Tractor Supply Responsible Disclosure Statement
Tractor Supply is dedicated to providing our customers with the best shopping experience possible, and the security of our customer data is a top priority. If you have discovered a vulnerability in our systems, we appreciate your help in disclosing it to us in a responsible manner by agreeing to and following the requirements below.
*Please note, Tractor Supply does not operate a bug bounty program and we make no offer of reward or compensation in exchange for submitting potential issues.
We will investigate all legitimate reports and do our best to quickly fix the problem. Before reporting though, please review this policy carefully. By submitting your findings without a quid-pro-quo request to Tractor Supply in accordance with this Statement, Tractor Supply agrees not to pursue legal action against you. In consideration of our agreement to not pursue legal action, you agree that you will not publicly disclose any vulnerability you may have discovered or disclosed to us. Tractor Supply reserves all legal rights in the event of noncompliance with these requirements.
To protect our company, our customers and their data, you must accept and comply with the following requirements:
- Do not disclose the potential security issue to any third party without Tractor Supply’s prior written permission.
- Avoid privacy violations, destruction of data, and interruption or degradation of our service.
- Only interact with accounts you own or with explicit permission of the account holder.
- Do not engage in any denial of service.
- Do not engage in any spamming of our customers or potential customers.
- Do not engage in social engineering (including phishing) of Tractor Supply employees, contractors or vendors.
- Do not engage in any physical attempts against Tractor Supply property or data centers.
- Once a report is submitted, Tractor Supply commits to provide prompt acknowledgement of receipt of all reports (within two business days of submission) and will keep you reasonably informed of the status of any validated vulnerability that you report through this program.
- You give us the right to use the content of your report for any purpose.
- Tractor Supply may update this policy from time to time.
How to Submit a Report
By reporting a security bug or vulnerability, you agree to the terms and conditions of this Tractor Supply Responsible Disclosure Statement.
Please visit our Responsible Disclosure Report form to submit a report.