Civil Aviation Safety Authority (CASA) · Vulnerability Disclosure

Casa Aviation Vulnerability Disclosure

Vulnerability disclosure

Civil Aviation Safety Authority (CASA) publishes a vulnerability disclosure policy for reporting security issues.

TravelAustraliaAviationAirportsGovernmentRegulatorAviation SafetyOpen DataDrones
Program:

Disclosure Policy

Policy
Policy

Security Contact

Source

Vulnerability Disclosure

casa-aviation-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-28'
method: searched
probe: true
source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
summary: >-
  CASA publishes an External Security Vulnerability Disclosure Program. It covers
  any product or service CASA operates that a researcher has legitimate need to
  access, products/services/infrastructure shared with service partners, and
  third-party-owned services CASA uses as part of its own services. Reports are
  submitted through a CASA vulnerability reporting portal. CASA commits to
  assessing and treating reports under its internal procedures and, with the
  reporter's consent, to publicly acknowledging researchers whose report leads to a
  valid fix. CASA explicitly offers NO monetary reward and runs NO bug bounty.
policy:
  - https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
  - https://www.casa.gov.au/external-vulnerability-disclosure-program
policy_document:
  title: External Security Vulnerability Disclosure Program
  dated: July 2025
  classification: OFFICIAL
  format: PDF
contact: []
contact_note: >-
  Reports are made through CASA's vulnerability reporting portal form (fields
  include a description of the vulnerability and its impact, steps to replicate,
  and optional reporter name, phone and email) rather than to a published
  security@ address. No security.txt Contact: line exists - see
  well-known/casa-aviation-well-known.yml.
bug_bounty:
  offered: false
  platform: null
  statement: >-
    CASA does not offer monetary rewards or a bug bounty initiative. Recognition is
    public acknowledgement only, and only with the reporter's consent.
scope:
  in_scope:
    - Any product or service CASA operates that the reporter has legitimate need to access
    - Products, services and infrastructure shared with CASA service partners
    - Services third parties own that CASA uses as part of its services
  prohibited_activities:
    - Publicly disclosing vulnerability information
    - Modifying, destroying, exfiltrating or retaining data stored by CASA
casa_commitments:
  - Assess and treat the vulnerability report in line with internal procedures
  - Following replication and confirmation, begin measures to fix and mitigate
  - With reporter consent, publicly recognise and thank the reporter where the report leads to a valid security fix or identification of a vulnerability in a CASA-owned system
security_txt:
  published: false
  note: >-
    No /.well-known/security.txt was located. Probing www.casa.gov.au directly from
    this host is not possible (no response to programmatic clients), so its absence
    on www is unconfirmed; services.casa.gov.au and my.casa.gov.au both return 404.
evidence:
  - source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
    kind: disclosure-program-page
    retrieved_via: >-
      Search-engine index, 2026-07-28. Direct retrieval from the API Evangelist
      probe host was not possible: www.casa.gov.au returns no response to
      programmatic clients (HTTP/2 INTERNAL_ERROR, HTTP/1.1 timeout) and a public
      text-rendering proxy failed the same way. The page's existence, title, scope
      language, reporting process and no-bug-bounty statement are recorded from the
      indexed content.
  - source: https://www.casa.gov.au/external-vulnerability-disclosure-program
    kind: policy-pdf
    title: 'OFFICIAL External Security Vulnerability Disclosure Program July 2025'
  - source: probe-security-programs.py
    kind: automated-probe
    result: >-
      No hit. The probe checks /.well-known/security.txt and the conventional
      /security, /responsible-disclosure and /vulnerability-disclosure paths; CASA
      files its program under
      /about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program,
      which none of those patterns reach, and www.casa.gov.au does not answer the
      probe host in any case. Recorded so the automated miss is not read as an
      absence.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/casa-aviation-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.