Homes.com · Trust Center
Homes Com Trust Center
Trust center
Homes.com maintains a public trust center documenting PCI DSS, ISO/IEC 27001, NIST CSF, SOC 1 Type 2, and SOC 1 Type 2 compliance.
Real-EstateUnited StatesProperty ListingsMLSRESOIDXRentalsPropTechPortalMarketplacesResidential Real EstateReal Estate AgentsBrokersListings SyndicationCoStar Group
Trust center: https://trust.costargroup.com/
Certifications & Compliance
PCI DSSISO/IEC 27001NIST CSFSOC 1 Type 2SOC 1 Type 2
Source
Trust Center
generated: '2026-07-26'
method: searched
probe: true
source: https://trust.costargroup.com/
url: https://trust.costargroup.com/
scope: parent-company
scope_note: >-
Homes.com publishes no trust center of its own — trust.homes.com is NXDOMAIN
and every path on www.homes.com returns HTTP 403 to non-browser clients behind
Akamai bot protection. The trust center recorded here belongs to CoStar Group,
Inc., the company that owns and operates Homes.com (acquired 2021, Homesnap
folded in). It is the corporate security posture that governs the Homes.com
property, but the portal does NOT name Homes.com, Apartments.com, Homesnap, or
LoopNet in its covered-product list; the only products named explicitly are
Visual Lease and CoStar Real Estate Manager. Read the certifications below as
CoStar Group corporate scope, not as a Homes.com-specific attestation.
platform: SafeBase
platform_evidence:
dns_cname: costargroup.portals.safebase.io
note: >-
trust.costargroup.com is a CNAME to costargroup.portals.safebase.io — a
SafeBase-hosted trust portal. The host is fronted by Cloudflare and returns
HTTP 403 with a managed browser challenge to curl; content below was read
through a rendering fetch.
certifications:
- name: PCI DSS
scope: CoStar Group
- name: ISO/IEC 27001
scope: CoStar Group
- name: NIST CSF
scope: CoStar Group
note: Framework alignment, listed alongside the certifications on the portal.
- name: SOC 1 Type 2
scope: Visual Lease
period: 'November 1, 2025 to April 30, 2026'
verbatim: >-
Visual Lease SOC 1 Type 2 attestation report for the examination period
from November 1, 2025 to April 30, 2026
- name: SOC 1 Type 2
scope: CoStar Real Estate Manager
period: 'April 1, 2025 to March 31, 2026'
verbatim: >-
CoStar Real Estate Manager's SOC 1 Type 2 attestation report for the
examination period from April 1, 2025 to March 31, 2026
not_found:
- SOC 2
- HIPAA
- FedRAMP
- CSA STAR
- subprocessor list
contacts:
security: costarsecurity1@costar.com
vulnerability_disclosure: csgpappsec@costar.com
document_access: >-
Attestation reports are listed on the portal; SafeBase gates document download
behind an NDA/request flow. No report was downloaded.
evidence:
- source: https://trust.costargroup.com/
status: 403
note: >-
403 to curl (Cloudflare managed challenge); content read via rendering
fetch on 2026-07-26.
keywords: [pci dss, iso/iec 27001, nist csf, soc 1 type 2, trust center]
- source: dig CNAME trust.costargroup.com
result: costargroup.portals.safebase.io
kind: dns
probes:
- url: https://trust.homes.com/
status: 000
note: DNS NXDOMAIN — Homes.com publishes no trust center subdomain.
- url: https://trust.costargroup.com/
status: 403
- url: https://security.costargroup.com/
status: 000
note: DNS NXDOMAIN.
- url: https://trust.costargroup.com/.well-known/security.txt
status: 403
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/homes-com-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.