Best Buy · Vulnerability Disclosure

Best Buy Vulnerability Disclosure

Vulnerability disclosure

Best Buy runs a public, named vulnerability disclosure program hosted on HackerOne. It is a VDP rather than a paid bug bounty, it carries an explicit safe-harbour clause, and it commits to a two-business-day acknowledgement. It is NOT advertised via RFC 9116 — no security.txt is served on any Best Buy host — so a machine discovering Best Buy through its API surface would never find it.

Best Buy runs a coordinated vulnerability disclosure program on Hackerone.

Fortune 100RetailConsumer ElectronicsE-CommerceProductStores
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: searched
source: https://hackerone.com/bestbuy
description: >-
  Best Buy runs a public, named vulnerability disclosure program hosted on HackerOne. It is a
  VDP rather than a paid bug bounty, it carries an explicit safe-harbour clause, and it commits
  to a two-business-day acknowledgement. It is NOT advertised via RFC 9116 — no security.txt is
  served on any Best Buy host — so a machine discovering Best Buy through its API surface would
  never find it.
program:
  name: Best Buy Vulnerability Disclosure Program
  platform: HackerOne
  url: https://hackerone.com/bestbuy
  status: 200
  probed: '2026-08-27'
  type: vulnerability-disclosure
  bounty: false
  bounty_note: Listed as a Vulnerability Disclosure Program; no bounty table is advertised on the program page.
  safe_harbour: true
  safe_harbour_text: For any activity conducted in compliance with the policy, Best Buy will not initiate legal action.
  acknowledgement_sla: within two business days of submission
  response_efficiency: above 90% (as reported on the HackerOne program page)
policy_pages:
- name: Best Buy Responsible Disclosure Policy
  url: https://www.bestbuy.com/site/help-topics/responsible-disclosure/pcmcat1584549036018.c
  status: 0
  note: >-
    Referenced by the HackerOne program. Not verifiable from this pass — www.bestbuy.com
    returned no HTTP response (curl status 000) to every request, including / and /robots.txt.
security_txt:
  served: false
  probed:
  - url: https://developer.bestbuy.com/.well-known/security.txt
    status: 404
  - url: https://api.bestbuy.com/.well-known/security.txt
    status: 403
  - url: https://corporate.bestbuy.com/.well-known/security.txt
    status: 404
  - url: https://www.bestbuy.com/.well-known/security.txt
    status: 0
  gap: >-
    The single highest-leverage, lowest-cost fix available to Best Buy here: publish an RFC 9116
    security.txt at www.bestbuy.com and developer.bestbuy.com pointing Contact and Policy at the
    HackerOne program that already exists.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/best-buy-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.