Skip to main content
1

security.txt Generator

Generate RFC 9116 compliant security.txt files for your website. Include contact information, encryption, policy, and acknowledgments.

security.txt Generator
security.txt
More options
Was this tool helpful?
Send output to:
Advertisement

How to use security.txt Generator

  1. Fill in your contact information (email, URL, or phone).
  2. Add your security policy and PGP key URL.
  3. Set the expiration date.
  4. Copy the security.txt file to /.well-known/security.txt.

What is security.txt Generator?

security.txt is a proposed standard (RFC 9116) that allows websites to define security policies and contact information for security researchers. It's placed at /.well-known/security.txt on your domain.

This generator creates a properly formatted security.txt file with fields for Contact, Expires, Encryption, Policy, Acknowledgments, and Hiring. It helps security researchers report vulnerabilities responsibly.

Advertisement

FAQ

Where should I put security.txt?
Place it at https://yourdomain.com/.well-known/security.txt or at the root of your domain.
Is security.txt required?
It's not required but is recommended by security best practices and helps security researchers report vulnerabilities to you.

Related tools

Advertisement