CMS Energy · Vulnerability Disclosure

Cms Energy Vulnerability Disclosure

Vulnerability disclosure

CMS Energy publishes a coordinated vulnerability disclosure contact in two independent places: an RFC 9116 security.txt served from the Consumers Energy web host, and the General Digital Terms & Conditions page that /security now resolves to. There is no bug-bounty program and no paid disclosure surface (no HackerOne / Bugcrowd / Intigriti listing was found).

CMS Energy runs a coordinated vulnerability disclosure program on Hackerone.

ElectricEnergyGreen ButtonMichiganNatural GasUtilityFortune 500
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-06'
method: searched
source: https://www.consumersenergy.com/.well-known/security.txt
description: >-
  CMS Energy publishes a coordinated vulnerability disclosure contact in two independent places:
  an RFC 9116 security.txt served from the Consumers Energy web host, and the General Digital
  Terms & Conditions page that /security now resolves to. There is no bug-bounty program and no
  paid disclosure surface (no HackerOne / Bugcrowd / Intigriti listing was found).
program:
  present: true
  type: coordinated-disclosure
  bounty: false
  bounty_platform: null
contacts:
  - channel: security.txt
    value: mailto:Vulnerability_Management@cmsenergy.com
    source: https://www.consumersenergy.com/.well-known/security.txt
    status: 200
  - channel: web page
    value: mailto:security@cmsenergy.com
    source: https://www.consumersenergy.com/security
    status: 200
    note: >-
      "Security issues such as vulnerabilities or misconfigurations can be reported to
      security@cmsenergy.com." — quoted verbatim from the Site & App Security section.
security_txt:
  url: https://www.consumersenergy.com/.well-known/security.txt
  status: 200
  file: ../well-known/cms-energy-security.txt
  fields:
    Contact: mailto:Vulnerability_Management@cmsenergy.com
    Expires: '2028-12-29T04:59:00.000Z'
    Preferred-Languages: en
    Canonical: https://www.consumersenergy.com/.well-known/security.txt
  rfc9116_notes:
    - Contact, Expires, Preferred-Languages and Canonical are present.
    - No Policy field — the document does not link a written disclosure policy.
    - No Encryption field — no PGP key is offered.
    - Not signed (no PGP SIGNED MESSAGE block).
policy_page:
  present: false
  note: >-
    https://www.consumersenergy.com/security is indexed under the title "Vulnerability
    Disclosure Program" but now 302s to /terms-and-conditions#security; the standalone VDP page
    describing scope, qualifying vulnerabilities and sanctions exclusions is no longer served.
    Only the reporting address survives on the live page.
scope_probed:
  - url: https://www.consumersenergy.com/.well-known/security.txt
    status: 200
  - url: https://www.cmsenergy.com/.well-known/security.txt
    status: 200
    note: Catch-all "Invalid key" body, not a security.txt.
  - url: https://greenbutton.consumersenergy.com/.well-known/security.txt
    status: 404
  - url: https://utilityapi.com/.well-known/security.txt
    status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cms-energy-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.