Earlier quoted context omitted.
No, this is illegal and can put namespace into huge trouble. Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing. This is why legal departments exist, you cannot just say this as a CEO without consulting to your advisors.
None of what you’re saying is true. > Responsible Disclosure Programme needs to explicitly state that access to other users data is illegal and test/self owned accounts need to be used for security testing. Why do you think so? You don’t lose out on any legal protections without explicitly stating that.
Company can't encourage/allow security researchers to access private data of the users, at best this is against GDPR but it can also cause monetary damage to users which can be far worse.