Loading…
Standardizing responsible vulnerability disclosure for your domain.
Learn how to implement the global Internet standard for responsible vulnerability disclosure. Give ethical hackers a secure reporting channel, protect your users from unaddressed zero-days, and fulfill enterprise compliance directives.
Published by the Internet Engineering Task Force (IETF) in May 2022, RFC 9116 established a machine-readable format for organizations to publish their security contact details. Prior to this standard, researchers who discovered security bugs frequently struggled to find the appropriate security contact, resulting in delayed patches, leaked exploits, or public disclosures.
Direct contact lines prevent researchers from sharing sensitive exploits on public forums.
Satisfies US CISA BOD 20-01, European NIS2 directives, and SOC 2 / ISO 27001 audit standards.
Encourages reporters to encrypt sensitive bug details using your public PGP key.
Specifies where vulnerability reports should be sent. Must use mailto: or https:// URL. Multiple contact directives are permitted.
An ISO 8601 timestamp after which the data in the security.txt file should no longer be considered valid.
A link to your public PGP/GPG key so reporters can encrypt confidential vulnerability reports.
A link to your vulnerability disclosure program or bug bounty policy terms and safe harbor guidelines.
security.txt is an IETF standard (RFC 9116) text file hosted at /.well-known/security.txt that defines how security researchers and bug bounty hunters can report vulnerabilities directly and securely to your organization.
RFC 9116 specifies the primary location as https://yourdomain.com/.well-known/security.txt. A secondary fallback at https://yourdomain.com/security.txt is also accepted.
The RFC 9116 standard mandates an expiration date so that outdated contact addresses and security policies are not used indefinitely. Stale files are flagged by automated scanners.
Yes. Search engines and security auditing algorithms check /.well-known/security.txt as a positive signal of proactive security hygiene, compliance, and active domain maintenance.
Use our interactive free generator to build, validate, and download an official RFC 9116 compliant file.
Launch Free GeneratorContinue with these guides to strengthen your technical SEO workflow.