SITA Advanced Travel Solutions Ltd

iBorders Border Management System

iBorders is the most comprehensive portfolio available: from the provision of traveller information, to analysing complex data sets for risk assessment, to providing complete situational awareness of every aspect of border operations, iBorders enables governments to transform border security and ensure the country stays open for legitimate travel, and trade.


  • The only integrated traveller data acquisition and risk assessment available
  • The only interactive system that supports real-time denial of boarding
  • iBorders acquires, collates and transforms vast amounts of disparate data
  • egates and kiosks provide self-service border crossing for low-risk travellers.
  • Forms of traveller data include API, PNR and DCS data
  • Fully interactive data (iAPI, APP, AQQ) capability
  • Automated quality auditing capability for all data forms
  • Identity Assurance links biographic and biometric data to the person
  • ESTA, EVISA, ETIAS, ETA for Travel Authorisation


  • SITA is at the centre of the global travel industry
  • Positioned to facilitate the commercial and technical relationship with airlines
  • iBorders is the most widely deployed border security portfolio available
  • Turns comprehensive passenger information into actionable intelligence
  • Governments respond in real-time authorizing or denying boarding of traveller
  • Right information at the right time for effective decisions
  • All data is validated, standardized, filtered according to business rules
  • Supports General Aviation & Maritime (GA/GM)


£800 per person per day

Service documents


G-Cloud 11

Service ID

1 1 6 9 3 5 0 5 6 8 2 6 5 9 6


SITA Advanced Travel Solutions Ltd

Andy Smith

+44 7785 223257

Service scope

Service scope
Software add-on or extension No
Cloud deployment model
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints None
System requirements No special system requirements

User support

User support
Email or online ticketing support Email or online ticketing
Support response times Remote support is provided 24x7 with a typical response SLA of between 30 minutes and 3 days depending on severity of incident / request.
User can manage status and priority of support tickets Yes
Online ticketing support accessibility None or don’t know
Phone support Yes
Phone support availability 24 hours, 7 days a week
Web chat support No
Onsite support Yes, at extra cost
Support levels Remote support is provided 24x7 with a typical response SLA of between 30 minutes and 3 days depending on severity of incident / request.

An account manager and service manager will be assigned.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started Training is typically provided by onsite training.
Service documentation Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction Data can be exported at the end of the contract in open format.
End-of-contract process There is no additional cost at the end of the contract, assuming the contract runs to agreed term.

Using the service

Using the service
Web browser interface Yes
Supported browsers
  • Internet Explorer 9
  • Internet Explorer 10
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install No
Designed for use on mobile devices Yes
Differences between the mobile and desktop service Referral Management only available on iPhone, iPad and Android devices.
Service interface No
What users can and can't do using the API Entirely configurable
API documentation Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
API sandbox or test environment No
Customisation available Yes
Description of customisation Fully configurable.


Independence of resources Individual instances are containerised.


Service usage metrics No


Supplier type Not a reseller

Staff security

Staff security
Staff security clearance Staff screening not performed
Government security clearance Up to Security Clearance (SC)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations United Kingdom
User control over data storage and processing locations Yes
Datacentre security standards Supplier-defined controls
Penetration testing frequency At least once a year
Penetration testing approach Another external penetration testing organisation
Protecting data at rest Scale, obfuscating techniques, or data storage sharding
Data sanitisation process No
Equipment disposal approach A third-party destruction service

Data importing and exporting

Data importing and exporting
Data export approach Request to SITA.
Data export formats
  • CSV
  • ODF
Data import formats CSV

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks
  • Private network or public sector network
  • IPsec or TLS VPN gateway
Data protection within supplier network TLS (version 1.2 or above)

Availability and resilience

Availability and resilience
Guaranteed availability Standard SLA is 99.9% availability which can be flexed up and down. Refunds are available subject to negotiation.
Approach to resilience Available on request.
Outage reporting Email alerts.

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication Username or password
Access restrictions in management interfaces and support channels Provided on request.
Access restriction testing frequency At least every 6 months
Management access authentication
  • 2-factor authentication
  • Username or password

Audit information for users

Audit information for users
Access to user activity audit information Users have access to real-time audit information
How long user audit data is stored for User-defined
Access to supplier activity audit information Users have access to real-time audit information
How long supplier audit data is stored for User-defined
How long system logs are stored for User-defined

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification No
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification No
Other security certifications No

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance certified Yes
Security governance standards ISO/IEC 27001
Information security policies and processes Provided on request.

Operational security

Operational security
Configuration and change management standard Supplier-defined controls
Configuration and change management approach ITIL Compliant configuration and change management processes.
Vulnerability management type Supplier-defined controls
Vulnerability management approach Provided on request.
Protective monitoring type Supplier-defined controls
Protective monitoring approach Provided on request.
Incident management type Supplier-defined controls
Incident management approach ITIL Compliant process. Provided on request.

Secure development

Secure development
Approach to secure software development best practice Conforms to a recognised standard, but self-assessed

Public sector networks

Public sector networks
Connection to public sector networks No


Price £800 per person per day
Discount for educational organisations No
Free trial available No

Service documents

Return to top ↑