CMS Energy · Vulnerability Disclosure
Cms Energy Vulnerability Disclosure
Vulnerability disclosure
CMS Energy publishes a coordinated vulnerability disclosure contact in two independent places: an RFC 9116 security.txt served from the Consumers Energy web host, and the General Digital Terms & Conditions page that /security now resolves to. There is no bug-bounty program and no paid disclosure surface (no HackerOne / Bugcrowd / Intigriti listing was found).
CMS Energy runs a coordinated vulnerability disclosure program on Hackerone.
ElectricEnergyGreen ButtonMichiganNatural GasUtilityFortune 500
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.