generated: '2026-08-09' method: searched probe: true scope: open-source-repository-only summary: >- Zillapi publishes a security policy, but only for its open-source agent-skills repository — not for the API service. There is no /.well-known/security.txt on either host, no bug bounty, and no disclosure page on zillapi.com. Recorded with that scope stated plainly rather than as a service-level VDP. policy: - https://github.com/ZeroPointRepo/zillow-skills/blob/main/SECURITY.md contact: - nikhil@landkit.pro terms: subject_line: 'SECURITY: zillow-skills' public_issues: not permitted for security reports acknowledgement_sla: 72 hours fix_target: 14 days for confirmed issues bug_bounty: program: null platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: false probes: - {url: 'https://zillapi.com/.well-known/security.txt', status: 404} - {url: 'https://api.zillapi.com/.well-known/security.txt', status: 404} - {url: 'https://github.com/ZeroPointRepo/zillow-skills/blob/main/SECURITY.md', status: 200} evidence: - source: https://github.com/ZeroPointRepo/zillow-skills/blob/main/SECURITY.md kind: security-policy fetched: '2026-08-09' excerpt: >- "Email nikhil@landkit.pro with the subject line `SECURITY: zillow-skills`. Please do not open public issues for security reports. We will acknowledge receipt within 72 hours and aim to publish a fix or mitigation within 14 days for confirmed issues." gap: >- The API service itself has no published disclosure route. A researcher who finds a flaw in api.zillapi.com has no documented channel — the only published contact is a repo-scoped address for the skills bundle. An RFC 9116 /.well-known/security.txt on zillapi.com would close this.