EIA · Vulnerability Disclosure

Eia Vulnerability Disclosure

Vulnerability disclosure

EIA publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyUnited StatesEnergy MarketsElectricityNatural GasPetroleumCoalNuclearRenewablesGridEmissionsGovernmentOpen DataEnergy Statistics
Program: security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
DOEOCIOInfo@hq.doe.gov

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-27'
method: searched
source: https://www.energy.gov/cio/articles/vulnerability-disclosure-policy
summary: |
  EIA does not run its own vulnerability disclosure program and publishes no security.txt
  (see well-known/eia-well-known.yml). It is covered by the parent Department of Energy
  Vulnerability Disclosure Program, and every page on www.eia.gov - including the Open Data
  and API documentation pages - carries a footer link to it: "Learn about the Department of
  Energy's Vulnerability Disclosure Program" ->
  https://www.energy.gov/cio/articles/vulnerability-disclosure-policy (HTTP 200,
  last updated 2024-10-02). The policy is published as Attachment 2 to DOE Order 205.1D and
  exists to meet OMB M-20-32 and CISA Binding Operational Directive 20-01. Intake is through
  the DOE responsible-disclosure portal at https://doe.responsibledisclosure.com (returns
  HTTP 403 to an anonymous scripted GET - it is a browser-gated submission portal, not an
  open page). Scope expands progressively under the Order until all DOE public,
  internet-accessible websites and digital services are in scope.
policy:
- https://www.energy.gov/cio/articles/vulnerability-disclosure-policy
- https://www.energy.gov/vulnerability-disclosure-policy
intake:
- https://doe.responsibledisclosure.com
contact:
- DOEOCIOInfo@hq.doe.gov
program:
  operator: U.S. Department of Energy, Office of the Chief Information Officer
  authority: DOE O 205.1D, Attachment 2
  drivers:
  - OMB M-20-32
  - CISA BOD 20-01
  bug_bounty: false
  security_txt: false
evidence:
- source: https://www.eia.gov/opendata/documentation.php
  kind: footer link
  detail: 'Anchor: "Learn about the Department of Energy''s Vulnerability Disclosure Program"
    -> https://www.energy.gov/cio/articles/vulnerability-disclosure-policy'
- source: https://www.energy.gov/cio/articles/vulnerability-disclosure-policy
  kind: policy page
  status: 200
- source: https://doe.responsibledisclosure.com
  kind: disclosure portal
  status: 403
- source: https://www.eia.gov/.well-known/security.txt
  kind: security.txt
  status: 404