Generator Settings
Your domain
*
RFC 9116 requires every URL in the file to use
https
and, ideally, your own domain.
Contact
*
Add
At least one is mandatory. List them in the order you prefer to be reached — email, form URL or phone.
Expires
*
Custom date…
90 days
6 months
12 months (recommended)
24 months
The only required date field. Researchers treat an expired file as unmaintained — set a calendar reminder to refresh it.
Policy URL
Your vulnerability disclosure policy: scope, safe harbour, expected response times.
Encryption (public key URL)
Must point
to
a key — never paste the key itself into security.txt.
Acknowledgments URL
A public thank-you page measurably increases quality report volume.
Hiring URL
CSAF (provider-metadata.json URL)
For vendors publishing machine-readable security advisories.
Preferred-Languages
Comma-separated RFC 5646 tags. Only one
Preferred-Languages
line is allowed.
Canonical URL(s)
Leave blank to auto-fill with the standard
/.well-known/
location.
Options
Auto-generate Canonical
Adds the
/.well-known/security.txt
URL for your domain.
Include header comments
Human-readable notes above the machine-readable fields.
Add PGP signature placeholder
Wraps the file in a clear-sign block for you to sign locally.
Generate security.txt
Generated File
ready
security.txt
RFC 9116 validation
Deploy & sign
.well-known/security.txt
Copy
Download
The canonical location is
/.well-known/security.txt
. Placing a copy at
/security.txt
as a fallback is allowed but optional.