Nesto · Vulnerability Disclosure

Nesto Vulnerability Disclosure

Vulnerability disclosure

Nesto publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Real-EstateCanadaMortgageLendingPropTechMortgage TechnologyFinancial-ServicesUnderwritingLoan Servicing
Program: security.txt present

Disclosure Policy

Policy
Policy
Policy

Security Contact

Contact
mailto:security@nesto.ca
Contact
mailto:support@nesto.ca
Contact
https://www.nesto.ca/contact/

Source

Vulnerability Disclosure

nesto-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: https://www.nesto.ca/security/
policy:
- https://www.nesto.ca/security/
- https://www.nesto.ca/.well-known/security.txt
- https://www.nesto.ca/contact/
contact:
- mailto:security@nesto.ca
- mailto:support@nesto.ca
- https://www.nesto.ca/contact/
encryption: https://www.nesto.ca/.well-known/pgp-key.txt
preferred_languages: [en, fr]
scope:
- '*.nesto.ca'
- Web applications, APIs, and customer-facing services
bug_bounty:
  offered: false
  platform: null
  statement: >-
    "we do not offer compensation for vulnerability disclosures" — nesto.ca/security/.
    The security.txt adds: "We might not send you a bounty, but we *will* send gratitude,
    respect, and fast fixes."
safe_harbor:
  published: false
  note: >-
    No explicit legal safe-harbour language. The published expectation is: "Please report
    vulnerabilities privately and give us a reasonable time to investigate before public
    disclosure."
gaps:
- security.txt has no `Expires:` field (RFC 9116 requires it)
- 'Policy: points at a generic contact form rather than a dedicated disclosure policy page'
- The security.txt Contact is support@nesto.ca while the /security/ page routes to
  security@nesto.ca — two different intake addresses for the same program
- No CVD program page, no acknowledgements/hall-of-fame, no response SLA
evidence:
- source: https://www.nesto.ca/.well-known/security.txt
  kind: security.txt (live probe, HTTP 200)
- source: https://www.nesto.ca/security/
  kind: first-party security policy page (HTTP 200)
  keywords: [report a security issue, security@nesto.ca, we do not offer compensation]
- source: well-known/nesto-security.txt
  kind: harvested security.txt

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/nesto-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.