Security.txt Implementation Guide
Complete guide to implementing security.txt according to RFC 9116. Enable security researchers to contact you properly.
What is Security.txt?
Security.txt is a standard defined in RFC 9116 that allows organizations to provide security contact information in a machine-readable format. It helps security researchers find the right way to report vulnerabilities.
The file is placed at /.well-known/security.txt on your domain and contains standardized fields for security contact information, policies, and acknowledgments.
Example Security.txt File
Implementation Steps
Step 1: Create Your Security.txt File
Create a plain text file with the required fields. All fields are optional except Contact and Expires.
Required Fields
- Contact: How to reach your security team (email, URL, phone)
- Expires: When this information expires (ISO 8601 format)
Optional Fields
- Encryption: Link to PGP key for encrypted communication
- Acknowledgments: URL to security researcher hall of fame
- Policy: Link to vulnerability disclosure policy
- Hiring: Link to security job openings
- Canonical: Canonical URL of this security.txt file
Step 2: Format Requirements
File Format Rules
- Use UTF-8 encoding
- Use Unix-style line endings (LF)
- Each field on a separate line
- Format:
Field: value - Comments start with #
- Blank lines are ignored
Step 3: Choose Deployment Location
Deploy your security.txt file to one of these locations:
Preferred Location
/.well-known/security.txt
RFC 9116 compliant location. Most tools check here first.
Legacy Location
/security.txt
Root location for backward compatibility.
Step 4: Configure Web Server
Ensure your web server serves the file with the correct content type:
Apache (.htaccess)
Nginx
Digital Signatures (Optional)
For enhanced security, you can digitally sign your security.txt file using PGP. This ensures authenticity and prevents tampering.
Creating a Signed File
Benefits of Signing
- Proves authenticity of contact information
- Prevents tampering by malicious actors
- Builds trust with security researchers
- Demonstrates security maturity
Best Practices
Content Guidelines
Keep expiration date current
Set expiration to maximum 1 year, update regularly
Provide multiple contact methods
Include email, web form, and phone if available
Link to disclosure policy
Clear guidelines for researchers on reporting process
Use absolute URLs
Include full URLs for all links and references
Maintenance
Regular Updates
Review and update your security.txt file every 6 months or when contact information changes.
Monitoring
Set up monitoring to alert when your security.txt file is about to expire.
Testing
Regularly test that your contact methods work and security team receives reports.
Validation and Testing
Online Validators
- securitytxt.org validator
- security.txt.org checker
- Manual curl testing
Manual Testing
Common Mistakes to Avoid
Format Errors
-
Using HTML formatting in plain text file
-
Incorrect date format for Expires field
-
Missing required fields (Contact, Expires)
Deployment Issues
-
Wrong content-type (text/html instead of text/plain)
-
File not accessible due to server configuration
-
Forgetting to update expiration dates
Ready to Implement Security.txt?
Use our generator tool to create a compliant security.txt file for your organization.