generated: '2026-07-26' method: searched probe: true summary: >- Alto itself publishes no vulnerability-disclosure policy: neither vebraalto.com, altosoftware.co.uk nor the Alto API hosts serve a security.txt, and no responsible-disclosure page exists on the Alto marketing site or the developer portal. The Zoopla side of this estate does have one — zoopla.co.uk (the registrable domain the Zoopla Leads, Premium Listing and WFP APIs sit under) serves an RFC 9116 security.txt whose Contact is a public vulnerability-disclosure page. Security questions for the Alto API itself are routed through the partner support mailbox, not a disclosure programme. policy: - https://www.zoopla.co.uk/vulnerability-disclosure/ contact: - https://www.zoopla.co.uk/vulnerability-disclosure/ - connectsupport@altosoftwaregroup.co.uk security_txt: url: https://www.zoopla.co.uk/.well-known/security.txt status: 200 canonical: https://www.zoopla.co.uk/.well-known/security.txt expires: '2026-02-04T02:00:00Z' stale: true note: The Expires field had already elapsed when fetched on 2026-07-26; RFC 9116 treats an expired file as no longer valid. file: well-known/alto-vebra-security.txt bug_bounty: program: none found platforms_checked: - hackerone.com - bugcrowd.com - intigriti.com evidence: - source: https://www.zoopla.co.uk/.well-known/security.txt kind: security.txt status: 200 - source: https://zoopla.co.uk/.well-known/security.txt kind: security.txt status: 200 note: apex serves the same document, declaring the www host canonical - source: https://www.zoopla.co.uk/vulnerability-disclosure/ kind: disclosure-page status: 403 note: Cloudflare JavaScript interstitial blocks anonymous fetch; the URL is the declared Contact in the live security.txt - source: https://www.altosoftware.co.uk/.well-known/security.txt kind: security.txt status: 404 - source: https://id.vebraalto.com/.well-known/security.txt kind: security.txt status: 404 - source: https://api.alto.zoopla.co.uk/.well-known/security.txt kind: security.txt status: 404