Kit vs YesWeHack: A researcher community, or proof you answered.
YesWeHack shows your program to a researcher community it counts at over 100,000, hosted where a European procurement desk will accept it. Kit brings no researchers, no triage team and no pentest bench. What it brings the reporter is a form with no account to make, and what it brings your auditor is the acknowledgment record.
Who should choose what?
Choose Kit if you're:
- Proving a disclosure process, not staffing a bug-finding program
- Working without an AppSec budget — the price is on the pricing page
- Comfortable attracting reporters yourself, because Kit brings none
- Answering and rewarding reporters from the screen you triage on
- Live before Friday, with security.txt and the 72-hour clock on day one
Choose YesWeHack if you're:
- Measured on vulnerabilities found, so researcher supply is the product
- Under DORA, NIS2 or a procurement gate that requires EU-sovereign hosting
- Planning bug bounty or CREST-accredited pentests with the same vendor
- Want YesWeHack's triage team filtering reports before your engineers read them
- Integrating through a documented REST API and bidirectional tracker sync
- An enterprise with an AppSec budget and room for a sales cycle
What makes YesWeHack special
Three axes Kit does not compete on: researcher supply, EU sovereignty, and the ladder above a VDP.
They bring the researchers
YesWeHack's own figures count a community of over 100,000 ethical hackers, and a Featured VDP is showcased to it directly. On bug bounty and Featured VDP programs, submitting costs a hunter credits and outcomes refund them, which prices spam out of the queue.
Why this matters: Kit hands you an empty inbox and expects reporters to find you. If the program is measured on vulnerabilities found, this community is the product.
EU sovereignty that survives procurement
YesWeHack's trust page commits to EU-only hosting and processing in a SecNumCloud-qualified private cloud, with ISO 27001 and 27017 for the ISMS and CREST accreditation verifiable on the CREST marketplace. In October 2025 it announced a four-year European Commission bug bounty framework potentially worth up to €7.68M.
Why this matters: If procurement requires the vendor to hold certifications, Kit clears none of this — no ISO 27001, no CREST, no SecNumCloud.
A ladder above the VDP
One account escalates from VDP to bug bounty, continuous pentesting and CREST-accredited tests without a new vendor, contract or DPA. Since September 2025 YesWeHack can also assign CVE IDs as a CVE Numbering Authority.
Why this matters: A program that outgrows disclosure has somewhere to go without a second procurement. Kit has no rung above the VDP.
What Kit does well
Four narrow things, each one screenshot-able.
The price is on the page
The VDP add-on price is published in four currencies with no annual commitment, and checkout is self-serve. YesWeHack's VDP product page offers a demo booking and a sales contact, and no figure anywhere.
You can put the number in the budget before the meeting ends. The alternative starts with a discovery call.
security.txt writes itself
Kit serves RFC 9116 security.txt at /.well-known/security.txt on your portal domain and alerts Slack 14 days before it expires. YesWeHack's setup guide tells customers to write and host the file themselves.
security.txt is the first place a researcher looks, and an expired file reads as an abandoned inbox.
A 72-hour acknowledgment clock
Every report starts an acknowledgment clock — 72 hours by default, one window for every severity — with at-risk paging to on-call, and MTTA and MTTR computed from the same record.
When the auditor asks how fast you acknowledge, the answer is a dashboard, not a memory.
You can answer your reporter
YesWeHack's help centre states a VDP report cannot be rewarded and allows no direct interaction with the researcher. In Kit the reporter gets a durable receipt, a magic-link portal and an appeal path, and a bounty lands in the append-only ledger with a W-9 or W-8BEN on file.
The outsider who found your bug deserves an answer from you, and thanking them should not require a bug bounty contract.
What Kit doesn't have
Five things YesWeHack does that Kit does not, and what we plan to do about each one.
A REST API and tracker sync
YesWeHack publishes an OpenAPI spec with 414 operations, and its ywh2bugtracker tool syncs reports both ways with GitHub, GitLab, Jira and ServiceNow. Kit ships MCP tools and 11 webhook events, and no REST API.
Will we add this? Webhooks and MCP keep growing. A documented REST API is not on the roadmap today.
CVE issuance
YesWeHack has been a CVE Numbering Authority since September 2025. Kit has no CNA status and no CVE workflow of any kind.
Will we add this? No. Becoming a CNA is not on any Kit roadmap.
Portal languages beyond five
A YesWeHack VDP page accepts any language you add, with JSON import and export for translations. Kit's portal ships five languages, and its security.txt advertises English only.
Will we add this? New locales arrive when we can maintain them natively. Arbitrary customer-supplied translations are not planned.
A researcher community
YesWeHack's own figures count its community at over 100,000 ethical hackers, and a Featured VDP is shown to that community directly. A Kit program receives only what finds your security.txt or your form — nobody is recruited for you.
Will we add this? No. Kit will not run a crowd or a marketplace. If report volume is the goal, buy it from someone who sells it.
Vendor certifications
YesWeHack holds ISO 27001 and 27017, CREST accreditation verifiable on the CREST marketplace, and hosting in a SecNumCloud-qualified private cloud. Kit is a small Rails application on one server in Nuremberg with no certification of its own.
Will we add this? No. SecNumCloud qualification and CREST accreditation are not coming — CREST accredits testing services Kit does not sell.
Philosophy differences
These products answer two different questions.
The evidence layer
The VDP as a compliance artifact. Intake with no researcher account, a 72-hour acknowledgment clock, and exports an auditor accepts, priced at $49 a month on top of a $8 seat. Kit assumes reports arrive on their own, and that your job is proving what happened next.
The researcher supply
Researcher supply as the product. Bug bounty, crowdsourced pentests and a managed VDP sold to European enterprises where sovereignty is a procurement gate, with the VDP as the entry ramp to the paid ladder. If the goal is finding vulnerabilities, that shape is the right one.
Pricing reality check
Kit
$8/seat/month + $49/month VDP add-on
Published prices, monthly billing, cancel anytime
- VDP included with a Kit seat, capped at 25 reports a month
- Triage board, 72-hour acknowledgment clock and SOC 2 evidence exports in the add-on
- Anonymous submissions plus an embeddable intake form
- Bounty matrix, append-only ledger, W-9 / W-8BEN collection
- Slack, Jira, Linear, PagerDuty and Vanta integrations
YesWeHack
No public price — contact sales
A consultancy's €20,000–€200,000 a year estimate spans HackerOne, Bugcrowd, Intigriti and YesWeHack together
- VDP product page offers a demo booking and no figure
- MyOpenVDP is free, MIT-licensed and self-hosted, with none of the managed product
- API access requires a CSM introduction
- Commenting to the triage team is marked 'if subscribed'
- A VDP report cannot be rewarded, and there is no direct researcher interaction
Pricing reality check
YesWeHack publishes no price for anything it sells, and every figure in circulation is a third-party estimate. Kit publishes $49 a month for the VDP on top of a $8 seat, self-serve, and the add-on's 30-day trial bills nothing until it ends.
Switching from YesWeHack?
You'll love Kit if:
- An auditor asked for proof of process and the deadline is this week
- Want the cost known before anyone books a call
- Want to answer and reward the person who reported the bug
- Getting single-digit reports a month, which the seat's included intake — form, receipts, 25 reports — already covers
- Want security.txt live this afternoon without writing it
Stay with YesWeHack if:
- Need EU-sovereign hosting you can evidence to procurement
- Want report volume from their researcher community
- Plan to escalate into bug bounty or CREST-accredited pentests with one vendor
- Rely on the REST API or the GitHub, GitLab, Jira and ServiceNow sync
Data portability: YesWeHack exports reports in CSV, XLS, JSON and PDF, and its help centre documents it. Export while the contract is live — API access goes with the CSM relationship, and the portal URL researchers bookmarked resolves to YesWeHack infrastructure.
Try Kit free for 30 days.
Card at checkout, cancel anytime in the first 30 days. There is no discovery call on the other side of the button.
$49€49159 zł£39 per month for the VDP add-on, on top of a Kit seat
Start free trial