Terms
The report flow
1
Draft
You write a draft for one program. Only you can see it. A draft does not hold priority for duplicates.
2
Submit
When you submit, Kalligator freezes the report content, the files, and the program policy at that time. The report uses one of your five active-report slots.
3
Triage
The triage agent reads the program scope and your report. It tries to reproduce the flaw with the smallest safe test. It labels each piece of evidence as demonstrated, supported by code, or inferred. It also writes a CVSS 3.1 vector.
4
Questions
If the agent needs information, it asks one clear question. The report status changes to
needs_info. Your reply starts the next triage turn.5
Review
When the agent recommends acceptance, or finds a possible duplicate, the report goes to the Kalligator team for review. The agent can close a report that is not valid. Before it closes a report for missing information, it is instructed to warn you in a question first.
6
Decision and reward
The Kalligator team makes the final decision. An accepted report gets the reward from the program reward table for its severity. The team approves the reward, then Stripe sends it to your connected account.
What you see
You see your report, its status, the message thread, the decision outcome, and the decision message. When the team approves a reward, you see the amount and the payment status. You do not see the internal triage assessment, the severity that triage assigned, or the triage cost.Early beta
Kalligator is in early beta. The triage agent can make mistakes. If you think a decision is wrong, send an email to nathan@kalligator.com. There is no appeal function in the app.