generated: '2026-09-06' method: searched source: https://sellerfusion.io/security name: Acquco / Sellerfusion vulnerability disclosure company: Acquco note: >- Acquco itself (acqu.co) publishes no security or disclosure page and serves no /.well-known/security.txt on any host. The disclosure program below is published on the Security & Trust page of Sellerfusion, Acquco's own seller-operations platform — the page footer reads "Sellerfusion ... powered by Acquco" and sellerfusion.io is linked from the acqu.co Resources navigation, so it is a first-party Acquco surface. program: published: true type: coordinated-disclosure bug_bounty: false bounty_platform: null safe_harbor_stated: false policy_url: https://sellerfusion.io/security contact_email: security@sellerfusion.io acknowledgement_sla: one business day credit_offered: true public_hall_of_fame: false page_last_updated: '2026-04-08' reporting_instructions: - Email security@sellerfusion.io with the affected URL, reproduction steps, impact and any proof-of-concept material. - Do not publicly disclose the issue until Sellerfusion has investigated and remediated. - Sellerfusion acknowledges receipt within one business day and provides status updates until resolution. - Responsible researchers may be credited in the acknowledgments. incident_response: plan_published: true framework: NIST SP 800-53 IR-8 phases: - preparation - identification - containment - eradication - recovery - lessons learned critical_initial_response: 15 minutes low_severity_response: next business day point_of_contact: designated Incident Management Point of Contact (IMPOC), primary and backup notification_commitments: - party: Amazon window: 24 hours of detecting a security incident affecting Amazon information basis: Amazon Data Protection Policy - party: EU supervisory authorities window: 72 hours of confirming a personal data breach affecting EU residents basis: GDPR - party: affected customers and marketplace partners window: in line with applicable law and contractual obligations basis: contract security_txt: served: false hosts_probed: - host: www.acqu.co path: /.well-known/security.txt status: 404 - host: acqu.co path: /.well-known/security.txt status: 404 - host: sellerfusion.io path: /.well-known/security.txt status: 404 - host: app.sellerfusion.io path: /.well-known/security.txt status: 404 recommendation: >- Publish an RFC 9116 /.well-known/security.txt on acqu.co and sellerfusion.io pointing at https://sellerfusion.io/security and mailto:security@sellerfusion.io — the program exists, but no machine can find it. x-evidence: fetched: '2026-09-06' url: https://sellerfusion.io/security http_status: 200 content_type: text/html