Logo StartupKit
PL

Takedown Notices

Receive and act on third-party abuse reports — phishing and brand-impersonation complaints from CERT teams and abuse desks — alongside your vulnerability disclosure program.

Why It Matters

Not everything that arrives at a security program is a vulnerability report. If your platform hosts user content, sooner or later a CERT team or an abuse desk will contact you about a phishing page or a brand-impersonation site running on your infrastructure — and they will want it taken down urgently, with confirmation of exactly what you did and when.

These reports don’t fit a vulnerability disclosure form. There is no severity to score, no bounty to pay, and the reporter is not a researcher testing your scope — they are a third party asking you to remove abusive content. Takedown notices give this class of report its own intake path, its own lifecycle, and a closed loop back to the reporter’s team.

What a Takedown Notice Is

A takedown notice is a structured abuse report submitted through your public disclosure page. It captures who is reporting (the organization and a contact address), what kind of abuse it is — such as credential phishing or brand impersonation — where the offending content lives, and what action the reporter is requesting.

It is deliberately separate from vulnerability reports:

Vulnerability report Takedown notice
Who submits A security researcher A CERT team, abuse desk, or affected brand
What it describes A weakness in your systems Abusive content hosted on your platform
Severity and bounty CVSS assessment, bounty matrix Not applicable
Scope validation Checked against your program scope Any abuse claim about your assets is valid intake
Who acts on it Your triage team Whoever is on your notify list — no Kit login needed

Note

Reported URLs are treated as hostile. The addresses in a takedown notice point at attacker infrastructure. Kit stores and displays them as plain, inert text and never visits or fetches them on your behalf.

Enabling Takedown Notices

Takedown notices are opt-in and off by default. Enable them per program in your program settings, where you also configure the notify email list — the addresses that should hear about every new notice. Typical entries are your abuse desk alias, your trust-and-safety team, or the individual responsible for content removal.

Until you enable the feature, nothing changes: your public disclosure page shows only the vulnerability report form.

The Public Intake Form

Once enabled, your public disclosure page — the same page your security.txt points to — offers a second option alongside the vulnerability report form: reporting abuse for takedown. Reporters fill in their organization and contact details, classify the abuse, identify the offending content, and can attach supporting evidence.

The takedown form sits behind the same anti-spam protections as the vulnerability form. See Submission Limits and Spam Blocks for how those gates work.

When a notice comes in, every address on your notify list receives an email with a secure action link. That link is built for the reality of abuse response — the person who removes a phishing page is often not someone with a Kit seat:

  • No Kit login required. Anyone holding the link can act on the notice.
  • Valid for 14 days from when the notice is created.
  • Scoped to that single notice. The link grants access to nothing else in your account.

Opening the link shows the notice and exactly three actions:

Action What it does
Acknowledge Confirms your team has seen the notice and is on it
Mark action taken Records a short note describing what was done (e.g., “page removed, account suspended”) and resolves the notice
Reject Closes the notice as invalid or out of scope

Once a notice is resolved or rejected, the link becomes read-only — it shows the final state but allows no further changes, even before the 14 days are up.

Managing Notices from the Dashboard

Team members with a Kit login can see and manage all takedown notices from the Workflow section of the CSIRT dashboard. Each notice moves through a simple lifecycle — submitted, acknowledged, action taken, resolved — or is rejected, and every transition is recorded on the notice’s timeline, whether it was made by a logged-in teammate or through an email action link. That timeline is your answer when the reporting CERT asks for the exact action taken and its timestamp.

Quick Checklist

  • Enable takedown notices in your program settings
  • Add your abuse desk and trust-and-safety contacts to the notify email list
  • Confirm the abuse-report option appears on your public disclosure page
  • Agree internally on who acknowledges, who removes content, and who writes the outcome note
  • Review open notices periodically in the CSIRT dashboard’s Workflow section

Next Steps

Wpisz, aby wyszukać...