generated: '2026-08-01' method: searched sources: - https://learn.crexi.com/listing-partnerships-crexi-help-center - https://learn.crexi.com/listing-api-overview-crexi-help-center - https://api.crexi.com/.well-known/openid-configuration - https://api.crexi.com/.well-known/oauth-authorization-server standards: - id: reso-data-dictionary name: RESO Data Dictionary organization: Real Estate Standards Organization conforms: true evidence: 'CREXi states on its Listing Partnerships help-centre page: "We are 100% compliant with the Real Estate Standards Organization''s (RESO) Data Dictionary".' source: https://learn.crexi.com/listing-partnerships-crexi-help-center scope: Listing API / listing syndication feeds - id: reso-web-api name: RESO Web API organization: Real Estate Standards Organization conforms: true evidence: The Listing API Overview lists "RESO, RETS, WebAPI, etc." among the data-feed formats CREXi accepts from listing partners. source: https://learn.crexi.com/listing-api-overview-crexi-help-center scope: Inbound partner feeds (CREXi consumes these formats; it does not publish a RESO Web API endpoint of its own). - id: rets name: RETS (Real Estate Transaction Standard) organization: Real Estate Standards Organization conforms: true evidence: RETS is named as an accepted partner feed format alongside RESO, WebAPI and XML. source: https://learn.crexi.com/listing-api-overview-crexi-help-center scope: Inbound partner feeds (legacy format). - id: oauth2 name: OAuth 2.0 conforms: true evidence: api.crexi.com operates an OAuth 2.0 authorization server with a /token endpoint and advertises password, refresh_token, switch_user and single_use_token_exchange grants. source: well-known/crexi-oauth-authorization-server.json - id: rfc8414-oauth-authorization-server-metadata name: RFC 8414 OAuth 2.0 Authorization Server Metadata conforms: true evidence: /.well-known/oauth-authorization-server returns HTTP 200 with a valid metadata document. source: well-known/crexi-oauth-authorization-server.json - id: oidc-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: /.well-known/openid-configuration returns HTTP 200 with issuer, token_endpoint, jwks_uri, id_token_signing_alg_values_supported (RS256) and subject_types_supported. source: well-known/crexi-openid-configuration.json - id: rfc7517-jwks name: RFC 7517 JSON Web Key Set conforms: true evidence: /.well-known/jwks returns an RSA RS256 signing key set. source: well-known/crexi-jwks.json - id: openapi name: OpenAPI Specification conforms: true partial: true evidence: 'Both CREXi API hosts serve Swagger tooling — a Swagger UI gateway at exchange.crexi.com with its document at /swagger/docs/v1, and a Swashbuckle Swagger UI at api.crexi.com/swagger — but every specification URL is authentication-gated (302 to an API-key login, and HTTP 401 Basic respectively), so no document could be retrieved or validated.' gated: true - id: rfc9457-problem-details conforms: unknown evidence: Cannot be assessed — no retrievable specification and no public error reference. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on api.crexi.com, exchange.crexi.com or learn.crexi.com (404). The www host returns a Cloudflare 403 challenge, so that result is inconclusive. - id: a2a-agent-card conforms: false evidence: No /.well-known/agent-card.json or /.well-known/agent.json on any CREXi host. - id: asyncapi conforms: false evidence: No published event, streaming or webhook surface was found. compliance_program: published: false note: 'No trust centre, and no named security/privacy certifications (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) were found on any publicly reachable CREXi host. The RESO Data Dictionary claim above is a data-standard conformance statement, not a certification programme, so no `Compliance` pointer is emitted.' x-evidence: fetched: '2026-08-01'