security.txt Generator - Create a Valid RFC 9116 security.txt File
security.txt Generator
Tell security researchers how to report a vulnerability to you
A Valid File
Fill in the fields and get a correctly formatted security.txt with the required Contact and Expires lines.
Checked as You Type
Emails and phone numbers get their mailto: and tel: prefix, web links must be https, and the expiry date must be in the future.
Download and Publish
Download the file and upload it to /.well-known/security.txt on your site, over HTTPS.
Full Privacy
The file is built in your browser and never uploaded.
What security.txt Is For
security.txt (RFC 9116) is a small text file at /.well-known/security.txt that tells people who find a vulnerability in your site where to report it. Without it, researchers guess at addresses, or give up, or publish. The two required lines are Contact, an email address, phone number or web page, and Expires, a date after which the file should no longer be trusted.
Optional lines help further: Encryption points to a public key for sensitive reports, Policy to your disclosure rules, Acknowledgments to a thank-you page, Canonical to the official location of the file, and Preferred-Languages to the languages you can read. The RFC recommends signing the file with an OpenPGP cleartext signature, which this tool does not do, so sign it yourself if you can. Set a reminder to renew the Expires date before it lapses.
Key Takeaways
- Where it goes: Serve it over HTTPS at /.well-known/security.txt (and optionally at /security.txt).
- Keep it current: The default expiry is a day short of a year, the longest the RFC recommends.
- Related tools: See also the CSP Header Generator and the robots.txt Generator.