Effective Date: March 25, 2025
Staples is committed to ensuring the security of our customers and the information they share with us via our online platforms and services. We also recognize the valuable efforts that security researchers play in highlighting cybersecurity vulnerabilities and concerns. The purpose of this policy is to provide clear guidelines for conducting vulnerability discovery activities and to convey how to submit discovered vulnerabilities.
If you act in good faith and adhere to this policy, Staples commits to not pursuing legal action or referring the matter to law enforcement. Any ambiguities will be resolved in favor of security researchers acting ethically and responsibly.
This policy requires that you:
Once you’ve established that a vulnerability exists or encounter any confidential or sensitive data (including personal information, financial information, or proprietary information), you must stop your test, notify us immediately and not disclose this data to anyone else.
The following test methods are not authorized:
This policy applies to the following Staples family websites and services:
Testing under this policy is strictly limited to the web applications listed above. Network infrastructure, internal systems, and third-party services (including cloud environments) are out of scope. If you believe a security issue exists outside the defined scope that affects Staples, please contact us at [email protected] before conducting any testing.
We may update this scope over time, and we encourage researchers to check back periodically for changes.
We accept vulnerability reports via email to [email protected]. Reports may be submitted anonymously.
What we would like to see from you
In order to help us triage and prioritize submissions, we recommend that your report:
What you can expect from us
If you submit a valid security vulnerability in compliance with this policy, we will:
Note that Staples does not operate a bug bounty program and we make no offer of compensation in exchange for submitting potential issues.
Staples may modify the terms of this policy or terminate this policy at any time.
If you are in doubt about the scope, acceptable test methods or any other provisions of this policy, you are encouraged to contact us first at [email protected]. We also invite you to contact us with suggestions for improving this policy.