Free Security Module

Your first vulnerability disclosure program. Live in 5 minutes.

Researchers are already probing your infrastructure. They have nowhere to report what they find. Kit publishes your security.txt, gives them a branded intake portal, and keeps a timestamped record for your auditor. Free to deploy.

EU-hosted security.txt live instantly 80% spam filtered $49/mo full triage

A VDP is how your company handles vulnerability reports.

A Vulnerability Disclosure Program is a formal, documented channel for security researchers to report bugs in your software. Think of it as a structured version of security@ email, with SLA tracking, CVSS scoring, and an audit trail. SOC 2 auditors, cyber insurers, and enterprise customers increasingly require one.

Kit already handles your candidate pipeline. Your VDP runs on the same infrastructure, the same audit trail, the same team.

Regulatory Deadlines

The window is narrowing.

Active now

SOC 2 Type II

CC7.1: auditors are flagging the absence of documented vulnerability monitoring programs.

September 11, 2026

EU Cyber Resilience Act

Article 14 requires vulnerability reporting for products with digital elements.

Active since October 2024

NIS2 Directive

Art. 21(2)(e) mandates VDP as one of ten required cybersecurity measures for essential and important entities. Fines up to EUR 10M or 2% of revenue.

Growing

Cyber Insurance

Cyber insurance underwriters are adding VDP to policy application questionnaires.

The problem with security@ email.

Every startup inherits the same broken workflow. Here's why it doesn't survive a SOC 2 audit.

Your auditor just asked about CC7.1

SOC 2 CC7.1 requires documented evidence of vulnerability monitoring. A Jira ticket isn't evidence. A timestamped audit trail is.

Enterprise deals blocked

Enterprise prospects send security questionnaires. "Do you have a VDP?" is now a standard question. Without one, the deal stalls at procurement.

Building it yourself costs a sprint

A form is an afternoon. The SLA clocks, CVSS history, bounty ledger, and audit export behind it are a quarter of backlog that never reaches the top.

From report to resolution.

Follow a single vulnerability report through the researcher's own portal — every step of the lifecycle, exactly as they see it.

Why it works this way

Branded portal

Your logo and your disclosure policy, on your own domain. The researcher never sees a Kit login.

Structured reports

Every report captures title, severity, proof-of-concept, and impact. No more parsing email threads.

Full lifecycle tracking

Reports flow from submission through triage to resolution. Full status history, SLA timers, and audit trail at every step.

From toggle to first report.

Three steps, none of them a procurement call.

1

Enable VDP

Toggle on the VDP module in your Kit settings. Your security.txt is published instantly at /.well-known/security.txt and your disclosure policy page goes live.

2

First report arrives structured

Researchers submit through a branded intake form on your custom domain. You see a clean report with CVSS score, not a forwarded email chain.

3

Upgrade when triage matters

Add the full triage module for $49/mo when you're ready for kanban boards, SLA tracking, bounty payments, and SOC 2 export.

Six free, four on the add-on.

The free six publish your program and structure what arrives. The add-on four run everything after a report lands: clocks, bounties, exports.

Free

security.txt + disclosure policy

RFC 9116-compliant security.txt auto-published at /.well-known/security.txt. Expiration alerts keep it current. Researchers know how to reach you.

Free

Structured intake form + CAPTCHA

No more freeform emails. Every report captures title, description, CVSS vector, proof-of-concept, and impact, structured from the start.

Free

Automated spam filtering

CAPTCHA and rate limiting stop the bots. AI-generated slop gets scored and flagged: fabricated CVEs, hallucinated code paths. More than 80% of the junk never reaches your queue.

Free

Invite-only mode

Run a private program with invite-only access. Share secure invite links with trusted researchers. Pending access requests appear in your sidebar.

Free

Custom domain portal

Run your security portal on security.yourcompany.com. A researcher never leaves your domain to file a report.

Free

EU-hosted infrastructure

Your vulnerability data never leaves the EU. Hosted on Hetzner in Germany. No US data transfers. No Schrems II concerns.

Add-on

Kanban triage + CVSS v3.1 + SLA

Move reports from New to Triaged to Resolved with full status history. The SLA clock starts when the report lands, not when someone notices it.

Add-on

Bounty pipeline + SOC 2 exports

Pay researchers via ACH/wire with 1099 tax handling. Every award, payout, and tax document is written to an append-only ledger, and exports as audit evidence in one click.

Add-on

Share a report, keep the chain of custody

Send a redacted report to an outside engineer via an email-bound link that expires in 7 days. Forwarded links don't work. Every open lands in an append-only access log: who, when, from where.

On-call rotations + per-severity SLAs

Add-on

Rotate who's on point daily or weekly, or sync your PagerDuty schedule. Every severity gets its own resolution clock — critical defaults to 72 hours — on top of the acknowledgment timer.

Slack integration

Run your VDP from Slack.

Notification-only Slack apps post a new message per event and send you to the browser to act. Kit posts one live card per report, keeps it current, and puts the next action on buttons your team can press.

Six actions your team can take without leaving Slack:

Assign to me

Take ownership from the channel the report landed in.

Acknowledge

Moves the report to Triaged and stops the acknowledgment SLA clock.

Accept or reject an appeal

Rule on a researcher's appeal from the appeal card itself.

Take it over

Claim a validated report from your component team's own channel.

Snooze 3 or 7 days

Quiet a stall reminder. Past the cap it escalates to your program admins.

Waiting on researcher

Pause reminders while the ball is in the researcher's court.

Every button re-authorizes before anything happens: the click must come from a Kit member with an affirmed Slack identity, then it passes the same permission check as the app. A matching email address alone confers nothing.

See how report threads work

One report, one message: Kit edits this card in place for as long as the report lives, and the history hangs in its thread. The card itself carries no researcher email, no share token, no presigned URL. Every button is a plain Kit link that re-authorizes whoever clicks it.

Paging that respects the pager

Five events page the on-call member — new report, escalation, SLA at risk, SLA breached, appeal — as a Slack DM, or email when Slack can't reach them. Exactly one channel per event, never both. Shifts open with a handoff brief and close with a recap of what happened on watch.

@Kit answers in the thread

Mention @Kit on a report thread and it reasons over the report with 13 read-only tools: duplicates, scope, severity, bounty benchmarks, program metrics. It has exactly one write: an internal note. It cannot message a researcher, approve a bounty, or change a report's state.

Restricted reports never post

A Slack channel is an audience, not a permission. So restricted reports post no card and no thread, ever. Restrict a report after its thread exists and Kit tombstones it: bot replies deleted, the root replaced with a neutral notice carrying no title, no id, no link.

One toggle publishes your security.txt.

44 MCP tools

An agent can read the whole queue. Only your team can answer a researcher.

Point an MCP client at your VDP and it reads the same queue your team does: new reports, duplicate candidates, severity history, bounty state.

Every triage step, as a tool.

44 tools cover the lifecycle: screening, duplicates, severity, bounties, shares, postmortems. Drafted researcher replies sit in Kit until someone on your team sends one.

Claude ChatGPT Gemini
Read the MCP integration docs

Ask it the way you'd ask a teammate.

Each request lands as one tool call against your own reports.

"Show me all High severity reports breaching SLA"
"Check report rpt_abc123 for duplicates and suggest severity"
"Draft a dismissal response — this looks out of scope"
"Approve a $500 bounty for the SQL injection report"
Your code never leaves your CI

AI triage that reads your codebase. Without Kit ever seeing it.

Kit hands each report to an agent running in your own CI, on your own model, with your own prompts. It checks the claim against your actual source — is this path really exploitable? — and sends back a verdict with severity, affected files, and reasoning. The code, the credentials, and the model stay on your side.

Runs in your CI, on your model Kit stores the verdict, never your source

$49/mo buys the clock, the ledger, and the export.

One column is what you would assemble. The other is what you would switch on.

Doing it yourself

security@ inbox (unstructured) $0
SLA clocks, CVSS history, ledger, exports You build it
Time to the first audit-ready report Weeks

Then someone owns the timers, the tax forms, and the export the week your auditor asks for it.

Live the day you turn it on

Kit VDP

Free to start

Full triage add-on, $49/mo

$588/yr, billed on top of your seats.

  • security.txt auto-published
  • Structured intake form + CAPTCHA
  • Kanban triage + CVSS + SLA (add-on)
  • SOC 2 audit exports (add-on)
EU-hosted

The triage add-on bills on top of a seat, alongside Outreach and Compensation. Kit has no all-in price.

We use what we ship.

We run our own disclosure program on Kit — same intake form, same SLA clock, same triage board. Our security.txt and disclosure policy are public; read them before you trust the rest of this page.

See our Trust Center

Before you publish an address.

We're too small for a bug bounty program.

A VDP isn't a bug bounty: you're not offering rewards. It's a documented, compliant channel for researchers to report vulnerabilities. SOC 2 Type II, cyber insurers, and enterprise customers increasingly require proof that you have one. Kit's free tier gives you exactly that, with no commitment to pay anything.

Won't this invite hackers to attack us?

Researchers are already looking. What a VDP changes is where the finding lands. Without published safe harbor terms, reporting to you is a legal risk, so a well-meaning researcher goes public instead. Publish the terms and they come to you first.

Can I run a private, invite-only program?

Yes. Switch your portal to invite-only mode in Security Portal Settings and Kit generates a secret access token. Share the invite URL directly with trusted researchers. It grants them a persistent session on click. Anyone else who visits the portal sees a short access request form instead of a dead end. Pending requests appear in your sidebar with a badge; one click approves the request and sends the researcher their invite link automatically.

We'll get flooded with spam and low-quality reports.

Kit's intake form runs CAPTCHA and rate limiting, then scores what survives for fabricated CVEs, hallucinated functions, and template language. More than 80% of the noise is filtered before it reaches your queue.

What about AI-generated slop reports?

Every incoming report is screened with a confidence score and named signals: fabricated CVEs, hallucinated functions, template language. Flagged reports are marked for review before they cost your team a minute. Combined with CAPTCHA and rate limiting, more than 80% of noise never reaches your queue.

We could just build a web form ourselves.

A form gets you intake. It doesn't give you SLA tracking, CVSS scoring, status history, researcher communication threads, bounty payments, tax document handling, or one-click SOC 2 export. Kit bundles all of that, so you spend an afternoon deploying it, not an engineering sprint building it.

We already use Vanta/Drata for compliance.

Perfect. Vanta and Drata track that you have a VDP. Kit runs it. Enable Kit's VDP, point your compliance tool at your published security.txt, and the box is checked with a real program behind it. On the add-on, Kit also syncs confirmed reports into Vanta as vulnerability evidence for SOC 2 CC7.1 and ISO 27001 A.8.8. Resolve a report in Kit and Vanta records it remediated on the next sync.

Why does an ATS company offer a VDP?

Kit started in hiring, but the machinery underneath is the same: structured intake, an SLA clock, an audit export. The VDP points it at a different queue. We run our own disclosure program on it.

What happens when a real critical vulnerability comes in?

When a critical report arrives, Kit notifies your team immediately. From there: you triage it, score it with CVSS v3.1, message the researcher in one thread, assign an owner, and run it against the SLA clock. When your auditor asks for evidence, the whole timeline exports.

Can my team triage reports from Slack, or is it notifications only?

Triage. Each report posts one live card that Kit edits in place, with the history hanging in its thread. From Slack your team can assign a report, acknowledge it (which stops the acknowledgment SLA clock), accept or reject an appeal, take over a component report, snooze a stall reminder, or mark it waiting on the researcher. Every click is re-authorized against the clicker's affirmed Slack identity and the same permission checks as the app.

See how report threads work
What about reports too sensitive for a Slack channel?

Mark a report restricted and it never posts to Slack: no card, no thread. A channel audience isn't a Kit permission, so nothing sensitive is ever left to channel hygiene. If a report becomes restricted after its thread exists, Kit tombstones the thread. Bot replies are deleted and the root message is replaced with a neutral notice carrying no title, no report id, and no link. On-call paging still fires so the SLA clock isn't orphaned, but by email only, with no report details in the alert.

Can I hand my auditor a single document for an incident?

Yes. Every report exports as an incident dossier PDF: executive summary, full timeline, CVSS breakdown, postmortem, evidence manifest, and sign-off page. One click, one file, ready for the audit binder.

What about HackerOne or Bugcrowd?

HackerOne and Bugcrowd both offer free submission forms. Kit's free tier does too. The difference is what happens after a report arrives: Kit adds SLA clocks, CVSS v3.1 scoring, kanban triage, a researcher thread, bounty disbursement, and SOC 2 exports for $49/mo on top of a seat. When you outgrow Kit, your whole program history exports as CSV or PDF — report summaries, CVSS scores, SLA performance, communication logs, and the financial ledger.

See how SOC 2 exports work
Is my VDP data portable if I leave Kit?

Yes. Kit's full account export packages every VDP record — programs, reports, assessments, messages, bounty awards, disbursements, researcher profiles, and screening results — into structured JSON. One click from Account Settings. You have 7 days to download the archive. Your security history is yours.

See what's included in a data export

Give the next researcher somewhere to send it.

No credit card required. security.txt published instantly. Upgrade when you need triage.

Free · no credit card

Enable VDP free