Best Buy · Vulnerability Disclosure
Best Buy Vulnerability Disclosure
Vulnerability disclosure
Best Buy runs a public, named vulnerability disclosure program hosted on HackerOne. It is a VDP rather than a paid bug bounty, it carries an explicit safe-harbour clause, and it commits to a two-business-day acknowledgement. It is NOT advertised via RFC 9116 — no security.txt is served on any Best Buy host — so a machine discovering Best Buy through its API surface would never find it.
Best Buy runs a coordinated vulnerability disclosure program on Hackerone.
Fortune 100RetailConsumer ElectronicsE-CommerceProductStores
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.