generated: '2026-08-27' method: searched source: https://hackerone.com/bestbuy description: >- Best Buy runs a public, named vulnerability disclosure program hosted on HackerOne. It is a VDP rather than a paid bug bounty, it carries an explicit safe-harbour clause, and it commits to a two-business-day acknowledgement. It is NOT advertised via RFC 9116 — no security.txt is served on any Best Buy host — so a machine discovering Best Buy through its API surface would never find it. program: name: Best Buy Vulnerability Disclosure Program platform: HackerOne url: https://hackerone.com/bestbuy status: 200 probed: '2026-08-27' type: vulnerability-disclosure bounty: false bounty_note: Listed as a Vulnerability Disclosure Program; no bounty table is advertised on the program page. safe_harbour: true safe_harbour_text: For any activity conducted in compliance with the policy, Best Buy will not initiate legal action. acknowledgement_sla: within two business days of submission response_efficiency: above 90% (as reported on the HackerOne program page) policy_pages: - name: Best Buy Responsible Disclosure Policy url: https://www.bestbuy.com/site/help-topics/responsible-disclosure/pcmcat1584549036018.c status: 0 note: >- Referenced by the HackerOne program. Not verifiable from this pass — www.bestbuy.com returned no HTTP response (curl status 000) to every request, including / and /robots.txt. security_txt: served: false probed: - url: https://developer.bestbuy.com/.well-known/security.txt status: 404 - url: https://api.bestbuy.com/.well-known/security.txt status: 403 - url: https://corporate.bestbuy.com/.well-known/security.txt status: 404 - url: https://www.bestbuy.com/.well-known/security.txt status: 0 gap: >- The single highest-leverage, lowest-cost fix available to Best Buy here: publish an RFC 9116 security.txt at www.bestbuy.com and developer.bestbuy.com pointing Contact and Policy at the HackerOne program that already exists.