generated: '2026-08-28' method: searched source: https://www.zillow.com/corporate/security-disclosure/ description: >- Zillow operates a published responsible-disclosure program with a Bugcrowd-backed intake and an explicit safe-harbour statement. It is published as an HTML policy page, not as an RFC 9116 /.well-known/security.txt — the machine-readable path was probed on seven Zillow Group and subsidiary hosts on 2026-08-28 and is served nowhere. program: published: true name: Zillow Security Disclosure policy_url: https://www.zillow.com/corporate/security-disclosure/ intake: web form on the policy page platform: Bugcrowd platform_role: >- Zillow partners with Bugcrowd to validate and assess reported vulnerabilities, and rates findings with the Bugcrowd Vulnerability Rating Taxonomy (VRT). bounty: >- Reported as a paid program; the program is not listed as a public Bugcrowd engagement (bugcrowd.com/zillow, /engagements/zillow and /programs/zillow all returned 404 on 2026-08-28), so intake runs through Zillow's own form rather than a public bounty page. safe_harbour: true safe_harbour_text: >- Zillow states it will not take legal action against, nor suspend or terminate the accounts of, researchers who discover and report security vulnerabilities in good faith and in accordance with its Vulnerability Disclosure Policy. security_txt: served: false probed_hosts: - www.zillowgroup.com - www.zillow.com - api-gateway.dotloop.com - auth.dotloop.com - api.bridgedataoutput.com - bridgedataoutput.com - dotloop.github.io note: >- Every host returned 404, 401, 403 or an SPA catch-all shell. No `SecurityTxt` pointer is emitted. Publishing an RFC 9116 file at https://www.zillow.com/.well-known/security.txt pointing at the existing policy page would be a one-line fix. x-evidence: - url: https://www.zillow.com/corporate/security-disclosure/ status: 403 fetched: '2026-08-28' note: >- HONEST RECORD OF THE PROBE. zillow.com sits behind a PerimeterX edge that answers "Access to this page has been denied" (5,856 bytes) to every non-browser client, including a full desktop Chrome user-agent and WebFetch. The page demonstrably exists and is indexed under the title "Security Disclosure | Zillow"; the 403 is a bot challenge against our crawler, not a dead page, and is recorded as such rather than treated as absent. - url: https://bugcrowd.com/zillow status: 404 fetched: '2026-08-28' - url: https://www.zillow.com/.well-known/security.txt status: 404 fetched: '2026-08-28' maintainers: - FN: Kin Lane email: kin@apievangelist.com