Vulnerability disclosure policy
Triagen B.V.
Purpose and Scope
Triagen B.V. ("Triagen") welcomes reports from the security community about potential vulnerabilities in its services. This policy explains how to report a vulnerability to Triagen, what researchers can expect in return, and the conditions under which Triagen will treat a report as good-faith security research.
The policy applies to any individual or organisation reporting a vulnerability in the assets listed in Section 4. It complements the technical and organisational controls described in the Secure configuration baseline and the Secure development policy.
1. Introduction
Triagen operates a cloud-native platform on which sensitive personal data, including health-related information, may be processed. Protecting that data and maintaining the availability of the platform are core obligations.
Despite continuous automated security testing (Trivy vulnerability scanning, Semgrep static analysis, secret scanning, infrastructure drift detection), no system is free of vulnerabilities. Triagen treats external vulnerability reports as a valuable input to its security programme and commits to handling them promptly, transparently, and in good faith.
This policy is a public commitment to researchers about how Triagen will receive, triage, and resolve responsibly-disclosed reports.
2. How to report a vulnerability
Reports are received by email at security@triagen.ai. This inbox is monitored confidentially.
To help Triagen triage and reproduce the issue quickly, please include:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce, including any URLs, accounts, payloads, or proof-of-concept code required.
- The affected component, hostname, or endpoint.
- The date and time of any testing performed, and the IP address(es) used.
- Contact details for follow-up, and any preferred name for public credit (see Section 7).
If you wish to encrypt your report, request a PGP key at the same address and Triagen will provide one. Until a key is provided, please avoid including more sensitive information than is strictly necessary to describe the issue.
Please do not disclose the issue publicly or to any third party until Triagen has confirmed remediation, in line with Section 8.
3. Safe harbor for good-faith research
Triagen considers security research conducted under this policy to be authorised activity. Triagen will not initiate or recommend legal action against a researcher for conduct that is consistent with this policy and conducted in good faith.
To remain within the safe harbor, a researcher must:
- Make a good-faith effort to avoid privacy violations, degradation of service, and destruction or modification of data.
- Access only the minimum data necessary to demonstrate the vulnerability, and never view, copy, transfer, modify, or delete data belonging to other users.
- Stop testing and notify Triagen immediately if sensitive data (personal data, credentials, financial information, internal documents) is encountered.
- Not exploit the vulnerability beyond what is necessary to confirm its existence and assess its impact.
- Not use social engineering, phishing, or any form of attack against Triagen employees, customers, suppliers, or their accounts and devices.
- Not perform denial-of-service attacks, volumetric testing, or any action that degrades availability for other users.
- Comply with all applicable laws, in particular data-protection laws applicable in the European Union.
- Report the vulnerability privately through the channel in Section 2, and observe the coordinated-disclosure timeline in Section 8.
If you are uncertain whether a planned test is consistent with this policy, please email security@triagen.ai first.
4. Assets in scope
The following assets are in scope for this policy:
- The Triagen platform and any service operated under
*.triagen.ai, including customer-facing dashboards and the management API. - The Triagen marketing website (https://triagen.ai).
- The Auth0-hosted identity service operating under
auth.triagen.ai, to the extent the issue relates to Triagen's configuration of the tenant.
5. Out of scope
The following are out of scope. Reports against these targets will not be eligible for safe harbor under this policy and Triagen will not be able to act on them.
- Third-party services Triagen does not control, including but not limited to Google Cloud Platform, Auth0 (platform), GitHub, Linear, Slack, Brevo, Bitwarden, and Netlify. Please report such issues to the relevant vendor directly.
- Social engineering, phishing, vishing, or any non-technical attack against Triagen employees, customers, or partners.
- Physical attacks against Triagen offices, equipment, or staff.
- Denial-of-service attacks (including volumetric, application-layer, or resource-exhaustion attacks).
- Attacks requiring physical access to a user's device, root-level access on a user's device, or already-compromised credentials.
- Attacks against systems or accounts that do not belong to Triagen.
6. Findings we do not act on
The following classes of finding are generally considered low-impact or not actionable. Triagen will acknowledge the report and explain the rationale but will not typically prioritise remediation, unless an exploit path with material impact is demonstrated:
- Missing security headers without a demonstrated, exploitable impact.
- Clickjacking on pages with no sensitive state-changing actions.
- SPF, DKIM, or DMARC findings on domains not used to send email.
- Self-XSS and content spoofing without a credible exploit path.
- Vulnerabilities reproducible only in unsupported or end-of-life browsers, operating systems, or devices.
- Publicly available information disclosure with no associated security impact (for example, software version disclosure without a known unpatched CVE).
- Output from automated scanners without manual validation or a clear exploit path.
- Rate-limit, brute-force, or enumeration findings on endpoints that are already rate-limited at the edge.
- Tabnabbing, missing cookie flags on non-sensitive cookies, and similar best-practice findings without a demonstrated impact.
7. Triagen's commitments
When a report is received and the conduct described in Section 3 has been observed, Triagen commits to:
- Acknowledge receipt within five (5) business days.
- Triage and provide an initial severity assessment within ten (10) business days of acknowledgement.
- Remediate in line with the patch service levels defined in the Secure configuration baseline: Critical within 7 days, High within 30 days, Medium within 90 days, measured from confirmation of severity.
- Provide reasonable updates on progress during the remediation window.
- Treat the reporter's contact details and the report content as confidential. Triagen will not share them with third parties without the reporter's consent, except where required by law or where coordinated remediation with a vendor is necessary.
- Where the vulnerability is also a security incident affecting Triagen customers, handle it under the Incident response framework.
- Publicly acknowledge the reporter on a security acknowledgements page, with the reporter's prior consent and using the reporter's preferred name. Triagen does not operate a paid bug-bounty programme at this stage.
8. Coordinated disclosure
Triagen follows a coordinated-disclosure model. The default embargo is ninety (90) days from the date Triagen acknowledges receipt of a report, during which the reporter agrees not to disclose the vulnerability publicly or to any third party.
Where remediation requires more time, Triagen and the reporter may agree in writing to extend the embargo. Where remediation is completed before 90 days, Triagen and the reporter may agree to a shorter window for public disclosure.
Public disclosure after the embargo is welcome, provided that the reporter has given Triagen reasonable opportunity to confirm that remediation has been deployed. Where Triagen and the reporter disagree on disclosure timing, both parties commit to working in good faith to reach a mutually acceptable position.
9. Ownership and review
This policy is owned by Triagen's Chief Technology Officer, who is responsible for its content, publication, and maintenance. The policy is reviewed at least annually, and additionally whenever a material change occurs in Triagen's services, infrastructure, or applicable legal obligations.
Questions about this policy can be sent to security@triagen.ai.
