Application security and AWS remediation for one of the largest real estate listing platforms in the United States, with security checks embedded into the delivery pipeline rather than bolted on afterward.
Application Security
Vulnerability remediation across production services
DevSecOps
Security checks embedded in the delivery pipeline
AWS Remediation
Cloud configuration, identity, and access hardening
Realtor.com is one of the largest real estate listing platforms in the United States, operated by Move, Inc., a subsidiary majority owned by News Corp with a perpetual license from the National Association of REALTORS to operate the realtor.com brand.
The platform connects consumers to for-sale property listings from multiple listing services nationwide, reaching buyers, sellers, and renters across web and mobile experiences that guide them through every stage of the home search journey.
Realtor.com operates at significant technical scale, running a large portion of its production workloads on Amazon Web Services with its infrastructure managed as code. That scale, combined with the platform's handling of sensitive consumer data, listing information, and real-time integrations with enterprise systems, makes application security and cloud security posture central to protecting both the business and its users.
At the scale Realtor.com operates, a large estate of production services running across a shared container environment creates a wide application attack surface, while an actively evolving AWS footprint spanning compute, serverless, event-driven pipelines, and third-party integrations makes consistent security configuration difficult to enforce without dedicated oversight.
Wide application attack surface
Many production services sharing a common runtime environment.
Security review outside the pipeline
Fast-moving DevOps practices where security review had not been consistently embedded into development and deployment.
Vulnerabilities reaching production
Without integrated application security testing, issues could ship before being identified.
Configuration drift at scale
Gaps in account configuration, identity and access management, and resource-level controls, across an environment too large for manual review to keep pace with.
Rivia was engaged to perform application security and DevSecOps remediation alongside AWS security remediation across Realtor.com's technology environment.
The engagement assessed Realtor.com's application codebase and production services for security vulnerabilities, addressing issues across the software stack supporting consumer-facing listing search, account management, and partner integration systems. Remediation focused on closing identified vulnerabilities, hardening authentication and authorization controls, and reducing exposure across the applications that process sensitive user and transaction data.
Security practices were embedded directly into existing DevOps workflows rather than treated as a separate downstream review, aligning with the company's own infrastructure-as-code and CI/CD driven approach to managing its production environment. Security checks were built into the deployment pipeline so vulnerabilities and misconfigurations could be caught before reaching production, reducing the risk introduced by high-velocity infrastructure and application changes.
A parallel workstream addressed security configuration across the AWS estate, reviewing and remediating identity and access management, network security, encryption, and resource-level configurations across the accounts supporting the platform. This brought the cloud environment's actual configuration in line with best-practice baselines for an environment of that scale and complexity, closing gaps that had accumulated as the footprint grew.
The engagement strengthened Realtor.com's security posture across both the application layer and the underlying AWS infrastructure, reducing vulnerability exposure in production services and closing cloud configuration gaps that had built up across a large, fast-moving environment.
By embedding security directly into the DevOps pipeline, the work gave engineering teams a sustainable way to catch security issues earlier in the development lifecycle rather than relying on periodic, after-the-fact reviews, aligning security practice with the same infrastructure-as-code and automation driven culture the company already applies to its cloud operations.
The combined remediation effort left Realtor.com better positioned to protect the consumer and listing data flowing through its platform while maintaining the deployment velocity required to operate at scale.
| Engagement Dimension | Detail |
|---|---|
| Client | Realtor.com, operated by Move, Inc. |
| Sector | Real estate listings and consumer marketplace |
| Engagement type | Application security and DevSecOps remediation, plus AWS security remediation |
| Cloud platform | Amazon Web Services, infrastructure managed as code |
| Outcome | Reduced vulnerability exposure, hardened cloud configuration, security checks embedded in the delivery pipeline |
Rivia embeds security into the delivery pipeline so issues surface before production, and remediates the cloud configuration underneath it at the same time.