Kit vs a security@ inbox: The report arrives either way. The proof doesn't.
A researcher who finds your bug at 2am can already reach you — CISA's own directive recommends security@<domain> by name, and the mailbox receives every report a Kit portal would. Kit brings no researchers either. What a year of that mailbox cannot produce is the record an auditor asks for first.
Who should choose what?
Choose Kit if you're:
- Answering an auditor who asked for median time-to-acknowledge
- In CRA scope — Annex I requires an enforced disclosure policy, Annex VII evidence of the contact address
- Proving you handle the reports that arrive, not hunting for new ones — Kit brings no crowd
- Past a handful of reports a year, with duplicates starting to collide
- Need it live before Friday — self-serve, no sales call
Keep the inbox if you're:
- Receiving a few reports a year with nobody external asking for evidence
- Pre-audit, with no budget line and no appetite for a new subprocessor
- Wanting zero vendors between a reporter and your team
- Satisfying the letter of most VDP asks — CISA's template names an email address as an acceptable channel
- Reading every report the day it lands, with one owner who can name every open thread
- Trying to find vulnerabilities — then neither side of this page is the answer; that is a researcher crowd like HackerOne or Bugcrowd
What the inbox gets right
The inbox is not a mistake. CISA's own directive recommends it by name.
It costs nothing and it is already running
An alias on the tenant you already run — Google Workspace includes up to 30 per user at no extra charge — plus disclose.io's CC0 policy templates for the legal text. No procurement cycle, no DPA, no subprocessor disclosure, no vendor security review, nothing to deploy.
Why this matters: For a company receiving a handful of reports a year this is correct sizing, not laziness. Tooling bought before there is report volume is a dashboard with no data in it.
Zero lock-in — the bytes are yours
Reports are RFC 5322 messages in a mailbox you own. IMAP, JMAP, mbox export and the Gmail API all read them, and migrating means pointing an MX record somewhere else. No vendor can deprecate your data model or go out of business holding your disclosure history.
Why this matters: Kit keeps reports in its own schema and ships no REST API; its exit is CSV and PDF exports. The mailbox never has that problem — though nothing structured exists to migrate into a tool later either.
The one channel every reporter already has
Email needs no account, works from a throwaway address, and works when a portal is down. BOD 20-01 recommends security@<domain> as the de facto address for security conversations, RFC 9116 accepts a mailto Contact, and CISA's template lists the mailbox alongside its form.
Why this matters: A portal a researcher finds annoying is a report you never receive. In January 2026 curl, after nearly seven years on HackerOne, moved its intake to GitHub private reporting plus [email protected] — a mature security team moved toward the mailbox.
What Kit does well
Four artifacts a mailbox never creates, starting with the clock.
A 72-hour acknowledgment clock that pages
The clock starts at submission and stops only when the report leaves an open status — a first reply does not stop it. At a quarter of the window left it pages as at-risk; past the deadline, breached. One window for every severity.
BOD 20-01 tells agencies to set target timelines and track them. A mailbox has no clock, so the SLA in your published policy is unenforced by construction.
Evidence an auditor can hold
MTTA and MTTR computed from recorded state transitions, SOC 2 CSV and PDF exports, and an incident-dossier PDF per report. The per-report timeline — received, acknowledged, assessed, resolved — exists as rows, not as mail-thread archaeology.
BOD 20-01's quarterly metrics — median time to respond, valid reports open past 90 days — are uncomputable from a mailbox, because the events they derive from were never recorded as data.
security.txt that cannot quietly expire
Kit publishes RFC 9116 security.txt at /.well-known/security.txt on its own and watches the mandatory Expires field, with an alert 14 days before it lapses. A hand-committed file has no renewal mechanism.
In a 2026 scan of 241 million domains, 7.3% of the security.txt files found had already expired — and RFC 9116 warns a stale file can be worse than none.
Anonymous intake with an attachment
A researcher submits without an email address, proof-of-concept attached, from your portal or a form embedded on your own site. The free structured-intake workaround — a Google Form — requires sign-in for any file upload.
CISA's VDP template instructs that reporters must be able to submit anonymously. The free form tool cannot take an anonymous proof-of-concept; Kit's portal can.
What Kit doesn't have
Four things the inbox has that Kit does not, and what we plan to do about each one.
One more vendor to answer for
Adopting Kit adds a subprocessor to your own vendor inventory, a recurring line item, and one more system to answer for in your next security questionnaire. The alias adds none of those, and Kit itself holds no SOC 2 or ISO 27001 attestation today.
Will we add this? The vendor row is the cost of any hosted tool. What we control is the exit — monthly billing, CSV and PDF exports, no annual contract.
No researchers
A Kit VDP receives what walks in off a security.txt and an embeddable form — the same reports the mailbox would. No crowd, no managed triage, no pentest service.
Will we add this? No. Finding vulnerabilities is a bug bounty crowd's job — HackerOne, Bugcrowd, Intigriti. Kit only handles the reports that arrive.
No REST API
The mailbox speaks IMAP, JMAP, mbox export and the Gmail API — generic protocols already in your stack. Kit ships MCP tools and 11 webhook events, and bulk extraction runs through CSV and PDF exports.
Will we add this? Not planned. MCP and webhooks are the surface we maintain; if you need raw programmatic access to every report body, the mailbox already has it.
Not $0, and not unbounded
The alias is $0 on the mail tenant you already pay for, with no report cap. Kit's intake needs a Kit subscription, the tier included with a seat caps at 25 reports a month, and the clock, ledger, exports and custom domain bill as a separate add-on.
Will we add this? The cap stays. What we can argue is what the included tier contains — a status machine, receipts, anonymous intake — never its volume.
Philosophy differences
These two reflect different answers to what a disclosure channel owes you afterwards.
The record is the product
Receiving reports was never the hard part — the inbox does that for nothing. Kit exists for the moment someone external says show me: a clock that was running, a status machine, an append-only ledger, exports shaped like an audit. Intake is included with a $8 seat up to 25 reports a month; the full module is the $49 add-on.
The channel is the process
Email is the one channel every reporter already has. No account to create, a throwaway address works, and BOD 20-01 recommends the exact address form as the de facto place to start a security conversation. What it cannot do is remember — no severity, no state, no timestamps — so the process lives in one engineer's head and in thread context.
Pricing reality check
Kit
$49/month
the VDP add-on, on top of a $8/seat Kit subscription
- 72-hour acknowledgment clock with at-risk paging
- MTTA/MTTR dashboard and SOC 2 CSV/PDF exports
- Auto-published RFC 9116 security.txt with expiry watchdog
- Anonymous submissions, CVSS v3.1 scoring, duplicate flagging
- Append-only bounty ledger with W-9/W-8BEN collection
A security@ inbox
$0 incremental
an alias on the mail tenant you already pay for
- Up to 30 free aliases per user on Google Workspace
- No report cap, no seat cap, no procurement cycle
- CC0 policy and safe-harbor templates from disclose.io
- Triage labour unbudgeted — curl reports 3-4 people per report, 30 minutes to hours each
- No acknowledgment clock and no evidence record
Pricing reality check
The inbox wins on price forever — nothing to pay, no report cap, no vendor. Kit's intake is included with a $8 seat up to 25 reports a month; the clock, ledger, exports and custom domain are the $49 add-on. What that buys is not receiving reports — it is proof of what happened next.
Switching from a security@ inbox?
You'll love Kit if:
- An auditor asked for median time-to-acknowledge and the answer lives in mail threads
- Your security.txt expired and nobody noticed — 7.3% of files found in a 2026 scan already had
- Two researchers reported the same bug and the threads never met
- Hand-sorting scanner dumps and AI slop — Kit screens every submission across 12 signals before a human reads it
- The CRA applies to you, and Annex VII wants evidence of your reporting contact in the technical documentation
Stay with the inbox if you:
- Receive a handful of reports a year and nobody external has asked for evidence
- Have no budget line and no appetite for one more subprocessor
- Want zero vendors between a reporter and your team
- Trust the precedent — in January 2026 curl moved its intake to GitHub private reporting plus [email protected]
Data portability: Email exports perfectly — mbox, IMAP, Takeout, an MX change. Nothing structured comes with it, so there is no per-report history to carry into any tool later. Kit's exit is CSV and PDF exports plus the dossier PDFs.
Try Kit free for 30 days.
Self-serve, no annual commitment, cancel anytime in the first 30 days. Nobody from sales will call you either way.
$49€49159 zł£39 per month, on top of a Kit seat
Start free trial