Contact

Open to private program invitations

Benjamin Gouleau

Bug bounty hunter. I find access-control and business-logic flaws in web apps and APIs.

Founder & Président of GBFS Holding SAS. I lead security for its products Liink and Looply and do its bug bounty research.

Rennes, France · French and English · @benoatsf

Public profiles

Figures from each public profile, checked

What I look for

How I work

Method

  1. Read the policy and scope before the first request.
  2. Map roles, money flows and states to find where the app trusts the user.
  3. Prove impact with my own test accounts and the smallest possible footprint.
  4. Report clear steps, real impact and a suggested fix.

I use automation and AI-assisted tooling; every report is reviewed and approved by me before submission.

Rules I follow

  • In scope only. If it isn't clearly allowed, I don't test it.
  • My own accounts only. Never other users' data beyond the minimum proof.
  • No denial of service, spam or social engineering.
  • Coordinated disclosure. Writeups only after the program approves.
  • When something is unclear, I stop and ask.

Contact

Let's talk privately

For private program invitations, disclosure coordination or research collaboration. Messages come straight to my inbox and I reply personally, in English or French.

Please don't send vulnerability details or credentials here. If needed, we'll agree on a secure channel.

0 / 5000

Used only to reply to you.