I think you proved my point. There's a 3rd option - they could be using a symmetric-key algorithm. This would make it trivial to decrypt for Amtrak - while difficult for anyone else to decrypt.
The problem with this, and why people don't view it as much better than plain text, is because it's a single point of failure - and if your DB has been compromised, your secret keys (in a config or in source) probably isn't too far behind.
The problem with this, and why people don't view it as much better than plain text, is because it's a single point of failure - and if your DB has been compromised, your secret keys (in a config or in source) probably isn't too far behind.