PB
Available
security
lock Free · Private · In-Browser

Security.txt Generator

Create a security.txt disclosure policy with required contact and expiration fields.

 

Publish a clear vulnerability contact policy

A security.txt file gives researchers a predictable way to find the correct reporting channel. This generator requires at least one Contact using mailto, HTTPS, or telephone syntax, parses an expiration timestamp into normalized UTC form, and can add preferred languages, a canonical policy location, an encryption-key link, and an acknowledgments page. Each directive is emitted on its own line.

The default output includes both email and web reporting contacts, an expiration at the start of 2030 UTC, English and French preferences, the canonical well-known URL, and an acknowledgments page. An invalid contact scheme or date returns a direct error instead of creating a policy clients cannot interpret.

Required fields and operational ownership

A syntactically correct file is useful only when the listed channels are monitored and the expiration is renewed. Publish it at the well-known path over HTTPS, consider a matching signature workflow, and align response expectations with the organization handling reports. Generation runs locally in your browser. Do not list an inbox, key, or acknowledgment process that the security team does not actually maintain.

Frequently Asked Questions

Which fields are required by this generator?

At least one Contact and a valid Expires timestamp are required; the remaining directives are optional.

Where should security.txt be published?

The standard location is the security.txt file under the site well-known directory, served over HTTPS.

Does the tool sign the policy?

No. It creates the text policy; cryptographic signing and key publication require a separate trusted workflow.

Take it further
All Free Tools

Browse the full set of free, private, in-browser tools.

Learn More arrow_forward