generated: '2026-07-25' method: searched probe: true probe_result: >- The mechanical probe (0-working/probe-security-programs.py) returned no hit because www.acma.gov.au is unreachable from the enrichment host — the Akamai edge completes the TLS handshake and then never responds (curl exit 28 across HTTP/2, HTTP/1.1, IPv4 and full browser headers). The policy below was therefore read from an Internet Archive snapshot of ACMA's own page and is recorded with that provenance. The page is linked from the footer of every acma.gov.au page, including the live radiocomms licence data page. policy: - https://www.acma.gov.au/vulnerability-disclosure-policy contact: - responsible.disclosure@acma.gov.au security_txt: false security_txt_note: >- No RFC 9116 security.txt is published on any ACMA host — the programme exists but is not machine-discoverable. See well-known/acma-well-known.yml. bug_bounty: false bounty_note: >- Explicitly none. ACMA states: "As an Australian Government agency, we can't financially compensate individuals or organisations for finding potential or confirmed security vulnerabilities." No HackerOne, Bugcrowd or Intigriti programme exists. safe_harbour: partial safe_harbour_note: >- ACMA commits to act in good faith with parties who report vulnerabilities, but frames lawful research as a precondition rather than granting an explicit legal safe harbour: research "must be undertaken under Australian law, and not compromise or exploit the ACMA's data, employees, infrastructure, operations and activities." scope: in_scope: - Any product, service or system wholly owned by the ACMA that the researcher has lawful access to or is authorised to use. out_of_scope_activities: - public disclosure of vulnerability information - clickjacking - deceptive techniques including social engineering or phishing - denial of service (DoS or DDoS) attacks - posting, transmitting, uploading, linking to or sending malware - physical attacks - attempts to modify or destroy data - attempts to extract or exfiltrate data - accessing or attempting to access accounts or data that do not belong to the researcher - testing third-party websites, applications or services that integrate with ACMA systems - any action that is unlawful or contrary to legally enforceable terms and conditions not_reportable: - weak, insecure or misconfigured SSL/TLS certificates - misconfigured DNS records such as SPF and DMARC - missing security HTTP headers (e.g. permissions policy) - theoretical cross-site request forgery and cross-site framing attacks not_reportable_note: >- ACMA explicitly excludes "missing security controls or protections that are not directly exploitable" — which is worth reading next to security/acma-domain-security.yml, where the probe records no CAA records and no DNSSEC on acma.gov.au or donotcall.gov.au. Those are, by ACMA's own policy, not vulnerabilities it wants reported. reporting: channel: email address: responsible.disclosure@acma.gov.au required_details: - explanation of the potential vulnerability and its potential impact - date the vulnerability was identified - list of affected products, services or systems including version numbers - step-by-step reproduction instructions - proof-of-concept code, scripts or screenshots - names of any test accounts created - reporter contact details instruction: >- Stop testing as soon as a vulnerability is established and report it immediately. Reporters must maintain confidentiality and must not disclose publicly without ACMA's express written consent. response: acknowledgement: Receipt confirmed within "a reasonable timeframe" (no SLA given). recognition: >- Public acknowledgement is available on request and with permission to publish a name or alias, after ACMA has confirmed the report's validity. The hall of fame is published on the policy page and currently reads "No current contributions." confidentiality: >- Reports and reporter personal information are handled confidentially and in accordance with ACMA's privacy policy; reporter details are not shared with other organisations without permission. evidence: - source: https://www.acma.gov.au/vulnerability-disclosure-policy via: https://web.archive.org/web/20260419053611/https://www.acma.gov.au/vulnerability-disclosure-policy kind: disclosure-policy-page status: 200 date: '2026-07-25' - source: https://www.acma.gov.au/radiocomms-licence-data kind: footer-link note: The vulnerability disclosure policy is linked from the standard acma.gov.au footer.