## Reward useful findings

A bounty boost gives one researcher a private incentive to keep contributing to your vulnerability disclosure program (VDP). The multiplier starts at 1× and rises as staff validate qualifying findings. Higher rates apply to future submissions, up to 1.5×, with a maximum extra bounty per report.

Boosts belong to one program and one researcher. They do not publish the researcher's identity or create a public competition. The researcher does not need a paid subscription. Your team needs an active Kit subscription to use the bounty workflow, and only staff authorized to approve bounties can start or end a boost.

## Start a boost

Open the researcher in your program and select **Start boost**. Set the duration, the maximum extra bounty per report, and its currency. The default duration is 30 days; supported durations are 7–90 days. Review the terms and start the boost. Only one live boost can apply to that researcher in the same program.

The terms are fixed when the boost starts. Check the cap and currency before activation. The staff card shows progress, the current rate, and the end time. The researcher's portal shows their private offer and its rules.

![Staff researcher profile with an active bounty boost](/docs-images/bounty-boosts/staff-desktop.png)

> [!IMPORTANT]
> The cap limits the **extra on each report**, not the total amount you may owe during the boost. Several qualifying reports can each receive an extra bounty.

## Notify the researcher

**Email the researcher** is selected by default when you start a boost. Leave **Personal message (optional)** blank to use a short message of appreciation in the researcher's language, or write your own note (up to 2,000 characters). Clear the checkbox to start the boost without an email.

The email always includes the submission window, progression milestones, maximum extra per report, eligibility rules and approval requirements. A custom note replaces only the personal message. It cannot remove or change the financial terms.

Only starting a new boost sends this email. Existing boosts stay silent. If the daily outbound email limit is reached, Kit retries after the next daily reset while the boost is still active. If sending is delayed until after the boost expires or ends, Kit skips the email. A queued or attempted send does not prove inbox delivery.

## How progress works

A finding qualifies when staff have validated the report and assigned an official severity of **Medium or higher**. It must be a distinct, eligible finding in your program, submitted during the boost. A researcher's claimed severity and a report that has only been triaged do not qualify.

| Qualifying validated findings | Rate for new submissions |
| --- | --- |
| 0 | 1× |
| 1–2 | Up to 1.1× |
| 3–4 | Up to 1.25× |
| 5 or more | Up to 1.5× |

The first qualifying report is submitted at 1× and earns no extra itself. Once validated, it unlocks up to 1.1× for later submissions. The report that unlocks another tier keeps the rate it had when submitted.

Low-severity reports, duplicates, dismissed or informative reports, retests, and discretionary bonuses do not advance progress or receive the boost extra. Each qualifying report counts once. Reopening it, validating it again, or reapproving its bounty adds no second finding. An invalid report does not reset other progress.

If staff correct a verdict or lower an official severity below Medium, the count and rate for future submissions may fall. Offers already recorded on other submissions remain fixed.

## Submission terms survive the end

Kit records the boost terms and current multiplier when a report is submitted. The start time is included; the end time is excluded. Read the displayed end time and timezone before submitting.

A report submitted during the boost keeps its recorded offer even if staff validate it or approve its bounty after the boost ends. It still needs to qualify as an official Medium-or-higher finding and receive an approved bounty. Reports submitted afterward receive no boost from that offer.

Authorized staff can end the boost early. This stops eligibility for new submissions; it does not remove offers recorded on earlier reports. A later boost begins with new progress.

![Researcher portal showing the private boost and next milestone](/docs-images/bounty-boosts/researcher-desktop.png)

## Approve the base, extra, and total

Enter the **base bounty** using your normal [bounty matrix and approval rules](/docs/bounties-and-payouts). Kit calculates the extra from the report's recorded multiplier and cap, then shows the total payable. Only qualifying Medium-or-higher findings receive that extra.

For example, at the 1.5× tier with a €200 extra cap:

| Base bounty | Calculated extra | Extra after cap | Total payable |
| --- | --- | --- | --- |
| €300 | €150 | €150 | €450 |
| €1,000 | €500 | €200 | €1,200 |

This is why the offer says **up to** 1.5×. The cap can make the effective increase smaller. The award currency must match the boost currency; Kit does not convert the cap between currencies.

Staff review and approve the total. A boost does not approve a report, award money, or send payment automatically. The normal payout, adjustment, and revocation safeguards still apply.

## Correct an award after eligibility changes

If an approved bounty loses boost eligibility after a severity correction or a change of researcher, payment is blocked until the award is corrected. An ordinary amount adjustment keeps the award's frozen multiplier and cap; it cannot remove that extra.

Open **Revoke bounty**, review the current total and enter a reason. Revocation leaves the report's decision and status unchanged. Kit records a compensating debit in the ledger for the revoked total. You can then approve a fresh bounty: if the report no longer qualifies for the boost, the new award receives no extra. The original submission terms stay recorded; the old credit, revocation debit and new credit leave the ledger with the corrected amount owed.

Revocation is prohibited while a payout is pending or processing, and after it has completed. Do not mark a payout as failed just to bypass this safeguard.

Through MCP, call `csirt_revoke_bounty` with `report_id`, a `reason`, `expected_amount_cents` (the current total) and `expected_award_id` (the current award's prefixed ID). Review the award with the user first. If its amount or identity changes, Kit refuses the revocation; fetch the current award and confirm again. Use `csirt_approve_bounty` separately for the replacement.

## Use MCP with the same controls

Authorized staff can use `csirt_create_bounty_boost` with `researcher_id`, `duration_days`, `bonus_cap_cents`, and `currency`; read offers with `csirt_list_bounty_boosts` using `page` and `limit`; and end an offer with `csirt_end_bounty_boost` using `boost_id`.

Relevant report and award summaries expose the recorded offer and monetary breakdown. For boosted approval, provide `base_amount_cents` so Kit can calculate the extra. The existing `amount_cents` input means the total, not a base to multiply again; do not provide both inputs. Human confirmation and financial permissions remain required. See [VDP AI integration](/docs/ai-integration-vdp) for agent access.

When approving through MCP with `base_amount_cents`, you must also provide `expected_total_amount_cents`, even if the report currently earns no boost extra. First review the base, extra and total with the user. If the calculated total changes before approval, Kit refuses the award; review the updated amounts before confirming again. The existing `amount_cents` input still means the total and does not require this additional field.