← Record Studio

security.txt

security.txt (RFC 9116) is a machine-readable file at /.well-known/security.txt that tells security researchers how to reach you when they find a vulnerability. This check's HTTP module validates the file strictly against the RFC – the generator produces a file that passes.

Serve the file at https://<domain>/.well-known/security.txt with Content-Type: text/plain; charset=utf-8. A PGP cleartext signature is recommended – and if your preferred contact is an email address, also publish an Encryption field pointing to your PGP key.

Comma-separated, most preferred first. Email addresses become mailto: URIs; you can also use an HTTPS URL or a tel: phone number (spaces in the number are removed).

Emitted as an RFC 3339 timestamp (…T23:59:59Z); should be less than a year away. Default: about 330 days.

Runs entirely in your browser. Record Studio · Verify the result with the domain security check