Zillow Group · Vulnerability Disclosure
Zillow Group Vulnerability Disclosure
Vulnerability disclosure
Zillow operates a published responsible-disclosure program with a Bugcrowd-backed intake and an explicit safe-harbour statement. It is published as an HTML policy page, not as an RFC 9116 /.well-known/security.txt — the machine-readable path was probed on seven Zillow Group and subsidiary hosts on 2026-08-28 and is served nowhere.
Zillow Group runs a coordinated vulnerability disclosure program on Bugcrowd.
Real-EstateProperty DataMLSMortgageRentalsValuationHousing DataTransaction Management
Program: Bugcrowd
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.