Civil Aviation Safety Authority (CASA) · Vulnerability Disclosure
Casa Aviation Vulnerability Disclosure
Vulnerability disclosure
Civil Aviation Safety Authority (CASA) publishes a vulnerability disclosure policy for reporting security issues.
TravelAustraliaAviationAirportsGovernmentRegulatorAviation SafetyOpen DataDrones
Program:
Disclosure Policy
Policy
Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-07-28'
method: searched
probe: true
source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
summary: >-
CASA publishes an External Security Vulnerability Disclosure Program. It covers
any product or service CASA operates that a researcher has legitimate need to
access, products/services/infrastructure shared with service partners, and
third-party-owned services CASA uses as part of its own services. Reports are
submitted through a CASA vulnerability reporting portal. CASA commits to
assessing and treating reports under its internal procedures and, with the
reporter's consent, to publicly acknowledging researchers whose report leads to a
valid fix. CASA explicitly offers NO monetary reward and runs NO bug bounty.
policy:
- https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
- https://www.casa.gov.au/external-vulnerability-disclosure-program
policy_document:
title: External Security Vulnerability Disclosure Program
dated: July 2025
classification: OFFICIAL
format: PDF
contact: []
contact_note: >-
Reports are made through CASA's vulnerability reporting portal form (fields
include a description of the vulnerability and its impact, steps to replicate,
and optional reporter name, phone and email) rather than to a published
security@ address. No security.txt Contact: line exists - see
well-known/casa-aviation-well-known.yml.
bug_bounty:
offered: false
platform: null
statement: >-
CASA does not offer monetary rewards or a bug bounty initiative. Recognition is
public acknowledgement only, and only with the reporter's consent.
scope:
in_scope:
- Any product or service CASA operates that the reporter has legitimate need to access
- Products, services and infrastructure shared with CASA service partners
- Services third parties own that CASA uses as part of its services
prohibited_activities:
- Publicly disclosing vulnerability information
- Modifying, destroying, exfiltrating or retaining data stored by CASA
casa_commitments:
- Assess and treat the vulnerability report in line with internal procedures
- Following replication and confirmation, begin measures to fix and mitigate
- With reporter consent, publicly recognise and thank the reporter where the report leads to a valid security fix or identification of a vulnerability in a CASA-owned system
security_txt:
published: false
note: >-
No /.well-known/security.txt was located. Probing www.casa.gov.au directly from
this host is not possible (no response to programmatic clients), so its absence
on www is unconfirmed; services.casa.gov.au and my.casa.gov.au both return 404.
evidence:
- source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program
kind: disclosure-program-page
retrieved_via: >-
Search-engine index, 2026-07-28. Direct retrieval from the API Evangelist
probe host was not possible: www.casa.gov.au returns no response to
programmatic clients (HTTP/2 INTERNAL_ERROR, HTTP/1.1 timeout) and a public
text-rendering proxy failed the same way. The page's existence, title, scope
language, reporting process and no-bug-bounty statement are recorded from the
indexed content.
- source: https://www.casa.gov.au/external-vulnerability-disclosure-program
kind: policy-pdf
title: 'OFFICIAL External Security Vulnerability Disclosure Program July 2025'
- source: probe-security-programs.py
kind: automated-probe
result: >-
No hit. The probe checks /.well-known/security.txt and the conventional
/security, /responsible-disclosure and /vulnerability-disclosure paths; CASA
files its program under
/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program,
which none of those patterns reach, and www.casa.gov.au does not answer the
probe host in any case. Recorded so the automated miss is not read as an
absence.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/casa-aviation-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.