Security.txt Generator
Create a security.txt disclosure file following the common well-known format.
Create a security.txt file
Security.txt gives researchers an authorized contact path for reporting vulnerabilities. Publish it at /.well-known/security.txt over HTTPS.
Keep contact details and the expiry date current.
How to use the Security.txt Generator
- Complete the available options using values appropriate for your project.
- Generate the result and read it before copying or downloading it.
- Test the generated output in a safe environment before production use.
Practical example
Review the result against the needs of the specific website or account instead of treating a generated value as a complete security review.
What this tool cannot guarantee
A focused browser tool cannot replace layered security controls, current software, monitoring or a professional assessment.
Continue this workflow with the Security.txt Validator
Read the Website Security Headers Guide for implementation guidance and common limitations.
Frequently asked questions
Is the Security.txt Generator free to use?
Yes. It is available without an account or paid subscription.
Is my input uploaded or stored?
The core operation runs in your browser. Avoid pasting secrets into any web page unless the individual tool explicitly explains how the data is handled.
Should I review the result before using it?
Yes. Check the output for your project and test it in the intended environment before production use.