AEMO · Vulnerability Disclosure

Aemo Vulnerability Disclosure

Vulnerability disclosure

AEMO publishes an RFC 9116 security.txt at https://www.aemo.com.au/.well-known/security.txt naming its Cyber Security Team as the reporting channel. There is no public bug bounty (no HackerOne / Bugcrowd / Intigriti program was found) and no published safe-harbour or coordinated-disclosure policy document; the security.txt carries a Contact and a Hiring field only — no Policy, Encryption, Preferred-Languages or Expires field.

AEMO runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyAustraliaElectricityGasEnergy MarketsGridMarket OperatorSystem OperatorOpen Energy DataConsumer Data RightCDRSmart MeteringDistributed Energy ResourcesRenewablesUtilities
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:cybersecurity@aemo.com.au

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
description: >-
  AEMO publishes an RFC 9116 security.txt at https://www.aemo.com.au/.well-known/security.txt
  naming its Cyber Security Team as the reporting channel. There is no public bug bounty
  (no HackerOne / Bugcrowd / Intigriti program was found) and no published safe-harbour or
  coordinated-disclosure policy document; the security.txt carries a Contact and a Hiring
  field only — no Policy, Encryption, Preferred-Languages or Expires field.
contact:
  - mailto:cybersecurity@aemo.com.au
policy: []
bug_bounty: none
security_txt:
  url: https://www.aemo.com.au/.well-known/security.txt
  status: 200
  file: well-known/aemo-security.txt
  fields_present:
    - Contact
    - Hiring
  fields_missing:
    - Policy
    - Expires
    - Encryption
    - Preferred-Languages
    - Acknowledgments
    - Canonical
evidence:
  - source: https://www.aemo.com.au/.well-known/security.txt
    kind: security.txt
    status: 200
    detail: 'Contact: mailto:cybersecurity@aemo.com.au'
  - source: well-known/aemo-security.txt
    kind: harvested-file
related:
  - name: Australian Energy Sector Cyber Security Framework (AESCSF)
    note: >-
      AEMO administers the AESCSF on behalf of the Australian energy sector. It is a sector-wide
      maturity framework AEMO runs for others, not a certification of AEMO's own API platform,
      and it is recorded here as context rather than as an AEMO compliance claim.
    url: https://www.aemo.com.au/-/media/files/initiatives/cyber-security/aescsf/aescsf-quick-reference-guide.pdf
gaps:
  - No published vulnerability-disclosure policy page or safe-harbour statement.
  - security.txt has no Expires field, which RFC 9116 requires.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aemo-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.