Security by Design.
We handle sensitive vulnerability data. We treat your security with the same rigor as we treat the vulnerabilities we help you manage.
Trust & Compliance
Built with security-first principles and compliance at our core.
Data Sovereignty (EU)
We implement strict data segregation: All platform information is strictly isolated to European facilities with no obligation to the US Cloud Act. Platform data never leaves these secure European systems. For office information only, we use Microsoft 365 to enable user-friendly collaboration and productivity tools.
Encryption Everywhere
Data is encrypted at rest (AES-256) and in transit (TLS 1.3). We utilize strict key management policies.
at-rest: AES-256-GCM in-transit: TLS 1.3 keys: HSM-backed
ISO 27001 Aligned
Our processes are built on the ISO 27001 framework. We implement rigorous access controls and audits.
Our Own Disclosure Policy
We practice what we preach. We believe that no software is flawless, including ours. We welcome security researchers to inspect our platform within the boundaries of our policy.
// 2024 Op onze Hall of Fame komen? Start vandaag met het testen van Triagio
We offer non-monetary rewards and recognition for valid reports.
Standard Rules of Engagement
Safety comes first. Our researchers are contractually bound to strict rules:
-
Geen Disruptie: DDoS attacks and brute-force tests that slow down services are prohibited.
-
Geen Privacy-inbreuk: Accessing customer data is strictly limited to demonstrating the vulnerability (Proof of Concept).
-
Geen Social Engineering: Phishing your employees is out-of-scope.
These rules ensure that security research remains constructive and doesn't impact business operations.
Frequently Asked Questions
What types of vulnerabilities do you accept?
We accept all valid security vulnerabilities, including but not limited to: SQL injection, XSS, CSRF, authentication bypass, privilege escalation, and information disclosure.
How do you handle reported vulnerabilities?
We validate, prioritize, and coordinate with the affected parties to ensure timely remediation. Researchers receive updates throughout the process.
What rewards do you offer?
We offer non-monetary rewards including recognition in our Hall of Fame, certificates, and exclusive access to security research opportunities.
How do you handle researcher access?
Researchers never get direct access to your internal systems via Triagio. They only report what they find on your public-facing assets. We validate their findings in an isolated environment before passing them to you.
Are you GDPR compliant?
Yes. We act as a Data Processor. We have a standard Data Processing Agreement (DPA) available for all customers. We minimize data collection and enforce strict retention policies.