Skip to content
bughunter.pro
/Request an audit

Raphaël, independent pentester.

I run every engagement end to end, on web and API perimeters, from France, and I am also an active researcher on public bug bounty platforms. The two feed each other: bug bounty keeps an offensive practice sharp on real perimeters under competition, penetration testing puts that practice at the service of one company, inside a written frame.

01Background

Two trades that answer each other.

Bug bounty and pentesting share the same moves but not the same economics. In bug bounty nobody pays for time spent: you are paid per flaw found, competing with hundreds of other researchers, on perimeters that have often already been audited several times over. That trains exactly one thing, looking where the others did not.

Which is precisely what many commissioned audits lack. An engagement billed by the day can get away with walking a checklist and delivering a compliant document. A researcher paid on results has no incentive to do that, because the checklist was already walked by somebody else before them.

Penetration testing brings the reverse: a frame, guaranteed coverage, a written perimeter, a report you can stand behind, and somebody to talk to when it is time to fix things. That is what you are buying here: the discipline of a serious provider, with the instincts of somebody whose trade is finding what everyone else missed.

02Track record

Where I have found vulnerabilities.

Vulnerabilities found, reported and fixed on French public services, CAC 40 groups and leaders in the luxury sector, among others. Perimeters and organizations are never named.

A practice kept current

Bug bounty is not a line on a CV: it is a continuous activity on public platforms, where findings are validated by the security teams of the organizations concerned before anything is rewarded.

Discretion that cuts both ways

No pentest client is named on this site, no perimeter is described, and the example findings published here are systematically rewritten to remove anything that could trace back to anyone.

03How I work

What I do not compromise on.

01

I do the work myself

There is no team behind this, deliberately. The person you scope the engagement with is the one who tests, the one who writes, and the one you will get on the phone six months later if a question comes back. Nothing is subcontracted.

02

I search by hand

Tools cover the known and make sure nothing mechanical is missed. No tool output reaches a report without being replayed and confirmed. What you pay for is the time spent on what is specific to you.

03

I turn down what I cannot do

I do web and APIs. Not native mobile, not industrial systems, not large-scale internal infrastructure. When a request falls outside that, I say so and point elsewhere rather than learning at your expense.

04

I write to be read

A report only its author can follow is a failed report. The summary addresses a management team, the sheets address developers, and nobody needs me on the line to reproduce a finding.

05

I raise the alarm immediately

A critical vulnerability cannot wait for report delivery. It is reported the same day, with enough to contain it, even when that cuts the engagement short.

06

I check behind you

An audit without a retest leaves a list of fixes nobody confirmed. The retest is part of every engagement, and its result is written down plainly.

04The frame

What is in writing before anything starts.

Trust is not a substitute for a document. Here is what gets signed or supplied on every engagement, without you having to ask.

  • A confidentiality agreement, signed before you share a single technical detail.
  • A written testing authorization, stating the perimeter, the testing window and the addresses in scope.
  • Explicit rules of engagement: no denial of service, no destructive action, no data extraction beyond proof.
  • A timestamped test log, so my activity is distinguishable from a real attack in your own records.
  • GDPR-compliant handling of anything I hold, with proofs destroyed after the agreed retention period.
05FAQ

Common questions.

Why an independent rather than a consultancy?

Two concrete reasons. The person selling the engagement is the person delivering it, which is not always the case elsewhere: you meet an expert during the sales process, and a junior arrives after signature. And there is no sales structure or project management layer inside the price. In exchange, I turn down perimeters that need a team, and I say so rather than subcontracting.

What kind of organizations do you work with?

Software vendors and online platforms mainly, along with retail sites and business applications. Size matters less than the nature of what is handled: a small team holding sensitive data needs an audit more than a large group whose website is a brochure.

Do you work outside France?

Yes, engagements run remotely and I work in French and in English. Where the company sits does not matter. What matters is the legal framing of the testing authorization, which is settled case by case.

What happens to what you learn about us?

None of it leaves. The NDA is signed before any technical exchange, proofs and engagement data are destroyed after the agreed retention period, and no client or perimeter is ever named, including in the examples published on this site.

06Contact

Let's talk about your perimeter.

The first conversation is about working out whether I have anything useful to offer you. If I do not, I will say so. No commitment, and confidential from the first line.