KitGradeSCORED ON WHAT A BUYER CAN CHECK
REFRESHED 05:41 UTCOpen API
38 kits scored16 installed and run here22 read, not run22 free and open source16 paid100 points, method 1.0captured 2026-09-13nothing here is sponsored

There is nothing to sign in to, and two things are stored.

What KitGrade stores, who else processes it, and how to report a vulnerability.

ACCOUNTS
none
PASSWORDS
none held
STORED
2 things, named below
PROCESSORS
3
REPORT TO
hello@thecompound.tech

Reporting a vulnerability

Email hello@thecompound.tech. Include the URL, what you did, and what you saw. There is no bounty and no NDA to sign. We will confirm receipt, and we will tell you what we changed.

The same address, with a machine-readable expiry, is published at /.well-known/security.txt under RFC 9116.

Accountsnone

KitGrade has no user accounts. There is nothing to sign in to, no password to reset and no session to steal; the site is a published dataset and a set of static pages, and a build gate fails the deploy if an authentication route ever appears while this page still says otherwise.

What is stored2

  • An email address, only if you type one into the subscribe form, and only after you confirm it by clicking a link.
  • Anonymous page analytics with the IP address truncated before it is stored.

Who else processes data3

  • Vercel, hosting and edge delivery; request logs
  • PostHog, product analytics, IP-truncated
  • Resend, delivering the one email the subscribe form sends

Also true

Everything on this site is generated from public sources and rendered as static pages; there is no user-generated content that another visitor can see.