ClassPass runs a global marketplace connecting consumers to fitness, wellness, beauty, and self-care experiences - gyms, studios, salons, spas - through a single membership and app. The company also operates a corporate wellness arm selling flexible benefit programs to employers. That means the security team is defending a two-sided platform handling payment data, personal health and preference information, and partner integrations across geographies.
The threat surface is familiar to any consumer marketplace: account takeover targeting stored credentials and credits, fraudulent partner transactions, and the privacy obligations that come with sensitive wellness and location data. On the corporate side, the attack model extends to B2B API integrations and the expectations of enterprise customers managing employee benefit access. Engineering operates out of New York with a global user base spanning multiple markets.
Security roles here likely touch identity and access management, application security across mobile and web surfaces, cloud infrastructure hardening, and fraud detection pipelines. The data mix - payment cards, personal health preferences, real-time booking APIs - demands rigorous controls around PCI compliance, data minimization, and secure partner onboarding. For practitioners interested in consumer marketplace security at scale, ClassPass presents a concrete set of problems without the ambiguity of an unshaped threat model.






