Its weird having protections against finding exploits: what if I developed the app? Would it require having the development steps still in the context.. thats unlikely and also not any kind of proof.
What if I intersperse exploit finding in my normal development, as you `probably should? Refusing there would be really weird to me.