Australian Energy Regulator · Vulnerability Disclosure

Aer Vulnerability Disclosure

Vulnerability disclosure

Australian Energy Regulator runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyAustraliaUtilitiesElectricityGasEnergy MarketsConsumer Data RightRetail EnergyRegulationsGovernmentOpen DataSmart Metering
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
mailto:AERWebTeam@aer.gov.au

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: https://www.aer.gov.au/.well-known/security.txt
url: https://www.aer.gov.au/.well-known/security.txt
policy: []
contact:
- mailto:AERWebTeam@aer.gov.au
bug_bounty: false
program:
  type: security.txt-contact-only
  detail: >-
    The AER publishes an RFC 9116 security.txt at the canonical location on its
    website host, carrying Contact, Expires (2099-11-01), Preferred-Languages (en) and
    a self-referencing Canonical. It carries no Policy, Encryption, Acknowledgments or
    Hiring field, so there is a published reporting channel but no published
    disclosure policy, no safe-harbour statement and no bounty. There is no
    HackerOne, Bugcrowd or Intigriti program. The contact is the AER web team mailbox
    rather than a dedicated security address.
  no_policy_url: true
scope_note: >-
  The security.txt lives on www.aer.gov.au. No security.txt is served on the API host
  cdr.energymadeeasy.gov.au or on www.energymadeeasy.gov.au (both 404), so a reporter
  who finds an issue in the product-data API has to work back to the corporate site to
  find a contact.
evidence:
- source: https://www.aer.gov.au/.well-known/security.txt
  kind: security.txt
  status: 200
  file: well-known/aer-security.txt
  retrieved_via: r.jina.ai text proxy (Akamai blocks direct probes from this host)
  date: '2026-07-27'
- source: https://cdr.energymadeeasy.gov.au/.well-known/security.txt
  kind: security.txt
  status: 404
  date: '2026-07-27'
related_channels:
- name: Public interest disclosure
  url: https://www.aer.gov.au/about/policies/public-interest-disclosure
  note: Commonwealth whistleblower scheme, not a vulnerability disclosure programme.
- name: CDR support mailbox
  url: mailto:cdr-support@aer.gov.au
  note: Data and API support, not security reporting.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aer-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.