generated: '2026-07-28' method: searched probe: true source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program summary: >- CASA publishes an External Security Vulnerability Disclosure Program. It covers any product or service CASA operates that a researcher has legitimate need to access, products/services/infrastructure shared with service partners, and third-party-owned services CASA uses as part of its own services. Reports are submitted through a CASA vulnerability reporting portal. CASA commits to assessing and treating reports under its internal procedures and, with the reporter's consent, to publicly acknowledging researchers whose report leads to a valid fix. CASA explicitly offers NO monetary reward and runs NO bug bounty. policy: - https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program - https://www.casa.gov.au/external-vulnerability-disclosure-program policy_document: title: External Security Vulnerability Disclosure Program dated: July 2025 classification: OFFICIAL format: PDF contact: [] contact_note: >- Reports are made through CASA's vulnerability reporting portal form (fields include a description of the vulnerability and its impact, steps to replicate, and optional reporter name, phone and email) rather than to a published security@ address. No security.txt Contact: line exists - see well-known/casa-aviation-well-known.yml. bug_bounty: offered: false platform: null statement: >- CASA does not offer monetary rewards or a bug bounty initiative. Recognition is public acknowledgement only, and only with the reporter's consent. scope: in_scope: - Any product or service CASA operates that the reporter has legitimate need to access - Products, services and infrastructure shared with CASA service partners - Services third parties own that CASA uses as part of its services prohibited_activities: - Publicly disclosing vulnerability information - Modifying, destroying, exfiltrating or retaining data stored by CASA casa_commitments: - Assess and treat the vulnerability report in line with internal procedures - Following replication and confirmation, begin measures to fix and mitigate - With reporter consent, publicly recognise and thank the reporter where the report leads to a valid security fix or identification of a vulnerability in a CASA-owned system security_txt: published: false note: >- No /.well-known/security.txt was located. Probing www.casa.gov.au directly from this host is not possible (no response to programmatic clients), so its absence on www is unconfirmed; services.casa.gov.au and my.casa.gov.au both return 404. evidence: - source: https://www.casa.gov.au/about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program kind: disclosure-program-page retrieved_via: >- Search-engine index, 2026-07-28. Direct retrieval from the API Evangelist probe host was not possible: www.casa.gov.au returns no response to programmatic clients (HTTP/2 INTERNAL_ERROR, HTTP/1.1 timeout) and a public text-rendering proxy failed the same way. The page's existence, title, scope language, reporting process and no-bug-bounty statement are recorded from the indexed content. - source: https://www.casa.gov.au/external-vulnerability-disclosure-program kind: policy-pdf title: 'OFFICIAL External Security Vulnerability Disclosure Program July 2025' - source: probe-security-programs.py kind: automated-probe result: >- No hit. The probe checks /.well-known/security.txt and the conventional /security, /responsible-disclosure and /vulnerability-disclosure paths; CASA files its program under /about-us/reporting-and-accountability/external-security-vulnerability-disclosure-program, which none of those patterns reach, and www.casa.gov.au does not answer the probe host in any case. Recorded so the automated miss is not read as an absence.