Trestle · Vulnerability Disclosure

Trestle Vulnerability Disclosure

Vulnerability disclosure

Trestle itself publishes nothing about vulnerability reporting on its documentation site, and no host in the estate serves a /.well-known/security.txt. Its operator, Cotality (formerly CoreLogic), does run a real, publicly documented responsible-disclosure program with a Bugcrowd-hosted submission form, and it applies to "Cotality digital assets" — which includes the Trestle hosts. Regional variants of the same policy exist for the UK, Australia and New Zealand.

Trestle runs a coordinated vulnerability disclosure program on Bugcrowd.

Real EstateUnited StatesMLSRESOProperty ListingsIDXPropTechData DistributionODataRETSListing Syndication
Program: Bugcrowd

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

trestle-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: >-
  https://www.cotality.com/security (which serves the Responsible Disclosure
  Policy) and https://www.cotality.com/legal/responsible-disclosure-policy
description: >-
  Trestle itself publishes nothing about vulnerability reporting on its
  documentation site, and no host in the estate serves a /.well-known/security.txt.
  Its operator, Cotality (formerly CoreLogic), does run a real, publicly
  documented responsible-disclosure program with a Bugcrowd-hosted submission
  form, and it applies to "Cotality digital assets" — which includes the Trestle
  hosts. Regional variants of the same policy exist for the UK, Australia and
  New Zealand.
policy:
  - https://www.cotality.com/legal/responsible-disclosure-policy
  - https://www.cotality.com/security
submission:
  platform: Bugcrowd
  form: https://bugcrowd.com/8deb6c5b-41a8-4e16-9803-eccb85a1a968/external/report
  embedded_on: https://www.cotality.com/legal/responsible-disclosure-policy
  bug_bounty_advertised: false
  note: >-
    The page describes a vulnerability submission form, not a paid bounty; no
    reward table, scope list or safe-harbour text is published on the public
    page.
contact: []
contact_note: No security@ address is published; intake is the Bugcrowd form only.
regional_policies:
  - {region: US, url: https://www.cotality.com/legal/responsible-disclosure-policy}
  - {region: UK, url: https://www.cotality.com/uk/legal/responsible-disclosure-policy}
  - {region: AU, url: https://www.cotality.com/au/legal/responsible-disclosure-policy}
  - {region: NZ, url: https://www.cotality.com/nz/legal/responsible-disclosure-policy}
security_txt:
  published: false
  hosts_probed:
    - {host: https://api.cotality.com, status: 404}
    - {host: https://www.cotality.com, status: 404}
    - {host: https://trestle-documentation.corelogic.com, status: 404}
    - {host: https://trestle.corelogic.com, status: 404}
  recommendation: >-
    Publishing an RFC 9116 /.well-known/security.txt pointing at the existing
    Bugcrowd form would make this program machine-discoverable at zero cost.
evidence:
  - source: https://www.cotality.com/legal/responsible-disclosure-policy
    kind: disclosure-policy
    quote: >-
      "We are committed to the responsible and ethical disclosure of
      vulnerabilities and the security of Cotality digital assets… Please use
      our official vulnerability submission form to share your findings."
  - source: https://www.cotality.com/legal/responsible-disclosure-policy
    kind: bugcrowd-embed
    detail: >-
      Page embeds bugcrowd.com/8deb6c5b-41a8-4e16-9803-eccb85a1a968/external/script
      with data-bugcrowd-program pointing at the external report form.
scope_caveat: >-
  The policy is written at the Cotality corporate level. It does not enumerate
  in-scope domains, so whether api.cotality.com and
  trestle-documentation.corelogic.com are formally in scope is not stated.