No security team? You've got a process and someone on call.
Researchers find your disclosure policy, file through your portal, and follow the status from one link, no account. The acknowledgment clock starts the moment a report lands; turn on auto-assign and it goes to whoever is on call. Fixing the bug is still yours.
A VDP is how your company handles vulnerability reports.
A Vulnerability Disclosure Program tells researchers what they can test and how to report a finding. Your team receives the report, assesses it, responds, and records the outcome.
Run it alongside hiring in the same Kit account, with your team, permissions, and audit records.
Know which obligations apply to your company.
SOC 2 Type II
Keep evidence of vulnerability monitoring and response. Agree the evidence your auditor needs for your controls.
EU Cyber Resilience Act
If you sell software products in the EU, you must report actively exploited vulnerabilities and severe product security incidents. A VDP supports intake; statutory reporting is a separate duty.
NIS2 Directive
Article 21 includes vulnerability handling and disclosure among risk management measures. Scope and deadlines depend on the national law that implements NIS2.
Cyber Insurance
Check which vulnerability handling records your insurer asks for. Requirements depend on the policy.
security@ collects reports. Nobody owns them.
An inbox can collect a report. Your team also needs ownership, deadlines, and a record of the response.
Show the history when an auditor asks.
Keep the report, severity assessment, response times, and resolution history together so you can show how your team handled it.
Answer security questionnaires with a link.
A published policy gives customers a link to your reporting process and tells them who handles incoming findings.
Intake is only part of the work.
A submission form is the first step. Someone still has to maintain deadlines, CVSS history, bounty records, and exports.
From report to resolution.
See how a researcher submits a report, follows its status, and talks to your team.
Report lifecycle
The form asks for the affected URL, reproduction steps, and proof-of-concept files.
Triage happens in one thread, with the researcher in the loop at every reply.
Researchers can check each report's status, severity, and bounty.
Scope, safe harbor, and response targets published on your portal.
Why it works this way
Branded portal
Your logo and your disclosure policy, on your own domain once you connect one. The researcher never sees a Kit login.
Structured reports
Read the title, vulnerability type, affected URL, reproduction steps, and attachments in dedicated fields.
Full lifecycle tracking
Reports flow from submission through triage to resolution. Full status history, SLA timers, and audit trail at every step.
Open your disclosure program.
Three steps from setup to a triaged report.
Turn on Security
Set up your program under Security in Kit. Your disclosure policy and security.txt go live on your Kit portal right away. Add a custom domain, or point yourcompany.com/.well-known/security.txt at the portal file.
Receive a structured report
Researchers use your branded form to submit the affected URL, description, and reproduction steps.
Triage and document the response
Use the included kanban board, response deadlines, bounty records, and evidence exports for your SOC 2 audit to manage what happens next.
Everything from security.txt to the bounty ledger.
Publish your policy, collect structured reports, and run triage with SLA timers, bounty records, and audit exports.
security.txt + disclosure policy
An RFC 9116 security.txt goes live on your Kit portal with your disclosure policy. Add a custom domain to serve it at /.well-known/security.txt, or redirect your main domain's file to it. Expiration alerts keep it current.
Structured intake form + CAPTCHA
Collect the title, vulnerability type, affected URL, description, reproduction steps, and attachments in separate fields. Your team adds the CVSS score during triage.
AI spam screening
Use CAPTCHA and rate limits at intake. AI screening flags suspected spam and invented code paths with reasons for review, using your included AI allowance.
Invite-only mode
Run a private program with invite-only access. Share secure invite links with trusted researchers. Pending access requests appear in your sidebar.
Custom domain portal
Run your security portal on security.yourcompany.com. A researcher never leaves your domain to file a report.
EU-hosted infrastructure
Core vulnerability records are stored on Hetzner in Germany. Connected services and model providers process data under their own terms.
Kanban triage + CVSS v3.1 + SLA
Move reports from New to Triaged to Resolved with a timestamped history. The SLA timer starts when the report arrives.
Bounty records + evidence for your SOC 2 audit
Record an award, collect payout details and tax documents, and give finance a confirmation page. Awards and adjustments go into an append-only ledger you can export.
Share a redacted report with an access log
Share a redacted report through a link bound to the recipient's email and expiring in 7 days. Each open records who accessed it, when, and from where.
On-call rotations + response deadlines
IncludedSet daily or weekly rotations, or sync a PagerDuty schedule. Set one acknowledgment deadline and a resolution target for each severity; critical reports default to 72 hours for resolution.
Slack integration
Run security reports from Slack.
Assign and acknowledge reports from a Slack card. Kit updates the card as the report changes and keeps its history in the thread.
Six actions your team can take without leaving Slack:
Assign to me
Take ownership from the channel the report landed in.
Acknowledge
Moves the report to Triaged and stops the acknowledgment SLA clock.
Accept or reject an appeal
Rule on a researcher's appeal from the appeal card itself.
Take it over
Claim a validated report from your component team's own channel.
Snooze 3 or 7 days
Quiet a stall reminder. Past the cap it escalates to your program admins.
Waiting on researcher
Pause reminders while waiting for the researcher's reply.
Each action requires a linked Slack identity and the same Kit permissions as the app. A matching email address alone does not grant access.
See how report threads work🟠 Stored XSS in invoice memo field
- Severity
- 🟠 High (CVSS 8.1)
- Status
- New
- Type
- Cross-site scripting
- Assignee
- Unassigned
- SLA
- Due Aug 11, 09:00 UTC
- Bounty
- —
👤 mira_k (trusted) · 4 valid reports
rpt_8kq2vd7m · Submitted Aug 8, 07:52 UTC · Acme VDP
Each report gets one card, updated as it changes, with the history in its thread. Cards contain no researcher email or access tokens. Opening a report checks your Kit permissions.
Alerts for the person on call
The on-call member gets alerts for new reports, escalations, SLA risk, breaches, and appeals. Kit sends a Slack DM, with email as the fallback. Each shift starts with a handoff brief and ends with a recap.
@Kit answers in the thread
Mention @Kit in a report thread to check duplicates, scope, severity, bounty benchmarks, and program metrics. It can save an internal note. It cannot contact a researcher, approve a bounty, or change the report's status.
Restricted reports never post
Restricted reports do not post to Slack. If you restrict a report after its thread exists, Kit deletes bot replies and replaces the card with a notice containing no title, report ID, or link.
Your policy and security.txt, ready in minutes.
Let an assistant prepare the triage work.
Ask your AI assistant about new reports, possible duplicates, severity history, and bounty status. It connects to Kit through MCP.
Tools for each triage step.
Tools cover screening, duplicates, severity, bounties, report sharing, and postmortems. Replies are saved as drafts by default. Program admins can enable direct sending.
Ask about your reports.
Tools use your account's reports and permissions.
Check a report against your source, in your own CI.
Run a triage agent in your own CI with your model and prompts. It checks the report against your source and returns severity, affected files, and reasoning. Kit stores that verdict; your source stays in your CI.
Intake to audit export, included in every seat.
Intake, triage, bounty records, and audit exports are included in every Kit seat.
Doing it yourself
Your team maintains the timers, tax forms, and exports.
Kit Security
Intake, triage, bounty ledger, and audit exports
Part of your Kit subscription, billed per team member.
- security.txt published for you
- Structured intake form + CAPTCHA
- Kanban triage + CVSS + SLA
- Evidence exports for your SOC 2 audit
Security and Compensation Research (beta) are included with Kit. Outreach is the only separately billed add-on.
Compare Kit with the tools on your shortlist.
Each comparison includes the capabilities Kit is missing.
See our own disclosure program.
We run our disclosure program on Kit's intake form, SLA timers, and triage board. Our security.txt and disclosure policy are public.
See our Trust CenterBefore you publish an address.
Do we need to offer bug bounties?
You can run a disclosure program without offering bounties. Publish your reporting channel and testing rules, then accept reports through the included intake form. Rewards are optional.
Won't this invite hackers to attack us?
A disclosure policy tells researchers what is in scope, which testing rules apply, and how to report a finding. You can start with an invite-only program if you want to work with a small group first.
Can I run a private, invite-only program?
Yes. Enable invite-only mode in Security Portal Settings and share the access link with trusted researchers. Other visitors see an access request form. Approve a request from the sidebar to send an invitation automatically.
How does Kit handle spam reports?
The intake form uses CAPTCHA and rate limits. Report screening then flags suspected spam with a confidence score and reasons. Your team can review those assessments.
What about AI-generated slop reports?
AI screening checks each report for signals such as fabricated CVEs, nonexistent functions, and copied template language. Each assessment includes a confidence score and reasons for review. Screening uses your included AI allowance; when the allowance runs out, reports wait unscreened until it resets. CAPTCHA and rate limits also protect the intake form.
What does Kit add beyond a submission form?
A form can collect reports. Every seat also gets SLA tracking, CVSS scores, researcher conversations, bounty records, tax document handling, and audit exports in one place.
We already use Vanta/Drata for compliance.
Keep using it for compliance management. Report intake and triage happen in Kit. Confirmed reports can sync to Vanta as vulnerability evidence, including resolution status. There is no Drata sync.
Why are hiring and security reports in one product?
Job applications and vulnerability reports both need a structured submission, an owner, a deadline, and a history of decisions. The same parts serve both, and we run our own disclosure program on them.
What happens when a real critical vulnerability comes in?
Whoever is on call gets an alert. Assign an owner, assess severity with CVSS v3.1, and discuss the report with the researcher in one thread. SLA timers track the deadlines, and the timeline can be exported for review.
Can my team triage reports from Slack, or is it notifications only?
Your team can assign and acknowledge reports, decide appeals, claim component reports, snooze reminders, and mark a report as waiting on the researcher. Each action checks the linked Slack identity and Kit permissions. Updates stay beneath one report card.
See how report threads workWhat about reports too sensitive for a Slack channel?
Restricted reports do not post to Slack. If an existing report becomes restricted, Kit deletes its bot replies and replaces the card with a notice containing no title, report ID, or link. On-call alerts still arrive by email without report details.
Can I hand my auditor a single document for an incident?
Yes. Export an incident dossier PDF with the executive summary, timeline, CVSS breakdown, postmortem, evidence manifest, and sign-off page.
What about HackerOne or Bugcrowd?
Intake, SLA timers, CVSS v3.1 scoring, a triage board, researcher messages, bounty records, and audit exports come with every Kit seat. Kit brings no researcher network. Compare the providers' current plans and the researchers you need before choosing.
See what the audit exports containIs my security data portable if I leave Kit?
Yes. The account export includes programs, reports, assessments, messages, bounties, disbursements, researcher profiles, and screening results as structured JSON. Request it in Account Settings, then download the archive within 24 hours of it being ready.
See what's included in a data exportGive the next report a place to land before it hits security@.
Intake, triage, response deadlines, bounty records, and audit exports come with every Kit seat. Your policy and security.txt go live on your Kit portal as soon as you set up the program.
Included in every seat
Open your disclosure program