Skip to main content
Terra PPC

Report a security or privacy issue

If you have found a vulnerability, or have a concern about the security of Terra PPC or the handling of Amazon-related data, tell us. Reports are reviewed by Terra Flora Global LLC.

Terra PPC is a software product operated by Terra Flora Global LLC. Terra Flora Global LLC is the legal operator responsible for the Terra PPC website and service.

What you can report

Researchers, customers and anyone else may report any of the following.

  • Security vulnerability

    A weakness in the Terra PPC website or service.

  • Unauthorized access

    Signs that someone accessed an account or data without permission.

  • Suspected Amazon data misuse

    Amazon-related data used outside authorized functionality.

  • Privacy concern

    Personal information handled in a way you believe is wrong.

  • Credential exposure

    Tokens, keys or passwords that may have been exposed.

  • Accidental disclosure

    Information shown or sent to the wrong person.

  • Account authorization concern

    An Amazon connection you did not expect or approve.

What to include

The more precise the report, the faster it can be verified.

  • A description of the issue
  • The affected URL or function
  • Safe reproduction details — steps that do not harm data or other users
  • The potential impact as you understand it
  • Contact information so we can follow up

Do not include passwords, tokens or customer data beyond what is needed to describe the issue.

Responsible conduct

Test only what you need to demonstrate the issue, then stop and report it.

  • Do not access another customer's data.
  • Do not conduct destructive testing.
  • Do not perform social engineering.
  • Do not publish private data.
  • Do not disrupt the service.

Please give us a reasonable opportunity to investigate and fix an issue before discussing it publicly.

How to report

Send your report through one of these channels. Choose the Security topic on the contact form so it reaches the right queue.

Machine-readable contact details are published at /.well-known/security.txt.

What happens next

We review each report we receive, ask for more detail if needed, investigate, and act where an issue is confirmed. This is a responsible disclosure channel, not a paid reward program.