AGL Energy · Vulnerability Disclosure

Agl Energy Vulnerability Disclosure

Vulnerability disclosure

AGL runs a named Responsible Disclosure Program with a published policy page. It is a coordinated-disclosure programme, explicitly NOT a bug bounty — AGL states it is unable to offer any form of compensation, monetary or otherwise, for a disclosure, and requires research to be conducted only against services and products the researcher has authorised access to. The policy page could not be read by any machine client (the Akamai edge in front of www.agl.com.au returns HTTP 403 to every non-browser request, including WebFetch and curl with a browser User-Agent), so its existence and substance were established from the public search index rather than from a direct fetch. Recorded honestly with the observed HTTP status.

AGL Energy runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served.

EnergyAustraliaUtilitiesElectricityGasEnergy RetailerConsumer Data RightCDRSmart MeteringSolarDERRenewablesEnergy Markets
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
probe: true
description: >-
  AGL runs a named Responsible Disclosure Program with a published policy page.
  It is a coordinated-disclosure programme, explicitly NOT a bug bounty — AGL
  states it is unable to offer any form of compensation, monetary or otherwise,
  for a disclosure, and requires research to be conducted only against services
  and products the researcher has authorised access to. The policy page could not
  be read by any machine client (the Akamai edge in front of www.agl.com.au
  returns HTTP 403 to every non-browser request, including WebFetch and curl with
  a browser User-Agent), so its existence and substance were established from the
  public search index rather than from a direct fetch. Recorded honestly with the
  observed HTTP status.
policy:
- https://www.agl.com.au/terms-conditions/responsible-disclosure-policy
contact: []
contact_note: >-
  No security contact address is published in a machine-readable form. There is
  no /.well-known/security.txt on any AGL host (all probes 404 or 403 — see
  well-known/agl-energy-well-known.yml), and the reporting channel named on the
  policy page could not be read through the edge block.
bug_bounty: false
bug_bounty_note: >-
  No HackerOne, Bugcrowd or Intigriti programme was found for AGL. The policy
  page states AGL is unable to offer compensation for disclosures.
safe_harbour:
  stated: partial
  detail: >-
    The policy requires research to be responsible, lawful, and limited to
    services and products the researcher has authorised access to, and states
    that AGL does not condone malicious or illegal behaviour in identifying or
    reporting vulnerabilities.
evidence:
- source: https://www.agl.com.au/terms-conditions/responsible-disclosure-policy
  kind: responsible-disclosure-policy
  http_status: 403
  http_status_note: Akamai edge denies non-browser clients; 403 is an access block, not an absence.
  verified_via: public search index result confirming the page title "Responsible Disclosure Policy" and its terms
  date: '2026-07-27'
- source: https://www.agl.com.au/.well-known/security.txt
  kind: security.txt
  http_status: 403
- source: https://public.cdr.agl.com.au/.well-known/security.txt
  kind: security.txt
  http_status: 404
probes_run:
  script: 0-working/probe-security-programs.py
  result: 'vdp=none trust=none'
  result_note: >-
    The mechanical probe found nothing because every AGL corporate URL answers
    403 to it. The policy was recovered by search instead. This artifact
    supersedes the probe result.