Security.txt Generator
Build an RFC 9116 compliant security.txt file with contact methods, expiry, and optional fields.
Required Fields
Optional & Advanced Fields
About this tool
A security.txt file tells security researchers exactly how to report a vulnerability to your organization, instead of leaving them guessing or giving up. This generator builds a fully RFC 9116 compliant file: add one or more contact methods (email, phone, or a web form URL), set a required expiration date, and optionally add preferred languages, a canonical URL, a vulnerability disclosure policy link, a PGP encryption key link, an acknowledgments page, and a security hiring page.
Where to publish it
Once generated, download or copy the file and publish it at /.well-known/security.txt on your domain — the standard location crawlers and researchers check first.
