Logo StartupKit
EN

Stalled Report Nudges

How Kit reminds the owner of a vulnerability report that has gone quiet, and escalates to your program admins if it stays quiet.

Why It Matters

A report gets assigned, everyone means to get to it, and then a week passes. The SLA clock keeps running whether or not anyone remembers. Stalled report nudges close that gap: Kit watches assigned reports, reminds the owner privately when one goes quiet, and — only if that fails — tells your program admins.

What Counts as “Gone Quiet”

Kit checks every hour. A report is quiet when nobody on your team has done any of these since it was assigned:

  • Changed its status
  • Replied to the researcher
  • Added an internal note
  • Re-assessed its severity

Note

A message from the researcher does not count. Inbound mail isn’t your team acting — otherwise a chatty researcher could keep a forgotten report permanently un-nudged.

How Long Kit Waits

The wait scales with severity, derived from the resolution targets on your SLA settings. By default a report may idle 25% of its severity’s resolution target before the first reminder: a Critical report on a 48-hour target is nudged after 12 quiet hours, while a Low report on a much longer target waits days.

Two exceptions worth knowing:

  • A report nobody has assessed yet is measured against your acknowledgment window instead — it’s late on triage, not on remediation.
  • Reports assessed as Informational are never nudged. They’re real, but not worth pushing anyone about.

What the Owner Gets

One reminder, on one channel — never both:

  • A Slack DM, if their Slack account is connected to Kit.
  • Otherwise, an email.

Either way it carries the same four actions:

Action What it does
Snooze for 3 days Defers the reminders for three days
Snooze for 7 days Defers them for a week
I’m waiting on the researcher Moves the report to Needs Clarification, which stops your clock
Open the report Jumps straight to it in Kit

From the email, these work without signing in — the link itself is the authority, and it retires as soon as the report moves on: a new owner, a new status, or a snooze all end it. From Slack, the buttons act as you, so your Slack account has to be connected to your Kit account; if it isn’t, Kit says so and asks you to open the report instead.

If the next round of silence would escalate, the reminder says so before it happens.

Snoozing

Each owner gets two snoozes per stall by default. Once they’re spent, the reminders resume and Kit moves on to escalation instead. Any real activity on the report — a status change, an internal note, a reassignment — ends the stall and refills the budget.

Escalation to Admins

After the owner has been reminded and the report still hasn’t moved, Kit tells your program admins once, asking them to reassign it, take it, or check in with the owner.

Important

Admin escalation is the one message nobody can mute for themselves. It exists precisely because the private reminders already failed — a personal notification setting must not be able to sink it.

The Daily Digest

Lower-severity reports don’t send an individual reminder. They surface on your dashboard under Needs Attention and in a once-a-day summary email of everything waiting on you, sent at 9am in your own time zone.

Which severities take the quiet path is up to you (Quiet threshold, default High). At the default, Super Critical, Critical and High reports interrupt someone right away, while Medium and Low take the quiet path (Informational is never nudged at all). A report nobody has assessed yet is treated as urgent and nudges immediately — an unknown severity is not a reason to go quiet. Super Critical and Critical always send immediately, whatever the threshold is set to.

Where Stalls Show in Kit

  • A badge on the report itself: nudged, snoozed until a date, or escalated.
  • A Snooze menu in the report header, so you can defer without leaving the page.
  • A Stalled Reports row in Needs Attention on your VDP dashboard, which opens the filtered list — plus a one-click snooze on the row.

Settings

Admins configure this under Program Settings → SLAs, in the Response nudges section:

Setting Default
Send nudges On
Idle before the first nudge 25% of the resolution target
Hours between nudges 48
Nudges before escalating 2
Snoozes per stall 2
Escalate to program admins Yes
Quiet threshold High

Muting Your Own Reminders

Owner reminders are yours to pause; admin escalations are not.

  • Slack — turn off VDP report reminders under Settings → Slack Notifications.
  • Email — unsubscribe from Security program activity in your email preferences.
  • Holiday Mode also pauses routine reminders while you’re away.

Quick Checklist

  • Confirm your resolution targets are realistic — the nudge clock is derived from them
  • Decide your Quiet threshold: which severities are worth interrupting someone for
  • Leave Escalate to program admins on unless you have a reason not to
  • Ask your team to connect Slack so reminders arrive as DMs rather than email
  • Make sure open reports are actually assigned — an unassigned report is never nudged

Type to search...