CI360 by Compass Island
Travel risk management

Know what's happening.
Know who's affected.

Global intelligence, traveler location, and itinerary data resolve into one live picture of the situation and the people in it.

Request a demo Explore the platform

Technology without an agenda

Your operation shouldn't come bundled with your software.

CI360 gives organizations the technology to build the operation they need—integrating intelligence, travel data, tracking technologies, communications, workflows and response partners into one operational environment.

Use your intelligence providers. Your TMCs. Your tracking technologies. Your response partners. Your people. CI360 brings them together around the way you operate—not the way a vendor wants you to operate.

On its own

Travel, tracking, intelligence, alerting, and automation, fully self-contained.

With your existing stack

Integrations across GDS and TMC providers, device networks, and third-party intelligence feeds.

{{ stat1 }}
Intel alerts, last 24 hours
{{ stat2 }}
Travelers tracked, last 7 days
{{ stat3 }}
Countries with users located

{{ quoteText }}

{{ quoteName }} {{ quoteRole }}

How it works

The situation and the people in it, in one view

Know what's happening

Real-time global intelligence on security, medical, and travel disruption. Bring in third-party feeds or publish your own tailored reporting, filtered to the places your people are.

CI360 security portal: an intelligence alert about a planned demonstration in central London, with the source, risk level and effective window beside the map

Know who's affected

Itinerary, device, and location data resolve into a live population for any event: who is in the area, who is inbound, and how to reach each of them.

CI360 security portal: a mass power outage alert with the travelers, devices and facilities inside the impact zone

A disruption, step by step

What the platform does before anyone calls a meeting

STEP 01

An event arrives and is scored for severity and location immediately.

STEP 02

Your footprint is already known: devices reporting position, itineraries tracked passively, offices and operating sites on the map. Proximity does the rest.

STEP 03

Your own rules decide the response. Messages, notifications, and alerts distribute themselves to the people the event actually reaches.

STEP 04

Instant action, and instant accountability: who was told, on which channel, and who has answered.

Rules engine

Rules that stack, and reach back into the field

Fire on a device, an intelligence alert, or an itinerary change. Escalate, start check-ins, publish an advisory, or change a tracker's settings mid-incident. Then let one rule's outcome trigger the next.

RULE 01
Fires on A critical alert inside 25 km of a traveler
Then does Raises their tracker to five-minute reporting and requests a check-in
RULE 02
Fires on That check-in going unanswered for fifteen minutes
Then does Notifies the duty officer and regional manager by SMS and voice
RULE 03
Fires on Two or more people unanswered in the same city
Then does Opens a group incident and messages everyone in the region

Packaging

Direct, white-label, or through a partner

Scoped by the modules you turn on and the people you cover, not by a fixed tier.

Direct

Your own tenant, run by your team.

White-label

Your brand on the portal and the app.

Partner-delivered

Bought and supported through a provider.

Partners and resellers

Deliver CI360 under your own brand

Security providers, travel managers, and intelligence firms run CI360 under their own brand, giving their clients tracking, intelligence, and operations management.

The CI360 security platform home: a live world map of tracked people and devices beside the dashboard, broadcast actions and recently reported devices

See CI360 running on your own travel data

A working session with the team that builds it. Bring a route, a region, or a scenario you care about.

Request a demo

Travel risk management platform

Four surfaces, one record underneath

The operations center, the travel manager, the traveler, and the people who report on all three. A single desk and a global network of operations centers run on the same system.

The CI360 travel manager dashboard: approved alerts, live travelers and pending itineraries above a color-coded risk map
01

Security Portal

The operations center view: live positions, intelligence, and alerting in one console.

02

Trip Manager

Planned travel, itinerary detail, and traveler records for the people who own duty of care.

03

Traveler portal and app

The traveler's own record, plus the toolkit they carry in the field.

04

Reports Dashboard

Reporting on footprint, exposure, and response, scheduled or on demand.

Access follows the role

Every portal is role-based. You define what each role can see and what it can act on, so a regional manager, a duty officer, and a traveler open the same platform to different views and different permissions.

Security portal: traveler tracking

Built for the operations center floor

Operators watch traveler locations, physical assets, and planned travel on a single map. Global intelligence alerts flag security, medical, and travel disruption as it happens.

Where every traveler is right now
Where they are booked to be next
What is happening near them
How to reach them, by text, email, or voice

We don't replace your GSOC. We make it better.

CI360 security portal: a severe weather advisory zone on the operational map, with the travelers and devices inside it
The CI360 trip manager: an itinerary list with travelers, destinations, dates, risk rating and approval status

Trip manager

Every travel detail in one record

Flights, accommodation, and ground transportation sit in one record, so updates and destination alerts reach the traveler before they need them.

A moderate-risk travel alert about a nationwide rail strike in France, shown in the CI360 traveler app The CI360 traveler app home screen: SOS, check-in, alerts, trips and tracking one tap from the front page A medium-risk travel alert about typhoon flight delays in Kyushu, Japan, shown in the CI360 traveler app

Select a screen to enlarge it

Traveler portal and safety app

Travelers keep their own record current

Travelers maintain their own trips, devices, personal details and emergency contacts — in the web portal before they go, and in the app once they are moving. Everything they need is one tap from the front page, and what they do there lands in the operations center immediately.

The app carries your own branding, and every tile below is switched on or off per client. Deploy the full set, or only the tools a given population should have.

When something goes wrong

SOS Monitor Me Check In Quick Call

Before and during the trip

Travel Advice Travel Alerts Documents Itineraries Maps

Keeping the record current

Tracking Devices Messages Journeys Take Photo Notes Emergency contacts

Mass communications and alerting

Reach everyone, or exactly the right group

The mass comms module reaches your entire staff, or a single group, office, or region, over SMS, email, in-app message, push, and interactive voice. Messages go out from the same screen as the live map, so notification happens where the response is already being run.

SMS Email In-app message Push Interactive voice

Send to

Entire staff every person on the roster
A group travelers, responders, executives
An office one site or facility
A region everyone inside the affected area
Composing a message in CI360 comms: channels, subject, content and recipient conditions summarized before sending to 32 recipients

Compose once, deliver over every channel the recipient has.

A CI360 message delivery report: delivered, responded, failed and opt-out counts for an earthquake check-in, with responses by option

Delivery and responses reported per message, down to each recipient.

Rules engine

The rules engine is not a feature. It is what the platform runs on.

A rule can fire on a device event, an intelligence alert, or a change to an itinerary. It can do far more than send a message: escalate to an on-call officer, start a check-in cadence, publish an advisory, open a workflow, or reach back into a tracker and change its settings mid-incident.

And rules stack. The outcome of one becomes the trigger for the next, which is how a single alert turns into a graduated response instead of a notification.

01

Triggers

What starts a rule.

Device event SOS Geofence crossed Low battery Missed check-in New intel alert Severity change Proximity to an event Itinerary booked Itinerary changed Flight delayed Schedule Another rule
02

Conditions

What narrows it.

Proximity Severity Country or region Group or role Traveler tag Device type Time of day Prior rule outcome
03

Actions

Whichever ones you already have. CI360 integrates commercial intelligence feeds, and your own analysts can write and publish reporting through the same channels your travelers already read. We can also provide turn-key intelligence integrations from any of our intelligence partners.

Notify people Notify a group Escalate to on-call Change device settings Raise reporting frequency Start check-ins Publish an advisory Open a workflow Fire another rule

Stacked, this is what one alert becomes

RULE 01

When a critical intelligence alert lands within 25 km of a traveler, raise their tracker to five-minute reporting and send a check-in request.

RULE 02

When that check-in goes unanswered for fifteen minutes, notify the duty officer and the regional manager by SMS and voice.

RULE 03

When two or more people in the same city are unanswered, open a group incident and message everyone in the region.

Walk the platform with our team

Request a demo

Travel risk management capabilities

Awareness, end to end

Nine modules, switched on as your program needs them. They share one record of every person, site, and event, so a change in one place updates the picture everywhere.

Modules

Nine modules that share one record

Turn on what your program needs. Every module writes to the same person, site, and event record, so nothing has to be reconciled across tools later.

01

Alerts and activity feed

Risk-rated, located, filtered to your people

Severity and proximity scored on every event
Filter the feed by person, site, or region
Your own analysts publish alongside commercial feeds
02

Live location

Position when it matters, on the terms you set

Traveler-activated sharing per trip or time window
Visible only to the roles you authorize
Runs alongside device and vehicle telemetry
03

Panic and SOS

One press, with position attached

Opens in the operations center with location
Escalation path set per population
Two-way contact from the same record
04

Check-ins and monitoring

Scheduled contact, with a flag on every miss

Check-in cadence per person, group, or journey
Missed windows raise on their own
Geofences on arrival, departure, and dwell
05

Mass communications

Everyone, or exactly the right group

SMS, email, push, in-app message, interactive voice
Audience by staff, group, office, or region
Replies land against the person’s record
06

Facilities and fixed sites

Offices, project sites, and residences on the same map

Create, edit, or bulk import sites
Proximity alerting and geofences per site
Shown beside travelers, not in a separate tool
07

Travel data and itineraries

Planned movement, without manual entry

30+ GDS and TMC integrations
Email parsing for anything booked elsewhere
Traveler-maintained trips from the app
08

Analytics and reporting

Footprint, exposure, and response, on demand

Build and save your own views
Filter by destination, date, person, or severity
Scheduled exports to the people who need them
09

Operational map

One view of people, sites, and events

Layer travelers, devices, facilities, and alerts
Cluster for global oversight, zoom to a single street
Start communications from the map itself
The CI360 operations console resolving nearby assets: the devices and travelers within a chosen radius of an incident, on the same map

Every module writes to the same console. Nothing has to be reconciled across tools later.

ISO 31030 evidence and compliance

Defensible, not just responsive

ISO 31030 is the international standard for travel risk management, setting out how organizations identify, assess, treat and monitor the risks of sending people to work away from home. CI360 supports the framework across every stage: assessing risk, treating it, monitoring it, and reviewing what happened. Duty of care is judged after the fact, so the platform keeps the record that shows what you knew, who you told, and how quickly.

Before travel

Briefings and destination advisories go out against the itinerary and its risk profile, with a record of who received and acknowledged them.

During travel

Position, check-ins, alerts served, and messages sent are timestamped against each person and each site.

During an incident

Who was notified, on which channel, who answered, what was escalated, and when each of those happened.

On review

Reports by destination, date, person, or severity, exportable for audit, insurer review, and board reporting.

Packaging

Three ways to run it

01

Direct

Your own tenant, your own rules, run by your team. Configuration, roles, and integrations are yours to set.

02

White-label

Your brand on the portal and the app, delivered to your own clients, with feature sets switched on per client.

03

Partner-delivered

Bought and supported through a security, travel, or intelligence provider who runs CI360 on your behalf.

In all three, access follows the role and modules are switched on per population. Pricing is scoped to the modules you turn on and the number of people covered, not to a fixed tier.

Integrations and deployment

CI360 works on its own, or with the technology you already run.

30+

GDS and TMC providers, including Sabre, Amadeus, and Concur, plus standalone email parsing for itineraries booked anywhere.

100+

Device types, from satellite phones and personal trackers to vehicle and aircraft telemetry.

5

Notification channels out of the box: SMS, email, push, in-app message, and interactive voice, driven by your own rules.

Common questions

What buyers, security teams, and procurement usually ask first.

What does CI360 do?

CI360 gives security and travel-risk teams a real-time operational view of their people, travel activity, threats, and emerging situations. It brings travel data, intelligence, communications, and response tools together in one platform so teams can quickly understand who may be affected, reach the right people, and coordinate action.

Does CI360 replace our GSOC?

No. CI360 is the technology platform that helps your GSOC operate more effectively. It provides the tools, data, visibility, communications, and workflows your team uses, but it does not replace your analysts, response capabilities, or human judgment—and it does not require you to purchase those services from us.

Which intelligence providers can we use?

Whichever ones you already have. CI360 integrates commercial intelligence feeds, and your own analysts can write and publish reporting through the same channels your travelers already read.

How does CI360 know where our people are?

Four ways, used together: booked itineraries from GDS and TMC integrations, app and device location where the traveler has enabled it, tracker and vehicle telemetry, and the offices and sites you have plotted.

Does CI360 support ISO 31030?

Yes. The platform covers each stage of the framework and retains the record behind it: briefings delivered and acknowledged, alerts served, check-ins made or missed, and every communication sent.

Can CI360 be delivered under our own brand?

Yes. The web portal and the mobile app can carry your branding, and each client deployment has its own feature set, so you decide which modules and app tiles a given population sees.

How are notifications targeted?

By your rules. Audiences resolve from live data — entire staff, a group, an office, or everyone inside an affected region — and messages go out over SMS, email, push, in-app message, or interactive voice.

How do I integrate with other systems?

CI360 is built entirely on a suite of well-documented APIs that let you pull data from the platform or push data into it. Virtually every record is available, so you stay in complete control of your data.

What is ISO 31030?

ISO 31030 is the international standard for travel risk management, published in 2021. It describes how an organization should identify travel risks, assess them against the trip and the traveler, treat them with controls such as briefings and monitoring, and review what happened afterwards. It is guidance rather than a certifiable standard, so organizations demonstrate alignment with it through evidence rather than a certificate.

What happens to data we already hold?

It stays authoritative. CI360 reads from your existing systems rather than asking you to re-enter records, and retention, residency, and role visibility are configured per deployment.

White-label partners and resellers

Deliver CI360 under your own brand

The same reason CI360 has no agenda about your intelligence providers applies to your clients. Run the platform as yours: your brand, your packaging, your pricing, your relationship.

The CI360 web portal, deployable under a partner brand

Who resells CI360

01

Security providers

Give existing protection, monitoring, and response clients a platform of their own, without building one.

02

Travel management

Add duty-of-care visibility to the itineraries you already hold, under your own brand.

03

Intelligence firms

Publish your reporting into a platform your clients work in daily, rather than sending it as attachments.

What you get

A platform you can put your name on

Your brand, end to end

Portal and mobile app carry your identity. Your clients see your name, not ours.

Per-client feature sets

Switch modules and app tiles on or off for each client, so a small account is not paying for an enterprise deployment.

Separate tenants

Each client is isolated, with its own users, rules, retention, and reporting.

Your intelligence in the feed

Your analysts write and distribute their own reporting, on your schedule, to the clients you choose.

Role-based access

Define what each role can see and do, per client, down to individual permissions.

Integration support

GDS and TMC connections, device networks, and third-party feeds set up with our team, not left to documentation.

In the field today

Built to power your brand

CI360 is already deployed behind partner brands, supporting offerings they take to market as their own. We protect those relationships—and yours—with the same discretion.

While we don't publicly name white-label deployments, qualified prospective partners can speak directly with select CI360 partners about the platform, its performance, and their experience building successful services around it.

How it works

STEP 01

Scope

We walk your client base and pick the module set that fits it, plus the branding and integration work involved.

STEP 02

Stand up

Your tenant, branding, and first client deployments go live with our team alongside yours.

STEP 03

Run it

You own the client relationship, the pricing, and the support tier. We support you, not around you.

Bring us your client base

Tell us what you sell today and who you sell it to. We will scope the module set and the branding work from there.

Talk about partnering
A global security operations center floor with analysts monitoring live incident feeds

Contact and demo requests

Talk to the CI360 team

Tell us how your travel and tracking data is set up today and we will show you CI360 against it.

Request a demo

Do you have travel data feeding a system today?
Send Thanks. Your request is queued. Take another moment with the form, then send again. Add your work email so we can reply. That didn't go through — email info@compassisland.co instead.

We use what you send here to reply to you and nothing else. See our privacy policy.

What happens next

01 A short call to understand your travel footprint and data sources.
02 A working demo of the three portals against a scenario you pick.
03 A deployment path: standalone, white-label, or partner-delivered.

CI360 is a Compass Island product

For company information, consulting services, and careers, visit Compass Island.

compassisland.co

Compass Island LLC
808 Lady Street Suite D #57
Columbia, SC 29201

Legal

Privacy policy

Effective August 25, 2026
Last updated August 25, 2026

This policy explains what Compass Island, LLC does with personal data in connection with the CI360 website, and the narrower set of personal data we process for our own purposes as the company behind CI360. It is written to be read, not to be tolerated.

1. Who we are

CI360 is a product of Compass Island, LLC. For the personal data described in this policy, Compass Island, LLC is the data controller and is responsible for how that data is handled.

Compass Island, LLC
808 Lady Street, Suite D #57
Columbia, SC 29201
United States

Privacy questions and requests: privacy@compassisland.co

2. What this policy covers

This policy covers this website and the inquiries people send through it.

It is not the policy that governs operational content inside the CI360 application. The two are separate, and the distinction matters to anyone assessing us as a vendor.

Operational content a customer puts into CI360 — traveler records, itineraries, locations, alerts, messages, check-ins, and the audit trail behind them — is handled on that customer's instructions. For that content Compass Island generally acts as a processor, and what we may do with it is set by the customer's agreement with us and the data processing terms attached to it, not by this policy.

There is a narrower set of information that we process for our own purposes, and there we act as a controller. It covers account administration, the business contact details of the people who administer and use a deployment, billing information, security and service logs generated by running the platform, and support correspondence. This policy describes that processing, along with the website.

We do not claim that a customer is automatically the controller of everything held in the application, and we do not claim that role for ourselves either. Which role applies to a given category of data is set out in the agreement covering that deployment.

3. What we collect

Information you give us. The demo and contact form asks for your first and last name, work email address, organization, what brings you to us, and whether travel data already feeds a system in your environment. If you write to us directly, we hold that correspondence and whatever you choose to put in it.

Technical information. Our web server keeps standard request logs: IP address, browser and device type, the pages requested, the referring page, and a timestamp.

Anti-spam signals. The form records how long it was on screen before submission, and it includes a hidden field that a person filling in the form never sees. Both exist to separate people from automated submissions. Neither is used to identify you or to build a profile.

We do not collect special category data through this site, we do not profile visitors, and no decision about you is made automatically.

Separately, we may hold professional contact details obtained from a conference, a referral, a public professional profile, or a business development tool. Where we do, they are held only so that we can get in touch about CI360, and we delete them on request.

4. Why we use it, and our legal basis

Where the GDPR or the UK GDPR applies, these are the purposes and the basis we rely on for each.

Purpose
Legal basis
Responding to a demonstration request or an inquiry, evaluating whether there is a potential customer relationship, and following up appropriately. The person who writes to us is acting for their employer, so we do not rely on steps taken prior to a contract with an individual.
Legitimate interests
Keeping the site available, and preventing spam and abuse.
Legitimate interests
Measuring how the site is used, if and when analytics are added. None is in place today; we will ask before any such tool is introduced, and you can withdraw consent at any time.
Consent
Meeting legal, tax and record-keeping obligations.
Legal obligation

Where we rely on legitimate interests, we have weighed our interest in reaching and supporting business customers against your interest in being left alone, and we have kept the data to the minimum that serves the purpose. You can object to that processing; section 10 explains how.

5. Cookies and similar technologies

This site sets no advertising cookies and runs no third-party tracking pixels.

Strictly necessary storage. When you make a choice in the cookie banner, that choice is recorded in your browser so we do not ask again. It holds the choice itself and nothing else — no identifier — and it is not transmitted to us.

Analytics. None is installed at present. If a measurement tool is added, it will load only after you accept analytics in the banner.

You can change your choice at any time: cookie settings. The same control is in the footer of every page.

6. Who we share it with

We do not sell personal data, and we do not share it for advertising.

We share it with service providers under written contract — website hosting, email and business communications, and the tools we use to track sales inquiries. We share it with professional advisers, such as our lawyers and accountants, where they need it to advise us. We disclose it to authorities where we are legally required to. And if the business or part of it is ever sold or reorganized, it may pass to the acquirer.

We will name the providers we currently use if you ask.

7. International transfers

Data covered by this policy is stored in the United States.

Where privacy law requires a transfer mechanism for personal data leaving the European Economic Area or the United Kingdom, an appropriate one is used — for example standard contractual clauses, or a provider's certification under a recognized transfer framework. Tell us which transfer you are asking about and we will tell you which mechanism applies to it.

8. How long we keep it

Inquiries and related correspondence that do not lead to a customer relationship: up to 36 months from our last contact with you.

Server logs: up to 12 months.

Records we are required to keep for tax or other legal reasons: for the period the law requires.

Data held in a customer's CI360 deployment is retained according to that deployment's configuration and the customer's agreement, not these periods.

9. Security

Traffic to this site is encrypted in transit using TLS. Access to personal data is limited to the people who need it for their work. Those people use individual accounts protected by multi-factor authentication. We collect as little as we can and keep it no longer than we need it.

We describe only the controls we can stand behind. If a security review needs more detail than this, ask and we will answer specifically rather than in general terms.

10. Your rights in the EEA and the UK

If the GDPR or the UK GDPR applies to our processing of your personal data, you have the right to:

ask what we hold about you and get a copy of it

have inaccurate data corrected, and incomplete data completed

have it erased, where we have no overriding reason to keep it

restrict how we use it while a question about it is resolved

object to processing we carry out on the basis of legitimate interests

receive data you gave us in a portable form, where that right applies

withdraw consent at any time, where we rely on consent

Write to privacy@compassisland.co. We answer within one month. There is no charge, and exercising a right will not count against you in any dealing with us. We may ask you to confirm your identity before we act, so that we do not disclose your data to someone else.

If your request concerns data held inside a customer's CI360 deployment, tell us and we will point you to the organization that controls it, or pass the request on where our agreement with them requires it.

11. California privacy rights

If the CCPA, as amended by the CPRA, applies to us, the following applies to California residents.

The categories of personal information we collect through this site are: identifiers, such as name, email address and IP address; professional and employment information, such as your organization and role; internet activity, from server logs; and the contents of the messages you send us. Why we collect each is set out in section 4.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

You may ask to know what we have collected about you, to have it deleted, and to have inaccurate information corrected. You may make a request through an authorized agent, and we may ask that agent for proof of authority. We will not discriminate against you for exercising any of these rights. Requests go to privacy@compassisland.co.

12. Canada

Under applicable Canadian privacy law, including PIPEDA where it applies, you may ask for access to the personal information we hold about you and challenge its accuracy. Write to us at the address in section 15. If you are not satisfied with how we handle your request, a complaint to the Office of the Privacy Commissioner of Canada may be available to you.

13. Children

CI360 is sold to organizations. This site is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, tell us and we will delete it.

14. Changes to this policy

When this policy changes, we update the date at the top of the page. If a change is material and affects data we already hold, we will tell the people it affects directly, where we have a way to reach them.

15. Contact and complaints

Email privacy@compassisland.co, or write to Compass Island, LLC, 808 Lady Street, Suite D #57, Columbia, SC 29201, United States.

Compass Island, LLC is based in the United States. Where applicable law requires us to appoint a representative in the European Economic Area or the United Kingdom, we will appoint one and publish the details here. Until then, requests come directly to the address above.

If you are in the EEA or the UK, you also have the right to complain to a national data protection authority — in the United Kingdom, the Information Commissioner's Office.

{{ lightboxImg }}
Cookies on this site

We use only essential storage by default. Optional analytics help us understand how the site is used and will not load unless you accept. Read our privacy policy.