From PCI Project to Long-Term Security Partnership: How TravelJoy Made Compliance Repeatable
This customer success story highlights how TravelJoy transformed PCI DSS compliance from a one-time project into a sustainable, repeatable part of its security program. The article emphasizes the value of having a long-term security partner that understands the organization's environment, reducing audit disruption while supporting ongoing compliance and security initiatives. It showcases how the relationship evolved beyond PCI DSS to include penetration testing, demonstrating the benefits of a trusted, strategic security partnership.
Published September 28, 2026

For TravelJoy, payment security is part of earning the trust of the travel advisors who rely on its platform to manage client payments.
Since 2022, TravelJoy has worked with GRSee to turn PCI DSS compliance from a standalone project into a repeatable, low-disruption part of its security program. The relationship has since expanded into a multi-year engagement and, in 2026, penetration testing, giving TravelJoy one team that understands its architecture, controls, and security program.
Chris Dodds, Staff DevOps Engineer, TravelJoy
THE CHALLENGE
TravelJoy designed its platform so sensitive card data would not pass directly through its systems. That architectural choice reduced risk and supported a safer payments experience for advisors and their clients.
As the company grew, customers, partners, and due-diligence processes increasingly raised questions about PCI DSS. TravelJoy needed a recognized, independently validated standard to point to when demonstrating its approach to payment security.
PCI DSS gave the company a clearer way to show that its controls and practices met established industry requirements.
For TravelJoy, compliance was ultimately about making trust easier to establish.
FROM A PCI PROJECT TO A LONG-TERM PARTNERSHIP
TravelJoy began working with GRSee on a full PCI DSS engagement in 2022. The relationship continued with consulting support alongside the audit work and, by 2024, had become a multi-year arrangement.
That continuity has become one of the partnership's biggest advantages.
A new assessor would need time to understand TravelJoy's architecture, business, past decisions, and security program. After several years together, GRSee already has that context, so each annual cycle builds on the last rather than starting from zero.
Chris Dodds, Staff DevOps Engineer, TravelJoy
That knowledge is especially valuable when a requirement does not map neatly to a modern technology environment. Instead of applying control language generically, the teams can determine whether TravelJoy needs a substantive security change or clearer documentation and interpretation.
MAKING THE ANNUAL PCI DSS CYCLE ROUTINE
TravelJoy maintains its controls and evidence throughout the year in Vanta rather than treating compliance as a once-a-year exercise.
Combined with the context built up between the two teams, that preparation has significantly reduced the internal burden. Dodds is now the primary person involved, with the CTO joining only where needed. Audit interviews total approximately eight hours annually.
The process remains rigorous without becoming a major engineering distraction.
TravelJoy also spends less time researching PCI DSS requirements on its own. With an expert resource already familiar with its environment, the team can quickly determine how requirements apply.
Over time, TravelJoy has also developed stronger internal judgment, particularly in distinguishing substantive security risks from issues that are primarily about documentation or interpretation.
NAVIGATING THE PCI DSS 4.0 TRANSITION
The biggest concern during the transition to PCI DSS 4.0 was uncertainty. Some requirements were still being interpreted across the industry as implementation timelines approached.
TravelJoy needed to identify which changes applied to its environment without overreacting to requirements that did not.
Working with a partner that already understood its architecture allowed the team to address that ambiguity in context. Together, they identified the changes that mattered and implemented them without unnecessary disruption.
The value was not simply knowing what the standard said. It was having the technical and business context to interpret it correctly.
BRINGING PENETRATION TESTING UNDER THE SAME ROOF
In March 2026, TravelJoy added penetration testing to its relationship with GRSee.
The decision was a natural extension of the existing PCI DSS work. GRSee already understood TravelJoy's environment and performed its PCI scans, so the testing team could start with more context and less duplicated onboarding.
For TravelJoy, this simplified vendor management and created a more connected view across PCI DSS, vulnerability scanning, penetration testing, and the broader security program.
KEY RESULTS
- A repeatable annual compliance process: The 2022 PCI DSS project has matured into an established annual cycle.
- Approximately eight hours of annual audit interviews: Year-round evidence management and accumulated context keep the process rigorous without unnecessarily pulling engineers away from product work.
- Less time interpreting PCI DSS internally: TravelJoy can resolve questions quickly with a partner that already understands its environment.
- Continuity instead of repeated onboarding: Each engagement builds on previous work and shared knowledge.
- A smoother PCI DSS 4.0 transition: TravelJoy focused on the requirements that applied to its environment and avoided unnecessary disruption.
- PCI DSS and penetration testing under one relationship: Adding penetration testing reduced duplicated onboarding, simplified vendor management, and improved continuity across security activities.
- Independent assurance for a high-trust product experience: PCI DSS gives TravelJoy a recognized way to demonstrate its commitment to payment security to advisors, partners, and vendors.
SECURITY THAT SUPPORTS TRUST
TravelJoy's customers are primarily small and mid-sized businesses, so the value of PCI DSS is not measured by a single deal or a high volume of enterprise questionnaires.
It is more fundamental.
Travel advisors ask their clients to make significant payments through the technology they use to run their businesses. Security is therefore part of the trust they place in TravelJoy.
Independent PCI DSS validation reinforces that trust by showing that TravelJoy's payment-security practices are assessed against an established external standard.
Chris Dodds, Staff DevOps Engineer, TravelJoy
For travel advisors, that means greater confidence that the payments experience they put in front of their clients is backed by a disciplined, independently validated security program.
WHY TRAVELJOY CONTINUES TO WORK WITH GRSEE
After several PCI DSS cycles, TravelJoy's reason for staying with GRSee goes beyond convenience. It is the combination of technical understanding and practical interpretation.
Chris Dodds, Staff DevOps Engineer, TravelJoy
For TravelJoy, that has turned PCI DSS from something the team must continually decode into an established part of how it manages payment security, and it has created a partnership that can continue to expand as the business evolves.





