generated: '2026-09-06' method: searched source: https://www.consumersenergy.com/.well-known/security.txt description: >- CMS Energy publishes a coordinated vulnerability disclosure contact in two independent places: an RFC 9116 security.txt served from the Consumers Energy web host, and the General Digital Terms & Conditions page that /security now resolves to. There is no bug-bounty program and no paid disclosure surface (no HackerOne / Bugcrowd / Intigriti listing was found). program: present: true type: coordinated-disclosure bounty: false bounty_platform: null contacts: - channel: security.txt value: mailto:Vulnerability_Management@cmsenergy.com source: https://www.consumersenergy.com/.well-known/security.txt status: 200 - channel: web page value: mailto:security@cmsenergy.com source: https://www.consumersenergy.com/security status: 200 note: >- "Security issues such as vulnerabilities or misconfigurations can be reported to security@cmsenergy.com." — quoted verbatim from the Site & App Security section. security_txt: url: https://www.consumersenergy.com/.well-known/security.txt status: 200 file: ../well-known/cms-energy-security.txt fields: Contact: mailto:Vulnerability_Management@cmsenergy.com Expires: '2028-12-29T04:59:00.000Z' Preferred-Languages: en Canonical: https://www.consumersenergy.com/.well-known/security.txt rfc9116_notes: - Contact, Expires, Preferred-Languages and Canonical are present. - No Policy field — the document does not link a written disclosure policy. - No Encryption field — no PGP key is offered. - Not signed (no PGP SIGNED MESSAGE block). policy_page: present: false note: >- https://www.consumersenergy.com/security is indexed under the title "Vulnerability Disclosure Program" but now 302s to /terms-and-conditions#security; the standalone VDP page describing scope, qualifying vulnerabilities and sanctions exclusions is no longer served. Only the reporting address survives on the live page. scope_probed: - url: https://www.consumersenergy.com/.well-known/security.txt status: 200 - url: https://www.cmsenergy.com/.well-known/security.txt status: 200 note: Catch-all "Invalid key" body, not a security.txt. - url: https://greenbutton.consumersenergy.com/.well-known/security.txt status: 404 - url: https://utilityapi.com/.well-known/security.txt status: 404