Open to private program invitations
Benjamin Gouleau
Bug bounty hunter. I find access-control and business-logic flaws in web apps and APIs.
Founder & Président of GBFS Holding SAS. I lead security for its products Liink and Looply and do its bug bounty research.
Public profiles
Figures from each public profile, checked
@benoatsf
- 4 reports submitted
- Identity verified
@benoatsf
- Joined September 2026
@benoatsf
- Skills: Web, API, AI/LLM
@benoatsf
- Bugcrowd sign-in required to view
What I look for
Access control
Users reaching data or actions that aren't theirs: IDOR, tenant leaks, privilege escalation.
Business logic
Flows that work as coded but not as intended: payments, coupons, limits, race conditions.
APIs
REST and GraphQL endpoints that trust the client more than they should.
Auth and sessions
Sign-in, password reset and SSO paths that can lead to account takeover.
How I work
Method
- Read the policy and scope before the first request.
- Map roles, money flows and states to find where the app trusts the user.
- Prove impact with my own test accounts and the smallest possible footprint.
- Report clear steps, real impact and a suggested fix.
I use automation and AI-assisted tooling; every report is reviewed and approved by me before submission.
Rules I follow
- In scope only. If it isn't clearly allowed, I don't test it.
- My own accounts only. Never other users' data beyond the minimum proof.
- No denial of service, spam or social engineering.
- Coordinated disclosure. Writeups only after the program approves.
- When something is unclear, I stop and ask.
Contact
Let's talk privately
For private program invitations, disclosure coordination or research collaboration. Messages come straight to my inbox and I reply personally, in English or French.
Please don't send vulnerability details or credentials here. If needed, we'll agree on a secure channel.