
Staples
External Program
Submit bugs directly to this organization
Effective Date: February 1, 2021
Staples is committed to ensuring the security of our customers and the information they share with us via our online platforms and services. We also recognize the valuable efforts that security researchers play in highlighting cybersecurity vulnerabilities and concerns. The purpose of this policy is to provide clear guidelines for conducting vulnerability discovery activities and to convey how to submit discovered vulnerabilities.
If you comply with this policy during your security research, and you discover and report security vulnerabilities in accordance with this policy, we will not take legal action against you. We reserve all legal rights in the event of any non-compliance with this policy.
This policy requires that you:
Once you’ve established that a vulnerability exists or encounter any confidential or sensitive data (including personal information, financial information, or proprietary information), you must stop your test, notify us immediately and not disclose this data to anyone else.
The following test methods are not authorized:
This policy applies to the following Staples family websites and services:
Though we develop and maintain other Internet-accessible systems and services, research and testing under this policy is restricted to the systems and services listed in this section. If there is a particular system or service not in scope that you think merits testing, please contact us to discuss. We may change the scope of this policy over time.
We accept vulnerability reports via email to [email protected]. Reports may be submitted anonymously.
What we would like to see from you
In order to help us triage and prioritize submissions, we recommend that your report:
What you can expect from us
If you submit a valid security vulnerability in compliance with this policy, we will:
Note that Staples does not operate a bug bounty program and we make no offer of compensation in exchange for submitting potential issues.
Staples may modify the terms of this policy or terminate this policy at any time.
If you are in doubt about the scope, acceptable test methods or any other provisions of this policy, you are encouraged to contact us first at [email protected]. We also invite you to contact us with suggestions for improving this policy.