Back to list
StartupKit.app logo
FeaturedPoznańFirst revenue

StartupKit.app

A startup making its first ten hires and facing its first enterprise security review runs both out of a shared inbox; Kit replaces that with one apply link for candidates and a published disclosure programme with a 72-hour clock for researchers.
HRtechAICybersecurity

About

Kit gives an early-stage startup two things it normally buys separately: a hiring pipeline and a vulnerability disclosure programme, on one account. Candidates apply through one link with no account to create, on the company's own careers domain, and follow their own application from there. Researchers report through a published security.txt and a branded intake form instead of a security@ inbox, against a 72-hour acknowledgment clock, per-severity SLAs and an append-only bounty ledger — so the first enterprise security review gets an evidence export, not screenshots. Both sides run from the browser or straight from Claude, ChatGPT or Cursor over MCP; built in Poznań, hosted in the EU, no sales calls.