Trestle · Vulnerability Disclosure

Trestle Vulnerability Disclosure

Vulnerability disclosure

Trestle itself publishes nothing about vulnerability reporting on its documentation site, and no host in the estate serves a /.well-known/security.txt. Its operator, Cotality (formerly CoreLogic), does run a real, publicly documented responsible-disclosure program with a Bugcrowd-hosted submission form, and it applies to "Cotality digital assets" — which includes the Trestle hosts. Regional variants of the same policy exist for the UK, Australia and New Zealand.

Trestle runs a coordinated vulnerability disclosure program on Bugcrowd.

Real-EstateUnited StatesMLSRESOProperty ListingsIDXPropTechData DistributionODataRETSListing Syndication
Program: Bugcrowd

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

trestle-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-26'
method: searched
probe: true
source: >-
  https://www.cotality.com/security (which serves the Responsible Disclosure
  Policy) and https://www.cotality.com/legal/responsible-disclosure-policy
description: >-
  Trestle itself publishes nothing about vulnerability reporting on its
  documentation site, and no host in the estate serves a /.well-known/security.txt.
  Its operator, Cotality (formerly CoreLogic), does run a real, publicly
  documented responsible-disclosure program with a Bugcrowd-hosted submission
  form, and it applies to "Cotality digital assets" — which includes the Trestle
  hosts. Regional variants of the same policy exist for the UK, Australia and
  New Zealand.
policy:
  - https://www.cotality.com/legal/responsible-disclosure-policy
  - https://www.cotality.com/security
submission:
  platform: Bugcrowd
  form: https://bugcrowd.com/8deb6c5b-41a8-4e16-9803-eccb85a1a968/external/report
  embedded_on: https://www.cotality.com/legal/responsible-disclosure-policy
  bug_bounty_advertised: false
  note: >-
    The page describes a vulnerability submission form, not a paid bounty; no
    reward table, scope list or safe-harbour text is published on the public
    page.
contact: []
contact_note: No security@ address is published; intake is the Bugcrowd form only.
regional_policies:
  - {region: US, url: https://www.cotality.com/legal/responsible-disclosure-policy}
  - {region: UK, url: https://www.cotality.com/uk/legal/responsible-disclosure-policy}
  - {region: AU, url: https://www.cotality.com/au/legal/responsible-disclosure-policy}
  - {region: NZ, url: https://www.cotality.com/nz/legal/responsible-disclosure-policy}
security_txt:
  published: false
  hosts_probed:
    - {host: https://api.cotality.com, status: 404}
    - {host: https://www.cotality.com, status: 404}
    - {host: https://trestle-documentation.corelogic.com, status: 404}
    - {host: https://trestle.corelogic.com, status: 404}
  recommendation: >-
    Publishing an RFC 9116 /.well-known/security.txt pointing at the existing
    Bugcrowd form would make this program machine-discoverable at zero cost.
evidence:
  - source: https://www.cotality.com/legal/responsible-disclosure-policy
    kind: disclosure-policy
    quote: >-
      "We are committed to the responsible and ethical disclosure of
      vulnerabilities and the security of Cotality digital assets… Please use
      our official vulnerability submission form to share your findings."
  - source: https://www.cotality.com/legal/responsible-disclosure-policy
    kind: bugcrowd-embed
    detail: >-
      Page embeds bugcrowd.com/8deb6c5b-41a8-4e16-9803-eccb85a1a968/external/script
      with data-bugcrowd-program pointing at the external report form.
scope_caveat: >-
  The policy is written at the Cotality corporate level. It does not enumerate
  in-scope domains, so whether api.cotality.com and
  trestle-documentation.corelogic.com are formally in scope is not stated.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/trestle-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.