CREA (REALTOR.ca) · Vulnerability Disclosure

Crea Vulnerability Disclosure

Vulnerability disclosure

CREA publishes an RFC 9116 security.txt on its corporate website, which is the estate's only vulnerability-disclosure channel. It is thin and partly broken: the security contact is CREA's web agency rather than a CREA address, and all three referenced pages return HTTP 404. No bug bounty programme (HackerOne, Bugcrowd, Intigriti) and no responsible-disclosure page could be found on crea.ca or realtor.ca.

CREA (REALTOR.ca) runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Real EstateCanadaProperty ListingsMLSIDXRESOODataIndustry BodyPropTechData Syndication
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
tech@alphabetcreative.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: https://www.crea.ca/.well-known/security.txt
description: >-
  CREA publishes an RFC 9116 security.txt on its corporate website, which is the estate's only
  vulnerability-disclosure channel. It is thin and partly broken: the security contact is
  CREA's web agency rather than a CREA address, and all three referenced pages return HTTP 404.
  No bug bounty programme (HackerOne, Bugcrowd, Intigriti) and no responsible-disclosure page
  could be found on crea.ca or realtor.ca.
policy:
- https://www.crea.ca/security-policy
policy_status:
- url: https://www.crea.ca/security-policy
  status: 404
  note: Advertised as Policy in security.txt but returns HTTP 404 as of 2026-07-26.
contact:
- tech@alphabetcreative.com
contact_note: >-
  Alphabet Creative is CREA's web agency; the security.txt exposes no @crea.ca or @realtor.ca
  security address. General API support is support@realtor.ca (English only), which is a
  support channel, not a security channel.
security_txt:
  url: https://www.crea.ca/.well-known/security.txt
  status: 200
  file: well-known/crea-security.txt
  fields:
    Contact: tech@alphabetcreative.com
    Expiration: '2026-07-26T18:56:22-04:00'
    Encryption: https://www.crea.ca/pgp-key.txt
    Policy: https://www.crea.ca/security-policy
    Acknowledgements: https://www.crea.ca/hall-of-fame
  issues:
  - Expiration was the same day the file was harvested, so the document is at or past its own expiry.
  - Encryption key URL returns HTTP 404.
  - Policy URL returns HTTP 404.
  - Acknowledgements URL returns HTTP 404.
  - Not served on any API host (ddfapi.realtor.ca, boardapi.realtor.ca, identity.crea.ca) or on www.realtor.ca.
bug_bounty:
  program: null
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  found: false
disclosure_pages_checked:
- url: https://www.crea.ca/security/
  status: 404
- url: https://www.crea.ca/security-policy
  status: 404
evidence:
- source: https://www.crea.ca/.well-known/security.txt
  kind: security.txt (live probe)
  status: 200
- source: https://www.crea.ca/security-policy
  kind: linked policy page
  status: 404