Sharing Reports With Peers
Share a single vulnerability report with an engineer outside your team via a secure, email-gated, expiring link — without exposing the researcher, bounty, or internal notes.
Why It Matters
A valid report often needs to reach someone who isn’t on your security team — the engineer who owns the affected service, an on-call lead, an external contractor. Forwarding the raw report leaks the researcher’s identity, your bounty figures, and your internal triage notes, and email threads can’t be revoked. Peer sharing gives that person exactly what they need to confirm and fix the bug — and nothing else — behind a link that expires and that you can revoke at any time.
Peer sharing is available on paid VDP plans.
Sharing a Report
Open a report and click Share in the report header (the Shared · N external viewers chip opens the same place once anyone has viewed). That opens the share window, where you can invite by email, create an “anyone with the link” link, and manage every active share in one spot.
To invite by email, enter the recipient’s address, choose whether to allow them to comment back, and send. Kit emails them a branded invitation on your program’s behalf — the email itself contains no vulnerability details.
The emailed link is bound to that address. Opening it doesn’t show the report: the peer types in the address the invitation went to, and Kit emails that address a second, short-lived confirmation link. Only opening the confirmation link reveals the report. So access needs the mailbox, not just knowledge of the address — a forwarded invitation is useless to anyone who can’t read the original recipient’s mail. Kit’s answer to the “which address was this sent to?” form is the same whether the guess was right or wrong, so the page never confirms who the invitation went to.
Two things follow. Peers need one extra click from their inbox the first time they open a report (and again in a new browser). And if the original recipient forwards the confirmation email as well, they have deliberately handed over their access — the same as forwarding a password-reset link.
Anyone With the Link
When you need to drop a report into a private channel — a company Slack, an incident bridge — and don’t have one specific recipient, switch on Anyone with the link. Kit gives you a single copy-pasteable URL that opens the same redacted report without an email step.
- One link per report. Creating it gives you the URL to copy; revoking it kills that URL. Create again for a fresh one.
- View-only. Link viewers can’t comment and can’t request to join your team — those need a named, verified person, so they stay on the email path.
- Same redaction, same limits. A link reveals exactly what an email invite does (and hides exactly what it hides). It still expires after 7 days and you can revoke it anytime. Closing the report revokes the links you’ve already shared — but you can deliberately share it again afterward.
Because anyone holding the link can open it, only share it where you’d share the redacted details themselves. When in doubt, invite by email instead — that ties access to a mailbox someone has to be able to read.
What the Peer Sees
The shared view is a redacted, read-only version of the report:
- Shown — vulnerability type, affected endpoint, severity, description, reproduction steps, and attachments (served as short-lived, off-origin downloads).
- Hidden — the researcher’s identity and email, bounty amounts, your internal notes, the assessment author, and your team’s timeline.
If you enabled comments, the peer can reply. Their replies land in the report as internal, staff-only notes (clearly marked as coming from an external peer) and are never shown to the researcher.
Expiry and Revocation
- Links expire 7 days after they’re created.
- Closing a report (resolved, paid, or dismissed) revokes the links you’ve already shared. You can share it again afterward — handy when you dismiss a report as “out of scope” and want to forward it to the upstream vendor. The peer then sees a small “this report was closed” note so they know it’s a snapshot.
- You can revoke any share at any time from the share window — the peer loses access immediately.
When a Link Has Expired
A peer who opens an expired email invite no longer hits a dead end. After completing the same mailbox confirmation, they can:
- Request a fresh link — as long as the report is still open, Kit emails a new 7-day link to that same address (never anywhere else). A revoked link can’t be self-renewed, and once a report is closed the peer can’t self-renew either — re-sharing a closed report stays your deliberate decision, so the peer only sees a notice to contact you.
- Request to join the team — the same request-to-join flow described below.
An expired “anyone with the link” link has no recipient to renew for, so it’s simply a dead end — create a new link from the share window if you still need one.
Seeing Who Opened a Report
External access is surfaced as a security signal, not a quiet “seen” receipt:
- The Active shares list in the share window shows each share — recipient (or “Anyone with the link”), status, view count, last-viewed time, and the country it was opened from.
- The report header shows a “Shared · N external viewers” chip (click it to open the share window).
- The report timeline records an External viewer opened this report event.
- Every distinct browser session that opens the report leaves its own row in the log, so a second reader can’t hide behind the first one’s recent visit. On an email invite each of those sessions means another trip through the recipient’s mailbox.
- The person who shared the link and the report’s assignee are notified the first time an address opens it, and again whenever it’s opened from a new country. On an email invite the address can never change (it’s the bound one), so the country is the signal worth watching: the same invite opening from somewhere new is worth a question.
Requesting to Join the Team
A peer who needs ongoing access can request to join your security team from the shared report. The request lands with your account admins alongside any other access requests; approving it sends a normal team invitation, and once accepted they become a full member with their own account — no more one-off links.
When you open the request, Kit shows you who’s asking and which report the share came from. Read those fields differently: the email is the address you invited (the requester can’t change it — Kit takes it from the confirmed share, not from the form) and the country comes from the connection, while the name and note are free text the requester typed. Treat the address as the fact and the name as a claim, and confirm you actually shared with this person before inviting them. Approve sends the team invitation; Dismiss silently drops the request (the requester is never notified).