security.txt Generator
Generate an RFC 9116 compliant security.txt file to streamline vulnerability reporting and responsible disclosure.
RFC 9116 Directives
Must start with mailto:, tel:, or https://
Must be an ISO 8601 formatted date-time in the future.
# security.txt - RFC 9116 Vulnerability Disclosure Policy # Generated by BosonWare Tools (https://bosonware.com/tools/security-txt) Contact: mailto:security@bosonware.com Contact: https://bosonware.com/contact Expires: 2027-09-11T05:57:39Z Encryption: https://bosonware.com/pgp-key.txt Acknowledgments: https://bosonware.com/legal/acknowledgments Policy: https://bosonware.com/legal/security-policy Hiring: https://bosonware.com/careers Canonical: https://bosonware.com/.well-known/security.txt Preferred-Languages: en
Where to deploy security.txt:
According to RFC 9116, upload this file to the /.well-known/ directory:
https://yourdomain.com/.well-known/security.txt
A fallback redirect or mirror at https://yourdomain.com/security.txt is also standard practice.
Enable Responsible Vulnerability Disclosure
Security researchers who identify software vulnerabilities need a straightforward, authorized channel to report findings directly to your security engineering team. RFC 9116 establishes /.well-known/security.txt as the standard discovery endpoint.
Required & Optional RFC 9116 Directives
- Contact (Required): Direct email address (
mailto:) or web reporting portal URL (https://). - Expires (Required): Future ISO 8601 timestamp after which the file should be re-validated.
- Encryption: URI to your team's public PGP key for encrypted communications.
- Policy: Link to your vulnerability disclosure policy, safe harbor terms, or bug bounty program.
- Acknowledgments: Link to your security hall of fame acknowledging ethical contributors.
Help & FAQs
Frequently Asked Questions
Common questions and technical guidance about this tool.
Discover More
Related Free Tools
Security Headers Checker
Inspect HTTP security headers including HSTS, CSP, X-Content-Type-Options, Referrer-Policy, and COOP with clear hardening instructions.
Meta Tag Checker
Inspect titles, descriptions, canonical URLs, robots directives, Open Graph tags, and heading structure with clear diagnostic insights.
Schema Markup Generator
Generate valid JSON-LD structured data for Organizations, WebSites, Articles, Products, Local Businesses, Breadcrumbs, and FAQs.