Comparison Overview

GOL Linhas Aéreas

VS

Cathay Pacific

GOL Linhas Aéreas

Pça Comandante Linneu Gomes, Portaria 3, São Paulo, SP, BR, 04626-900
Last Update: 2025-12-09
Between 800 and 849

Somos a maior Companhia Aérea do País e estamos entre as que mais crescem no mundo. A nossa história começou em 2001 e, desde então, somos responsáveis por inovar o mercado da aviação no Brasil. Tudo isso graças à dedicação do nosso Time para garantir o nosso Valor número 1, a Segurança, entregando sempre a melhor experiência em voar. Carregamos em nossa bagagem o respeito para promover a diversidade e a inclusão em nosso ambiente de trabalho, valorizando o talento das nossas Águias e seguindo nosso propósito de ser a Primeira para Todos, seja no solo ou no céu. Além disso, criamos uma série de facilidades que tornam as viagens dos nossos Clientes ainda mais tranquilas, como: Novo App, Selfie Check-in, GOL+ Conforto, Programa de fidelidade da Smiles e Entretenimento a bordo. Com a laranjinha, você voa mais alto e leva a nossa essência Simples, Humana e Inteligente em todas as decolagens.

NAICS: 481
NAICS Definition: Air Transportation
Employees: 16,049
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Cathay Pacific

Cathay City, Chek Lap Kok, undefined, undefined, HK
Last Update: 2025-12-09
Between 750 and 799

Welcome to the official Cathay Pacific LinkedIn page. We have over 200 destinations in our global network, but want to do more than just move you from A to B. We want to take you further in your journey, and ultimately, to move beyond. And we’re here to do what we can to help you discover what’s next. For flight and other inquiries, please contact us via WhatsApp (+852 2747 2747) and Facebook.

NAICS: 481
NAICS Definition: Air Transportation
Employees: 13,834
Subsidiaries: 18
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/gol.jpeg
GOL Linhas Aéreas
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/cathay-pacific-airways.jpeg
Cathay Pacific
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
GOL Linhas Aéreas
100%
Compliance Rate
0/4 Standards Verified
Cathay Pacific
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Airlines and Aviation Industry Average (This Year)

No incidents recorded for GOL Linhas Aéreas in 2025.

Incidents vs Airlines and Aviation Industry Average (This Year)

No incidents recorded for Cathay Pacific in 2025.

Incident History — GOL Linhas Aéreas (X = Date, Y = Severity)

GOL Linhas Aéreas cyber incidents detection timeline including parent company and subsidiaries

Incident History — Cathay Pacific (X = Date, Y = Severity)

Cathay Pacific cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/gol.jpeg
GOL Linhas Aéreas
Incidents

No Incident

https://images.rankiteo.com/companyimages/cathay-pacific-airways.jpeg
Cathay Pacific
Incidents

No Incident

FAQ

GOL Linhas Aéreas company demonstrates a stronger AI Cybersecurity Score compared to Cathay Pacific company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, Cathay Pacific company has disclosed a higher number of cyber incidents compared to GOL Linhas Aéreas company.

In the current year, Cathay Pacific company and GOL Linhas Aéreas company have not reported any cyber incidents.

Neither Cathay Pacific company nor GOL Linhas Aéreas company has reported experiencing a ransomware attack publicly.

Neither Cathay Pacific company nor GOL Linhas Aéreas company has reported experiencing a data breach publicly.

Neither Cathay Pacific company nor GOL Linhas Aéreas company has reported experiencing targeted cyberattacks publicly.

Neither GOL Linhas Aéreas company nor Cathay Pacific company has reported experiencing or disclosing vulnerabilities publicly.

Neither GOL Linhas Aéreas nor Cathay Pacific holds any compliance certifications.

Neither company holds any compliance certifications.

Cathay Pacific company has more subsidiaries worldwide compared to GOL Linhas Aéreas company.

GOL Linhas Aéreas company employs more people globally than Cathay Pacific company, reflecting its scale as a Airlines and Aviation.

Neither GOL Linhas Aéreas nor Cathay Pacific holds SOC 2 Type 1 certification.

Neither GOL Linhas Aéreas nor Cathay Pacific holds SOC 2 Type 2 certification.

Neither GOL Linhas Aéreas nor Cathay Pacific holds ISO 27001 certification.

Neither GOL Linhas Aéreas nor Cathay Pacific holds PCI DSS certification.

Neither GOL Linhas Aéreas nor Cathay Pacific holds HIPAA certification.

Neither GOL Linhas Aéreas nor Cathay Pacific holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing errors; SyntaxError from express.json() includes user input in the error message, which gets reflected in responses. User input (including HTML/JavaScript) can be exposed in error responses, creating an XSS risk if Content-Type isn't strictly enforced. This issue does not have a fix at the time of publication.

Risk Information
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modify the prompts via PATCH endpoint for prompt groups (/api/prompts/groups/:groupId). However, the request bodies are not sufficiently validated for proper input, enabling users to modify prompts in a way that was not intended as part of the front end system. The patchPromptGroup function passes req.body directly to updatePromptGroup() without filtering sensitive fields. This issue is fixed in version 0.8.1.

Risk Information
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the iconURL parameter of the POST request can be modified by an attacker. The malicious code is then stored in the chat which can then be shared to other users. When sharing chats with a potentially malicious “tracker”, resources loaded can lead to loss of privacy for users who view the chat link that is sent to them. This issue is fixed in version 0.8.1.

Risk Information
cvss4
Base: 8.6
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege escalation. This issue is fixed in version 2.4.0.

Risk Information
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description

MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.

Risk Information
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H