Features Pricing Triagio for MSPs About Contact Tenant Portal
TRUST CENTER

Security by Design.

We handle sensitive vulnerability data. We treat your security with the same rigor as we treat the vulnerabilities we help you manage.

AES-256Encryption
TLS 1.3In Transit
EUData Sovereignty

Trust & Compliance

Built with security-first principles and compliance at our core.

01

Data Sovereignty (EU)

We implement strict data segregation: All platform information is strictly isolated to European facilities with no obligation to the US Cloud Act. Platform data never leaves these secure European systems. For office information only, we use Microsoft 365 to enable user-friendly collaboration and productivity tools.

Region: EU · Azure Netherlands · M365 (office only)
02

Encryption Everywhere

Data is encrypted at rest (AES-256) and in transit (TLS 1.3). We utilize strict key management policies.

at-rest: AES-256-GCM
in-transit: TLS 1.3
keys: HSM-backed
03

ISO 27001 Aligned

Our processes are built on the ISO 27001 framework. We implement rigorous access controls and audits.

✓ISO 27001 · ISMS
✓access control · audited
✓annual review ✓

Our Own Disclosure Policy

We practice what we preach. We believe that no software is flawless, including ours. We welcome security researchers to inspect our platform within the boundaries of our policy.

Hall of Fame
// 2024
Op onze Hall of Fame komen? Start vandaag met het testen van Triagio

We offer non-monetary rewards and recognition for valid reports.

Standard Rules of Engagement

Safety comes first. Our researchers are contractually bound to strict rules:

  • Geen Disruptie: DDoS attacks and brute-force tests that slow down services are prohibited.
  • Geen Privacy-inbreuk: Accessing customer data is strictly limited to demonstrating the vulnerability (Proof of Concept).
  • Geen Social Engineering: Phishing your employees is out-of-scope.

These rules ensure that security research remains constructive and doesn't impact business operations.

Frequently Asked Questions

Still have a question? Contact us →

What types of vulnerabilities do you accept?

We accept all valid security vulnerabilities, including but not limited to: SQL injection, XSS, CSRF, authentication bypass, privilege escalation, and information disclosure.

How do you handle reported vulnerabilities?

We validate, prioritize, and coordinate with the affected parties to ensure timely remediation. Researchers receive updates throughout the process.

What rewards do you offer?

We offer non-monetary rewards including recognition in our Hall of Fame, certificates, and exclusive access to security research opportunities.

How do you handle researcher access?

Researchers never get direct access to your internal systems via Triagio. They only report what they find on your public-facing assets. We validate their findings in an isolated environment before passing them to you.

Are you GDPR compliant?

Yes. We act as a Data Processor. We have a standard Data Processing Agreement (DPA) available for all customers. We minimize data collection and enforce strict retention policies.