Feature comparison

Kit and Open Bug Bounty: Reports and your response

Open Bug Bounty verifies submissions and notifies site owners for free, under its disclosure timeline. Kit tracks how your team responds, including acknowledgment deadlines and bounty paperwork. It supplies no researchers.

Which fits your team?

Kit fits teams that need:

  • An owner and next action for each report
  • Evidence of their disclosure process
  • Intake for a wider range of report types
  • Acknowledgment deadlines and response metrics
  • Bounty paperwork for reports they handle themselves

Open Bug Bounty fits teams that need:

  • Outside researchers testing public websites
  • Free verification of supported report types
  • A public record of research findings
  • Direct discussions between owner and researcher
  • A service with an established disclosure timeline

What Open Bug Bounty does well

A researcher community, verification and public disclosure records.

Researchers testing public websites

Researchers submit issues they find on the web, including sites whose owners did not recruit them.

In practice: Kit provides an intake channel but no researchers to find vulnerabilities.

Verification before notification

Open Bug Bounty reproduces supported report types before emailing the owner. Its FAQ allows up to five days for XSS and ten for improper access control.

In practice: The owner receives a report that has had an independent review.

Public disclosure records

Public submissions have timestamped pages with CVSS scores and CWE classifications. Open Bug Bounty restricts removal of those records.

In practice: Researchers can point to a public record of their findings. Owners do not control that archive.

What Kit includes

Each report gets a deadline and a reminder, so none sits unanswered while you ship. Kit brings no researchers or managed triage.

Researchers see missing payout paperwork

The report page shows whether an agreement, tax form or payout details are missing. Researchers accept the recorded agreement by clicking a button. Rejected tax forms include a reason.

Researchers can complete the missing step from their own report page.

The next action on each report

Kit highlights the current step: Assignment, Assessment, Decision or Bounty. Moving a report backward requires a comment. Idle reports trigger reminders, then an escalation to admins.

The report shows what needs doing, and its owner cannot mute the final escalation.

An acknowledgment deadline

Reports start a 72-hour acknowledgment clock by default, with warnings as the deadline approaches. Needs Clarification pauses the clock and idle-report reminders.

The dashboard records response and resolution times for your team's reports.

Triage tools for your assistant

Connect an MCP client to read reports and use guided prompts for triage, assessment, bounty approval and postmortems. Write access requires consent and the appropriate role.

Researcher replies are saved as drafts unless an admin enables direct sending. Reporter text is marked as untrusted.

What Kit doesn't have

Check these limits before choosing Kit.

Disclosure deadlines

Open Bug Bounty permits disclosure 90 days after submission, or 30 days after patching. Kit has no disclosure timer or embargo date.

Will we add it? An embargo date may be added. Kit currently tracks acknowledgment deadlines.

Independent verification

Open Bug Bounty reproduces supported report types before notifying the owner. Its FAQ allows up to five days for XSS and ten for improper access control. Kit leaves reproduction to your engineers.

Will we add it? No. Kit will not provide report validation services.

A public disclosure archive

Public submissions receive timestamped pages on Open Bug Bounty. Kit's optional Hall of Fame belongs to your program and requires researcher consent.

Will we add it? A separate public disclosure archive is not planned.

A researcher community

Open Bug Bounty researchers submit issues they find on the web. Kit receives reports through the channels you publish and recruits no researchers.

Will we add it? No. You can keep using Open Bug Bounty alongside Kit.

How each works

Open Bug Bounty can find and verify a report. Kit can organize your team's response.

Kit

Your team's response record

Every $8 Kit seat includes the Security workflow: intake, triage, SLAs, bounty records, and exports. Your team validates findings and handles any payouts.

Open Bug Bounty

Verification and disclosure

Open Bug Bounty is a nonprofit that verifies supported reports and notifies owners. Researchers and owners then communicate directly. It does not handle bounty payments.

Plans and costs

Kit

$8/seat/month

Security workflow included in the $8/seat/month Kit subscription

  • 72-hour acknowledgment clock with at-risk and breach alerts
  • Append-only bounty ledger and exports for your own SOC 2 audit
  • security.txt, branded portal and embeddable form on your domain
  • Anonymous submissions with rate limits and spam screening
  • Slack triage buttons, on-call rotation, Jira and Linear sync

Open Bug Bounty

Free

Bounties are arranged and paid directly between the owner and researcher

  • Reporting and hosted programs are free
  • Supported report types verified before notification
  • Disclosure allowed after 90 days from submission or 30 days from patching
  • SQL injection and RCE reports directed to email

Source · Sep 2026

Plans and costs

Kit publishes its $8/seat/month price and includes the Security workflow. Your team handles triage and any bounty payments.

Using Kit alongside Open Bug Bounty?

Consider Kit for:

  • An owner and response deadline for each report
  • Evidence of your disclosure process
  • Intake for report types outside Open Bug Bounty's scope
  • Response and resolution metrics
  • On-call routing and Slack triage

Stay with Open Bug Bounty if:

  • Need free verification for supported report types
  • Handle follow-up directly with researchers
  • Accept its verification and disclosure timelines
  • Want to keep your claimed domain and public presence

Data portability: Open Bug Bounty does not delete disclosed submissions. Kit starts a record for incoming reports.

Run Security with Kit.

The Security workflow is included in every Kit seat.

$8

Get started free