Honest Comparison

Kit vs Intigriti: A researcher crowd, or a price you can read.

The researcher who finds your bug either comes from a crowd Intigriti recruits and pays, or walks in off your security.txt. Intigriti sells the crowd and the triage, priced on a scoping call. Kit brings zero researchers — it sells the intake form, the 72-hour acknowledgment clock, and the record your auditor reads.

Who should choose what?

Choose Kit if you're:

  • Answering an auditor who asked for proof of a disclosure process
  • Buying from the GRC budget without a sales conversation
  • Fine triaging your own inbound — Kit brings no researchers
  • After an acknowledgment clock and MTTA/MTTR numbers for the audit
  • A startup whose whole security team is two engineers

Choose Intigriti if you're:

  • An EU mid-market or enterprise security team with an AppSec budget
  • Trying to find vulnerabilities, not to document a process
  • After managed triage standing between researchers and your inbox
  • Able to absorb a reported ~$42.7k annual contract plus a bounty budget
  • In need of PTaaS, sprint programs or a live hacking event option
  • Bound by procurement to vendor ISO 27001

What makes Intigriti special

Intigriti sells three things Kit does not: a standing researcher community, validated findings, and a certified vendor posture.

150,000+ researchers, by their count

Intigriti's recruitment page reports 150K+ registered researchers and 400+ active programs — its own figures, checked August 2026. Researchers self-register, so supply stands ready without you recruiting anyone, and managed triage promises your team "fully validated vulnerabilities".

Why this matters: A VDP without a crowd only hears from whoever stumbles in. A crowd means someone is actively looking, and a triage team means your engineers read findings instead of noise.

A documented REST API in every package

OAuth 2.0, GET /v2/submissions down to proof of concept, impact, recommended fix, attachments and a CVSS vector, plus signed webhooks and a documented write surface. The API help article lists it across Starter, Core, Premium and Enterprise.

Why this matters: Pulling full report history into a data warehouse or GRC tool is a documented, connector-supported path — one Kit does not offer at all.

An EU vendor with certificates

Intigriti NV is Belgian, headquartered in Antwerp, and its companies page states it is "ISO 27001 and SOC 2 certified". A 2023 help article documents application-level encryption with purpose-specific subkeys rotated every 30 days.

Why this matters: When the security questionnaire asks about the vendor's own posture, Intigriti has paperwork to hand over. Kit does not.

What Kit does well

Four artifacts Kit ships that a scoping call cannot: a price, a file, a clock, a ledger.

A price on the pricing page

The VDP add-on price is printed on the pricing page, bills monthly with no annual commitment, and starts with a 30-day trial you begin yourself. Intigriti's three tiers each end in a Request-pricing button.

You can budget it, expense it and cancel it from the GRC line this week, without opening a sales cycle to learn the number.

security.txt publishes itself

Kit serves RFC 9116 security.txt at /.well-known/security.txt on your domain, watches its 14-day expiry window, and alerts your Slack before the file lapses.

The researcher with no login finds the right contact in the place RFC 9116 tells them to look, and the file never quietly expires.

A 72-hour acknowledgment clock

Every report starts an acknowledgment clock — 72 hours by default, one window for all severities — that flags at-risk in the last quarter of the window and pages your on-call. MTTA and MTTR fall out as dashboard numbers.

When the auditor asks how fast you respond, you read MTTA off the dashboard.

A ledger the audit can read

An append-only bounty ledger with a nightly balance check, W-9 and W-8BEN collection on a 3-year renewal clock, and compliance-evidence sync into Vanta.

What you paid, when you acknowledged, and who consented to be named in the hall of fame — each answer is an export, never a screenshot.

What Kit doesn't have

Four things Intigriti does that Kit does not, and what we plan to do about each one.

A researcher crowd and managed triage

Intigriti reports 150,000+ registered researchers — its own figure, on its own recruitment page — and validates findings before your team sees them. Kit brings zero researchers and performs zero triage. Your program receives what arrives through security.txt and the portal, and your engineers read every report.

Will we add this? No. Recruiting and paying a researcher community is a different business. If the goal is finding vulnerabilities rather than proving a process, buy Intigriti.

Researcher accounts and reputation

Intigriti researchers self-register, build reputation and carry an identity across programs. Kit has no researcher self-signup — an identity is minted from an email on first report, with magic-link login only.

Will we add this? Partially. Karma scoring and a consent-first hall of fame ship today; researcher self-signup and researcher SSO are not planned.

A REST API

Intigriti documents a company REST API with OAuth 2.0 — GET /v2/submissions returns full report bodies with proof of concept, impact, CVSS vector and attachments — and its product page says integrations come with every package. Kit ships MCP tools and webhooks, and no REST API.

Will we add this? Maybe. Webhooks, Jira, Linear, PagerDuty and Vanta cover today's hand-offs; a documented REST surface is under consideration, not scheduled.

Vendor certifications

Intigriti's companies page states it is "ISO 27001 and SOC 2 certified". Kit is a small Rails application on a single Hetzner server in Nuremberg, with no ISO 27001 and no SOC 2 report of its own.

Will we add this? SOC 2 is on our security roadmap. If procurement requires the vendor to hold a certificate today, Kit does not clear that gate.

Philosophy differences

Two different purchases wearing the same acronym.

Kit

The process, on a page

Publish the policy, receive the reports, run the clock, keep the record. Intake and 25 reports a month come with a $8 seat; the $49 add-on carries the triage board, ledger, bounties and custom domain. Bought self-serve, live the same afternoon.

Intigriti

Outcomes, sales-led

Put a researcher crowd and a triage team on your assets, scoped in a call, contracted from the AppSec budget. Intigriti is built for an EU security team that wants vulnerabilities found and validated, and its buyers accept a sales cycle as the price of that outcome.

Pricing reality check

Kit

$8/seat/month + $49/month VDP add-on

Both numbers are published on the pricing page; the add-on starts with a 30-day trial you begin yourself.

  • Intake portal and 25 reports a month included with a Kit seat
  • Add-on unlocks the triage board, ledger, bounties and custom domain
  • Anonymous submissions and an embeddable intake form
  • 72-hour acknowledgment clock with MTTA/MTTR reporting
  • Monthly billing, no annual commitment, cancel self-serve

Intigriti

Request pricing (all three tiers)

Every figure below the button is a third-party estimate — Intigriti publishes no number for any tier.

  • Core, Premium and Enterprise — each tier ends in a Request-pricing button
  • No free version and no free trial
  • Reported ~$42.7k average annual contract (Vendr estimate, Feb 2026)
  • Bounty rewards are a second, variable budget line
  • REST API and integrations included in every package

Pricing reality check

Intigriti publishes no price for any of its three tiers; Vendr, a buyer-side negotiation firm, estimates the average annual contract at roughly $42.7k, with reward budgets of $10,000–$400,000+ on top. Kit's numbers sit on its pricing page — $8 per seat and the $49 VDP add-on — and the evaluation needs nobody's calendar.

Switching from Intigriti?

You'll love Kit if:

  • An auditor asked you to prove you have a disclosure process
  • Have no AppSec budget, and a GRC line that can carry a monthly add-on
  • Need security.txt, a policy page and an intake form live before Friday
  • Your report volume is low enough for your own engineers to triage
  • Refuse to book a scoping call to learn a price

Stay with Intigriti if:

  • Want a standing researcher community — 150,000+ by Intigriti's own count — hunting your scope
  • Want findings validated before your engineers see them
  • Procurement requires the vendor to hold ISO 27001
  • Need a REST API that returns full report bodies

Data portability: Intigriti's API is a real exit path — full report history with proof of concept, CVSS vectors, events and payouts — though its batch CSV export deliberately omits PoC, impact, messages and attachments. What never exports is the crowd.

Try Kit free for 30 days.

Card up front, cancel anytime in the first 30 days. Nobody from sales will call you either way.

$49

Start free trial