generated: '2026-07-26' method: searched probe: true source: >- https://www.cotality.com/security (which serves the Responsible Disclosure Policy) and https://www.cotality.com/legal/responsible-disclosure-policy description: >- Trestle itself publishes nothing about vulnerability reporting on its documentation site, and no host in the estate serves a /.well-known/security.txt. Its operator, Cotality (formerly CoreLogic), does run a real, publicly documented responsible-disclosure program with a Bugcrowd-hosted submission form, and it applies to "Cotality digital assets" — which includes the Trestle hosts. Regional variants of the same policy exist for the UK, Australia and New Zealand. policy: - https://www.cotality.com/legal/responsible-disclosure-policy - https://www.cotality.com/security submission: platform: Bugcrowd form: https://bugcrowd.com/8deb6c5b-41a8-4e16-9803-eccb85a1a968/external/report embedded_on: https://www.cotality.com/legal/responsible-disclosure-policy bug_bounty_advertised: false note: >- The page describes a vulnerability submission form, not a paid bounty; no reward table, scope list or safe-harbour text is published on the public page. contact: [] contact_note: No security@ address is published; intake is the Bugcrowd form only. regional_policies: - {region: US, url: https://www.cotality.com/legal/responsible-disclosure-policy} - {region: UK, url: https://www.cotality.com/uk/legal/responsible-disclosure-policy} - {region: AU, url: https://www.cotality.com/au/legal/responsible-disclosure-policy} - {region: NZ, url: https://www.cotality.com/nz/legal/responsible-disclosure-policy} security_txt: published: false hosts_probed: - {host: https://api.cotality.com, status: 404} - {host: https://www.cotality.com, status: 404} - {host: https://trestle-documentation.corelogic.com, status: 404} - {host: https://trestle.corelogic.com, status: 404} recommendation: >- Publishing an RFC 9116 /.well-known/security.txt pointing at the existing Bugcrowd form would make this program machine-discoverable at zero cost. evidence: - source: https://www.cotality.com/legal/responsible-disclosure-policy kind: disclosure-policy quote: >- "We are committed to the responsible and ethical disclosure of vulnerabilities and the security of Cotality digital assets… Please use our official vulnerability submission form to share your findings." - source: https://www.cotality.com/legal/responsible-disclosure-policy kind: bugcrowd-embed detail: >- Page embeds bugcrowd.com/8deb6c5b-41a8-4e16-9803-eccb85a1a968/external/script with data-bugcrowd-program pointing at the external report form. scope_caveat: >- The policy is written at the Cotality corporate level. It does not enumerate in-scope domains, so whether api.cotality.com and trestle-documentation.corelogic.com are formally in scope is not stated.