Security.txt URL Generator

Security.txt URL hero

Hosted security.txt in minutes.

Generate a standards-compliant security.txt file with a stable URL for researchers and compliance checklists.

Start

What is a security.txt file?

security.txt is a standardized file (RFC 9116) that tells security researchers how to report a vulnerability to you — where to send reports, your policy, and contact details. It is expected to live at /.well-known/security.txt on your domain and appears on many compliance and vendor-assessment checklists.

You get a properly formatted, hosted file with the required fields, so researchers and questionnaires find a clear point of contact.

Where a security.txt helps

  • Vendor security questionnaires and due diligence
  • Bug bounty and responsible-disclosure programs
  • Compliance checklists that look for a disclosure contact
  • Any public-facing domain that wants clean vulnerability reports

How it works

  1. 1Answer a few short questions about your business.
  2. 2We generate a compliant Security.txt URL page and host it at a stable link.
  3. 3Paste your URL wherever it's required — and update it anytime.

Frequently asked questions

Is security.txt required?

It is not legally mandated, but it is a widely adopted standard (RFC 9116) and increasingly requested in security reviews. Publishing one signals a mature disclosure process.

Where does the file go?

The standard location is /.well-known/security.txt on your domain. The generator produces the correctly formatted content and a hosted link you can reference.

What fields does it need?

At minimum a Contact field, and commonly an Expires date, Policy link, and preferred languages. The generator includes the required and recommended fields.

How often should I update it?

The Expires field should be kept current, so refresh the file periodically. You can update it at the same URL whenever your contacts change.