Kit vs HackerOne: The crowd, or the paper trail.
HackerOne brings the researchers — its community page claims two million — and its free tier prints the attestation PDF your auditor asked for. Kit brings zero researchers. What it sells is the record of what happens next — a 72-hour acknowledgment clock, a CVSS v3.1 vector, an append-only ledger row. If your goal is finding vulnerabilities, HackerOne is the right category and Kit is not.
Who should choose what?
Choose Kit if you're:
- Proving you handle reports, not hunting for more of them
- A team with no AppSec budget putting the VDP on a GRC line
- Fine receiving only what finds you — Kit brings zero researchers
- Counting on the acknowledgment clock, the ledger and the exports
- Need intake live this week: security.txt, embedded form, anonymous reports
Choose HackerOne if you're:
- A funded security team with an AppSec budget line
- Want HackerOne's claimed two-million researcher community probing your scope
- Plan to buy managed triage so the inbox never reaches engineering
- Integrate reports into an existing security stack over the REST API
- A federal programme feeding BOD 20-01 metrics into CyberScope
- Comfortable with quote-based pricing and a private Order Form
What makes HackerOne special
HackerOne is famous for three things: the researcher community, a free attestation tier, and humans who triage for you.
Two million claimed researchers
HackerOne's community page claims 2M+ researchers and 500k+ bugs found — vendor figures, but a decade of accumulated supply either way. A programme listed there is discoverable by people already hunting for scopes to test, with reputation scores, Signal metrics and disclosure history attached.
Why this matters: A crowd is rented, never owned. Leave, and inbound drops to whatever finds your security.txt on its own. Kit brings zero researchers.
A free tier that prints the auditor's artifact
Essential VDP is free by contract text, and its launch announcement lists attestation reports as included: a PDF stating your programme exists, plus a per-asset CSV with median time to resolution and criticals open past 90 days. The docs name NIST 800-53 rev. 5 and FedRAMP, and say federal programmes may feed the CSV into CyberScope for BOD 20-01.
Why this matters: The exact artifact a SOC 2 auditor asks for, at $0. Any paid VDP — Kit included — has to justify itself on the working system, not the PDF.
Humans who absorb the inbox
Managed triage means someone else reads the firehose, kills duplicates and junk, asks the researcher for a working proof of concept, and hands your engineers a validated queue. Vendr estimates it adds 15–35% to total programme cost.
Why this matters: The labour is real. curl's public programme took 20 submissions in the first 21 days of 2026 — none a real vulnerability — and ended its HackerOne bounty that January. Debunking is work someone has to do.
What Kit does well
Four things Kit does differently for the researcher and the auditor — the people with no login.
A cap you can write into a control description
Kit's free-tier cap is a published constant: 25 reports a month on any paid seat. Essential VDP publishes no report, asset or user cap, and its terms let HackerOne change the limits at any time, at its sole discretion, without notice.
A SOC 2 control description needs a limit that stays put. You cannot cite a cap the vendor may redefine tomorrow.
security.txt that publishes itself
Kit serves RFC 9116 security.txt at /.well-known/security.txt on your domain, with a watchdog that alerts Slack 14 days before the expiry lapses. The intake form embeds on your own site and accepts anonymous reports.
A researcher who has never heard of Kit finds the channel exactly where RFC 9116 says to look.
The 72-hour acknowledgment clock
Every report starts an acknowledgment countdown — 72 hours by default, one window for every severity — flagged at-risk at 25% remaining and breached past zero, with MTTA and MTTR on a dashboard. Per-severity resolution targets are reported retrospectively.
An auditor asking how fast you acknowledge gets a number the system measured, not one reconstructed the week before the audit.
An append-only ledger a lawyer can read
Every bounty movement is a ledger row that cannot be edited once written, checked nightly for balance integrity, alongside collected W-9 and W-8BEN forms and the CVSS v3.1 vector on each report.
When the auditor asks who was paid what and when, the answer is ledger rows with dates on them.
What Kit doesn't have
Five things HackerOne does that Kit does not, and what we plan to do about each one.
Duplicate merge
HackerOne triage collapses duplicate reports. Kit flags likely duplicates by embedding similarity and shows a banner — it never merges them.
Will we add this? Maybe. The flag stays advisory for now; a merge that rewrites a report's timeline fights the append-only ledger.
A free tier with no subscription behind it
Essential VDP requires no subscription of any kind. Kit's free VDP tier is included with a paid Kit seat and caps at 25 reports a month — there is no free-account path to running a VDP in Kit.
Will we add this? No. The seat and the cap are how Kit's free tier stays a published number instead of a fair-use clause.
Managed triage
HackerOne sells humans who validate, deduplicate and severity-rate inbound reports for you. Kit's AI screening scores each submission and flags slop, but the report stays on your engineer's desk.
Will we add this? No. Kit is software; it will not staff a triage desk.
Researchers
HackerOne's community page claims two million researchers. Kit supplies none — your programme receives whatever finds your security.txt, your embedded form, and your inbound email.
Will we add this? No. Kit is not a marketplace and will not become one.
A REST API
HackerOne documents API v1 at api.hackerone.com/v1/ — reports, activities, state changes over HTTP. Kit ships 52 MCP tools and 11 webhook events, and no REST API.
Will we add this? Not soon. MCP and webhooks are Kit's integration surface; a REST API is not on the near-term roadmap.
Philosophy differences
These products answer different questions about what a VDP is for.
The record
Kit assumes the reports will find you — through security.txt, an embedded form, inbound email — and sells the record of what you did next. The clock, the ledger, the export. It is a $49-a-month line on a GRC budget, not an AppSec programme.
The marketplace
A two-sided marketplace: researchers on one side, funded security teams on the other, managed triage in between, and a free intake tier bolted on the bottom. If your goal is people finding vulnerabilities in your product, this is the category that does it — and Kit is not in it.
Pricing reality check
Kit
$49/month VDP add-on
$49/month on top of a $8/seat Kit subscription
- 25 reports a month included with any paid Kit seat
- Triage board, ledger, SOC 2 exports and custom domain in the add-on
- Self-serve 30-day add-on trial on any Kit seat
- Monthly billing, no annual commitment
- Price published on this page, in your currency
HackerOne
Essential VDP $0 — paid tiers quote-only
Free-tier limits changeable at HackerOne's sole discretion, without notice
- Essential VDP: $0, no subscription required
- Paid VDP: no published list price, sales quote only
- Estimates conflict: $8,000–12,000/yr (Penetrify, July 2026) vs $20,000–50,000/yr (Vendr, Feb 2026)
- Essential liability capped at $1,000, terminable without prior notice
- Managed triage adds an estimated 15–35% of programme cost (Vendr)
Pricing reality check
Essential VDP is free, and Kit cannot beat free. What $49 a month buys is terms you can plan against: a published 25-report cap and a self-serve exit. HackerOne's free tier may change your limits without notice and caps its liability to you at $1,000 — on the channel your regulator reads. When you outgrow Essential, the next step is a sales quote: $8,000–12,000 a year (Penetrify, July 2026) or $20,000–50,000 (Vendr, Feb 2026), estimates that never overlap.
Switching from HackerOne?
You'll love Kit if:
- An auditor asked you to prove a process exists, and the deadline is Friday
- Want the price and the report cap published before you talk to anyone
- Need the 72-hour acknowledgment clock running from day one
- Want security.txt at /.well-known on your domain and the intake form embedded in your own site
- Prefer a monthly line item you can cancel to a quote you have to request
Stay with HackerOne if you:
- Want researchers finding vulnerabilities, not only handling the ones that arrive
- Have budget for managed triage to absorb the inbound queue
- Build against the documented REST API
- Only need the free attestation PDF and accept Essential's terms as written
Data portability: HackerOne's docs describe self-service export to CSV, markdown and PDF plus the API — though the page predates Essential VDP, and on that tier the terms make exporting before termination your sole responsibility. Kit's SOC 2 exports ship with the add-on and run any day you ask, not only ahead of a termination you weren't warned about.
Try Kit free for 30 days.
Card up front, cancel anytime in the first 30 days. Nobody from sales will call you either way.
$49€49159 zł£39 per month, on top of a Kit seat
Start free trial