Australian Energy Regulator · Vulnerability Disclosure

Aer Vulnerability Disclosure

Vulnerability disclosure

Australian Energy Regulator runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyAustraliaUtilitiesElectricityGasEnergy MarketsConsumer Data RightRetail EnergyRegulationGovernmentOpen DataSmart Metering
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:AERWebTeam@aer.gov.au

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://www.aer.gov.au/.well-known/security.txt
url: https://www.aer.gov.au/.well-known/security.txt
policy: []
contact:
- mailto:AERWebTeam@aer.gov.au
bug_bounty: false
program:
  type: security.txt-contact-only
  detail: >-
    The AER publishes an RFC 9116 security.txt at the canonical location on its
    website host, carrying Contact, Expires (2099-11-01), Preferred-Languages (en) and
    a self-referencing Canonical. It carries no Policy, Encryption, Acknowledgments or
    Hiring field, so there is a published reporting channel but no published
    disclosure policy, no safe-harbour statement and no bounty. There is no
    HackerOne, Bugcrowd or Intigriti program. The contact is the AER web team mailbox
    rather than a dedicated security address.
  no_policy_url: true
scope_note: >-
  The security.txt lives on www.aer.gov.au. No security.txt is served on the API host
  cdr.energymadeeasy.gov.au or on www.energymadeeasy.gov.au (both 404), so a reporter
  who finds an issue in the product-data API has to work back to the corporate site to
  find a contact.
evidence:
- source: https://www.aer.gov.au/.well-known/security.txt
  kind: security.txt
  status: 200
  file: well-known/aer-security.txt
  retrieved_via: r.jina.ai text proxy (Akamai blocks direct probes from this host)
  date: '2026-07-27'
- source: https://cdr.energymadeeasy.gov.au/.well-known/security.txt
  kind: security.txt
  status: 404
  date: '2026-07-27'
related_channels:
- name: Public interest disclosure
  url: https://www.aer.gov.au/about/policies/public-interest-disclosure
  note: Commonwealth whistleblower scheme, not a vulnerability disclosure programme.
- name: CDR support mailbox
  url: mailto:cdr-support@aer.gov.au
  note: Data and API support, not security reporting.