Exporting Your Account Data
How to request, download, and understand a full export of your account data for compliance or portability, including a complete breakdown of VDP/CSIRT data categories.
Why It Matters
Data exports are useful for backups, audits, and migrating to other tools. GDPR Article 20 and CCPA govern individuals’ rights to their data. The account export described here is a product feature; its scope is defined by the categories and exclusions below.
Kit provides a one-click data export that packages the included records, files, and attachments into a single downloadable ZIP archive.
Who Can Request an Export
Only account administrators can request data exports. This protects sensitive hiring data, candidate information, and billing records from unauthorized access.
Non-admin team members will not see the Data Export option in account settings.
How to Request an Export
- Navigate to Account Settings in the sidebar
- Click Data Export
- Click Request Data Export
- Watch the progress bar as each data category is processed
- Once complete, click Download to get your ZIP archive
The export runs in the background, so you can navigate away and come back later. You’ll also receive an email when it’s ready.
What’s Included
The export contains more than 130 data categories covering your entire account:
| Category | What’s Included |
|---|---|
| Core | Account details, team members, invitations, settings, role-specific onboarding plans and checklist progress |
| Hiring | Job postings, closure outcomes, recorded hires, candidates, candidate profile links, applications, stages, submissions, submission-file identity, integrity, and extraction metadata, reviews, notes, interviews, interview invitations, offers, rejections, payouts, finance handoffs, tax-form metadata, candidate email threads and reply-resolution audit records, candidate channels, email triages, talent pool invitations, external-board distributions, selected Krisp meeting snapshots, and the human publication-confirmation audit trail (who approved and when) |
| Communication | AI chat history, SMS messages, email records, Slack messages, email unsubscriptions, and contextual reminders with their selected people, delivery choice, due date, and completion state |
| Integrations | Connection records for GitHub, Slack, Google Calendar, Google Meet, Krisp, Cloudflare, Stalwart, SMTP, MCP servers, OLX, Just Join IT/RocketJobs, PagerDuty, Vanta, exported as connection metadata only (which account/domain/channel, status, dates). The Just Join IT/RocketJobs record also includes the selected organization unit’s ID and name. Tokens and internal provisioning details are never included; personal OAuth profile claims are not stored. |
| Scheduling | Availability schedules, weekly hours, date overrides, meeting limits, calendar sources, meeting records |
| Outreach | Campaigns, templates, experiments, prospects, messages, delivery-attempt outcomes, audited delivery resolutions, replies and normalized chronological reply turns, suppressions, bounce events, tracking events |
| Vulnerability Disclosure | 20+ data categories: programs, reports, assessments, messages, bounties, disbursements, researchers, on-call shifts, and more. See full breakdown below. |
| AI & LLM | Credit limits, usage records |
| Billing | Customer records, subscriptions, charge history |
| Other | Ideas, webhooks, webhook delivery logs, custom domains, knowledge entries, API tokens |
Krisp exports are bounded. hiring_krisp_meetings.json includes each attached snapshot’s meeting metadata, selection settings, visibility, and importer, while the encrypted selected notes and transcript content are replaced with [REDACTED]. krisp_connections.json includes connection metadata such as the member and Krisp user, team, and workspace identifiers; the API key is never included.
hiring_carddav_connections.json includes the recruiter, CardDAV username, and last contact request time. The device password digest is never exported.
hiring_submission_files.json links each portfolio, work-sample, or application-form file to its submission and includes the attachment ID, extraction status, page count, SHA-256 digest, and timestamps. Extracted page text and extraction errors are encrypted and exported as [REDACTED]; the original file remains available under attachments/.
Attachments
All uploaded files are included in an attachments/ directory within the ZIP:
- Candidate resumes and portfolios
- Code assignment submissions
- File-based stage submissions
- Candidate and researcher tax forms (W-9/W-8BEN/W-8BEN-E)
- Any other uploaded documents
Attachment contents are not redacted. Redaction applies only to structured JSON fields. Uploaded files are copied byte-for-byte into the archive exactly as they were submitted. This includes candidate and researcher tax forms, which can contain unredacted tax identification numbers (see the VDP tax-document note below).
hiring_tax_documents.jsonandcsirt_tax_documents.jsoncontain the workflow metadata; the form itself is underattachments/. Treat the exported archive as containing sensitive personal data and store it accordingly.
Vulnerability Disclosure (VDP)
If your account has the VDP module enabled, the export includes a complete snapshot of your program’s history. This structured JSON export covers the categories below, subject to the documented redaction and exclusions. You can use it for migration, preserving data for legal proceedings, or long-term backup.
| JSON File | What It Contains |
|---|---|
csirt_programs.json |
Program configuration: name, slug, scope config, SLA targets, bounty matrix, portal config, activation date |
csirt_reports.json |
All submitted reports: title, description, severity, status, CVSS vector, vulnerability type, submission timestamp, screening flags |
csirt_status_transitions.json |
Complete status history for every report: who transitioned it, when, and from which status |
csirt_assessments.json |
Severity assessments: CVSS vector, computed score, severity tier, notes, assessor |
csirt_assignments.json |
Report assignment history: assignee, assigner, timestamp |
csirt_dismissals.json |
Dismissal records: reason code, notes, dismisser, timestamp |
csirt_appeals.json |
Appeal records: grounds, outcome, reviewer, timestamp |
csirt_agreements.json |
Researcher safe harbor agreement acceptances: version, accepted_at |
csirt_messages.json |
Full message threads: both researcher-facing and internal staff notes, with sender and timestamp |
csirt_message_templates.json |
Custom message templates for researcher communication |
csirt_report_shares.json |
Peer report-share invitations: recipient (email-redacted), share type, status, expiry, view count, last viewed (the encrypted recipient address is redacted) |
csirt_bounty_awards.json |
Approved bounty amounts, currencies, and notes |
csirt_disbursements.json |
Disbursement records: status, method, amount (transaction references redacted) |
csirt_ledger_entries.json |
Complete financial audit trail: entry type, amount, actor, timestamp |
csirt_researchers.json |
Researcher profiles: handle, email, reputation tier, karma score, report counts (payout info redacted) |
csirt_karma_events.json |
Karma change events: reason, delta, associated report |
csirt_ai_screenings.json |
AI screening results: confidence score, flags detected, recommendation, reasoning |
csirt_hall_of_fame_entries.json |
Hall of Fame credits: researcher, display name, note, link, credited date, featured status, and the consent behind the entry (which recognition the researcher agreed to, when they agreed, where the consent came from, and who recorded it) |
csirt_tax_documents.json |
Tax document metadata only: document type (W-9/W-8BEN), review status, verification date, rejection reason. There is no tax-ID field in this record; the identification number lives only inside the uploaded form file, which is exported separately as an attachment (see note below). |
csirt_on_call_shifts.json |
On-call rotation history: who was on call, start/end times, source (manual/rotation) |
Redacted VDP fields (replaced with [REDACTED]):
-
researcher.payout_info: Bank account details, routing numbers, account holder names -
disbursement.transaction_reference: External payment processor transaction IDs
Note on tax documents: There is no
tax_idfield anywhere in the export data. A researcher’s tax identification number exists only inside the W-9/W-8BEN form they upload, which is stored as a file attachment. On export,csirt_tax_documents.jsoncarries only metadata (document type, status, dates); the uploaded form file itself is copied as-is, unredacted, intoattachments/csirt_tax_documents/<id>/. If you need to hand off an export without the tax identifiers, remove that attachment directory before sharing the archive.
Excluded from VDP export entirely:
-
csirt_researcher_events: IP addresses, user agents, and browser fingerprints logged during researcher portal sessions. These are an internal audit trail, not your data to export. -
csirt_spam_records: Kit’s anti-abuse blocklist holding the email addresses and IPs of submitters flagged as spam. This is third-party data Kit keeps to protect your program, not your own data. -
csirt_disbursement_readinesses: Internal timing markers used to recognize stale payout requests and invalidate superseded notifications. They are derived from the exported bounty, report, and program configuration rather than authored account data. -
csirt_update_request_email_batchesandcsirt_update_request_email_deliveries: Internal batching and delivery records for staff email notifications. Researcher update requests remain incsirt_update_requests.json; their internalemail_batch_idis omitted.
What’s Excluded or Redacted (all categories)
For security and compliance, certain data is handled specially across the entire export:
| Treatment | Examples |
|---|---|
Redacted (replaced with [REDACTED]) |
OAuth tokens, API keys, signing secrets, refresh tokens, magic link tokens, researcher payout info, disbursement transaction references. Redaction applies to structured JSON fields only, not to file attachments (see Attachments). |
| Reduced to metadata | Integration connections export only customer-facing details (provider, connected account/domain/channel, status, dates, and the selected Just Join IT/RocketJobs organization unit’s ID and name). Personal OAuth profile claims are not stored. Internal provisioning state (Cloudflare worker/zone wiring, Stalwart DKIM keys, SMTP/IMAP sync and health columns, webhook channel IDs) is left out. |
| Excluded entirely | Payment methods (PCI compliance), encrypted passwords, OTP secrets, candidate-specific task preparation values and rendered credential briefs, candidate submission-file MCP access ledger, researcher event logs (IP/user-agent audit trail), anti-abuse spam blocklist (third-party PII), internal notification-delivery ledgers, and Outreach queue claims, recovery leases, and confirmation digests |
Job posting exports include the date a team member confirmed that recruiting should continue. Internal inactivity-reminder delivery records and calculated activity timestamps are excluded.
The candidate submission-file MCP access ledger is excluded as internal security telemetry. Account administrators can inspect it on the application in Kit, but it is not copied into the account export.
For Outreach, outreach_delivery_resolutions.json includes each decision’s message, delivery attempt, outcome, origin, retained resolver attribution, and timestamps. The decision remains if its resolver is later erased, with resolved_by_id set to null. Its optional free-form note is encrypted and exported as [REDACTED] because it may contain recipient details copied from a mailbox.
Outreach reply bodies and sender addresses remain encrypted and export as [REDACTED]. outreach_replies.json still carries turn_timeline, a chronological archived/current/pending summary with each turn’s received timestamp, sentiment, and triage status.
Outreach reply-turn bodies, sender addresses, drafted response content, and quarantine payloads remain encrypted and export as [REDACTED]. outreach_reply_turns.json still carries portable chronology and outcome metadata: its parent reply, sequence, state, received/actioned/approved/sent timestamps, sentiment, triage status, response status, and quarantine reason. This reconstructs the conversation workflow without exposing message content. Transport fingerprints, source keys, projection markers, and internal work-claim fields are not exported.
Contextual reminders are exported in reminders.json, reminder_recipients.json, and reminder_completions.json. Their due date, time zone, email choice, linked Hiring or CSIRT record, selected team members, and completion state are included. Reminder text is encrypted and therefore appears as [REDACTED]; internal delivery generations, claims, and delivery timestamps are excluded.
Two Types of VDP Exports
Kit provides two distinct export mechanisms for VDP data. They serve different purposes. Knowing the difference prevents confusion at audit time.
| Account Data Export (this page) | SOC 2 VDP Export (Metrics and Exports) | |
|---|---|---|
| Purpose | Data portability, backup, migration | Auditor evidence, compliance reporting |
| Format | JSON (subject to the redaction and exclusions above) | CSV or PDF (formatted for auditors) |
| Scope | Complete program history, all 20+ data types | Filtered by date range, status, severity |
| Access | Account Settings → Data Export | VDP → Exports |
| Requires active Kit subscription | Yes | Yes |
| Best for | Migrating to HackerOne, legal hold, full backup | Quarterly SOC 2 CC4/CC7 evidence folders |
If your goal is to hand evidence to an auditor, use the SOC 2 VDP Export. If your goal is to move your data, keep a backup, or migrate to another platform, use the Account Data Export described on this page.
Archive Format
The ZIP archive contains:
-
manifest.json: Metadata about the export (account info, record counts, timestamp) -
One JSON file per data category: e.g.,
hiring_candidates.json,csirt_reports.json -
attachments/: Uploaded files organized by category and record ID
JSON was chosen because it’s universally readable, preserves data structure (including nested fields), and is widely supported by programming languages and data tools.
Download Window
- Archives are available for 24 hours after completion
- Download links expire after 1 hour; refresh the page to get a new link
- After 24 hours, the archive is automatically deleted from storage
- The export record itself is retained for audit purposes
Limits
- One export at a time: You cannot start a new export while one is in progress
- Processing time: Depends on account size; most accounts complete within a few minutes
- File size: Varies with the number of attachments; the record count and file size are shown after completion
If an Export Fails
Occasionally an export may fail due to a temporary issue. When this happens:
- The failure reason is displayed on the export card
- You’ll receive an email notification
- Request a new export. The previous failed export doesn’t block you
Quick Checklist
- You are an account administrator
- No other export is currently in progress
- You have access to the email address on your account (for the ready notification)
- You’ll download the archive within 24 hours of completion
- If migrating VDP data, verify researcher payout info was captured separately before export (it is redacted in the archive)
- If you need auditor-formatted evidence rather than a full backup, use VDP > Exports instead
See Also
- Metrics and Exports: SOC 2 evidence exports (CSV/PDF) filtered by date range and severity
- Bounties and Payouts: Financial ledger details that feed into both export types
- AI Integration: Using the AI agent to pull metrics and generate summaries before exporting