Sign in

security.txt: What It Is and How to Publish It

A simple text file that helps researchers find your security contact and policy.

What is security.txt?

security.txt is a proposed standard (RFC 9116) that provides a standardized way for websites to define security policies and contact information for security researchers. It solves the common problem of researchers not knowing how to report vulnerabilities they discover.

Why security.txt matters

Discoverability: Researchers can automatically find your security contact information without guessing email addresses or hunting through websites.

Standardization: Consistent format across organizations makes it easier for security tools and researchers to parse contact information.

Legal Clarity: Direct link to your vulnerability disclosure policy and safe harbor terms reduces legal uncertainty.

Automation: Security scanners and research tools can automatically discover and respect your disclosure preferences.

Standard Locations

Primary: https://example.com/.well-known/security.txt
Fallback: https://example.com/security.txt
The /.well-known/ location is preferred as it follows RFC 8615 for well-known URIs.

Fields & Format Specification

Required Fields

Contact
At least one contact method must be provided. Multiple contacts are allowed.
Contact: mailto:[email protected]
Contact: https://example.com/security-contact
Contact: tel:+1-555-123-4567
Expires
RFC 3339 timestamp indicating when this file should be considered stale. Maximum 1 year from creation.
Expires: 2025-12-31T23:59:59.000Z

Optional Fields

Policy
Link to your vulnerability disclosure policy
Encryption
Link to PGP key for encrypted communications
Acknowledgments
Link to researcher hall of fame or thanks page
Preferred-Languages
ISO 639-1 language codes (comma-separated)
Canonical
Authoritative URL for this security.txt file
Hiring
Link to security job openings

Format Requirements

  • Plain text file encoded in UTF-8
  • One field per line in "Field: Value" format
  • Lines starting with # are comments
  • Empty lines are ignored
  • Field names are case-insensitive
  • URLs must be absolute (include https://)
  • Maximum file size: 64KB

Deployment and Web Server Configuration

File Placement

The security.txt file must be accessible via HTTPS at specific locations. The primary location follows RFC 8615 for well-known URIs:

Primary Location (Recommended)
https://example.com/.well-known/security.txt
This location is preferred as it follows established standards for well-known URIs.
Fallback Location
https://example.com/security.txt
Use this if you cannot configure the /.well-known/ directory.

Web Server Configuration

Apache (.htaccess)
# Serve security.txt with correct MIME type
<Files "security.txt">
    Header set Content-Type "text/plain; charset=utf-8"
    Header set Cache-Control "public, max-age=86400"
</Files>

# Enable /.well-known/ directory
RewriteEngine On
RewriteRule ^\.well-known/security\.txt$ /security.txt [L]
Nginx
location = /.well-known/security.txt {
    alias /var/www/html/security.txt;
    add_header Content-Type "text/plain; charset=utf-8";
    add_header Cache-Control "public, max-age=86400";
}

location = /security.txt {
    add_header Content-Type "text/plain; charset=utf-8";
    add_header Cache-Control "public, max-age=86400";
}
Cloudflare Workers
addEventListener('fetch', event => {
  event.respondWith(handleRequest(event.request))
})

async function handleRequest(request) {
  const url = new URL(request.url)

  if (url.pathname === '/.well-known/security.txt' || url.pathname === '/security.txt') {
    const securityTxt = `Contact: mailto:[email protected]
Policy: https://example.com/security-policy
Expires: 2025-12-31T23:59:59.000Z
Canonical: https://example.com/.well-known/security.txt`

    return new Response(securityTxt, {
      headers: {
        'Content-Type': 'text/plain; charset=utf-8',
        'Cache-Control': 'public, max-age=86400'
      }
    })
  }

  return fetch(request)
}
Live Example: View our security.txt file at https://responsibledisclosure.io/.well-known/security.txt

Complete Examples

Basic Example

Minimal security.txt with required fields only:

# Basic security.txt for example.com
Contact: mailto:[email protected]
Expires: 2025-12-31T23:59:59.000Z

Comprehensive Example

Full-featured security.txt with all recommended fields:

# Security contact information for example.com
# Updated: 2024-01-15

Contact: mailto:[email protected]
Contact: https://example.com/security/contact
Contact: tel:+1-555-123-4567

# Link to our vulnerability disclosure policy
Policy: https://example.com/security/disclosure-policy

# PGP key for encrypted communications
Encryption: https://example.com/.well-known/pgp-key.asc

# Hall of fame for security researchers
Acknowledgments: https://example.com/security/hall-of-fame

# We prefer reports in English, but accept German and French
Preferred-Languages: en, de, fr

# Canonical location of this file
Canonical: https://example.com/.well-known/security.txt

# Security job openings
Hiring: https://example.com/careers/security

# File expires at end of 2025
Expires: 2025-12-31T23:59:59.000Z

Enterprise Example

Enterprise security.txt with multiple contact methods and detailed policies:

# Enterprise Corp Security Team
# For immediate security issues, use the phone number
# For non-urgent issues, use email or web form

Contact: tel:+1-800-SECURITY (24/7 hotline)
Contact: mailto:[email protected]
Contact: https://enterprise.com/security/report

# Detailed disclosure policy with legal safe harbor
Policy: https://enterprise.com/security/responsible-disclosure

# Department PGP key (4096-bit RSA)
Encryption: https://enterprise.com/.well-known/security-pgp.asc

# Security researcher recognition program
Acknowledgments: https://enterprise.com/security/researchers

# Multilingual support
Preferred-Languages: en, es, fr, de, ja

# This file's canonical location
Canonical: https://enterprise.com/.well-known/security.txt

# Join our world-class security team
Hiring: https://enterprise.com/careers/security

# File valid through Q4 2025
Expires: 2025-12-31T23:59:59.000Z

Validation and Testing

Automated Validation Tools

Online Validators
Command Line Tools
  • curl for basic connectivity testing
  • security-txt Python package
  • Custom scripts for CI/CD integration

Manual Testing Checklist

Monitoring and Maintenance

Regular Updates: Review and update your security.txt file at least every 6 months, or when contact information changes.

Expiration Monitoring: Set calendar reminders to update the Expires field before it lapses. Some organizations use monitoring tools to alert when expiration approaches.

Contact Testing: Periodically test all contact methods to ensure they reach the security team and generate appropriate responses.

Policy Synchronization: Keep the Policy URL synchronized with your actual vulnerability disclosure process and legal requirements.

Implementation Best Practices

Security Considerations

Contact Method Security
  • Use dedicated security email addresses that are monitored 24/7
  • Ensure phone numbers reach security personnel, not general support
  • Implement email encryption for sensitive vulnerability reports
  • Avoid personal email addresses or unmonitored contact methods
Infrastructure Security
  • Serve security.txt over HTTPS only
  • Use appropriate caching headers (24-hour cache is reasonable)
  • Monitor access logs for unusual patterns or automated scraping
  • Ensure the file is accessible even during maintenance windows

Organizational Integration

Process Integration
  • Include security.txt in incident response procedures
  • Train support staff to escalate security contacts
  • Document security.txt maintenance in security policies
  • Include file updates in change management processes
Legal and Compliance
  • Coordinate policy URLs with legal team
  • Ensure contact methods comply with data protection laws
  • Review language preferences for regulatory requirements
  • Document security.txt for compliance audits

Generate Your security.txt File

Use our interactive generator to create a compliant security.txt file for your domain. The generator includes validation, best practice recommendations, and deployment instructions.

Interactive Generator
Create, validate, and download your security.txt file