CREA (REALTOR.ca) · Vulnerability Disclosure
Crea Vulnerability Disclosure
Vulnerability disclosure
CREA publishes an RFC 9116 security.txt on its corporate website, which is the estate's only vulnerability-disclosure channel. It is thin and partly broken: the security contact is CREA's web agency rather than a CREA address, and all three referenced pages return HTTP 404. No bug bounty programme (HackerOne, Bugcrowd, Intigriti) and no responsible-disclosure page could be found on crea.ca or realtor.ca.
CREA (REALTOR.ca) runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Real EstateCanadaProperty ListingsMLSIDXRESOODataIndustry BodyPropTechData Syndication
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
tech@alphabetcreative.com