Security.txt generator
Builds an RFC 9116-compliant security.txt entirely in your browser - nothing is sent to a server.
1 · Required fields
2 · Optional fields
What this builds
A ready-to-install security.txt covering the fields RFC 9116 defines - Contact and Expires are required; Encryption, Acknowledgments, Preferred-Languages, Policy, Hiring and Canonical are optional. Built entirely client-side; nothing you type is sent anywhere until you copy or download it yourself.
Where to put it
Install the generated file at /.well-known/security.txt - that is the location RFC 9116 requires. A copy at the legacy /security.txt is optional once the well-known location works.
Rate this tool
Was this tool useful? Your feedback helps us improve it.