security.txt Generator
Create a security.txt file (RFC 9116) so researchers know how to report vulnerabilities to you.
security.txt
Upload the file to /.well-known/security.txt on your site. Update it before the Expires date; an expired file tells researchers it may no longer be read.
security.txt Generator
security.txt is a small text file, standardised as RFC 9116, that tells security researchers how to report a vulnerability they find on your website. Without it, reports often go nowhere. Fill in a contact and an expiry date (both required), plus optional fields such as your disclosure policy and encryption key, and upload the file to /.well-known/security.txt.
How to use security.txt Generator
- Enter a contact: an email address (mailto:), a web form URL or a phone number (tel:).
- Set the expiry date, no more than a year ahead. Put a reminder in your calendar to renew it.
- Add the optional fields you have: policy, acknowledgments, preferred languages, encryption key and canonical URL.
- Download the file and upload it to https://yourdomain/.well-known/security.txt.
When it comes in handy
- Giving ethical hackers a clear way to reach you.
- Meeting security questionnaire and bug bounty requirements.
Frequently asked questions
- Why is Expires required?
- So that stale files with old contacts are not trusted forever. RFC 9116 recommends an expiry less than a year in the future.
- Should the file be signed?
- Optionally, with an OpenPGP cleartext signature, which lets readers check it was not tampered with. The file must still be served over HTTPS.