Sharing Reports With Peers
Share a single vulnerability report with an engineer outside your team via a secure, email-gated, expiring link — without exposing the researcher, bounty, or internal notes.
Why It Matters
A valid report often needs to reach someone who isn’t on your security team — the engineer who owns the affected service, an on-call lead, an external contractor. Forwarding the raw report leaks the researcher’s identity, your bounty figures, and your internal triage notes, and email threads can’t be revoked. Peer sharing gives that person exactly what they need to confirm and fix the bug — and nothing else — behind a link that expires and that you can revoke at any time.
Peer sharing is available on paid VDP plans.
Sharing a Report
Open a report and click Share in the report header (the Shared · N external viewers chip opens the same place once anyone has viewed). That opens the share window, where you can invite by email, create an “anyone with the link” link, and manage every active share in one spot.
To invite by email, enter the recipient’s address, choose whether to allow them to comment back, and send. Kit emails them a branded invitation on your program’s behalf — the email itself contains no vulnerability details.
The emailed link is bound to that address. When the peer opens it they must confirm the address before the report is shown, so a forwarded link is useless to anyone else — the confirmation only ever reaches the original recipient.
Anyone With the Link
When you need to drop a report into a private channel — a company Slack, an incident bridge — and don’t have one specific recipient, switch on Anyone with the link. Kit gives you a single copy-pasteable URL that opens the same redacted report without an email step.
- One link per report. Creating it gives you the URL to copy; revoking it kills that URL. Create again for a fresh one.
- View-only. Link viewers can’t comment and can’t request to join your team — those need a named, verified person, so they stay on the email path.
- Same redaction, same limits. A link reveals exactly what an email invite does (and hides exactly what it hides). It still expires after 7 days and you can revoke it anytime. Closing the report revokes the links you’ve already shared — but you can deliberately share it again afterward.
Because anyone holding the link can open it, only share it where you’d share the redacted details themselves. When in doubt, invite by email instead — that ties access to a confirmed address.
What the Peer Sees
The shared view is a redacted, read-only version of the report:
- Shown — vulnerability type, affected endpoint, severity, description, reproduction steps, and attachments (served as short-lived, off-origin downloads).
- Hidden — the researcher’s identity and email, bounty amounts, your internal notes, the assessment author, and your team’s timeline.
If you enabled comments, the peer can reply. Their replies land in the report as internal, staff-only notes (clearly marked as coming from an external peer) and are never shown to the researcher.
Expiry and Revocation
- Links expire 7 days after they’re created.
- Closing a report (resolved, paid, or dismissed) revokes the links you’ve already shared. You can share it again afterward — handy when you dismiss a report as “out of scope” and want to forward it to the upstream vendor. The peer then sees a small “this report was closed” note so they know it’s a snapshot.
- You can revoke any share at any time from the share window — the peer loses access immediately.
When a Link Has Expired
A peer who opens an expired email invite no longer hits a dead end. After confirming the email the link was sent to, they can:
- Request a fresh link — as long as the report is still open, Kit emails a new 7-day link to that same address (never anywhere else). A revoked link can’t be self-renewed, and once a report is closed the peer can’t self-renew either — re-sharing a closed report stays your deliberate decision, so the peer only sees a notice to contact you.
- Request to join the team — the same request-to-join flow described below.
An expired “anyone with the link” link has no recipient to renew for, so it’s simply a dead end — create a new link from the share window if you still need one.
Seeing Who Opened a Report
External access is surfaced as a security signal, not a quiet “seen” receipt:
- The Active shares list in the share window shows each share — recipient (or “Anyone with the link”), status, view count, last-viewed time, and the country it was opened from.
- The report header shows a “Shared · N external viewers” chip (click it to open the share window).
- The report timeline records an External viewer opened this report event.
- The person who shared the link and the report’s assignee are notified the first time each new address opens it — a new address on the same link can signal forwarding.
Requesting to Join the Team
A peer who needs ongoing access can request to join your security team from the shared report. The request lands with your account admins alongside any other access requests; approving it sends a normal team invitation, and once accepted they become a full member with their own account — no more one-off links.
When you open the request, Kit shows you who’s asking (name, email, the country they requested from) and which report the share came from — so you can confirm you actually shared with this person before inviting them. Approve sends the team invitation; Dismiss silently drops the request (the requester is never notified).