Skip to main content

Intigriti Triage

Updated yesterday

For programs with managed triage enabled, the Intigriti Triage team performs an initial review of incoming submissions. Their goal is to ensure you are notified only of valid and unique vulnerabilities, so your team can focus on issues that require action.


During triage, submissions are reviewed to confirm they are reproducible, in scope, and not duplicates. Submissions that clearly add no value, such as duplicates or out-of-scope findings, are closed before they reach your team.

During the triage process, the Intigriti Triage team performs the following actions:

  • Validate the report
    The triager verifies whether the reported behavior can be reproduced. If reproduction is unclear, they communicate with the researcher to request additional information until the report is sufficiently clear.

  • Assess severity
    Severity is assessed according to the criteria defined in your program description. Business impact is taken into account during this assessment. The assigned severity can still be adjusted by your team after triage if needed.

  • Check uniqueness
    The triager checks whether the issue has already been reported. Duplicate submissions are closed based on previous submissions or known issues, such as findings documented in penetration test reports that you have shared.

  • Validate scope
    The triager verifies whether the reported issue falls within the defined scope of your program. Clearly out-of-scope findings are closed.

  • Team and researcher communication
    The triage team uses internal messages to ask questions or provide context for your team. They also communicate with researchers in all messages to confirm verification or request additional information when needed.

💡Note: Also read our Triage standards.

After triage is complete, valid submissions are forwarded to your team in the Pending state so you can begin handling them.

Related articles

Did this answer your question?