Kit vs Open Bug Bounty: Someone else's disclosure clock, or your own.
A researcher you never invited files an XSS against your site; Open Bug Bounty verifies it, emails you, and the 90-day disclosure clock started at submission. Kit brings zero researchers — it brings the intake, the acknowledgment deadline and the record you need once that email lands.
Who should choose what?
Choose Kit if you're:
- Holding an Open Bug Bounty notification and unsure who answers it
- Asked by an auditor to show a disclosure process, with evidence
- Running intake for SQL injection and RCE, the classes Open Bug Bounty routes to raw email
- Wanting an acknowledgment deadline your team owns, measured in MTTA and MTTR
- Trying to prove you handle the reports that arrive, not to find more of them
Choose Open Bug Bounty if you're:
- After free outside eyes on your public web surface — Kit brings zero researchers
- Fine with XSS and CSRF-class findings, verified for you at no cost
- A researcher building a portable, timestamped public record of finds
- Comfortable negotiating one-on-one with each reporter, with no deadline on either side
- Able to live with a disclosure clock the policy keys to submission, and an unsubscribe that stops the emails and nothing else
What makes Open Bug Bounty special
Three things Kit cannot match: a crowd that shows up unpaid, verification before you are contacted, and a public record nobody edits.
A crowd that arrives on its own
Its last archived counters, October 2025, self-report 69,256 researchers and 1,508,421 fixed vulnerabilities since 2014. Nobody recruits them — they scan the open web and file against whatever they find, your site included.
Why this matters: Kit brings zero researchers. A portal nobody visits is an empty pipeline, and Open Bug Bounty supplies the visitors for free.
Verification before notification
Open Bug Bounty reproduces each report before emailing the owner — up to 5 days for XSS, up to 10 for improper access control, by its own FAQ — so what reaches your inbox has survived a first pass.
Why this matters: Free first-pass triage from an unpaid third party. Scanner noise is filtered before it reaches a two-person security team.
A permanent public record
Every public submission gets a permanent, timestamped page, CVSS-scored and CWE-classified, on a process it models on ISO 29147. It states it never removes vulnerability records for political or business reasons.
Why this matters: That immutability is why researchers show up — and why you cannot delete a report about your own site. The researcher can, before disclosure; Open Bug Bounty deletes only as an ethics sanction.
What Kit does well
Four things Kit does for the owner who received the email.
The clock is yours
Every report starts an acknowledgment countdown — 72 hours by default — flagged at-risk in the last quarter of the window, alerted on breach, checked every 15 minutes. MTTA and MTTR fall out of the same timestamps.
Open Bug Bounty's 90-day clock runs from the researcher's submission. This one runs on your acknowledgment, and it is the one an auditor asks about.
security.txt, published for you
Kit auto-publishes RFC 9116 security.txt at /.well-known/security.txt, watches its 14-day expiry, and alerts Slack before it lapses.
A researcher who checks the standard location finds your intake before they find a clearing house.
A record that survives an audit
Backward status moves require a comment, the bounty ledger is append-only with a nightly integrity check, and SOC 2 evidence exports come out of the same rows.
Open Bug Bounty states it keeps no logs of owner or researcher activity and disclaims all warranties — there is nothing there to hand an auditor.
Intake for the severe classes
SQL injection and RCE come through the same form as everything else — anonymous if the researcher prefers, behind Turnstile, rate limits and AI slop screening.
Open Bug Bounty routes SQLi and RCE to raw email for hosted programmes, and offers no route at all for sites that never claimed one.
What Kit doesn't have
Four things Open Bug Bounty does that Kit does not, and what we plan to do about each one.
A coordinated-disclosure clock
Open Bug Bounty's policy sets an explicit clock — details may be disclosed 90 days after submission, or 30 once patched. Kit models no disclosure timers or embargo dates at all.
Will we add this? Maybe. An embargo-date field is a fair ask; today Kit tracks acknowledgment, not disclosure.
Verification done for you
Open Bug Bounty reproduces each report before it emails you — up to 5 days for XSS, up to 10 for improper access control, by its own FAQ — at no cost. Kit screens for AI slop and flags likely duplicates, but reproduction is your engineer's job.
Will we add this? No. The verdict on a report stays with a human in your account.
A neutral public archive
Every public Open Bug Bounty submission gets a permanent, timestamped page — portable discovery credit a researcher can show anyone. Kit's Hall of Fame is consent-first and lives inside your account.
Will we add this? No. A public record only works when the vendor can't edit it, and Kit is your vendor.
A researcher crowd
Roughly 69,000 researchers by its own October 2025 counters, filing against whatever they find on the open web. Kit ships zero researchers; a Kit portal receives only what walks in.
Will we add this? No. Kit will never recruit researchers. Keeping a free Open Bug Bounty presence next to Kit costs nothing.
Philosophy differences
These two are not rivals. One supplies researcher attention; the other supplies the process that attention lands on.
Your domain, your record
Kit assumes the reports are already coming; the job is proving what happens next. Intake on your own domain, a 72-hour acknowledgment deadline, an append-only ledger. Up to 25 reports a month ride on a Kit seat; the clocks, ledger and evidence exports are the $49 add-on.
Disclosure as a public good
A non-profit clearing house running since 2014. Researchers file against any site, Open Bug Bounty verifies and notifies, then steps back — it never brokers the exchange, never touches money, and says it never removes a vulnerability record for political or business reasons. The site owner is not the customer; the disclosure ecosystem is.
Pricing reality check
Kit
$49/month
add-on on top of a $8/seat/month Kit plan; 30-day trial
- 72-hour acknowledgment clock with at-risk and breach alerts
- Append-only bounty ledger and SOC 2 evidence exports
- security.txt, branded portal and embeddable form on your domain
- Anonymous submissions behind Turnstile, rate limits and AI slop screening
- Slack triage buttons, on-call rotation, Jira and Linear sync
Open Bug Bounty
$0 — a non-profit that charges nobody
Bounties go directly from you to the researcher — it handles no money; a hosted programme is expected to honour its own remuneration guidelines
- Reporting and hosted programmes free by policy — it never charges fees
- Independent verification before you are notified
- No contract, no DPA, no uptime commitment, all liability disclaimed
- Disclosure permitted 90 days after submission, 30 once patched
- SQL injection and RCE routed to raw email, outside the programme
Pricing reality check
Open Bug Bounty charges nobody and never has, so price is not the contest. Kit is paid either way: up to 25 reports a month ride on a $8/seat/month plan, card at checkout, and the $49/month add-on — which also stands alone — buys the acknowledgment clock, the ledger, bounties and the SOC 2 exports. You are not replacing a free service; you are answering its email.
Switching from Open Bug Bounty?
You'll love Kit if:
- The last notification reached you late, and the disclosure clock didn't care
- An auditor asked for evidence of a vulnerability disclosure process
- SQL injection and RCE need a real intake with a record, not a raw inbox
- You want a 72-hour acknowledgment deadline your team owns, with MTTA and MTTR to show
- On-call rotation and Slack should decide who answers, before the deadline does
Stay with Open Bug Bounty if:
- Free verified XSS findings are all you need
- No auditor, framework or customer is asking you to prove a process
- You can absorb up-to-5-day verification and a 90-day disclosure clock
- You claimed your domain there — keep it claimed either way; Kit can't replace the crowd
Data portability: Open Bug Bounty documents no report export for site owners, and closing a hosted programme removes no public pages. There is nothing to move — Kit's record starts with the next report.
Try Kit's VDP for 30 days.
Self-serve, no sales call. The VDP add-on trials for 30 days and stands alone — you don't need the rest of Kit to run it.
$49€49159 zł£39 per month, alone or on a Kit seat
Start free trial