Security.txt URL Generator
Hosted security.txt in minutes.
Generate a standards-compliant security.txt file with a stable URL for researchers and compliance checklists.
StartWhat is a security.txt file?
security.txt is a standardized file (RFC 9116) that tells security researchers how to report a vulnerability to you — where to send reports, your policy, and contact details. It is expected to live at /.well-known/security.txt on your domain and appears on many compliance and vendor-assessment checklists.
You get a properly formatted, hosted file with the required fields, so researchers and questionnaires find a clear point of contact.
Where a security.txt helps
- Vendor security questionnaires and due diligence
- Bug bounty and responsible-disclosure programs
- Compliance checklists that look for a disclosure contact
- Any public-facing domain that wants clean vulnerability reports
How it works
- 1Answer a few short questions about your business.
- 2We generate a compliant Security.txt URL page and host it at a stable link.
- 3Paste your URL wherever it's required — and update it anytime.
Frequently asked questions
Is security.txt required?
It is not legally mandated, but it is a widely adopted standard (RFC 9116) and increasingly requested in security reviews. Publishing one signals a mature disclosure process.
Where does the file go?
The standard location is /.well-known/security.txt on your domain. The generator produces the correctly formatted content and a hosted link you can reference.
What fields does it need?
At minimum a Contact field, and commonly an Expires date, Policy link, and preferred languages. The generator includes the required and recommended fields.
How often should I update it?
The Expires field should be kept current, so refresh the file periodically. You can update it at the same URL whenever your contacts change.