CREA (REALTOR.ca) · Vulnerability Disclosure

Crea Vulnerability Disclosure

Vulnerability disclosure

CREA publishes an RFC 9116 security.txt on its corporate website, which is the estate's only vulnerability-disclosure channel. It is thin and partly broken: the security contact is CREA's web agency rather than a CREA address, and all three referenced pages return HTTP 404. No bug bounty programme (HackerOne, Bugcrowd, Intigriti) and no responsible-disclosure page could be found on crea.ca or realtor.ca.

CREA (REALTOR.ca) runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Real-EstateCanadaProperty ListingsMLSIDXRESOODataIndustry BodyPropTechData Syndication
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
tech@alphabetcreative.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: https://www.crea.ca/.well-known/security.txt
description: >-
  CREA publishes an RFC 9116 security.txt on its corporate website, which is the estate's only
  vulnerability-disclosure channel. It is thin and partly broken: the security contact is
  CREA's web agency rather than a CREA address, and all three referenced pages return HTTP 404.
  No bug bounty programme (HackerOne, Bugcrowd, Intigriti) and no responsible-disclosure page
  could be found on crea.ca or realtor.ca.
policy:
- https://www.crea.ca/security-policy
policy_status:
- url: https://www.crea.ca/security-policy
  status: 404
  note: Advertised as Policy in security.txt but returns HTTP 404 as of 2026-07-26.
contact:
- tech@alphabetcreative.com
contact_note: >-
  Alphabet Creative is CREA's web agency; the security.txt exposes no @crea.ca or @realtor.ca
  security address. General API support is support@realtor.ca (English only), which is a
  support channel, not a security channel.
security_txt:
  url: https://www.crea.ca/.well-known/security.txt
  status: 200
  file: well-known/crea-security.txt
  fields:
    Contact: tech@alphabetcreative.com
    Expiration: '2026-07-26T18:56:22-04:00'
    Encryption: https://www.crea.ca/pgp-key.txt
    Policy: https://www.crea.ca/security-policy
    Acknowledgements: https://www.crea.ca/hall-of-fame
  issues:
  - Expiration was the same day the file was harvested, so the document is at or past its own expiry.
  - Encryption key URL returns HTTP 404.
  - Policy URL returns HTTP 404.
  - Acknowledgements URL returns HTTP 404.
  - Not served on any API host (ddfapi.realtor.ca, boardapi.realtor.ca, identity.crea.ca) or on www.realtor.ca.
bug_bounty:
  program: null
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  found: false
disclosure_pages_checked:
- url: https://www.crea.ca/security/
  status: 404
- url: https://www.crea.ca/security-policy
  status: 404
evidence:
- source: https://www.crea.ca/.well-known/security.txt
  kind: security.txt (live probe)
  status: 200
- source: https://www.crea.ca/security-policy
  kind: linked policy page
  status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/crea-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.