Security.txt Generator
Create a security.txt file to help researchers report vulnerabilities.
Runs in your browser Your input never leaves your device.
About this tool
Creates the text of a security.txt file, a small standard file that tells security researchers how to report a vulnerability to you. Fill in a Contact (such as mailto:security@example.com or a web form URL), an Expires date (left blank, it defaults to one year from now), an Encryption key URL, a Policy URL and Preferred languages, and the tool outputs the matching lines. Empty fields are skipped. The tool does not validate your entries, so check the format of any Expires date you type (ISO 8601, such as 2027-12-31T23:59:59Z) yourself. Publish the finished file at /.well-known/security.txt on your site over HTTPS. The text is generated in your browser.
How to use it
- Enter a contact address or URL, usually starting with mailto: or https://.
- Optionally set an Expires date (blank = one year from now), and add an encryption key, a policy page and languages.
- Copy the output into a plain text file named security.txt.
- Upload it to /.well-known/security.txt on your domain.
Example
Contact: mailto:security@example.com Expires: 2027-12-31T23:59:59Z
Contact: mailto:security@example.com Expires: 2027-12-31T23:59:59Z
Common problems
- The file is ignored by scanners
- The standard (RFC 9116) requires Contact and Expires. The tool adds Expires one year ahead when you leave it blank; renew the file before that date.
- The file is not found
- It must be served at https://yourdomain/.well-known/security.txt as plain text, not inside a page or behind a login.
- The Expires date is old
- An expired file is considered stale. Set a date in the future and renew it before it passes.