generated: '2026-07-27' method: searched source: https://www.energy.gov/cio/articles/vulnerability-disclosure-policy summary: | EIA does not run its own vulnerability disclosure program and publishes no security.txt (see well-known/eia-well-known.yml). It is covered by the parent Department of Energy Vulnerability Disclosure Program, and every page on www.eia.gov - including the Open Data and API documentation pages - carries a footer link to it: "Learn about the Department of Energy's Vulnerability Disclosure Program" -> https://www.energy.gov/cio/articles/vulnerability-disclosure-policy (HTTP 200, last updated 2024-10-02). The policy is published as Attachment 2 to DOE Order 205.1D and exists to meet OMB M-20-32 and CISA Binding Operational Directive 20-01. Intake is through the DOE responsible-disclosure portal at https://doe.responsibledisclosure.com (returns HTTP 403 to an anonymous scripted GET - it is a browser-gated submission portal, not an open page). Scope expands progressively under the Order until all DOE public, internet-accessible websites and digital services are in scope. policy: - https://www.energy.gov/cio/articles/vulnerability-disclosure-policy - https://www.energy.gov/vulnerability-disclosure-policy intake: - https://doe.responsibledisclosure.com contact: - DOEOCIOInfo@hq.doe.gov program: operator: U.S. Department of Energy, Office of the Chief Information Officer authority: DOE O 205.1D, Attachment 2 drivers: - OMB M-20-32 - CISA BOD 20-01 bug_bounty: false security_txt: false evidence: - source: https://www.eia.gov/opendata/documentation.php kind: footer link detail: 'Anchor: "Learn about the Department of Energy''s Vulnerability Disclosure Program" -> https://www.energy.gov/cio/articles/vulnerability-disclosure-policy' - source: https://www.energy.gov/cio/articles/vulnerability-disclosure-policy kind: policy page status: 200 - source: https://doe.responsibledisclosure.com kind: disclosure portal status: 403 - source: https://www.eia.gov/.well-known/security.txt kind: security.txt status: 404