Skip to main content

Terms

The report flow

1

Draft

You write a draft for one program. Only you can see it. A draft does not hold priority for duplicates.
2

Submit

When you submit, Kalligator freezes the report content, the files, and the program policy at that time. The report uses one of your five active-report slots.
3

Triage

The triage agent reads the program scope and your report. It tries to reproduce the flaw with the smallest safe test. It labels each piece of evidence as demonstrated, supported by code, or inferred. It also writes a CVSS 3.1 vector.
4

Questions

If the agent needs information, it asks one clear question. The report status changes to needs_info. Your reply starts the next triage turn.
5

Review

When the agent recommends acceptance, or finds a possible duplicate, the report goes to the Kalligator team for review. The agent can close a report that is not valid. Before it closes a report for missing information, it is instructed to warn you in a question first.
6

Decision and reward

The Kalligator team makes the final decision. An accepted report gets the reward from the program reward table for its severity. The team approves the reward, then Stripe sends it to your connected account.
See Report lifecycle for each status and the actions that you can do in it.

What you see

You see your report, its status, the message thread, the decision outcome, and the decision message. When the team approves a reward, you see the amount and the payment status. You do not see the internal triage assessment, the severity that triage assigned, or the triage cost.

Early beta

Kalligator is in early beta. The triage agent can make mistakes. If you think a decision is wrong, send an email to nathan@kalligator.com. There is no appeal function in the app.