Sign in

Security.txt Implementation Guide

Complete guide to implementing security.txt according to RFC 9116. Enable security researchers to contact you properly.

What is Security.txt?

Security.txt is a standard defined in RFC 9116 that allows organizations to provide security contact information in a machine-readable format. It helps security researchers find the right way to report vulnerabilities.

The file is placed at /.well-known/security.txt on your domain and contains standardized fields for security contact information, policies, and acknowledgments.

Example Security.txt File

# Security Contact Information
Contact: mailto:[email protected]
Contact: https://example.com/security
Expires: 2025-12-31T23:59:59.000Z
Encryption: https://example.com/pgp-key.asc
Acknowledgments: https://example.com/security/hall-of-fame
Policy: https://example.com/security/disclosure-policy
Hiring: https://example.com/jobs/security

Implementation Steps

Step 1: Create Your Security.txt File

Create a plain text file with the required fields. All fields are optional except Contact and Expires.

Required Fields

  • Contact: How to reach your security team (email, URL, phone)
  • Expires: When this information expires (ISO 8601 format)

Optional Fields

  • Encryption: Link to PGP key for encrypted communication
  • Acknowledgments: URL to security researcher hall of fame
  • Policy: Link to vulnerability disclosure policy
  • Hiring: Link to security job openings
  • Canonical: Canonical URL of this security.txt file

Step 2: Format Requirements

File Format Rules

  • Use UTF-8 encoding
  • Use Unix-style line endings (LF)
  • Each field on a separate line
  • Format: Field: value
  • Comments start with #
  • Blank lines are ignored

Step 3: Choose Deployment Location

Deploy your security.txt file to one of these locations:

Preferred Location

/.well-known/security.txt

RFC 9116 compliant location. Most tools check here first.

Legacy Location

/security.txt

Root location for backward compatibility.

Step 4: Configure Web Server

Ensure your web server serves the file with the correct content type:

Apache (.htaccess)

<Files "security.txt">
  Header set Content-Type "text/plain; charset=utf-8"
</Files>

Nginx

location ~* /security\.txt$ {
  add_header Content-Type "text/plain; charset=utf-8";
}

Digital Signatures (Optional)

For enhanced security, you can digitally sign your security.txt file using PGP. This ensures authenticity and prevents tampering.

Creating a Signed File

# Create security.txt
echo "Contact: [email protected]" > security.txt
echo "Expires: 2025-12-31T23:59:59.000Z" >> security.txt
# Sign the file
gpg --clearsign security.txt
# Deploy the signed file
mv security.txt.asc /.well-known/security.txt

Benefits of Signing

  • Proves authenticity of contact information
  • Prevents tampering by malicious actors
  • Builds trust with security researchers
  • Demonstrates security maturity

Best Practices

Content Guidelines

Keep expiration date current

Set expiration to maximum 1 year, update regularly

Provide multiple contact methods

Include email, web form, and phone if available

Link to disclosure policy

Clear guidelines for researchers on reporting process

Use absolute URLs

Include full URLs for all links and references

Maintenance

Regular Updates

Review and update your security.txt file every 6 months or when contact information changes.

Monitoring

Set up monitoring to alert when your security.txt file is about to expire.

Testing

Regularly test that your contact methods work and security team receives reports.

Validation and Testing

Online Validators

Manual Testing

# Test accessibility
curl https://yoursite.com/.well-known/security.txt
# Check content type
curl -I https://yoursite.com/.well-known/security.txt

Common Mistakes to Avoid

Format Errors

  • Using HTML formatting in plain text file
  • Incorrect date format for Expires field
  • Missing required fields (Contact, Expires)

Deployment Issues

  • Wrong content-type (text/html instead of text/plain)
  • File not accessible due to server configuration
  • Forgetting to update expiration dates

Ready to Implement Security.txt?

Use our generator tool to create a compliant security.txt file for your organization.