Zillow Group · Vulnerability Disclosure

Zillow Group Vulnerability Disclosure

Vulnerability disclosure

Zillow operates a published responsible-disclosure program with a Bugcrowd-backed intake and an explicit safe-harbour statement. It is published as an HTML policy page, not as an RFC 9116 /.well-known/security.txt — the machine-readable path was probed on seven Zillow Group and subsidiary hosts on 2026-08-28 and is served nowhere.

Zillow Group runs a coordinated vulnerability disclosure program on Bugcrowd.

Real-EstateProperty DataMLSMortgageRentalsValuationHousing DataTransaction Management
Program: Bugcrowd

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

zillow-group-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-28'
method: searched
source: https://www.zillow.com/corporate/security-disclosure/
description: >-
  Zillow operates a published responsible-disclosure program with a Bugcrowd-backed intake and
  an explicit safe-harbour statement. It is published as an HTML policy page, not as an RFC 9116
  /.well-known/security.txt — the machine-readable path was probed on seven Zillow Group and
  subsidiary hosts on 2026-08-28 and is served nowhere.
program:
  published: true
  name: Zillow Security Disclosure
  policy_url: https://www.zillow.com/corporate/security-disclosure/
  intake: web form on the policy page
  platform: Bugcrowd
  platform_role: >-
    Zillow partners with Bugcrowd to validate and assess reported vulnerabilities, and rates
    findings with the Bugcrowd Vulnerability Rating Taxonomy (VRT).
  bounty: >-
    Reported as a paid program; the program is not listed as a public Bugcrowd engagement
    (bugcrowd.com/zillow, /engagements/zillow and /programs/zillow all returned 404 on
    2026-08-28), so intake runs through Zillow's own form rather than a public bounty page.
  safe_harbour: true
  safe_harbour_text: >-
    Zillow states it will not take legal action against, nor suspend or terminate the accounts
    of, researchers who discover and report security vulnerabilities in good faith and in
    accordance with its Vulnerability Disclosure Policy.
security_txt:
  served: false
  probed_hosts:
    - www.zillowgroup.com
    - www.zillow.com
    - api-gateway.dotloop.com
    - auth.dotloop.com
    - api.bridgedataoutput.com
    - bridgedataoutput.com
    - dotloop.github.io
  note: >-
    Every host returned 404, 401, 403 or an SPA catch-all shell. No `SecurityTxt` pointer is
    emitted. Publishing an RFC 9116 file at https://www.zillow.com/.well-known/security.txt
    pointing at the existing policy page would be a one-line fix.
x-evidence:
  - url: https://www.zillow.com/corporate/security-disclosure/
    status: 403
    fetched: '2026-08-28'
    note: >-
      HONEST RECORD OF THE PROBE. zillow.com sits behind a PerimeterX edge that answers
      "Access to this page has been denied" (5,856 bytes) to every non-browser client, including
      a full desktop Chrome user-agent and WebFetch. The page demonstrably exists and is indexed
      under the title "Security Disclosure | Zillow"; the 403 is a bot challenge against our
      crawler, not a dead page, and is recorded as such rather than treated as absent.
  - url: https://bugcrowd.com/zillow
    status: 404
    fetched: '2026-08-28'
  - url: https://www.zillow.com/.well-known/security.txt
    status: 404
    fetched: '2026-08-28'
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/zillow-group-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.