Logo StartupKit
EN

Configuring Your Program

Step-by-step guide to all seven program settings tabs — scope, bounty matrix, SLAs, triage, payouts, spam, and security.txt.

Why It Matters

Good configuration is the difference between a credible VDP and a vague policy researchers ignore. Scope clarity protects your engineering team from off-topic reports, SLA targets keep your response times honest, and a well-defined bounty matrix sets researcher expectations before they submit.

Kit ships sensible defaults for every setting. You can go live immediately and tune later, but spending 15 minutes on configuration upfront will save you hours of misdirected triage.

Enabling VDP

Navigate to VDP to enable your program. Choose the Free tier to get started immediately, or the VDP Add-on ($49/mo) to unlock the full pipeline. You can upgrade anytime from Account Settings > Billing.

Once your program is created, navigate to VDP > Program Settings to configure it. Your program starts in Draft status — it will not accept reports until you set the status to Active.

General Tab

The General tab controls your program identity and disclosure policy.

Field Description
Program Name Displayed on your disclosure policy page and researcher portal
Status Draft, Active, or Paused — set to Active when configuration is complete
Disclosure Policy Rich text field pre-populated with safe harbor language. Supports formatting, links, and lists.
Prohibited Actions Actions researchers must not perform (e.g., social engineering, physical attacks, denial of service)

Keep your program in Draft while you configure the remaining tabs. Switch to Active only when you are ready to accept submissions.

Scope Tab

Scope defines what researchers should and should not test. Vague scope generates vague reports — be specific.

Field Description
In-Scope Targets Hosts, URLs, or IP ranges researchers should test (one per line). Example: app.yourcompany.com, api.yourcompany.com
Out-of-Scope Categories OWASP-style category exclusions (e.g., “Denial of Service”, “Physical Attacks”)
Excluded Vulnerability Types Specific vulnerability classes you will not accept (e.g., “Self-XSS”, “Missing rate limiting on non-critical endpoints”)

If you leave in-scope targets empty, all targets are implicitly in scope. This is rarely what you want. At minimum, list your primary application domains.

Kit uses the scope configuration to validate incoming reports automatically. Reports targeting excluded vulnerability types or out-of-scope categories are flagged before they reach your triage board.

Bounty Matrix Tab

VDP Add-on — This tab requires the VDP Add-on ($49/mo). Free programs operate as no-bounty VDPs.

The bounty matrix defines payout ranges for each severity tier. Amounts are displayed on your disclosure policy page so researchers know what to expect.

Severity Default Min Default Max
Super Critical $5,000 $10,000
Critical $1,500 $5,000
High $500 $1,500
Medium $150 $500
Low $50 $150
Informational $0 $0

Adjust these ranges to match your budget and risk tolerance. When a CVSS assessment is recorded on a report, Kit automatically suggests a bounty amount within the matching tier’s range.

Bounty Vote Visibility

Below the matrix, the same tab carries a vote visibility setting. It controls whether a bounty proposal’s tally — the running count, who voted which way, and any counter-amounts — is readable before a teammate has cast their own vote.

What colleagues see before they vote
Blind (default) The amount, who proposed it and why, plus how many responses are sealed and how many people are still pending. No stances, no names, no counter-amounts.
Live Everything, from the first vote onwards.

Blind is the default because the first number on screen anchors the ones after it. Pick live only if you deliberately want the room to see each other’s positions as they form. Either setting is saved with the rest of the tab and survives later tier edits; you can also change it by asking your connected AI assistant to reconfigure the program (see AI Integration).

SLAs Tab

SLAs define your team’s response time commitments. The SLA clock starts at report submission. Your dashboard shows each report’s status as on-track, at-risk, or breached.

Acknowledgment SLA applies to all severities uniformly — it is the maximum time from submission to first response. Default: 72 hours.

Resolution targets vary by severity:

Severity Default Resolution Target
Super Critical 24 hours
Critical 72 hours (3 days)
High 168 hours (1 week)
Medium 336 hours (2 weeks)
Low 720 hours (30 days)
Informational 720 hours (30 days)

Override any of these values to match your team’s capacity. Aggressive SLAs look good on paper but lose credibility if you routinely breach them. Set targets you can actually meet, then tighten them over time.

SLA indicators appear on each report card in the triage board:

  • On Track (green) — more than 25% of the SLA window remains
  • At Risk (yellow) — 25% or less of the SLA window remains (75% or more elapsed)
  • Breached (red) — the SLA deadline has passed

Triage Tab

Triage settings control how incoming reports are routed and processed.

Field Default Description
Default Assignee None Team member who receives new reports automatically. Set this to your primary security contact.
Escalation Severities Critical, Super Critical Severity tiers that trigger an escalation alert via email and Slack
Deduplication Enabled Flag potential duplicate reports before they reach your board
Require Retest Off Require researcher verification that a fix works before resolving
Max Appeals 3 Maximum number of appeals a researcher can file on a dismissed report

On-call rotation settings (mode, schedule, members, and auto-assignment) have their own dedicated page. See On-Call Rotation for details.

If you do not set a default assignee, new reports appear unassigned on the triage board. Your team can still pick them up manually, but assignment ensures nothing slips through the cracks.

An escalation posts a line in the report’s Slack thread and, once the report is validated, pages whoever is on call by Slack DM or email. Configure Slack integration under Account Settings > Integrations.

Payouts Tab

VDP Add-on — This tab requires the VDP Add-on ($49/mo). Free programs do not process payouts through Kit.

The Payouts tab configures how bounty disbursements are handled.

Field Default Description
Supported Payment Methods PayPal Select the methods you support: Bank Transfer, PayPal, and Check
Require Tax Documents Yes Researchers must upload a W-9 (US) or W-8BEN (international) before receiving payout
Require Agreement Yes Researchers must accept your disclosure agreement before payout
Minimum Payout $50 Researchers below this threshold are batched until cumulative earnings reach the minimum
Currency USD Currency for all bounty amounts and payouts
Finance Email Blank The inbox that schedules payments. When set, initiating a payout emails it a payment request with a secure link where finance confirms the payment — or reports that it failed — without a Kit account. Leave blank to record payments yourself. See Finance Team Confirmation

Tax document requirements exist for your legal compliance. Disabling this setting means researchers can receive payouts without providing tax documentation — consult your finance team before turning it off.

Spam Tab

Spam settings protect your program from submission flooding and low-quality bulk reports. They measure a burst — reports arriving close together — not a researcher’s total history with you.

Field Default Description
Max Reports per Window 5 How many reports one email address or IP can file inside a single window before it is blocked
Window Duration 5 minutes The window, measured from the report that opened it. A report arriving after it closes opens a fresh one and resets the counter
Block Duration 1 hour How long an automatic block lasts. Blocks applied by hand from the Spam Records screen always run one week

The defaults are conservative. If legitimate researchers are getting blocked, raise Max Reports per Window or shorten the Window so their reports fall into separate windows. If you are receiving heavy spam, lower the threshold and lengthen the Block Duration.

A blocked submitter sees a deliberately non-specific notice — Kit does not tell an abuser which filter caught them. Blocks lift on their own when the Block Duration expires, and a researcher who stops submitting for the length of your window is un-blocked on their next report. You can also see and release any block from VDP > Spam Records.

See Submission Limits and Spam Blocks for the full picture — every gate a submission passes, how to read a spam record, and what to tell a researcher who was refused.

security.txt Tab

This tab configures the fields used to generate your /.well-known/security.txt file per RFC 9116. Kit serves this file automatically when your program is active.

Field Default Description
Contact Email None (required) The email address researchers use to report vulnerabilities. Published in the Contact: field.
Expiration 365 days Days from generation until the security.txt expires. RFC 9116 requires an Expires: field.
Policy URL Auto-generated URL to your disclosure policy page. Defaults to your Kit-hosted policy.
Acknowledgments URL None URL to your Hall of Fame page, if enabled
Hiring URL None Link to your security team’s job postings
Encryption URL None URL to your PGP public key for encrypted communication

You must set a contact email before your security.txt will be served. For full details on security.txt configuration, formatting, and verification, see security.txt Setup.

Email Branding

Researcher notification emails automatically use your account’s branding – logo, primary color, and program name as the sender. Configure these in Account Settings > Branding. No additional VDP-specific setup is required. See Communicating with Researchers for details.

Quick Checklist

  • Set program name and customize disclosure policy text
  • Define in-scope targets and out-of-scope categories
  • Configure bounty matrix (VDP Add-on) or acknowledge no-bounty program (Free)
  • Set SLA targets per severity tier
  • Assign a default triage owner
  • Configure payout methods and tax requirements (VDP Add-on)
  • Review spam thresholds — set them above the largest batch of real reports you’d want to receive at once
  • Set contact email for security.txt
  • Configure Slack integration for escalation alerts
  • Set status to Active when ready

Next Steps

Type to search...