security.txt Generator

Generate an RFC 9116 security.txt file so researchers know how to report vulnerabilities on your site.

Runs instantly in your browser — results update as you type.

What is security.txt?

security.txt is a standard file (RFC 9116) at /.well-known/security.txt that tells security researchers how to report vulnerabilities. It must contain at least one Contact and an Expires date less than a year ahead; the generator adds optional Encryption, Policy, Acknowledgments, Preferred-Languages and Canonical fields.

Example

Contact: mailto:security@example.com
Expires: 2027-10-01T00:00:00Z
Policy: https://example.com/security-policy
Preferred-Languages: en

Set a reminder to update the Expires date before it passes — an expired file is treated as invalid.

Frequently asked questions

Is security.txt required?

Not by law, but it is recommended by CISA and many security teams.

Should I sign it?

Optionally with OpenPGP; then publish your key URL in Encryption.

Where exactly do I put it?

https://yourdomain/.well-known/security.txt