Last updated 17 August 2026
Vortrek — User Guide
For new customers. Everything you need to go from signing up to issuing your first approved travel risk assessment.
What Vortrek does
If you send people overseas for work, your organisation carries a duty of care. Vortrek exists to make sure that duty is genuinely discharged — not merely documented.
It puts a structured risk assessment process around every trip: research the destination properly, agree how the identified risks will actually be managed, have that plan signed off by someone with the authority to accept it, and make sure the traveller is briefed before they go.
The value is in what the process forces to happen. Risks get identified rather than assumed. Controls get agreed in consultation between the planner, the traveller and the approver — the three people who between them know the job, the person, and what the organisation is willing to accept. The traveller leaves knowing what they're walking into and what the plan is if it goes sideways. Nothing gets issued half-finished, and nobody signs off risk they aren't authorised to carry.
Done properly, that means your people travel better prepared and better supported. And because the process was sound and the record is complete, your organisation is also protected if something does go wrong.
Vortrek's risk methodology is aligned to ISO 31000 and ISO 31030 (risk management, and travel risk management respectively).
Duty of care stays with you. Vortrek documents and supports your duty of care as an employer. It doesn't transfer it to Vortrek, to Atlas Risk, or to the traveller.
Before you start
You'll need:
- A work email address you can receive mail at (you'll verify it)
- A payment method — Vortrek is subscription-only, there's no free tier
- Your travellers' names and email addresses
- Your approvers' details — name, email, and what level of risk each is authorised to sign off
- The itinerary — destinations, dates, and purpose of travel
1. Setting up
Create your account
- Go to vortrek.com.au and choose Get started
- Enter your work email and set a password
- Verify your email — check your inbox and click the link. You can't generate assessments until you do
- Accept the Terms and Privacy Policy
- Name your workspace (this is your organisation)
Choose a plan
You need an active subscription before you can generate anything.
| Plan | Assessments/month | Users |
|---|---|---|
| Solo | 5 | 1 |
| Team | 20 | 5 |
| Enterprise | Custom | Custom |
Current pricing is shown on the billing page and at vortrek.com.au. GST is added on top at checkout. You can cancel any time, and you keep access until the end of the period you've paid for.
Turn on two-factor authentication
Under Settings, enable MFA using an authenticator app. Strongly recommended — you're storing travel plans and approval records.
Add your branding (optional)
Settings → Branding. Upload your logo and set your brand colour. It appears in the app header, on your assessment PDFs, on Travel Cards, and in the emails your travellers and approvers receive — so documents look like they came from your organisation, not from us.
2. Set up your people
Travellers
Add the people you send abroad — name and email. You'll select them when creating an assessment.
Approvers
This is the part worth getting right, because it drives the whole approval flow.
Each approver has an authority level that determines the maximum risk they can sign off:
| Authority level | Can approve |
|---|---|
| Medium | Low and Medium risk |
| High | Low, Medium and High risk |
| Critical | All risk levels, including Critical |
Set these to match how your organisation actually delegates. If a trip comes back as High risk, only an approver with High or Critical authority will be selectable — Vortrek will grey out anyone who isn't authorised, and won't let you route around it.
You can link approvers to specific travellers so they're suggested automatically.
3. Sensitive travel and operational security
Most business travel won't need this section. Some will — read it if you support journalists, investigators, NGO or humanitarian staff, executives travelling on commercially sensitive business, security personnel, or anyone whose movements would be of interest to a third party.
Start from the right assumption
Vortrek is a computer system. So is your email, your calendar, your phone and the airline's booking system. Any digital record of who is going where, when, and why is a record that can in principle be compromised, subpoenaed, mis-sent, or exposed by a breach — ours or anyone else's. We've built Vortrek carefully, and we host your data in Australia, but no responsible vendor should tell you their system is the exception.
For sensitive travel, the sound approach isn't to trust the system harder. It's to put less in it that matters.
Use non-attributable identifiers
You don't need to enter a traveller's real name for Vortrek to work. Destination risk doesn't depend on who's going.
Consider recording travellers as:
- Employee or staff numbers —
EMP-4471 - Pseudonyms or call-signs — consistent, but not the person's name
- Project or task references —
PROJ-KESTREL-02 - Initials plus a sequence — where that's genuinely not identifying in your context
Keep the linkage off-app. Maintain the register that maps identifier to real person separately — on paper, in a controlled document, or in a system with appropriate protection — held by the people who need it. Vortrek then holds a risk assessment for EMP-4471 travelling to a destination, and the connection to a named individual lives somewhere you control.
The audit trail still works. It simply resolves to a reference you can interpret and others can't.
Think about the rest of the record too
Identity isn't the only thing that reveals intent:
- Purpose of travel — "site visit" tells the assessment engine what it needs; the name of the counterparty, the client, or the story usually doesn't
- Exact addresses and meeting locations — the city or region is normally enough to assess risk
- Email addresses — a Travel Card sent to
firstname.surname@company.comre-attributes the person you just carefully de-identified. Consider a role-based or neutral address for sensitive travel - Your organisation name — if the organisation itself is the sensitive fact, think about what your workspace is called and what your branding shows on documents
- Distribution lists — every additional recipient is another copy in another mailbox
Get the balance right
This is a proportionality judgement, not a rule. Over-applied, it makes assessments harder to action in an emergency — if something happens, someone needs to resolve EMP-4471 to a person quickly, and that register must be reachable at 3am, not locked in an office.
Under-applied, you've created a neat, structured, searchable record of exactly who your organisation sends into sensitive environments and when.
Decide deliberately, document the decision, and make sure whoever runs your emergency response can resolve the identifiers.
If you're routinely running travel where this matters, the identifier scheme should be part of a considered operational security posture rather than an ad-hoc choice. Atlas Risk can help you design one — see Getting help.
4. If you manage your own travel
Plenty of Vortrek users are sole operators — consultants, contractors, small businesses — where the person planning the trip, taking the trip and approving it are all the same person.
Vortrek works for you, with two things worth understanding.
You can approve your own travel, but it's deliberately opt-in. Tick "Approve this myself" on the briefing screen and Vortrek will warn you that self-approval removes the independent second check. That warning isn't bureaucratic box-ticking — a second pair of eyes is genuinely the most reliable way to catch a risk you've normalised because you've travelled somewhere before.
Consider nominating someone anyway. A business partner, a client contact at the destination, a colleague, or a family member who knows your itinerary. They don't need to be a security professional. What matters is that somebody other than you knows where you're going, what the risks are, and what the plan is if something goes wrong. You can add them as an approver with an appropriate authority level.
Everything else works the same — you're both the traveller and the approver, and the record you build is the same defensible evidence.
If you're a sole operator working in genuinely elevated-risk environments, this is exactly the point at which a conversation with Atlas Risk is worth having. See Getting help.
5. Create an assessment
- New assessment
- Choose the traveller (or several, for a group trip)
- Enter the itinerary — destinations, dates, purpose of travel
- Generate
Generation takes a couple of minutes. Vortrek researches current conditions for each destination and produces:
- An overall risk rating — Low, Medium, High or Critical
- Priority risks with suggested treatments
- Entry requirements — visas, passport validity, documentation
- Health advisories — vaccinations, medical considerations
- Local laws and customs — including things that are legal at home but not at your destination
- Emergency contacts — local services, embassies, consulates
- Five Eyes advisories — the official government travel advice from Australia, the UK, the US, Canada and New Zealand
If a section can't be completed, Vortrek will tell you loudly and mark the assessment incomplete. An incomplete assessment can't be sent, approved or exported — deliberately. A document that looks finished but has a hole in it is worse than no document.
6. Designate your approver chain
Once the assessment has generated, you'll see the assessed risk level and an approver picklist on the briefing screen.
This happens after generation on purpose: until the risk is known, you can't tell who's authorised to approve it.
- Pick your primary approver. Anyone whose authority is below the assessed risk is greyed out with the reason shown
- Add fallbacks in order — if your primary is unavailable, you can escalate to the next
- Self-approval is possible but opt-in, with a warning (see If you manage your own travel)
7. Agree the risk treatment plan
This is the most important step in Vortrek, and the one that most needs your judgement.
Identifying a risk is only half the job. The treatment plan is where you decide what you're actually going to do about it — and that decision belongs to you, the traveller and the approver, not to the software.
Vortrek gives you a starting point, not an answer
For each risk identified, Vortrek suggests treatments. Those suggestions are ideas to work from. They're generated from general destination conditions, and they cannot know:
- Your traveller's experience, health, or personal circumstances
- Your organisation's existing policies, insurance and support arrangements
- Who you're meeting, where you're staying, or how you're moving around
- What's actually practical or affordable for your operation
Do not accept the generated treatments on trust. A suggestion that's sensible for one traveller may be irrelevant, impractical or inadequate for another.
How to work through it
- Review each suggested treatment against your actual circumstances
- Edit anything that doesn't fit — reword it, make it specific, tie it to real arrangements
- Delete what isn't relevant to this trip or this traveller
- Add your own — the controls you know matter that the software wouldn't know to suggest
- Do this in consultation with the traveller and the approver
That last point matters most. The traveller often knows things the planner doesn't — a contact at the destination, a medical consideration, prior experience of the city. The approver may have organisational context or authority to fund a control. The plan is better when all three have shaped it.
Why it works this way
The treatment plan is what turns a risk assessment into an agreed course of action. A list of hazards doesn't help anyone at the airport. A set of controls the traveller helped shape, understands, and has actually agreed to — that changes what happens on the ground.
By the time the assessment reaches the traveller for briefing, everyone is looking at the same document, the mitigations are ones that have genuinely been agreed, and the approver is signing off on a plan rather than a list of problems.
It follows that the record is also defensible — but that's the consequence of doing it properly, not the reason for doing it.
If you're unsure whether a treatment is adequate — particularly for High or Critical risk travel — that's the right moment to get expert input rather than guess. See Getting help.
8. Brief the traveller
Once the treatment plan is agreed, choose Send to traveller.
They receive an email with a secure link — no account or password needed. They can read the full brief: the risks, the agreed treatments, entry requirements, health advice, local laws and emergency contacts.
They then acknowledge it. That acknowledgement is recorded with a timestamp and forms part of your audit trail.
The point of briefing after the treatment plan is agreed is that the traveller, the planner and the approver are all working from the same understanding of the trip and how it will be managed.
9. Approval
The primary approver receives an email with a secure link. They can approve or decline either:
- From the email link, or
- In the app, if they have a Vortrek login — the assessment appears in their list as pending approval
If the primary doesn't respond, you can escalate to the next approver in the chain.
Vortrek enforces the authority rule at the point of approval, not just in the picklist — an under-authorised approver cannot sign off a higher-risk plan.
When it's approved
- The plan is marked approved, with who approved it and when
- The travel is cleared to proceed on the terms that were agreed
- The traveller automatically receives their Travel Card
10. The Travel Card (tear-line)
The Travel Card is a condensed, carry-safe summary for the traveller — emergency contacts, key practical details, branded with your organisation's logo.
It deliberately excludes risk ratings, security classifications and the full assessment detail, so it's safe to carry, print or leave in a hotel room. If a traveller needs the full assessment, they're directed to contact their approver.
11. Refreshing an assessment
Conditions change. Refresh re-runs the research against the same itinerary and updates the assessment with current information.
Useful when dates shift, or when something happens at the destination between approval and departure. If a refresh materially changes the risk picture, revisit the treatment plan and re-brief the traveller.
Refreshes are metered separately from assessments (see Billing).
12. Your team
Settings → Members.
| Role | Can do |
|---|---|
| Owner | Everything, including billing and deleting the organisation. One per organisation. Cannot be removed or demoted by anyone |
| Admin | Manage members, create and manage assessments |
| Member | Create and manage assessments |
Inviting people
Send an invitation to their email address. They'll be prompted to sign in or create an account, and will land straight in your shared workspace.
If you send an invitation to the wrong address, you can revoke it while it's still pending — the link stops working immediately.
13. Plans, quota and billing
Your monthly allowance
Your assessment allowance resets on the 1st of each month (Australian Eastern time). Unused assessments don't roll over.
Going over your allowance
- Solo stops at your monthly limit. Upgrade to Team for more capacity
- Team can continue past the included allowance with overage. You'll be asked to authorise the extra charges first — Vortrek won't quietly bill you. Current overage rates are shown at the point of authorisation and on your billing page, which also tracks how many extras you've authorised, used and have remaining
Changing or cancelling
Billing → Manage billing opens the payment portal, where you can change plan, update your card, or cancel.
Cancelling takes effect at the end of the period you've paid for. After that you can't generate new assessments, but all your existing assessments, PDFs and audit history stay available to you — that record is your evidence, and you don't lose it by ceasing to subscribe.
14. Data, deletion and retention
- Deleting an assessment is a soft delete. It's recoverable for 30 days before permanent removal — accidental loss of duty-of-care evidence is worse than the inconvenience of a bin
- Legal hold exempts a record from automatic deletion if it may be evidence in a live investigation
- Retention is configurable under Settings, if your organisation has a records policy that applies
What Vortrek deliberately doesn't store
We don't hold passport numbers, dates of birth, medical or health records, or emergency contacts as stored personal attributes. Personal risk considerations are handled as destination-level information, never as a stored profile of an individual.
Your data is hosted in Sydney, Australia.
15. Getting help
There are two places to go, depending on what you need.
The app — support@vortrek.com.au
For anything to do with Vortrek itself:
- Something isn't working, or an assessment didn't generate properly
- Billing, plans, invoices and account questions
- Adding users, permissions, branding
- General enquiries about the product
When reporting a problem with an assessment, include the assessment reference (e.g. VTK-202608-0014-01) — it's on the assessment page and in the PDF footer.
The risk — enquiries@atlasrisk.com.au
Vortrek is built by Atlas Risk Management Services, a travel risk and security consultancy. When the issue isn't the software but the risk itself, that's who you talk to:
- You're not confident the treatments are adequate — particularly for High or Critical risk travel
- You need a plan for a specific risk that goes beyond generic controls — a hostile environment, a sensitive meeting, a location with limited emergency infrastructure
- You need capability on the ground — local support, secure transport and accommodation, in-country contacts, crisis response
- You're travelling somewhere the standard controls don't reach, and you need something purpose-built
Vortrek will tell you where the risks are. When a trip needs more than a documented plan — when it needs people, arrangements and judgement on the ground — Atlas Risk is where that comes from.
Quick reference
| I want to… | Where |
|---|---|
| Create an assessment | New assessment |
| Change who can approve what | Approvers → authority level |
| Edit the suggested treatments | Assessment → treatment plan |
| Send a brief to a traveller | Assessment → Send to traveller |
| Chase an approval | Assessment → Escalate to next approver |
| Approve my own travel | Briefing screen → "Approve this myself" |
| Add a colleague | Settings → Members → Invite |
| Cancel an invitation | Settings → Members → Revoke |
| Add our logo | Settings → Branding |
| Change plan or cancel | Billing → Manage billing |
| Check how many assessments are left | Dashboard or Billing |
| Recover something deleted | Assessments → Deleted (within 30 days) |
| Protect a sensitive traveller's identity | Use an identifier, keep the register off-app (§3) |
| Get help with the app | support@vortrek.com.au |
| Get help managing a risk | enquiries@atlasrisk.com.au |
Vortrek is a product of Atlas Risk Management Services Pty Ltd.