Security.txt Generator
Generate a security.txt file so researchers can report vulnerabilities to the right place.
Last reviewed by the Radiatus Cloud team
Security.txt Generator
Generate a standard security.txt file to help security researchers report vulnerabilities.
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
A standard place to look
RFC 9116 defines a file at /.well-known/security.txt listing how to report a security issue. Without one, a researcher who finds a flaw guesses at contact addresses, tries support, or gives up — and the alternative to a report reaching you is not silence, it is disclosure somewhere else.
Required and useful fields
Contact and Expires are mandatory. Contact may be an email, a form URL or a phone number, and multiple entries are allowed in preference order. Expires forces the file to be reviewed rather than left stale for years. Encryption points to a PGP key, Policy to your disclosure policy, Acknowledgments to a thanks page and Preferred-Languages to the languages your team reads.
Location and format are strict
It belongs at /.well-known/security.txt, served over HTTPS as text/plain. A copy at the web root is permitted for legacy reasons but the well-known path is what tools check. Serving it as HTML, or behind a redirect chain, causes scanners to miss it.
Signing is optional and worth it
The file may carry a detached PGP signature at security.txt.sig, which proves the contact details were not altered by whoever could edit the site. For a high-value target that matters, since a modified security.txt routes reports to an attacker.
A contact address is a commitment
Publishing an address that nobody monitors is worse than publishing nothing, because a researcher reasonably concludes they have discharged their obligation. The address needs an owner and a response expectation stated in the linked policy.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
Where does security.txt go?
At /.well-known/security.txt, served over HTTPS as plain text. A web-root copy is allowed for legacy reasons but tools check the well-known path.
Which fields are required?
Contact and Expires. Contact can be an email, form URL or phone number, and Expires forces periodic review so the file does not go stale.
Should I sign the file?
For a high-value target, yes. A detached PGP signature proves the contact details were not altered by whoever could edit the site, which would otherwise route reports to an attacker.
What if nobody monitors the address?
That is worse than having no file, because a researcher reasonably concludes they have discharged their obligation once they have sent the report.
Privacy & Security
Local generation.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.