ACMA · Vulnerability Disclosure

Acma Vulnerability Disclosure

Vulnerability disclosure

ACMA runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

TelecommunicationsAustraliaRegulatorSpectrumBroadcastingNumberingDo Not Call RegisterRadiocommunicationsLicensingOpen DataGovernmentSOAP
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
responsible.disclosure@acma.gov.au

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
probe_result: >-
  The mechanical probe (0-working/probe-security-programs.py) returned no hit because
  www.acma.gov.au is unreachable from the enrichment host — the Akamai edge completes the TLS
  handshake and then never responds (curl exit 28 across HTTP/2, HTTP/1.1, IPv4 and full browser
  headers). The policy below was therefore read from an Internet Archive snapshot of ACMA's own
  page and is recorded with that provenance. The page is linked from the footer of every
  acma.gov.au page, including the live radiocomms licence data page.
policy:
- https://www.acma.gov.au/vulnerability-disclosure-policy
contact:
- responsible.disclosure@acma.gov.au
security_txt: false
security_txt_note: >-
  No RFC 9116 security.txt is published on any ACMA host — the programme exists but is not
  machine-discoverable. See well-known/acma-well-known.yml.
bug_bounty: false
bounty_note: >-
  Explicitly none. ACMA states: "As an Australian Government agency, we can't financially
  compensate individuals or organisations for finding potential or confirmed security
  vulnerabilities." No HackerOne, Bugcrowd or Intigriti programme exists.
safe_harbour: partial
safe_harbour_note: >-
  ACMA commits to act in good faith with parties who report vulnerabilities, but frames lawful
  research as a precondition rather than granting an explicit legal safe harbour: research "must
  be undertaken under Australian law, and not compromise or exploit the ACMA's data, employees,
  infrastructure, operations and activities."
scope:
  in_scope:
  - Any product, service or system wholly owned by the ACMA that the researcher has lawful
    access to or is authorised to use.
  out_of_scope_activities:
  - public disclosure of vulnerability information
  - clickjacking
  - deceptive techniques including social engineering or phishing
  - denial of service (DoS or DDoS) attacks
  - posting, transmitting, uploading, linking to or sending malware
  - physical attacks
  - attempts to modify or destroy data
  - attempts to extract or exfiltrate data
  - accessing or attempting to access accounts or data that do not belong to the researcher
  - testing third-party websites, applications or services that integrate with ACMA systems
  - any action that is unlawful or contrary to legally enforceable terms and conditions
  not_reportable:
  - weak, insecure or misconfigured SSL/TLS certificates
  - misconfigured DNS records such as SPF and DMARC
  - missing security HTTP headers (e.g. permissions policy)
  - theoretical cross-site request forgery and cross-site framing attacks
  not_reportable_note: >-
    ACMA explicitly excludes "missing security controls or protections that are not directly
    exploitable" — which is worth reading next to security/acma-domain-security.yml, where the
    probe records no CAA records and no DNSSEC on acma.gov.au or donotcall.gov.au. Those are, by
    ACMA's own policy, not vulnerabilities it wants reported.
reporting:
  channel: email
  address: responsible.disclosure@acma.gov.au
  required_details:
  - explanation of the potential vulnerability and its potential impact
  - date the vulnerability was identified
  - list of affected products, services or systems including version numbers
  - step-by-step reproduction instructions
  - proof-of-concept code, scripts or screenshots
  - names of any test accounts created
  - reporter contact details
  instruction: >-
    Stop testing as soon as a vulnerability is established and report it immediately. Reporters
    must maintain confidentiality and must not disclose publicly without ACMA's express written
    consent.
response:
  acknowledgement: Receipt confirmed within "a reasonable timeframe" (no SLA given).
  recognition: >-
    Public acknowledgement is available on request and with permission to publish a name or
    alias, after ACMA has confirmed the report's validity. The hall of fame is published on the
    policy page and currently reads "No current contributions."
  confidentiality: >-
    Reports and reporter personal information are handled confidentially and in accordance with
    ACMA's privacy policy; reporter details are not shared with other organisations without
    permission.
evidence:
- source: https://www.acma.gov.au/vulnerability-disclosure-policy
  via: https://web.archive.org/web/20260419053611/https://www.acma.gov.au/vulnerability-disclosure-policy
  kind: disclosure-policy-page
  status: 200
  date: '2026-07-25'
- source: https://www.acma.gov.au/radiocomms-licence-data
  kind: footer-link
  note: The vulnerability disclosure policy is linked from the standard acma.gov.au footer.