Responsible disclosure

Security Acknowledgements

We appreciate the independent security researchers who help us improve Rehearse's security through responsible vulnerability disclosure. We're grateful for their contributions to keeping our users safe.

Program status
Public bug bounty not currently active
Last updated
25 July 2026

Recognition notice

While we don't currently run a public bug bounty program, we value responsible security research. Valid reports may be acknowledged on this page, with the researcher's permission, as a token of our appreciation.

Hall of fame

Recognized researchers

  • Researcher: Sankalp Tripathi

    Date: 25 July 2026

    Contribution: Reported and responsibly disclosed a business logic vulnerability in the free-session allocation mechanism, allowing repeated free sessions via email-alias registrations. Resolved by the Rehearse security team.

Responsible disclosure

If you believe you've found a security vulnerability in Rehearse, please report it responsibly. Include enough technical detail and proof of concept for us to reproduce and investigate. Please avoid accessing other users' data, disrupting the service, or exploiting a vulnerability beyond what's necessary to demonstrate it.

Contact our security team

Report an issue

We sincerely thank everyone who helps improve Rehearse's security. Your work helps make the platform safer for everyone.