KNOWLEDGE BASE
Frequently Asked Questions
Everything you need to know about the platform, security, and partnership.
01
General & Contractual
What is the contract duration?
There is no fixed contract period. You can cancel monthly with a 1-month notice period.
How does billing work?
We bill per MSP, not per End Client. You receive one consolidated invoice monthly for all your connected tenants. Payment is by direct debit (SEPA).
What does the 'Fair Use Policy' entail?
Triagio does not enforce hard limits on the number of domains. We do look at the number of validated reports per month. If you structurally exceed your package limit (e.g. >5 incidents per month), we will discuss an upgrade to a higher Tier.
02
Security & Privacy
Where is the data stored?
All data is stored encrypted in data centers within the European Union (Netherlands/Germany). We comply with data sovereignty requirements.
Who has access to the vulnerabilities?
Only our screened analysts and authorized users within your MSP account. Thanks to strict 'Tenant Isolation', MSP A can never see MSP B's data.
What do you do about researchers who hold data hostage (extortion)?
We have a zero-tolerance policy. Researchers must agree to strict terms. Attempted extortion leads to an immediate ban and reporting to authorities (NCSC). We also do not anonymize payments/rewards; we know who the researcher is.
03
For Researchers (Ethical Hackers)
Do you pay Bug Bounties?
This varies by program. Most programs on Triagio operate on a 'Points & Swag' basis and Hall of Fame mentions. Some Enterprise clients do offer cash bounties; this is clearly stated in their policy.
What do you mean by Safe Harbor?
Here, Safe Harbor means legal protection for good-faith security research under coordinated disclosure rules. It is not the (outdated) EU–US data transfer framework. As long as you follow the rules (no data exfiltration, no DDoS, report responsibly), our clients commit not to take legal action against you.
How quickly is my report reviewed?
We aim to triage every report within 48 hours. You get immediate feedback on whether your report is accepted, rejected, or a duplicate.
04
Technical & Integration
Does Triagio perform automated scans?
Yes. Besides human researchers, the Triagio platform continuously performs automated checks for known vulnerabilities (CVEs), open ports, and configuration errors.
Do I need to install software?
No. Triagio is a 100% SaaS solution (External Attack Surface Management). We look from the outside in, just like a hacker does. No agents or installations are required.