> and she finds an issue in my product that I don't agree is a real vulnerability
If it’s not a real vulnerability then why would it matter if she publicised it?
Or, is it actually a real vulnerability but you don’t want to admit it because she (the security consultant) is getting paid per vulnerability found?