BosonWareEnterprises
Security Tool

security.txt Generator

Generate an RFC 9116 compliant security.txt file to streamline vulnerability reporting and responsible disclosure.

100% Free No Account Required Zero Data Tracking

RFC 9116 Directives

Standardized Format

Must start with mailto:, tel:, or https://

Must be an ISO 8601 formatted date-time in the future.

Generated security.txt
# security.txt - RFC 9116 Vulnerability Disclosure Policy
# Generated by BosonWare Tools (https://bosonware.com/tools/security-txt)

Contact: mailto:security@bosonware.com
Contact: https://bosonware.com/contact
Expires: 2027-09-11T05:57:39Z
Encryption: https://bosonware.com/pgp-key.txt
Acknowledgments: https://bosonware.com/legal/acknowledgments
Policy: https://bosonware.com/legal/security-policy
Hiring: https://bosonware.com/careers
Canonical: https://bosonware.com/.well-known/security.txt
Preferred-Languages: en

Where to deploy security.txt:

According to RFC 9116, upload this file to the /.well-known/ directory:

https://yourdomain.com/.well-known/security.txt

A fallback redirect or mirror at https://yourdomain.com/security.txt is also standard practice.

Enable Responsible Vulnerability Disclosure

Security researchers who identify software vulnerabilities need a straightforward, authorized channel to report findings directly to your security engineering team. RFC 9116 establishes /.well-known/security.txt as the standard discovery endpoint.

Required & Optional RFC 9116 Directives

  • Contact (Required): Direct email address (mailto:) or web reporting portal URL (https://).
  • Expires (Required): Future ISO 8601 timestamp after which the file should be re-validated.
  • Encryption: URI to your team's public PGP key for encrypted communications.
  • Policy: Link to your vulnerability disclosure policy, safe harbor terms, or bug bounty program.
  • Acknowledgments: Link to your security hall of fame acknowledging ethical contributors.

Help & FAQs

Frequently Asked Questions

Common questions and technical guidance about this tool.

security.txt is an IETF standard (RFC 9116) that provides a standardized way for security researchers to find a company's contact information and vulnerability disclosure policy quickly.

Discover More

Related Free Tools

View all tools →