Security Acknowledgements
Thank you to our security researchers
We appreciate the efforts of independent security researchers and members of the security community who help us improve the security of Resistaa through responsible vulnerability disclosure. We are grateful for their contributions in helping keep our users safe.
- Program status
- Public bug bounty not currently active
- Last updated
- 25 August 2026
Recognition notice
While we do not currently operate a public bug bounty program, we greatly value responsible security research. Valid reports may be acknowledged on this page, with the researcher's permission, as a token of our appreciation.
Hall of fame
Recognized researchers
| Researcher | Contribution | Date |
|---|---|---|
| Devansh Chauhan | Reported and responsibly disclosed an HTML Injection vulnerability that was resolved by the Resistaa security team. | 17 June 2026 |
| Sankalp Tripathi | Reported and responsibly disclosed business logic vulnerabilities in the free trial subscription mechanism and the logged-in password change flow that were resolved by the Resistaa security team. | 24 July 2026 |
| Shubham Mali | Reported and responsibly disclosed rate-limiting and referral-abuse vulnerabilities in the AI generation endpoint and referral system that were resolved by the Resistaa security team. | 3 August 2026 |
| Tippagalla Jaswanth | Reported and responsibly disclosed a missing re-authentication control on account deletion, and a session management vulnerability where active sessions were not invalidated after a password reset, both resolved by the Resistaa security team. | 24 August 2026 |
| Immadisetty Kiran Kumar | Reported and responsibly disclosed an account enumeration vulnerability in the email lookup endpoint that was resolved by the Resistaa security team. | 25 August 2026 |
Devansh Chauhan
Reported and responsibly disclosed an HTML Injection vulnerability that was resolved by the Resistaa security team.
17 June 2026
Sankalp Tripathi
Reported and responsibly disclosed business logic vulnerabilities in the free trial subscription mechanism and the logged-in password change flow that were resolved by the Resistaa security team.
24 July 2026
Shubham Mali
Reported and responsibly disclosed rate-limiting and referral-abuse vulnerabilities in the AI generation endpoint and referral system that were resolved by the Resistaa security team.
3 August 2026
Tippagalla Jaswanth
Reported and responsibly disclosed a missing re-authentication control on account deletion, and a session management vulnerability where active sessions were not invalidated after a password reset, both resolved by the Resistaa security team.
24 August 2026
Immadisetty Kiran Kumar
Reported and responsibly disclosed an account enumeration vulnerability in the email lookup endpoint that was resolved by the Resistaa security team.
25 August 2026
Responsible disclosure
If you believe you've discovered a security vulnerability in Resistaa, please report it responsibly. Include sufficient technical details and proof of concept so our security team can reproduce and investigate the issue. Please avoid accessing user data, disrupting services, or exploiting vulnerabilities beyond what is necessary for verification.
Contact our security team
Send responsible disclosure reports to hello@maisongr.com