Honest Comparison

Kit vs Intigriti: A crowd priced in a call, or a process priced on the page.

The researcher who finds your bug either comes from a crowd Intigriti recruits and validates, or walks in off your security.txt. Kit brings zero researchers. What it sells is the path a report walks after it arrives — one highlighted next step for your team, a blocking-item checklist for the researcher — at a monthly price printed on the pricing page rather than quoted in a scoping call.

Who should choose what?

Choose Kit if you're:

  • Answering an auditor who asked for proof of a disclosure process
  • Buying from the GRC budget without a sales conversation
  • Fine triaging your own inbound — Kit brings no researchers
  • After an acknowledgment clock and MTTA/MTTR numbers for the audit
  • A startup whose whole security team is two engineers

Choose Intigriti if you're:

  • An EU mid-market or enterprise security team with an AppSec budget
  • Trying to find vulnerabilities, not to document a process
  • After managed triage standing between researchers and your inbox
  • Able to absorb a reported ~$42.7k annual contract plus a bounty budget
  • In need of PTaaS, sprint programs or a live hacking event option
  • Bound by procurement to vendor ISO 27001

What makes Intigriti special

Intigriti sells three things Kit does not: a standing researcher community, validated findings, and a certified vendor posture.

150,000+ researchers, by their count

Intigriti's recruitment page reports 150K+ registered researchers and 400+ active programs — its own figures, checked August 2026. Researchers self-register, so supply stands ready without you recruiting anyone, and managed triage promises your team "fully validated vulnerabilities".

Why this matters: A VDP without a crowd only hears from whoever stumbles in. A crowd means someone is actively looking, and a triage team means your engineers read findings instead of noise.

A documented REST API in every package

OAuth 2.0, GET /v2/submissions down to proof of concept, impact, recommended fix, attachments and a CVSS vector, plus signed webhooks and a documented write surface. The API help article lists it across Starter, Core, Premium and Enterprise.

Why this matters: Pulling full report history into a data warehouse or GRC tool is a documented, connector-supported path — one Kit does not offer at all.

An EU vendor with certificates

Intigriti NV is Belgian, headquartered in Antwerp, and its companies page states it is "ISO 27001 and SOC 2 certified". A 2023 help article documents application-level encryption with purpose-specific subkeys rotated every 30 days.

Why this matters: When the security questionnaire asks about the vendor's own posture, Intigriti has paperwork to hand over. Kit does not.

What Kit does well

Four things Kit puts in writing: the researcher's checklist, the payout mechanics, your team's next step, and the price.

The researcher sees what's blocking their bounty

A researcher's report card shows which of the three is blocking them: participation agreement, payout details, or a tax document. The agreement is one click that records the exact text in force, a timestamp and an encrypted IP; a rejected W-8BEN always carries a reason; and one magic link shows every report they have filed to any program on Kit.

The person you owe money reads the hold-up off their own report card instead of emailing to ask.

The payout form waits for an approved bounty

The payout form appears only once a bounty is approved, never speculatively, and staff cannot read the saved details in full — masking is enforced inside the encrypted value, not by the page that displays it. When a payout bounces, Kit emails the researcher automatically for four of the five bounce causes, and an HMAC over the rail's fields distinguishes changed details from an identical re-save.

You collect bank details only from researchers you are paying, and even then your staff sees a masked value.

Exactly one next step, computed for you

The triage rail — Assignment, Assessment, Decision, Bounty — computes a single current step, disables the locked ones, and names the next action on the page. A backward status move without a comment is refused, and setting a report to Needs Clarification stops the acknowledgment clock — 72 hours by default — so waiting on the researcher and about to breach stay different states.

Whoever opens the report sees the same next action, and the stall ladder's third rung reaches your admins past any snooze.

A price on the pricing page

The VDP add-on price is printed on the pricing page and opens with a cardless 30-day trial. Intigriti's three published tiers each end in a Request-pricing button, and its fourth tier — Starter — surfaces only in an API help article, also unpriced.

The number the budget line needs exists before anyone books a call.

What Kit doesn't have

Four things Intigriti does that Kit does not, and what we plan to do about each one.

A researcher crowd and managed triage

Intigriti reports 150,000+ registered researchers — its own figure, on its own recruitment page — and validates findings before your team sees them. Kit brings zero researchers and performs zero triage. Your program receives what arrives through security.txt and the portal, and your engineers read every report.

Will we add this? No. Recruiting and paying a researcher community is a different business. If the goal is finding vulnerabilities rather than proving a process, buy Intigriti.

Researcher accounts and reputation

Intigriti researchers self-register, build reputation and carry an identity across programs. Kit has no researcher self-signup — an identity is minted from an email on first report, with magic-link login only.

Will we add this? Partially. Karma scoring and a consent-first hall of fame ship today; researcher self-signup and researcher SSO are not planned.

A REST API

Intigriti documents a company REST API with OAuth 2.0 — GET /v2/submissions returns full report bodies with proof of concept, impact, CVSS vector and attachments — and its product page says integrations come with every package. Kit ships MCP tools and webhooks, and no REST API.

Will we add this? Maybe. Webhooks, Jira, Linear, PagerDuty and Vanta cover today's hand-offs; a documented REST surface is under consideration, not scheduled.

Vendor certifications

Intigriti's companies page states it is "ISO 27001 and SOC 2 certified". Kit is a small Rails application on a single Hetzner server in Nuremberg, with no ISO 27001 and no SOC 2 report of its own.

Will we add this? SOC 2 is on our security roadmap. If procurement requires the vendor to hold a certificate today, Kit does not clear that gate.

Philosophy differences

Two different purchases wearing the same acronym.

Kit

The process, on a page

Publish the policy, receive the reports, run the clock, keep the record. Intake and 25 reports a month come with a $8 seat; the $49 add-on carries the triage board, ledger, bounties and custom domain. Bought self-serve, live the same afternoon.

Intigriti

Outcomes, sales-led

Put a researcher crowd and a triage team on your assets, scoped in a call, contracted from the AppSec budget. Intigriti is built for an EU security team that wants vulnerabilities found and validated, and its buyers accept a sales cycle as the price of that outcome.

Pricing reality check

Kit

$8/seat/month + $49/month VDP add-on

Both numbers are published on the pricing page; the add-on starts with a 30-day trial you begin yourself.

  • Intake portal and 25 reports a month included with a Kit seat
  • Add-on unlocks the triage board, ledger, bounties and custom domain
  • Anonymous submissions and an embeddable intake form
  • 72-hour acknowledgment clock with MTTA/MTTR reporting
  • Monthly billing, no annual commitment, cancel self-serve

Intigriti

Request pricing (all three tiers)

Every figure below the button is a third-party estimate — Intigriti publishes no number for any tier.

  • Core, Premium and Enterprise — each tier ends in a Request-pricing button
  • No free version and no free trial
  • Reported ~$42.7k average annual contract (Vendr estimate, Feb 2026)
  • Bounty rewards are a second, variable budget line
  • REST API and integrations included in every package

Pricing reality check

Intigriti publishes no price for any of its three tiers; Vendr, a buyer-side negotiation firm, estimates the average annual contract at roughly $42.7k, with reward budgets of $10,000–$400,000+ on top. Kit's numbers sit on its pricing page — $8 per seat and the $49 VDP add-on — and the evaluation needs nobody's calendar.

Switching from Intigriti?

You'll love Kit if:

  • An auditor asked you to prove you have a disclosure process
  • Have no AppSec budget, and a GRC line that can carry a monthly add-on
  • Need security.txt, a policy page and an intake form live before Friday
  • Your report volume is low enough for your own engineers to triage
  • Refuse to book a scoping call to learn a price

Stay with Intigriti if:

  • Want a standing researcher community — 150,000+ by Intigriti's own count — hunting your scope
  • Want findings validated before your engineers see them
  • Procurement requires the vendor to hold ISO 27001
  • Need a REST API that returns full report bodies

Data portability: Intigriti's API is a real exit path — full report history with proof of concept, CVSS vectors, events and payouts — though its batch CSV export deliberately omits PoC, impact, messages and attachments. What never exports is the crowd.

Try Kit free for 30 days.

Card up front, cancel anytime in the first 30 days. Nobody from sales will call you either way.

$49

Start free trial