Compliance

Security.txt Generator

Generate a security.txt file so researchers can report vulnerabilities to the right place.

Last reviewed by the Radiatus Cloud team

Security.txt Generator

Generate a standard security.txt file to help security researchers report vulnerabilities.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

A standard place to look

RFC 9116 defines a file at /.well-known/security.txt listing how to report a security issue. Without one, a researcher who finds a flaw guesses at contact addresses, tries support, or gives up — and the alternative to a report reaching you is not silence, it is disclosure somewhere else.

Required and useful fields

Contact and Expires are mandatory. Contact may be an email, a form URL or a phone number, and multiple entries are allowed in preference order. Expires forces the file to be reviewed rather than left stale for years. Encryption points to a PGP key, Policy to your disclosure policy, Acknowledgments to a thanks page and Preferred-Languages to the languages your team reads.

Location and format are strict

It belongs at /.well-known/security.txt, served over HTTPS as text/plain. A copy at the web root is permitted for legacy reasons but the well-known path is what tools check. Serving it as HTML, or behind a redirect chain, causes scanners to miss it.

Signing is optional and worth it

The file may carry a detached PGP signature at security.txt.sig, which proves the contact details were not altered by whoever could edit the site. For a high-value target that matters, since a modified security.txt routes reports to an attacker.

A contact address is a commitment

Publishing an address that nobody monitors is worse than publishing nothing, because a researcher reasonably concludes they have discharged their obligation. The address needs an owner and a response expectation stated in the linked policy.

Related tools

Frequently Asked Questions

Where does security.txt go?

At /.well-known/security.txt, served over HTTPS as plain text. A web-root copy is allowed for legacy reasons but tools check the well-known path.

Which fields are required?

Contact and Expires. Contact can be an email, form URL or phone number, and Expires forces periodic review so the file does not go stale.

Should I sign the file?

For a high-value target, yes. A detached PGP signature proves the contact details were not altered by whoever could edit the site, which would otherwise route reports to an attacker.

What if nobody monitors the address?

That is worse than having no file, because a researcher reasonably concludes they have discharged their obligation once they have sent the report.

Privacy & Security

Local generation.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.