Honest Comparison

Kit vs Bugcrowd: A recruited crowd, or proof you handled what arrived.

Bugcrowd recruits researchers to your scope and, above its free tier, has staff validate every report before your engineers see it. Kit brings no researchers and no triage service. It receives what a security.txt and an intake form bring in, and it keeps the record an auditor asks to see.

Who should choose what?

Choose Kit if you're:

  • Answering an auditor who asked for proof of a disclosure process, with no AppSec budget
  • Handling the reports that arrive on their own — security.txt, scanners, walk-ins
  • Reading your own inbound and want it pre-flagged by slop screening and duplicate detection
  • Putting a published monthly price on a GRC line without a sales call
  • Live before Friday — the embeddable intake form drops into your own site on day one

Choose Bugcrowd if you're:

  • Trying to find vulnerabilities — a recruited crowd is the point, and Kit is the wrong category for that
  • Wanting reports validated and prioritised before your engineers see them
  • Standardising severity on the VRT's class-to-priority baseline with CWE and CVSS v4 mappings
  • Scripting against your report queue over a REST API
  • Expecting more inbound than 25 reports a month on a free tier
  • Comfortable with a 12-month contract and an unpublished renewal

What makes Bugcrowd special

Bugcrowd is known for three things: a recruited crowd with human triage, the VRT, and an uncapped free tier.

A crowd, then a human filter

Bugcrowd recruits researchers and routes them at your scope. From VDP Basic upward, staff validate and prioritise each report first — the tiers are sold as units of that labour, "Managed Triage for First 15 or 75 Submissions". Fully Managed adds Researcher Relations and a public-directory listing Bugcrowd markets as bringing "18x more submissions on average".

Why this matters: What reaches your engineers has already survived a human reading. Kit's AI slop screening shrinks the pile; it does not replace the reader.

The Vulnerability Rating Taxonomy

Named vulnerability classes map to P1 through P5, so two triagers rating a subdomain takeover agree without re-arguing CVSS vectors. Apache-2.0 on GitHub, with machine-readable CVSS v3, CVSS v4 and CWE mappings, maintained by a weekly internal VRT Council — v1.19.1 shipped July 2026.

Why this matters: Kit has a CVSS v3.1 calculator and no answer to this. Severity in Kit is per-analyst judgement defended with a vector.

Uncapped free intake and a real REST API

VDP Compliance takes unlimited submissions at no cost, self-managed. The documented API at api.bugcrowd.com ships token auth, role-scoped access, optional IP allowlisting and a 60-requests-per-minute-per-IP limit.

Why this matters: Two places Bugcrowd is plainly better than Kit: volume on the free tier, and a queue your scripts can read.

What Kit does well

Four things Kit does well, starting with the researcher who has no account.

A price on the pricing page

Kit's VDP add-on has a published monthly price, a 30-day trial, and no annual commitment. Bugcrowd's Basic figures are first-year rates for new customers paying upfront, and renewal pricing appears on none of the pages that carry the price.

A GRC line item you can approve without a sales call, and without a year-two surprise.

security.txt published for you

Kit auto-publishes an RFC 9116 security.txt at /.well-known/security.txt, with a 14-day expiry watchdog that alerts Slack before the file lapses.

The file researchers check first is live from day one and never silently expires.

The evidence layer in the box

An append-only bounty ledger with a nightly integrity check, SOC 2 evidence exports, Vanta sync, W-9/W-8BEN collection, and an MTTA/MTTR dashboard.

When an auditor asks how you handle disclosures, the answer is an export, not a slide.

A 72-hour acknowledgment clock

Every report starts a 72-hour acknowledgment window — one window, all severities — with at-risk alerts in the last quarter of the clock and an on-call rotation or PagerDuty schedule to catch them.

At-risk alerts fire with zero configuration; per-severity resolution targets are reported retrospectively.

What Kit doesn't have

Four things Bugcrowd does that Kit does not, and what we plan to do about each one.

A researcher crowd and managed triage

Bugcrowd routes a recruited researcher community at your assets and sells triage in units — the Basic tiers are literally "Managed Triage for First 15 or 75 Submissions". Kit recruits nobody and triages nothing on your behalf. AI slop screening and embedding-based duplicate flags shrink the pile, but a human on your team reads every report, and Kit flags duplicates without merging them.

Will we add this? No. This is structural. If you want someone else to read the reports, a managed vendor is the correct answer and Kit is not one.

Uncapped free intake

Bugcrowd's free VDP Compliance tier accepts unlimited submissions, self-managed. Kit's free tier caps at 25 reports a month, and it rides on a paid Kit seat rather than standing alone.

Will we add this? Unlikely. The cap is what lets the intake ride along with a seat at no extra charge.

A REST API

Bugcrowd documents a REST API at api.bugcrowd.com with token auth, role-scoped access and a 60-requests-per-minute-per-IP limit. Kit has no REST API — MCP tools and webhooks only, which suits an AI-agent workflow and does not suit a Python script against your report queue.

Will we add this? Maybe. MCP and webhooks ship today; a REST surface is not scheduled.

The VRT

Bugcrowd's Vulnerability Rating Taxonomy maps named vulnerability classes to P1–P5 and ships CVSS v3, CVSS v4 and CWE mappings as Apache-2.0 JSON, with v1.19.1 released July 2026. Kit has a CVSS v3.1 calculator, a fixed 13-value class list, and no CWE taxonomy or CVSS v4.

Will we add this? Possibly. The VRT is Apache-2.0, so adopting it is a licensing non-issue; nothing is scheduled.

Philosophy differences

These products answer different questions.

Kit

Prove you handled it

Kit assumes reports already arrive — off a security.txt, a scanner, a stranger's email — and sells the record of what happened next. An acknowledgment clock, an append-only ledger, evidence exports sized to an audit. A seat is $8; the full module is the $49 add-on. Nobody hunts on your behalf.

Bugcrowd

Bring researchers, meter the triage

Bugcrowd's premise is that finding vulnerabilities takes outside researchers and that reading their reports takes trained staff, so it sells both — a recruited community aimed at your scope, and triage metered in units of 15 or 75 submissions. If your question is who will find our bugs, that premise is right.

Pricing reality check

Kit

$8/seat/month + $49/month VDP add-on

$49/month on top of a $8 seat, cancel monthly

  • Intake, portal and receipts included with a Kit seat, capped at 25 reports a month
  • Triage board, 72-hour acknowledgment clock, ledger, bounty matrix and SOC 2 evidence exports in the add-on
  • 30-day trial of the add-on; billing starts only if you keep it
  • Cancel monthly; no 12-month contract
  • W-9/W-8BEN collection and bounty accounting in 7 currencies

Bugcrowd

Free self-managed tier; $299–$999/month Basic, first year only

Basic prices are first-year-only, paid upfront, new VDP customers only

  • VDP Compliance: free, self-managed, unlimited submissions, no managed triage
  • VDP Basic 15: $299/month first year — $3,588 as a 12-month AWS Marketplace contract
  • VDP Basic 75: $999/month first year — $11,988 for 12 months on AWS
  • Fully Managed: "Custom", and the CTA is Contact Us
  • Renewal pricing is not on the tier page, the quote page, or the AWS listing

Pricing reality check

Bugcrowd publishes real prices, which is rare in this category — but the Basic figures are first-year rates for new customers paying upfront, AWS lists both tiers as 12-month contracts, and renewal is not published on any of the pages that carry the price. Vendr's buyer data puts Bugcrowd's VDP fee band at $15,000–$40,000 a year, an estimate from real contracts rather than a list price. Kit's add-on is $49 a month on top of a $8 seat, cancel monthly.

Switching from Bugcrowd?

You'll love Kit if:

  • Self-managing every report on free VDP Compliance already, and the auditor wants more than a dashboard
  • You want year-two pricing in writing before signing year one
  • An auditor asked for evidence of your disclosure process by Friday
  • You asked what happens after triage submission 15 and the pricing page does not say
  • Your triage happens in Slack — report cards, appeal buttons, on-call pings

Stay with Bugcrowd if:

  • Managed triage absorbs a volume your team cannot read
  • Your programme's researcher reputation and public-directory listing matter — neither moves with you
  • You script against the REST API
  • You are inside a 12-month Basic contract

Data portability: Bugcrowd's REST API reaches your reports programmatically; bulk export is not covered on its API getting-started page. Kit's record starts with the next report that arrives.

A disclosure programme live before Friday.

The add-on trial runs 30 days and bills nothing unless you keep it. Nobody from sales will call you either way.

$49

Start free trial