Feature comparison

Kit and GitHub: Vulnerability reports beyond the repo

GitHub private reporting keeps reports, patches and CVE requests with public repositories. Kit handles reports about the rest of your company, with response deadlines and bounty paperwork. You can use both.

Which fits your team?

Kit fits teams that need:

  • A company-wide report and response record
  • Intake for hosted products and private assets
  • Reports without GitHub accounts or names
  • Acknowledgment deadlines and breach records
  • Tax forms and a bounty ledger, with payments sent manually

GitHub fits teams that need:

  • Private reporting for public repositories
  • Free CVE requests
  • Private patch collaboration with reporters
  • Advisories that notify supported dependencies
  • REST access to the advisory queue
  • A free reporting channel beside the code

What GitHub does well

CVE requests, private patches and a report button on the repository.

Free CVE requests

An advisory admin can request a CVE from GitHub. The identifier stays private until publication; GitHub says review usually takes up to 72 hours.

In practice: Kit cannot reserve or issue a CVE.

Private patch collaboration

Add the reporter to an advisory and work on a patch in a temporary private fork. Publishing the advisory can trigger Dependabot alerts in supported ecosystems.

In practice: The report, fix and public advisory remain with the code.

A report button on the repository

Enable private reporting on a public repository so researchers can submit a vulnerability from its security page.

In practice: Researchers reading the code do not need to find a separate company portal.

What Kit includes

Each report gets a deadline and a reminder, so none sits unanswered while you ship. Kit brings no researchers or managed triage.

Reports without researcher accounts

The intake form accepts reports with or without an email address. Researchers who provide an email can open their reports through an email link.

Researchers can report a problem without creating a password or sharing their identity.

Bounty records and masked payout details

Kit requests payout details after a bounty is approved and masks the saved details for staff. Each award enters a ledger that prevents edits to existing entries.

You can trace the award and its paperwork. Your team still sends the payment.

Researchers see missing payout paperwork

The report page shows whether an agreement, tax form or payout details are missing. Researchers accept the recorded agreement by clicking a button. Rejected tax forms include a reason.

Researchers can complete the missing step from their own report page.

The next action on each report

Kit highlights the current step: Assignment, Assessment, Decision or Bounty. Moving a report backward requires a comment. Idle reports trigger reminders, then an escalation to admins.

The report shows what needs doing, and its owner cannot mute the final escalation.

What Kit doesn't have

Check these limits before choosing Kit.

A report button beside the code

GitHub puts the reporting button on the public repository a researcher is already reading. People must discover your Kit form through security.txt or a link you publish.

Will we add it? Kit will not provide a researcher community. Keep GitHub private reporting enabled.

CVE issuance

GitHub is a CVE Numbering Authority and reviews CVE requests for free. Kit cannot reserve or issue a CVE.

Will we add it? No. Use a CNA such as GitHub for CVE requests.

Private patch collaboration

GitHub provides temporary private forks for a maintainer and reporter to work on a fix. Kit tracks reports and syncs issues to Jira or Linear; it does not host patches.

Will we add it? No. Patches belong in your code repository.

An advisory REST API

GitHub documents REST endpoints for repository advisories. Kit's security queue uses MCP and webhooks, with no REST API.

Will we add it? A security REST API is not scheduled.

How each works

Keep repository disclosure on GitHub. Use Kit for reports that need a separate company process.

Kit

Company-wide intake and response

Every $8 Kit seat includes the Security workflow: intake, triage, SLAs, bounty records, and exports. Your team validates findings and handles any payouts.

GitHub

Report through patch and advisory

On a public repository, GitHub keeps the report, private patch, CVE request and advisory together. Publication can notify users through Dependabot in supported ecosystems.

Plans and costs

Kit

$8/seat/month

Security workflow included in the $8/seat/month Kit subscription

  • Security workflow included in every seat
  • 72-hour acknowledgment clock and a response-time dashboard
  • Anonymous intake with a durable receipt link
  • Append-only bounty ledger, W-9/W-8BEN collection
  • Hosted security.txt with its expiry date kept current

GitHub private vulnerability reporting

Free on public repositories

Private vulnerability reporting is free on public repositories

  • Free for public repositories on any GitHub plan
  • CVE request review at no charge
  • Temporary private forks for patches; CI is unavailable in those forks
  • Documented advisory REST endpoints
  • Dependabot alerts for supported dependencies

Source · Sep 2026

Plans and costs

Kit publishes its $8/seat/month price and includes the Security workflow. Your team handles triage and any bounty payments.

Adding Kit next to GitHub?

Consider Kit for:

  • Reports about a hosted product or private assets
  • Acknowledgment deadlines and recorded response times
  • Reports from people without GitHub accounts
  • Intake alongside GitHub Enterprise Server
  • A published security.txt and intake form

Stay with GitHub alone if:

  • Your reports concern public repositories on GitHub.com
  • You need CVE requests and advisories
  • Reporters help patch through private forks
  • You want Dependabot alerts for supported dependencies

Data portability: GitHub advisories are accessible through its REST API. Keep repository reports on GitHub and start Kit records for reports about other assets.

Run Security with Kit.

The Security workflow is included in every Kit seat.

$8

Get started free