security.txt Generator

Generate security.txt files following the RFC 9116 standard for vulnerability disclosure

All processing happens in your browser. No data is uploaded.
Offline Ready

security.txt Generator

Generate security.txt files following the RFC 9116 standard for vulnerability disclosure

🔒All processing happens in your browser. No data is uploaded.
Contact
Required

URI for reporting security vulnerabilities. Must use mailto:, https://, or tel: scheme. At least one Contact field is required.

mailto:security@example.com
Expires
Required

Date and time after which this security.txt data should be considered stale. Required by RFC 9116. Recommended: no more than one year from now.

YYYY-MM-DD
Encryption
Optional

URI pointing to an encryption key for secure communication. Must use https://, dns:, or openpgp4fpr: scheme.

https://example.com/.well-known/pgp-key.txt
Acknowledgments
Optional

URI to a page listing security researchers who have responsibly reported vulnerabilities.

https://example.com/hall-of-fame
Canonical
Optional

The canonical URI where this security.txt file is located. Helps verify authenticity.

https://example.com/.well-known/security.txt
Policy
Optional

URI to the organization's vulnerability disclosure policy.

https://example.com/security-policy
Preferred Languages
Optional

Comma-separated list of preferred language codes (ISO 639) for security reports.

Hiring
Optional

URI to the organization's security-related job positions.

https://example.com/careers
Options
Include explanatory comments
Validation
Generated security.txt
Place this file at: /.well-known/security.txt
# This is a security.txt file that follows the RFC 9116 standard.
# https://www.rfc-editor.org/rfc/rfc9116

Contact: mailto:security@example.com
Preferred-Languages: en