Civil Aviation Safety Authority (CASA) · Vulnerability Disclosure
Casa Aviation Vulnerability Disclosure
Vulnerability disclosure
Civil Aviation Safety Authority (CASA) publishes a vulnerability disclosure policy for reporting security issues.
TravelAustraliaAviationAirportsGovernmentRegulatorAviation SafetyOpen DataDrones
Program:
Disclosure Policy
Policy
Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-07-28'
method: searched
probe: true
source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
summary: >-
CASA publishes an External Security Vulnerability Disclosure Program. It covers
any product or service CASA operates that a researcher has legitimate need to
access, products/services/infrastructure shared with service partners, and
third-party-owned services CASA uses as part of its own services. Reports are
submitted through a CASA vulnerability reporting portal. CASA commits to
assessing and treating reports under its internal procedures and, with the
reporter's consent, to publicly acknowledging researchers whose report leads to a
valid fix. CASA explicitly offers NO monetary reward and runs NO bug bounty.
policy:
- https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
- https://www.casa.gov.au/external-vulnerability-disclosure-program
policy_document:
title: External Security Vulnerability Disclosure Program
dated: July 2025
classification: OFFICIAL
format: PDF
contact: []
contact_note: >-
Reports are made through CASA's vulnerability reporting portal form (fields
include a description of the vulnerability and its impact, steps to replicate,
and optional reporter name, phone and email) rather than to a published
security@ address. No security.txt Contact: line exists - see
well-known/casa-aviation-well-known.yml.
bug_bounty:
offered: false
platform: null
statement: >-
CASA does not offer monetary rewards or a bug bounty initiative. Recognition is
public acknowledgement only, and only with the reporter's consent.
scope:
in_scope:
- Any product or service CASA operates that the reporter has legitimate need to access
- Products, services and infrastructure shared with CASA service partners
- Services third parties own that CASA uses as part of its services
prohibited_activities:
- Publicly disclosing vulnerability information
- Modifying, destroying, exfiltrating or retaining data stored by CASA
casa_commitments:
- Assess and treat the vulnerability report in line with internal procedures
- Following replication and confirmation, begin measures to fix and mitigate
- With reporter consent, publicly recognise and thank the reporter where the report leads to a valid security fix or identification of a vulnerability in a CASA-owned system
security_txt:
published: false
note: >-
No /.well-known/security.txt was located. Probing www.casa.gov.au directly from
this host is not possible (no response to programmatic clients), so its absence
on www is unconfirmed; services.casa.gov.au and my.casa.gov.au both return 404.
evidence:
- source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
kind: disclosure-program-page
retrieved_via: >-
Search-engine index, 2026-07-28. Direct retrieval from the API Evangelist
probe host was not possible: www.casa.gov.au returns no response to
programmatic clients (HTTP/2 INTERNAL_ERROR, HTTP/1.1 timeout) and a public
text-rendering proxy failed the same way. The page's existence, title, scope
language, reporting process and no-bug-bounty statement are recorded from the
indexed content.
- source: https://www.casa.gov.au/external-vulnerability-disclosure-program
kind: policy-pdf
title: 'OFFICIAL External Security Vulnerability Disclosure Program July 2025'
- source: probe-security-programs.py
kind: automated-probe
result: >-
No hit. The probe checks /.well-known/security.txt and the conventional
/security, /responsible-disclosure and /vulnerability-disclosure paths; CASA
files its program under
/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program,
which none of those patterns reach, and www.casa.gov.au does not answer the
probe host in any case. Recorded so the automated miss is not read as an
absence.