Nesto · Vulnerability Disclosure

Nesto Vulnerability Disclosure

Vulnerability disclosure

Nesto publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Real EstateCanadaMortgageLendingPropTechMortgage TechnologyFinancial ServicesUnderwritingLoan Servicing
Program: security.txt present

Disclosure Policy

Policy
Policy
Policy

Security Contact

Contact
mailto:security@nesto.ca
Contact
mailto:support@nesto.ca
Contact
https://www.nesto.ca/contact/

Source

Vulnerability Disclosure

nesto-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: https://www.nesto.ca/security/
policy:
- https://www.nesto.ca/security/
- https://www.nesto.ca/.well-known/security.txt
- https://www.nesto.ca/contact/
contact:
- mailto:security@nesto.ca
- mailto:support@nesto.ca
- https://www.nesto.ca/contact/
encryption: https://www.nesto.ca/.well-known/pgp-key.txt
preferred_languages: [en, fr]
scope:
- '*.nesto.ca'
- Web applications, APIs, and customer-facing services
bug_bounty:
  offered: false
  platform: null
  statement: >-
    "we do not offer compensation for vulnerability disclosures" — nesto.ca/security/.
    The security.txt adds: "We might not send you a bounty, but we *will* send gratitude,
    respect, and fast fixes."
safe_harbor:
  published: false
  note: >-
    No explicit legal safe-harbour language. The published expectation is: "Please report
    vulnerabilities privately and give us a reasonable time to investigate before public
    disclosure."
gaps:
- security.txt has no `Expires:` field (RFC 9116 requires it)
- 'Policy: points at a generic contact form rather than a dedicated disclosure policy page'
- The security.txt Contact is support@nesto.ca while the /security/ page routes to
  security@nesto.ca — two different intake addresses for the same program
- No CVD program page, no acknowledgements/hall-of-fame, no response SLA
evidence:
- source: https://www.nesto.ca/.well-known/security.txt
  kind: security.txt (live probe, HTTP 200)
- source: https://www.nesto.ca/security/
  kind: first-party security policy page (HTTP 200)
  keywords: [report a security issue, security@nesto.ca, we do not offer compensation]
- source: well-known/nesto-security.txt
  kind: harvested security.txt