generated: '2026-07-26' method: searched probe: true scope: parent-company scope_note: >- Homes.com itself publishes no vulnerability disclosure surface: no /.well-known/security.txt is retrievable (every path on www.homes.com returns 403 behind Akamai bot protection, and support.homes.com — the one reachable Homes.com host — returns 404 for /.well-known/security.txt), and there is no security or responsible-disclosure page on any reachable Homes.com host. The disclosure channel recorded here is the one published by CoStar Group, Inc., the owner and operator of Homes.com, on its SafeBase trust center. policy: - https://trust.costargroup.com/ contact: - csgpappsec@costar.com - costarsecurity1@costar.com program: type: responsible-disclosure bug_bounty: false platform: null note: >- No HackerOne, Bugcrowd, or Intigriti program was found for Homes.com, Homesnap, or CoStar Group. The published channel is an email intake on the trust center — verbatim: "If you think you may have discovered a vulnerability, please send us a note", linking to mailto:csgpappsec@costar.com with the subject "SafeBase Responsible Disclosure Report for CoStar Group". No safe-harbour language, no scope statement, and no reward schedule are published. safe_harbor: unknown scope_published: false rewards: false security_txt: published: false probes: - url: https://www.homes.com/.well-known/security.txt status: 403 note: Akamai bot protection; 403 to browser-header requests alike. - url: https://support.homes.com/.well-known/security.txt status: 404 - url: https://www.costargroup.com/.well-known/security.txt status: 404 - url: https://costargroup.com/.well-known/security.txt status: 404 - url: https://www.costar.com/.well-known/security.txt status: 404 - url: https://trust.costargroup.com/.well-known/security.txt status: 403 evidence: - source: https://trust.costargroup.com/ kind: trust-center-disclosure-section status: 403 note: >- 403 to curl (Cloudflare managed challenge); disclosure section read via rendering fetch on 2026-07-26.