Vulnerability Disclosure Overview
What Kit's VDP module is, who it's for, and what's included.
Why It Matters
Security researchers are already probing your systems. Unsolicited reports arrive via email, Slack, Twitter, and support tickets with no structure, no SLA tracking, and no audit trail. A Vulnerability Disclosure Program (VDP) organizes that influx instead of ignoring it.
Three converging mandates eliminate the “do nothing” option:
| Mandate | Requirement | Deadline |
|---|---|---|
| SOC 2 Type II (CC4/CC7) | Evidence of vulnerability monitoring and structured response process | Ongoing; auditors increasingly treat a formal VDP as standard evidence |
| EU Cyber Resilience Act (CRA) | Vulnerability reporting obligations for products with digital elements | September 11, 2026 |
| Cyber insurance carriers | Verifiable vulnerability management as a condition of coverage | Varies by carrier, tightening quarterly |
Kit’s VDP module gives your team a place to receive reports, track responses, and keep evidence for audits. The tools support your disclosure process; enabling them does not establish regulatory compliance.
The full VDP workflow is included with every Kit subscription. Configure your scope, response commitments, and payout process before publishing the program.
Who It’s For
| Persona | Goal | Primary Pain |
|---|---|---|
| Founder / CTO | Pass SOC 2 audit, unblock enterprise deals, comply with CRA | Reports scattered across security@ and other inboxes; missing response records; manual payout administration |
| Security Team Member | Efficiently assess, route, and close vulnerability reports | Context-switching between email, Slack, and Jira; no standardized severity scoring; SLA breaches invisible |
| Security Researcher | Get acknowledged quickly, communicate clearly, receive fair payment | Ghosting by program managers; 30-90 day payout cycles; opaque triage process |
All three personas interact with the same program. Each section of these docs is labeled for the relevant audience.
How It Works
- Configure: Open VDP > Program Settings and prepare your scope and program settings.
-
Publish: Set your program status to Active. Your submission form goes live and
security.txtis published automatically. Researchers discover you viasecurity.txtand your disclosure policy page. - Receive Reports: The structured intake form filters spam with a CAPTCHA and burst limits you control. Valid reports land in your triage board.
- Resolve: Triage the report, assess severity with CVSS v3.1, communicate with the researcher, fix the issue, and close the loop.
Program Statuses
| Status | Accepting Reports | Visible to Researchers | When to Use |
|---|---|---|---|
| Draft | No | No | Still configuring scope and policy |
| Active | Yes | Yes | Actively running your VDP |
| Paused | No | No | Temporarily suspending intake (e.g., during an incident) |
What’s Included
Every Kit subscription includes security.txt, the disclosure policy and intake form, unlimited reports, triage, CVSS, SLA tracking, team assignment, deduplication, on-call rotations, Slack, custom email templates, the researcher portal, metrics, Hall of Fame, bounty workflows, payout and tax-document collection, the immutable financial ledger, and SOC 2 evidence exports.
Quick Checklist
- Open your settings in VDP > Program Settings
- Review default scope and adjust in-scope/out-of-scope targets
- Publish your program (status → Active)
-
Verify
security.txtis served at/.well-known/security.txt -
Share your submission URL (
/security/{program-slug}/report) with your team so they know where reports go
Next Steps
- Configuring Your Program: scope, bounty matrix, SLAs, and all seven settings tabs
- security.txt Setup: RFC 9116 compliance, custom domains, and expiration management
- Navigate to VDP to enable your program