security.txt Generator - Create a Valid RFC 9116 security.txt File

AdSense Placeholder
Slot: header_tool

security.txt Generator

Tell security researchers how to report a vulnerability to you

Publish it at: example.com/.well-known/security.txt

    AdSense Placeholder
    Slot: tool_mid_article

    A Valid File

    Fill in the fields and get a correctly formatted security.txt with the required Contact and Expires lines.

    Checked as You Type

    Emails and phone numbers get their mailto: and tel: prefix, web links must be https, and the expiry date must be in the future.

    Download and Publish

    Download the file and upload it to /.well-known/security.txt on your site, over HTTPS.

    Full Privacy

    The file is built in your browser and never uploaded.

    What security.txt Is For

    security.txt (RFC 9116) is a small text file at /.well-known/security.txt that tells people who find a vulnerability in your site where to report it. Without it, researchers guess at addresses, or give up, or publish. The two required lines are Contact, an email address, phone number or web page, and Expires, a date after which the file should no longer be trusted.

    Optional lines help further: Encryption points to a public key for sensitive reports, Policy to your disclosure rules, Acknowledgments to a thank-you page, Canonical to the official location of the file, and Preferred-Languages to the languages you can read. The RFC recommends signing the file with an OpenPGP cleartext signature, which this tool does not do, so sign it yourself if you can. Set a reminder to renew the Expires date before it lapses.

    Key Takeaways

    • Where it goes: Serve it over HTTPS at /.well-known/security.txt (and optionally at /security.txt).
    • Keep it current: The default expiry is a day short of a year, the longest the RFC recommends.
    • Related tools: See also the CSP Header Generator and the robots.txt Generator.
    AdSense Placeholder
    Slot: footer_leaderboard