RFC 9116
security.txt Configuration Creator
Generate compliant security.txt files following RFC 9116 standards for vulnerability disclosure coordination.
Configuration Fields
Generated security.txt
Contact: Expires: Encryption: Acknowledgments: Preferred-Languages: Canonical: Policy: Hiring:
Deployment Instructions
1
Place the file at/.well-known/security.txt
Must be accessible via HTTPS from your domain root
2
Set appropriate Content-Type header
Content-Type: text/plain; charset=utf-8
3
Keep the Expires field updated
Renew before expiration to maintain validity
RFC 9116 Compliance Checklist
auto.tools.securitytxt.page.checklist.contact
auto.tools.securitytxt.page.checklist.expires
auto.tools.securitytxt.page.checklist.fileAccessible
auto.tools.securitytxt.page.checklist.contentType
auto.tools.securitytxt.page.checklist.fileSize
auto.tools.securitytxt.page.checklist.lineEndings
auto.tools.securitytxt.page.checklist.noComments
auto.tools.securitytxt.page.checklist.caseInsensitive