Concierge
DocsPricing Support
Back to Concierge
Legal

Core policies

PrivacyTermsCookiesAI DisclosureAcceptable UsePolicy Changes

Privacy and trust

Privacy ChoicesData DeletionSecurityAccessibilityData Retention

Business resources

Data Processing AddendumSubprocessors

Reporting

Report AbuseSecurity ReportingCopyright and DMCA
Concierge legal

Security Reporting

Guidance for good-faith researchers and customers reporting a potential vulnerability.

Last updated: August 19, 2026

Contact

Email support@poweredbyconcierge.com with “Security report” in the subject. Include the affected host or feature, a concise impact description, reproducible steps, and a safe method for follow-up. Do not send passwords, live tokens, full customer records, or destructive exploit code.

Good-faith research rules

  • Use accounts, sites, and data you own or are expressly authorized to test.
  • Stop if you encounter another person's information and report the minimum evidence needed.
  • Do not disrupt service, degrade availability, send spam, access private networks, install malware, or use social engineering.
  • Do not exfiltrate, alter, publish, retain, or demand payment for customer information.
  • Give us a reasonable opportunity to investigate and correct a confirmed issue before public disclosure.

Out of scope

Automated scanner output without demonstrated impact, denial-of-service testing, physical attacks, social engineering, missing best-practice headers without an exploit, rate-limit observations that do not expose data or compromise an account, and issues solely in an unrelated third-party service are normally out of scope.

Our response

We will acknowledge a credible report, assign it for triage, request clarification if needed, and communicate material status where practical. Time to remediation depends on severity, reproducibility, provider involvement, and operational risk. This program does not promise a bounty or payment.

Authorization

When research is conducted in good faith, within this policy, and without violating another person's rights, we will treat it as authorized security research and will not recommend legal action by Testamplify LLC solely for that compliant activity. This does not authorize conduct prohibited by law or by systems owned by another party.

© 2026 Testamplify LLC. Concierge is built by PracticaLabs.

PrivacyTermsPrivacy choicesReport abuse