Security policy
Last updated October 7, 2026 · McIntosh.Farm LLC
We take the security of farm records seriously. If you find a vulnerability in TractorTrack or mcintosh.farm, please tell us.
How to report
Email [email protected] with “Security” in the subject line. Include:
- What you found and where (the URL, API endpoint or app screen).
- Steps to reproduce it, and what an attacker could do with it.
- Your contact details, if you’d like credit or updates.
We’ll acknowledge your report within 5 business days, keep you updated, and tell you when it’s fixed.
Ground rules
If you follow these, we won’t pursue legal action against you for your research:
- Only test with accounts you created. Never access, change or delete other people’s data. If you come across it by accident, stop, and tell us.
- Don’t degrade the service: no denial-of-service, load testing, spam or automated scanning that sends large volumes of requests.
- No social engineering, phishing or physical attacks, and don’t test our providers (Cloudflare, Google, Apple, Stripe) through us.
- Give us a reasonable time to fix the problem before you share it publicly.
In scope
mcintosh.farmtractor-tracker.mcintosh.farm(web app and/api/)- The TractorTrack iPhone app
Other *.mcintosh.farm names are private systems and out of scope.
We’re a small company and don’t offer paid bug bounties, but we’re grateful for every report and will credit you if you’d like.