generated: '2026-07-26' method: searched probe: true source: https://www.crea.ca/.well-known/security.txt status: published-but-unmaintained policy: [] contact: - tech@alphabetcreative.com security_txt: url: https://www.crea.ca/.well-known/security.txt status: 200 file: well-known/realtor-ca-security.txt format: RFC 9116 expiration: '2026-07-26T18:56:22-04:00' expired_at_fetch: true declared_but_broken: - field: Policy url: https://www.crea.ca/security-policy status: 404 - field: Encryption url: https://www.crea.ca/pgp-key.txt status: 404 - field: Acknowledgements url: https://www.crea.ca/hall-of-fame status: 404 bug_bounty: program: null platform: null note: >- No HackerOne, Bugcrowd or Intigriti program found for crea.ca or realtor.ca; no bounty or responsible-disclosure page exists on either domain. evidence: - source: https://www.crea.ca/.well-known/security.txt kind: security.txt finding: >- A real RFC 9116 file is served at the canonical location with a security contact — tech@alphabetcreative.com, CREA's web agency rather than a CREA security function. Every URL the file points at (Policy, Encryption, Acknowledgements) returns 404, and the Expiration timestamp had already lapsed when fetched, so the file is published but not maintained. - source: https://ddfapi.realtor.ca/.well-known/security.txt kind: probe status: 404 finding: The API host itself carries no security.txt. - source: https://www.realtor.ca/security.txt kind: probe status: 200 trusted: false finding: >- Discarded. www.realtor.ca sits behind Imperva/Incapsula and returns 200 with an identical ~1KB challenge shell for any path, including a control request for a nonexistent path. - source: https://www.crea.ca/security-policy kind: probe status: 404 finding: The disclosure policy the security.txt advertises does not exist.