SkyScanner is a global travel search platform with a mission to “become the world’s number one travel ally.” As a metasearch travel aggregator, Skyscanner helps users compare prices for flights, hotels, and car rentals from hundreds of travel sites. Founded in 2003 in Edinburgh, Skyscanner serves over 100 million customers monthly, providing information on over 80 billion prices daily, and operating in over 30 languages.
In recent years, post-pandemic, travel demand has exploded, and so has Skyscanner’s business. This rapid growth, combined with Skyscanner’s adoption of a hybrid work policy put increasing strain on the company’s traditional on-premises IT and security architecture, particularly its virtual private network (VPN), and made it challenging to respond to threats.
“With all our services hosted on-premises, we were expending huge amounts of time and resources just keeping everything online,” says Leonardo Almeida, Senior Engineer at Skyscanner. “Every time we exposed a vulnerability, we had to act immediately — usually out of hours. The complexity of managing all the infrastructure behind the scenes slowed us down, limiting our ability to develop new products for our customers.”
Skyscanner aspired to a more flexible architecture that could deliver “security by design — rather than as an afterthought.” To that end, the company prioritized modernizing remote access with Zero Trust controls delivered by Cloudflare, and replacing its legacy VPN. Implementing Cloudflare has helped Skyscanner:
“We wanted to re-architect our internal network and give our employees safe and scalable access to the systems they need to do their jobs from anywhere in the world,” says Jordan Craig, Principal Engineer. “Cloudflare was the perfect platform to deliver that seamless experience for our end users.”
Replacing their legacy VPN, Skyscanner onboarded Cloudflare’s Zero Trust Network Access (ZTNA) solution. Now, the company enforces granular controls for specific users to specific apps, including verification based on Skyscanner’s corporate identity provider. Skyscanner now bases access policies on least privilege for specific user roles, groups, and application purposes legacy methods like IP addresses, ports, or device locations.
“Once we define and assign user, application, and network groups, Cloudflare is there, frictionlessly protecting us against breaches, unwanted data flows, or inappropriate use of resources,” says Almeida.
Transitioning to Cloudflare’s cloud-native solution has eliminated VPN-related operational inefficiencies, including frequent manual interventions and costly maintenance cycles.