Responsible disclosure
Security Acknowledgements
We appreciate the independent security researchers who help us improve Rehearse's security through responsible vulnerability disclosure. We're grateful for their contributions to keeping our users safe.
- Program status
- Public bug bounty not currently active
- Last updated
- 25 July 2026
Recognition notice
While we don't currently run a public bug bounty program, we value responsible security research. Valid reports may be acknowledged on this page, with the researcher's permission, as a token of our appreciation.
Hall of fame
Recognized researchers
Researcher: Sankalp Tripathi
Date: 25 July 2026
Contribution: Reported and responsibly disclosed a business logic vulnerability in the free-session allocation mechanism, allowing repeated free sessions via email-alias registrations. Resolved by the Rehearse security team.
Responsible disclosure
If you believe you've found a security vulnerability in Rehearse, please report it responsibly. Include enough technical detail and proof of concept for us to reproduce and investigate. Please avoid accessing other users' data, disrupting the service, or exploiting a vulnerability beyond what's necessary to demonstrate it.
Contact our security team
Report an issueWe sincerely thank everyone who helps improve Rehearse's security. Your work helps make the platform safer for everyone.