Logo StartupKit
EN

Vulnerability Disclosure Overview

What Kit's VDP module is, who it's for, and what's included.

Why It Matters

Security researchers are already probing your systems. Unsolicited reports arrive via email, Slack, Twitter, and support tickets with no structure, no SLA tracking, and no audit trail. A Vulnerability Disclosure Program (VDP) organizes that influx instead of ignoring it.

Three converging mandates eliminate the “do nothing” option:

Mandate Requirement Deadline
SOC 2 Type II (CC4/CC7) Evidence of vulnerability monitoring and structured response process Ongoing; auditors increasingly treat a formal VDP as standard evidence
EU Cyber Resilience Act (CRA) Vulnerability reporting obligations for products with digital elements September 11, 2026
Cyber insurance carriers Verifiable vulnerability management as a condition of coverage Varies by carrier, tightening quarterly

Kit’s VDP module gives your team a place to receive reports, track responses, and keep evidence for audits. The tools support your disclosure process; enabling them does not establish regulatory compliance.

The full VDP workflow is included with every Kit subscription. Configure your scope, response commitments, and payout process before publishing the program.

Who It’s For

Persona Goal Primary Pain
Founder / CTO Pass SOC 2 audit, unblock enterprise deals, comply with CRA Reports scattered across security@ and other inboxes; missing response records; manual payout administration
Security Team Member Efficiently assess, route, and close vulnerability reports Context-switching between email, Slack, and Jira; no standardized severity scoring; SLA breaches invisible
Security Researcher Get acknowledged quickly, communicate clearly, receive fair payment Ghosting by program managers; 30-90 day payout cycles; opaque triage process

All three personas interact with the same program. Each section of these docs is labeled for the relevant audience.

How It Works

  1. Configure: Open VDP > Program Settings and prepare your scope and program settings.
  2. Publish: Set your program status to Active. Your submission form goes live and security.txt is published automatically. Researchers discover you via security.txt and your disclosure policy page.
  3. Receive Reports: The structured intake form filters spam with a CAPTCHA and burst limits you control. Valid reports land in your triage board.
  4. Resolve: Triage the report, assess severity with CVSS v3.1, communicate with the researcher, fix the issue, and close the loop.

Program Statuses

Status Accepting Reports Visible to Researchers When to Use
Draft No No Still configuring scope and policy
Active Yes Yes Actively running your VDP
Paused No No Temporarily suspending intake (e.g., during an incident)

What’s Included

Every Kit subscription includes security.txt, the disclosure policy and intake form, unlimited reports, triage, CVSS, SLA tracking, team assignment, deduplication, on-call rotations, Slack, custom email templates, the researcher portal, metrics, Hall of Fame, bounty workflows, payout and tax-document collection, the immutable financial ledger, and SOC 2 evidence exports.

Quick Checklist

  • Open your settings in VDP > Program Settings
  • Review default scope and adjust in-scope/out-of-scope targets
  • Publish your program (status → Active)
  • Verify security.txt is served at /.well-known/security.txt
  • Share your submission URL (/security/{program-slug}/report) with your team so they know where reports go

Next Steps

Type to search...