Security.txt Generator
Generate a security.txt file so researchers can report vulnerabilities to the right place.
Security.txt Generator
Generate a standard security.txt file to help security researchers report vulnerabilities.
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
A standard place to look
RFC 9116 defines a file at /.well-known/security.txt listing how to report a security issue. Without one, a researcher who finds a flaw guesses at contact addresses, tries support, or gives up — and the alternative to a report reaching you is not silence, it is disclosure somewhere else.
Required and useful fields
Contact and Expires are mandatory. Contact may be an email, a form URL or a phone number, and multiple entries are allowed in preference order. Expires forces the file to be reviewed rather than left stale for years. Encryption points to a PGP key, Policy to your disclosure policy, Acknowledgments to a thanks page and Preferred-Languages to the languages your team reads.
Location and format are strict
It belongs at /.well-known/security.txt, served over HTTPS as text/plain. A copy at the web root is permitted for legacy reasons but the well-known path is what tools check. Serving it as HTML, or behind a redirect chain, causes scanners to miss it.
Signing is optional and worth it
The file may carry a detached PGP signature at security.txt.sig, which proves the contact details were not altered by whoever could edit the site. For a high-value target that matters, since a modified security.txt routes reports to an attacker.
A contact address is a commitment
Publishing an address that nobody monitors is worse than publishing nothing, because a researcher reasonably concludes they have discharged their obligation. The address needs an owner and a response expectation stated in the linked policy.
Frequently Asked Questions
Privacy & Security
Local generation.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.