TractorTrack™

Security policy

Last updated October 7, 2026 · McIntosh.Farm LLC

We take the security of farm records seriously. If you find a vulnerability in TractorTrack or mcintosh.farm, please tell us.

How to report

Email [email protected] with “Security” in the subject line. Include:

  • What you found and where (the URL, API endpoint or app screen).
  • Steps to reproduce it, and what an attacker could do with it.
  • Your contact details, if you’d like credit or updates.

We’ll acknowledge your report within 5 business days, keep you updated, and tell you when it’s fixed.

Ground rules

If you follow these, we won’t pursue legal action against you for your research:

  • Only test with accounts you created. Never access, change or delete other people’s data. If you come across it by accident, stop, and tell us.
  • Don’t degrade the service: no denial-of-service, load testing, spam or automated scanning that sends large volumes of requests.
  • No social engineering, phishing or physical attacks, and don’t test our providers (Cloudflare, Google, Apple, Stripe) through us.
  • Give us a reasonable time to fix the problem before you share it publicly.

In scope

  • mcintosh.farm
  • tractor-tracker.mcintosh.farm (web app and /api/)
  • The TractorTrack iPhone app

Other *.mcintosh.farm names are private systems and out of scope.

We’re a small company and don’t offer paid bug bounties, but we’re grateful for every report and will credit you if you’d like.