ACMA · Vulnerability Disclosure
Acma Vulnerability Disclosure
Vulnerability disclosure
ACMA runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
TelecommunicationsAustraliaRegulatorSpectrumBroadcastingNumberingDo Not Call RegisterRadiocommunicationsLicensingOpen DataGovernmentSOAP
Program: Hackerone
Disclosure Policy
Security Contact
Contact
responsible.disclosure@acma.gov.au
Source
Vulnerability Disclosure
generated: '2026-07-25'
method: searched
probe: true
probe_result: >-
The mechanical probe (0-working/probe-security-programs.py) returned no hit because
www.acma.gov.au is unreachable from the enrichment host — the Akamai edge completes the TLS
handshake and then never responds (curl exit 28 across HTTP/2, HTTP/1.1, IPv4 and full browser
headers). The policy below was therefore read from an Internet Archive snapshot of ACMA's own
page and is recorded with that provenance. The page is linked from the footer of every
acma.gov.au page, including the live radiocomms licence data page.
policy:
- https://www.acma.gov.au/vulnerability-disclosure-policy
contact:
- responsible.disclosure@acma.gov.au
security_txt: false
security_txt_note: >-
No RFC 9116 security.txt is published on any ACMA host — the programme exists but is not
machine-discoverable. See well-known/acma-well-known.yml.
bug_bounty: false
bounty_note: >-
Explicitly none. ACMA states: "As an Australian Government agency, we can't financially
compensate individuals or organisations for finding potential or confirmed security
vulnerabilities." No HackerOne, Bugcrowd or Intigriti programme exists.
safe_harbour: partial
safe_harbour_note: >-
ACMA commits to act in good faith with parties who report vulnerabilities, but frames lawful
research as a precondition rather than granting an explicit legal safe harbour: research "must
be undertaken under Australian law, and not compromise or exploit the ACMA's data, employees,
infrastructure, operations and activities."
scope:
in_scope:
- Any product, service or system wholly owned by the ACMA that the researcher has lawful
access to or is authorised to use.
out_of_scope_activities:
- public disclosure of vulnerability information
- clickjacking
- deceptive techniques including social engineering or phishing
- denial of service (DoS or DDoS) attacks
- posting, transmitting, uploading, linking to or sending malware
- physical attacks
- attempts to modify or destroy data
- attempts to extract or exfiltrate data
- accessing or attempting to access accounts or data that do not belong to the researcher
- testing third-party websites, applications or services that integrate with ACMA systems
- any action that is unlawful or contrary to legally enforceable terms and conditions
not_reportable:
- weak, insecure or misconfigured SSL/TLS certificates
- misconfigured DNS records such as SPF and DMARC
- missing security HTTP headers (e.g. permissions policy)
- theoretical cross-site request forgery and cross-site framing attacks
not_reportable_note: >-
ACMA explicitly excludes "missing security controls or protections that are not directly
exploitable" — which is worth reading next to security/acma-domain-security.yml, where the
probe records no CAA records and no DNSSEC on acma.gov.au or donotcall.gov.au. Those are, by
ACMA's own policy, not vulnerabilities it wants reported.
reporting:
channel: email
address: responsible.disclosure@acma.gov.au
required_details:
- explanation of the potential vulnerability and its potential impact
- date the vulnerability was identified
- list of affected products, services or systems including version numbers
- step-by-step reproduction instructions
- proof-of-concept code, scripts or screenshots
- names of any test accounts created
- reporter contact details
instruction: >-
Stop testing as soon as a vulnerability is established and report it immediately. Reporters
must maintain confidentiality and must not disclose publicly without ACMA's express written
consent.
response:
acknowledgement: Receipt confirmed within "a reasonable timeframe" (no SLA given).
recognition: >-
Public acknowledgement is available on request and with permission to publish a name or
alias, after ACMA has confirmed the report's validity. The hall of fame is published on the
policy page and currently reads "No current contributions."
confidentiality: >-
Reports and reporter personal information are handled confidentially and in accordance with
ACMA's privacy policy; reporter details are not shared with other organisations without
permission.
evidence:
- source: https://www.acma.gov.au/vulnerability-disclosure-policy
via: https://web.archive.org/web/20260419053611/https://www.acma.gov.au/vulnerability-disclosure-policy
kind: disclosure-policy-page
status: 200
date: '2026-07-25'
- source: https://www.acma.gov.au/radiocomms-licence-data
kind: footer-link
note: The vulnerability disclosure policy is linked from the standard acma.gov.au footer.