generated: '2026-07-26' method: derived source: >- Derived from live probes, robots.txt (Internet Archive 2025-11-13), archived responses, review.yml RESO findings, and json-ld/zolo-organization.jsonld summary: >- Zolo conforms to the web-syndication standards a consumer marketplace needs to be found — robots.txt, sitemaps.org, RSS 2.0, schema.org — and to none of the API or real-estate data standards that would make its listing data usable by a machine it does not own. There is no RESO certification, no OpenAPI, no OAuth, and no RFC 9116 security.txt. standards: - id: robots-exclusion-protocol name: Robots Exclusion Protocol (RFC 9309) conforms: true evidence: >- /robots.txt served with User-agent/Disallow/Sitemap directives; recovered verbatim at well-known/zolo-robots.txt. - id: sitemaps-org name: sitemaps.org XML Sitemap 0.9 conforms: true evidence: >- Six sitemap documents declared in robots.txt; site_map_index_https.php and xmlsitemap-index/listings.xml both archived as text/xml HTTP 200. - id: rss-2.0 name: RSS 2.0 conforms: true evidence: >- https://www.zolo.ca/rss_new_listings.php returns with a channel and 3,899 items (Internet Archive, 2026-01-03). - id: schema-org name: schema.org structured data (JSON-LD) conforms: true evidence: >- Site-wide application/ld+json block declaring WebSite and Corporation nodes; saved at json-ld/zolo-organization.jsonld. - id: schema-org-real-estate-listing name: schema.org RealEstateListing / Residence markup conforms: false evidence: >- No listing-level structured data observed; the JSON-LD block carries organization identity only. Consistent with the VOW licence on listing content. - id: openapi name: OpenAPI 3.x / Swagger 2.0 conforms: false evidence: >- Every contract path probed on www.zolo.ca returned HTTP 403 (Cloudflare challenge) and no api./developer./docs./data. host exists in DNS or Certificate Transparency. See well-known/zolo-well-known.yml. - id: graphql name: GraphQL conforms: false evidence: No /graphql surface resolves; no GraphQL endpoint is advertised. - id: asyncapi name: AsyncAPI conforms: false evidence: No event, streaming, or webhook surface is published. - id: mcp name: Model Context Protocol conforms: false evidence: No MCP server is published or advertised. - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No authorization server; /.well-known/oauth-authorization-server and /.well-known/openid-configuration are unreachable and no OAuth documentation exists. Account access is browser-session based. - id: oidc name: OpenID Connect conforms: false evidence: No discovery document; no OIDC documentation. - id: rfc9457-problem-details name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: No API responses exist to carry problem+json. - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: false evidence: >- /.well-known/security.txt is unreachable live and has never been captured by the Internet Archive; no disclosure policy or bug bounty was found. - id: rfc8615-well-known name: RFC 8615 well-known URIs conforms: false evidence: No /.well-known/ document retrievable on any Zolo host. - id: rfc9727-api-catalog name: RFC 9727 API Catalog conforms: false evidence: /.well-known/api-catalog unreachable; no catalog published. - id: llms-txt name: llms.txt conforms: false evidence: No /llms.txt live or archived. - id: reso-web-api name: RESO Web API Core 2.0.0 conforms: false evidence: >- Zolo is not among the nineteen Canadian organizations on RESO's Canadian Membership roster, appears in no RESO certification directory, and exposes no OData endpoint or $metadata document. See review.yml sectorPosture. - id: reso-data-dictionary name: RESO Data Dictionary 2.0 conforms: false evidence: No Data Dictionary certification; no DD-conformant field names observed. - id: reso-upi name: RESO Universal Property Identifier (UPI) conforms: false evidence: >- No UPI usage observed; listings are keyed by a Zolo internal numeric id plus a board code (e.g. board "DND") and MLS® number carried in prose. - id: odata name: OData 4.0 conforms: false evidence: No OData service root or $metadata document exists. - id: idx-vow name: 'CREA / board IDX-VOW display rules' conforms: true evidence: >- The undocumented map JSON carries show_idx, show_basic, disp_addr and agent_name (brokerage attribution) flags — the display-permission fields IDX and VOW rules require — and Terms of Use s.23 implements the VOW licence with CREA, TRREB, ITSO, REBGV, Pillar9 and OREB named as enforcing parties. note: >- This is the one data standard Zolo demonstrably implements. It is a restriction regime, not an interoperability one — which is precisely why the API surface is closed. compliance_program: published: false note: >- No trust centre, no named certifications (SOC 2, ISO 27001, PCI DSS), and no security or compliance page was found on any Zolo host. As the licensed brokerage arm of Questrade Financial Group, Zolo is subject to provincial real estate regulators (RECO, RECA, BCFSA, etc.) and PIPEDA, but publishes no machine-readable or developer-facing compliance posture. No Compliance pointer is wired into apis.yml.