Kit vs HackerOne: The crowd, or the working system.
HackerOne brings the researchers — its community page claims two million — and free Essential VDP launched with attestation reports included. Kit brings zero researchers. What it sells is the path a report walks after it arrives — a portal that tells the researcher what is blocking their payout, one highlighted next step for your engineer, and the same queue readable by the agent in your MCP client. If your goal is finding vulnerabilities, HackerOne is the right category and Kit is not.
Who should choose what?
Choose Kit if you're:
- Proving you handle reports, not hunting for more of them
- A team with no AppSec budget putting the VDP on a GRC line
- Fine receiving only what finds you — Kit brings zero researchers
- Counting on the acknowledgment clock, the ledger and the exports
- Need intake live this week: security.txt, embedded form, anonymous reports
Choose HackerOne if you're:
- A funded security team with an AppSec budget line
- Want HackerOne's claimed two-million researcher community probing your scope
- Plan to buy managed triage so the inbox never reaches engineering
- Integrate reports into an existing security stack over the REST API
- A federal programme feeding BOD 20-01 metrics into CyberScope
- Comfortable with quote-based pricing and a private Order Form
What makes HackerOne special
HackerOne is famous for three things: the researcher community, a free attestation tier, and humans who triage for you.
Two million claimed researchers
HackerOne's community page claims 2M+ researchers and 500k+ bugs found — vendor figures, but a decade of accumulated supply either way. A programme listed there is discoverable by people already hunting for scopes to test, with reputation scores, Signal metrics and disclosure history attached.
Why this matters: A crowd is rented, never owned. Leave, and inbound drops to whatever finds your security.txt on its own. Kit brings zero researchers.
A free tier that prints the auditor's artifact
Essential VDP is free by contract text, and its launch announcement lists attestation reports as included: a PDF stating your programme exists, plus a per-asset CSV with median time to resolution and criticals open past 90 days. The docs name NIST 800-53 rev. 5 and FedRAMP, and say federal programmes may feed the CSV into CyberScope for BOD 20-01.
Why this matters: The exact artifact a SOC 2 auditor asks for, at $0. Any paid VDP — Kit included — has to justify itself on the working system, not the PDF.
Humans who absorb the inbox
Managed triage means someone else reads the firehose, kills duplicates and junk, asks the researcher for a working proof of concept, and hands your engineers a validated queue. Vendr estimates it adds 15–35% to total programme cost.
Why this matters: The labour is real. curl's public programme took 20 submissions in the first 21 days of 2026 — none a real vulnerability — and ended its HackerOne bounty that January. Debunking is work someone has to do.
What Kit does well
Four things Kit does differently for the people in the loop: the researcher with no login, the engineer on triage duty, and the agent in your MCP client.
The researcher can see what blocks their payout
The payout form appears only once a bounty is approved, never speculatively. From there the researcher's own report page names what is missing — participation agreement, payout details, or tax document — and a rejected W-8BEN always carries a reason. The agreement is one click that records the exact text in force, a timestamp and an encrypted IP; staff see payout details masked, enforced inside the encrypted value itself.
A researcher who can see why the money is stuck fixes it. One who cannot writes you an email — or a blog post.
One current step per report, and the page names it
Every report computes exactly one current step — Assignment, Assessment, Decision, Bounty — with the locked ones disabled and the next action named on the page. A backward status move without a comment is refused, and a three-rung stall ladder ends in an escalation to admins that the report's owner cannot mute.
A stalled report cannot sit quietly on a busy engineer's desk. It nags twice, allows two snoozes, then goes over their head.
An acknowledgment clock that knows whose turn it is
Every report starts an acknowledgment countdown — 72 hours by default — flagged at-risk at 25% remaining and breached past zero, with MTTA and MTTR on a dashboard. Setting a report to Needs Clarification stops the clock and exempts it from stall nudges, so "waiting on the researcher" and "about to breach" are different states.
The auditor gets a number the system measured, and nobody gets paged over a report that is waiting on the researcher.
The triage playbook ships as slash commands
Your MCP client connects straight to the queue: 49 MCP tools, four server-side prompts that appear as slash commands — each names the ordered chain of tools to call, so nobody on your team writes the playbook — and an untrusted_fields list on every fetched report naming what the reporter controls.
Reading the queue is a two-minute connect. Acting on it is deliberately gated — write scope is a consent toggle shipped off, and an agent cannot email a researcher unless an admin enables direct send; the default saves a draft that emails nobody.
What Kit doesn't have
Five things HackerOne does that Kit does not, and what we plan to do about each one.
Duplicate merge
HackerOne triage collapses duplicate reports. Kit flags likely duplicates by embedding similarity and shows a banner — it never merges them.
Will we add this? Maybe. The flag stays advisory for now; a merge that rewrites a report's timeline fights the append-only ledger.
A free tier with no subscription behind it
Essential VDP requires no subscription of any kind. Kit's free VDP tier is included with a paid Kit seat and caps at 25 reports a month — there is no free-account path to running a VDP in Kit.
Will we add this? No. The seat and the cap are how Kit's free tier stays a published number instead of a fair-use clause.
Managed triage
HackerOne sells humans who validate, deduplicate and severity-rate inbound reports for you. Kit's AI screening scores each submission and flags slop, but the report stays on your engineer's desk.
Will we add this? No. Kit is software; it will not staff a triage desk.
Researchers
HackerOne's community page claims two million researchers. Kit supplies none — your programme receives whatever finds your security.txt, your embedded form, and your inbound email.
Will we add this? No. Kit is not a marketplace and will not become one.
A REST API
HackerOne documents API v1 at api.hackerone.com/v1/ — reports, activities, state changes over HTTP. Kit ships 49 MCP tools and 11 webhook events, and no REST API.
Will we add this? Not soon. MCP and webhooks are Kit's integration surface; a REST API is not on the near-term roadmap.
Philosophy differences
These products answer different questions about what a VDP is for.
The record
Kit assumes the reports will find you — through security.txt, an embedded form, inbound email — and sells the record of what you did next. The clock, the ledger, the export. It is a $49-a-month line on a GRC budget, not an AppSec programme.
The marketplace
A two-sided marketplace: researchers on one side, funded security teams on the other, managed triage in between, and a free intake tier bolted on the bottom. If your goal is people finding vulnerabilities in your product, this is the category that does it — and Kit is not in it.
Pricing reality check
Kit
$49/month VDP add-on
$49/month on top of a $8/seat Kit subscription
- 25 reports a month included with any paid Kit seat
- Triage board, ledger, SOC 2 exports and custom domain in the add-on
- Self-serve 30-day add-on trial on any Kit seat
- Monthly billing, no annual commitment
- Price published on this page, in your currency
HackerOne
Essential VDP $0 — paid tiers quote-only
Free-tier limits changeable at HackerOne's sole discretion, without notice
- Essential VDP: $0, no subscription required
- Paid VDP: no published list price, sales quote only
- Estimates conflict: $8,000–12,000/yr (Penetrify, July 2026) vs $20,000–50,000/yr (Vendr, Feb 2026)
- Essential liability capped at $1,000, terminable without prior notice
- Managed triage adds an estimated 15–35% of programme cost (Vendr)
Pricing reality check
Essential VDP is free, and Kit cannot beat free. What $49 a month buys is terms you can plan against: a published 25-report cap and a self-serve exit. HackerOne's free tier may change your limits without notice and caps its liability to you at $1,000 — on the channel your regulator reads. When you outgrow Essential, the next step is a sales quote: $8,000–12,000 a year (Penetrify, July 2026) or $20,000–50,000 (Vendr, Feb 2026), estimates that never overlap.
Switching from HackerOne?
You'll love Kit if:
- An auditor asked you to prove a process exists, and the deadline is Friday
- Want the price and the report cap published before you talk to anyone
- Need the 72-hour acknowledgment clock running from day one
- Want security.txt at /.well-known on your domain and the intake form embedded in your own site
- Prefer a monthly line item you can cancel to a quote you have to request
Stay with HackerOne if you:
- Want researchers finding vulnerabilities, not only handling the ones that arrive
- Have budget for managed triage to absorb the inbound queue
- Build against the documented REST API
- Only need the free attestation PDF and accept Essential's terms as written
Data portability: HackerOne's docs describe self-service export to CSV, markdown and PDF plus the API — though the page predates Essential VDP, and on that tier the terms make exporting before termination your sole responsibility. Kit's SOC 2 exports ship with the add-on and run any day you ask, not only ahead of a termination you weren't warned about.
Try Kit free for 30 days.
Card up front, cancel anytime in the first 30 days. Nobody from sales will call you either way.
$49€49159 zł£39 per month, on top of a Kit seat
Start free trial