generated: '2026-07-27' method: searched probe: true source: https://www.aer.gov.au/.well-known/security.txt url: https://www.aer.gov.au/.well-known/security.txt policy: [] contact: - mailto:AERWebTeam@aer.gov.au bug_bounty: false program: type: security.txt-contact-only detail: >- The AER publishes an RFC 9116 security.txt at the canonical location on its website host, carrying Contact, Expires (2099-11-01), Preferred-Languages (en) and a self-referencing Canonical. It carries no Policy, Encryption, Acknowledgments or Hiring field, so there is a published reporting channel but no published disclosure policy, no safe-harbour statement and no bounty. There is no HackerOne, Bugcrowd or Intigriti program. The contact is the AER web team mailbox rather than a dedicated security address. no_policy_url: true scope_note: >- The security.txt lives on www.aer.gov.au. No security.txt is served on the API host cdr.energymadeeasy.gov.au or on www.energymadeeasy.gov.au (both 404), so a reporter who finds an issue in the product-data API has to work back to the corporate site to find a contact. evidence: - source: https://www.aer.gov.au/.well-known/security.txt kind: security.txt status: 200 file: well-known/aer-security.txt retrieved_via: r.jina.ai text proxy (Akamai blocks direct probes from this host) date: '2026-07-27' - source: https://cdr.energymadeeasy.gov.au/.well-known/security.txt kind: security.txt status: 404 date: '2026-07-27' related_channels: - name: Public interest disclosure url: https://www.aer.gov.au/about/policies/public-interest-disclosure note: Commonwealth whistleblower scheme, not a vulnerability disclosure programme. - name: CDR support mailbox url: mailto:cdr-support@aer.gov.au note: Data and API support, not security reporting.