# Internal notes and talking to a reporter

**Category:** [Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/bug-bounty)
**Updated:** 2026-10-04

## Two kinds of comment

Every comment on a report is either an internal note or a message to the reporter. The checkbox is unticked by default, so a comment stays internal unless you say otherwise. Guessing wrong in the other direction would publish a colleague’s private assessment to a stranger.
## What the reporter receives

The reporter is emailed when a report changes state, and when you send them a comment. They can see their own reports — and only their own — from the link they used to submit.
## Attachments

Proof-of-concept files download rather than opening in your browser, and every download is recorded in the audit log. These files were uploaded by somebody proving an exploit works, so opening one on a page inside your workspace is exactly what you do not want.

---

## Related Articles

- [Put the program on your own domain](https://help.totalctrl.app/en-US/articles/bugbounty-custom-domain-1)
- [Response times and the disclosure window](https://help.totalctrl.app/en-US/articles/bugbounty-sla-1)
- [Getting started with Bug Bounty](https://help.totalctrl.app/en-US/articles/bugbounty-getting-started-1)
- [Scope groups and reward tables](https://help.totalctrl.app/en-US/articles/bugbounty-scope-and-rewards-1)
- [Automate on reports: webhooks and the API](https://help.totalctrl.app/en-US/articles/bugbounty-api-and-webhooks-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)