generated: '2026-07-26' method: searched probe: true source: https://www.pexa.com.au/.well-known/security.txt policy: - https://www.pexa.com.au/security/ contact: - mailto:security@pexa.com.au evidence: - source: https://www.pexa.com.au/.well-known/security.txt kind: security.txt (live probe, HTTP 200, text/plain) - source: https://www.pexa.com.au/security/ kind: security policy page (HTTP 200) security_txt_file: well-known/pexa-security.txt security_txt: contact: mailto:security@pexa.com.au expires: '2026-09-03T23:59:59+10:00' preferred_language: en policy: https://www.pexa.com.au/security/ canonical: https://pexa.com.au/.well-known/security.txt rfc: RFC 9116 policy_page: url: https://www.pexa.com.au/security/ status: 200 title: PEXA Security Assurance covers: - report suspicious emails to security@pexa.com.au - caller verification via 03 7002 4500 - PEXA Support Centre 1300 084 515 - business cyber-security guidance - PEXA Residential Seller Guarantee (fraud protection for sellers) - PEXA Key app for secure communication of bank account details bug_bounty: program: null platform: null note: No public bug bounty was found on HackerOne, Bugcrowd or Intigriti, and no safe-harbour or reward terms are published. The disclosure route is the security.txt contact address and the security page. negative_findings: - https://trust.pexa.com.au/ does not resolve - https://security.pexa.com.au/ does not resolve - https://api.pexa.com.au/.well-known/security.txt returns 404 - No named certification (SOC 2, ISO 27001, PCI DSS) is asserted on any PEXA public page