retention, residency, and role visibility are configured per deployment.
Give existing protection, monitoring, and response clients a platform of their own, without building one.
Add duty-of-care visibility to the itineraries you already hold, under your own brand.
Publish your reporting into a platform your clients work in daily, rather than sending it as attachments.
What you get
Portal and mobile app carry your identity. Your clients see your name, not ours.
Switch modules and app tiles on or off for each client, so a small account is not paying for an enterprise deployment.
Each client is isolated, with its own users, rules, retention, and reporting.
Your analysts write and distribute their own reporting, on your schedule, to the clients you choose.
Define what each role can see and do, per client, down to individual permissions.
GDS and TMC connections, device networks, and third-party feeds set up with our team, not left to documentation.
In the field today
CI360 is already deployed behind partner brands, supporting offerings they take to market as their own. We protect those relationships—and yours—with the same discretion.
While we don't publicly name white-label deployments, qualified prospective partners can speak directly with select CI360 partners about the platform, its performance, and their experience building successful services around it.
We walk your client base and pick the module set that fits it, plus the branding and integration work involved.
Your tenant, branding, and first client deployments go live with our team alongside yours.
You own the client relationship, the pricing, and the support tier. We support you, not around you.
Tell us what you sell today and who you sell it to. We will scope the module set and the branding work from there.
We use what you send here to reply to you and nothing else. See our privacy policy.
For company information, consulting services, and careers, visit Compass Island.
compassisland.coCompass Island LLC
808 Lady Street Suite D #57
Columbia, SC 29201
Legal
Effective August 25, 2026
Last updated August 25, 2026
This policy explains what Compass Island, LLC does with personal data in connection with the CI360 website, and the narrower set of personal data we process for our own purposes as the company behind CI360. It is written to be read, not to be tolerated.
CI360 is a product of Compass Island, LLC. For the personal data described in this policy, Compass Island, LLC is the data controller and is responsible for how that data is handled.
Compass Island, LLC
808 Lady Street, Suite D #57
Columbia, SC 29201
United States
Privacy questions and requests: privacy@compassisland.co
This policy covers this website and the inquiries people send through it.
It is not the policy that governs operational content inside the CI360 application. The two are separate, and the distinction matters to anyone assessing us as a vendor.
Operational content a customer puts into CI360 — traveler records, itineraries, locations, alerts, messages, check-ins, and the audit trail behind them — is handled on that customer's instructions. For that content Compass Island generally acts as a processor, and what we may do with it is set by the customer's agreement with us and the data processing terms attached to it, not by this policy.
There is a narrower set of information that we process for our own purposes, and there we act as a controller. It covers account administration, the business contact details of the people who administer and use a deployment, billing information, security and service logs generated by running the platform, and support correspondence. This policy describes that processing, along with the website.
We do not claim that a customer is automatically the controller of everything held in the application, and we do not claim that role for ourselves either. Which role applies to a given category of data is set out in the agreement covering that deployment.
Information you give us. The demo and contact form asks for your first and last name, work email address, organization, what brings you to us, and whether travel data already feeds a system in your environment. If you write to us directly, we hold that correspondence and whatever you choose to put in it.
Technical information. Our web server keeps standard request logs: IP address, browser and device type, the pages requested, the referring page, and a timestamp.
Anti-spam signals. The form records how long it was on screen before submission, and it includes a hidden field that a person filling in the form never sees. Both exist to separate people from automated submissions. Neither is used to identify you or to build a profile.
We do not collect special category data through this site, we do not profile visitors, and no decision about you is made automatically.
Separately, we may hold professional contact details obtained from a conference, a referral, a public professional profile, or a business development tool. Where we do, they are held only so that we can get in touch about CI360, and we delete them on request.
Where the GDPR or the UK GDPR applies, these are the purposes and the basis we rely on for each.
Where we rely on legitimate interests, we have weighed our interest in reaching and supporting business customers against your interest in being left alone, and we have kept the data to the minimum that serves the purpose. You can object to that processing; section 10 explains how.
This site sets no advertising cookies and runs no third-party tracking pixels.
Strictly necessary storage. When you make a choice in the cookie banner, that choice is recorded in your browser so we do not ask again. It holds the choice itself and nothing else — no identifier — and it is not transmitted to us.
Analytics. None is installed at present. If a measurement tool is added, it will load only after you accept analytics in the banner.
You can change your choice at any time: cookie settings. The same control is in the footer of every page.
We do not sell personal data, and we do not share it for advertising.
We share it with service providers under written contract — website hosting, email and business communications, and the tools we use to track sales inquiries. We share it with professional advisers, such as our lawyers and accountants, where they need it to advise us. We disclose it to authorities where we are legally required to. And if the business or part of it is ever sold or reorganized, it may pass to the acquirer.
We will name the providers we currently use if you ask.
Data covered by this policy is stored in the United States.
Where privacy law requires a transfer mechanism for personal data leaving the European Economic Area or the United Kingdom, an appropriate one is used — for example standard contractual clauses, or a provider's certification under a recognized transfer framework. Tell us which transfer you are asking about and we will tell you which mechanism applies to it.
Inquiries and related correspondence that do not lead to a customer relationship: up to 36 months from our last contact with you.
Server logs: up to 12 months.
Records we are required to keep for tax or other legal reasons: for the period the law requires.
Data held in a customer's CI360 deployment is retained according to that deployment's configuration and the customer's agreement, not these periods.
Traffic to this site is encrypted in transit using TLS. Access to personal data is limited to the people who need it for their work. Those people use individual accounts protected by multi-factor authentication. We collect as little as we can and keep it no longer than we need it.
We describe only the controls we can stand behind. If a security review needs more detail than this, ask and we will answer specifically rather than in general terms.
If the GDPR or the UK GDPR applies to our processing of your personal data, you have the right to:
ask what we hold about you and get a copy of it
have inaccurate data corrected, and incomplete data completed
have it erased, where we have no overriding reason to keep it
restrict how we use it while a question about it is resolved
object to processing we carry out on the basis of legitimate interests
receive data you gave us in a portable form, where that right applies
withdraw consent at any time, where we rely on consent
Write to privacy@compassisland.co. We answer within one month. There is no charge, and exercising a right will not count against you in any dealing with us. We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else.
If your request concerns data held inside a customer's CI360 deployment, tell us and we will point you to the organization that controls it, or pass the request on where our agreement with them requires it.
If the CCPA, as amended by the CPRA, applies to us, the following applies to California residents.
The categories of personal information we collect through this site are: identifiers, such as name, email address and IP address; professional and employment information, such as your organization and role; internet activity, from server logs; and the contents of the messages you send us. Why we collect each is set out in section 4.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
You may ask to know what we have collected about you, to have it deleted, and to have inaccurate information corrected. You may make a request through an authorized agent, and we may ask that agent for proof of authority. We will not discriminate against you for exercising any of these rights. Requests go to privacy@compassisland.co.
Under applicable Canadian privacy law, including PIPEDA where it applies, you may ask for access to the personal information we hold about you and challenge its accuracy. Write to us at the address in section 15. If you are not satisfied with how we handle your request, a complaint to the Office of the Privacy Commissioner of Canada may be available to you.
CI360 is sold to organizations. This site is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, tell us and we will delete it.
When this policy changes, we update the date at the top of the page. If a change is material and affects data we already hold, we will tell the people it affects directly, where we have a way to reach them.
Email privacy@compassisland.co, or write to Compass Island, LLC, 808 Lady Street, Suite D #57, Columbia, SC 29201, United States.
Compass Island, LLC is based in the United States. Where applicable law requires us to appoint a representative in the European Economic Area or the United Kingdom, we will appoint one and publish the details here. Until then, requests come directly to the address above.
If you are in the EEA or the UK, you also have the right to complain to a national data protection authority — in the United Kingdom, the Information Commissioner's Office.
We use only essential storage by default. Optional analytics help us understand how the site is used and will not load unless you accept. Read our privacy policy.