Free Tools

security.txt Generator and Validator

Check a domain

We'll look for a security.txt file and check it against RFC 9116.

You can also , or use the editor below.

Build a file

Make your fixes here, then press Update file at the bottom to rebuild. Nothing changes for you until you do.

Contact Required

How someone reports a vulnerability to you. List them in the order you want them used.

Expires Required Only once

After this date the file should be treated as out of date.

Encryption

A link to the key someone should encrypt their report with.

Acknowledgments

Where you credit researchers who have reported to you.

Preferred-Languages Only once

The languages your security team reads, comma separated.

Canonical

Where this file is officially published.

Policy

Your vulnerability disclosure policy.

Hiring

A link to your security-related job openings.

Bug-Bounty

Whether you run a reward programme for vulnerability reports.

CSAF

A link to your Common Security Advisory Framework provider metadata.

Published your security.txt? Find out what your site is actually reporting.

Report URI collects security telemetry from real browsers on your site — CSP violations, certificate changes, script tampering — so problems reach you before someone has to write to the address you just published.