Kit and Open Bug Bounty: Reports and your response
Open Bug Bounty verifies submissions and notifies site owners for free, under its disclosure timeline. Kit tracks how your team responds, including acknowledgment deadlines and bounty paperwork. It supplies no researchers.
Which fits your team?
Kit fits teams that need:
- An owner and next action for each report
- Evidence of their disclosure process
- Intake for a wider range of report types
- Acknowledgment deadlines and response metrics
- Bounty paperwork for reports they handle themselves
Open Bug Bounty fits teams that need:
- Outside researchers testing public websites
- Free verification of supported report types
- A public record of research findings
- Direct discussions between owner and researcher
- A service with an established disclosure timeline
What Open Bug Bounty does well
A researcher community, verification and public disclosure records.
Researchers testing public websites
Researchers submit issues they find on the web, including sites whose owners did not recruit them.
In practice: Kit provides an intake channel but no researchers to find vulnerabilities.
Verification before notification
Open Bug Bounty reproduces supported report types before emailing the owner. Its FAQ allows up to five days for XSS and ten for improper access control.
In practice: The owner receives a report that has had an independent review.
Public disclosure records
Public submissions have timestamped pages with CVSS scores and CWE classifications. Open Bug Bounty restricts removal of those records.
In practice: Researchers can point to a public record of their findings. Owners do not control that archive.
What Kit includes
Each report gets a deadline and a reminder, so none sits unanswered while you ship. Kit brings no researchers or managed triage.
Researchers see missing payout paperwork
The report page shows whether an agreement, tax form or payout details are missing. Researchers accept the recorded agreement by clicking a button. Rejected tax forms include a reason.
Researchers can complete the missing step from their own report page.
The next action on each report
Kit highlights the current step: Assignment, Assessment, Decision or Bounty. Moving a report backward requires a comment. Idle reports trigger reminders, then an escalation to admins.
The report shows what needs doing, and its owner cannot mute the final escalation.
An acknowledgment deadline
Reports start a 72-hour acknowledgment clock by default, with warnings as the deadline approaches. Needs Clarification pauses the clock and idle-report reminders.
The dashboard records response and resolution times for your team's reports.
Triage tools for your assistant
Connect an MCP client to read reports and use guided prompts for triage, assessment, bounty approval and postmortems. Write access requires consent and the appropriate role.
Researcher replies are saved as drafts unless an admin enables direct sending. Reporter text is marked as untrusted.
What Kit doesn't have
Check these limits before choosing Kit.
Disclosure deadlines
Open Bug Bounty permits disclosure 90 days after submission, or 30 days after patching. Kit has no disclosure timer or embargo date.
Will we add it? An embargo date may be added. Kit currently tracks acknowledgment deadlines.
Independent verification
Open Bug Bounty reproduces supported report types before notifying the owner. Its FAQ allows up to five days for XSS and ten for improper access control. Kit leaves reproduction to your engineers.
Will we add it? No. Kit will not provide report validation services.
A public disclosure archive
Public submissions receive timestamped pages on Open Bug Bounty. Kit's optional Hall of Fame belongs to your program and requires researcher consent.
Will we add it? A separate public disclosure archive is not planned.
A researcher community
Open Bug Bounty researchers submit issues they find on the web. Kit receives reports through the channels you publish and recruits no researchers.
Will we add it? No. You can keep using Open Bug Bounty alongside Kit.
How each works
Open Bug Bounty can find and verify a report. Kit can organize your team's response.
Your team's response record
Every $8 Kit seat includes the Security workflow: intake, triage, SLAs, bounty records, and exports. Your team validates findings and handles any payouts.
Verification and disclosure
Open Bug Bounty is a nonprofit that verifies supported reports and notifies owners. Researchers and owners then communicate directly. It does not handle bounty payments.
Plans and costs
Kit
$8/seat/month
Security workflow included in the $8/seat/month Kit subscription
- 72-hour acknowledgment clock with at-risk and breach alerts
- Append-only bounty ledger and exports for your own SOC 2 audit
- security.txt, branded portal and embeddable form on your domain
- Anonymous submissions with rate limits and spam screening
- Slack triage buttons, on-call rotation, Jira and Linear sync
Open Bug Bounty
Free
Bounties are arranged and paid directly between the owner and researcher
- Reporting and hosted programs are free
- Supported report types verified before notification
- Disclosure allowed after 90 days from submission or 30 days from patching
- SQL injection and RCE reports directed to email
Plans and costs
Kit publishes its $8/seat/month price and includes the Security workflow. Your team handles triage and any bounty payments.
Using Kit alongside Open Bug Bounty?
Consider Kit for:
- An owner and response deadline for each report
- Evidence of your disclosure process
- Intake for report types outside Open Bug Bounty's scope
- Response and resolution metrics
- On-call routing and Slack triage
Stay with Open Bug Bounty if:
- Need free verification for supported report types
- Handle follow-up directly with researchers
- Accept its verification and disclosure timelines
- Want to keep your claimed domain and public presence
Data portability: Open Bug Bounty does not delete disclosed submissions. Kit starts a record for incoming reports.
$8€6,9929,99 zł£5.99 per seat, per month
Get started free