WebTools

307 Useful Tools & Utilities to make life easier.

Security.txt Generator

Create a security.txt file to help researchers report vulnerabilities.

How researchers should reach you.
When this policy expires (Max 1 year recommended).
Link to your public PGP key.
Link to your vulnerability disclosure policy.
Link to your security researchers hall of fame.
Link to security-related job openings.
The permanent URL for this file.
Comma-separated list of language codes.
Generated security.txt Content

Place this file at /.well-known/security.txt or the root directory.

Instant Online Security.txt Generator: A Vulnerability Disclosure Policy Is Created in Seconds

When a security researcher discovers a vulnerability in a website, they often have no clear way to report it. The security.txt file, defined by RFC 9116, solves this problem by placing a standardized contact point at a well‑known URL: /.well-known/security.txt. The security.txt generator on this page is the tool by which this file is created through a simple form, without the user needing to memorize the specification. The resulting file is immediately ready to be uploaded to any web server, and the entire generation process happens in the browser—no data is stored or shared.

Why a Security.txt File Is Essential

A security.txt file signals to the security community that a website welcomes vulnerability reports. It can contain an email address, a PGP key for encrypted communication, a policy link, an acknowledgments page, and an expiration date. A generate security.txt file that is correctly formatted and signed with a digital signature (if desired) can turn a frustrated researcher into a responsible reporter. Conversely, the absence of such a file may lead to vulnerabilities being disclosed publicly because no private channel was available. An rfc 9116 generator ensures that the file is syntactically perfect and contains all the recommended fields.

How the Security.txt Generator Is Operated

A form with labeled fields is presented. The user fills in their preferred contact method—an email address or a web page URL for vulnerability reports. Optional fields include an encryption key (a link to a PGP key), a policy link, an acknowledgments page, a hiring page, and an expiration date. The tool validates each field as it is filled: email addresses are checked for format, URLs are verified to be absolute, and the expiration date is ensured to be in the future.

As the fields are completed, the rendered security.txt file is shown in a preview pane. The user can choose to include a digital signature by pasting a private PGP key (the signing is performed entirely in the browser, and the key is never transmitted). The final file can be copied or downloaded. A reminder is displayed to upload the file to the /.well-known/ directory of the website.

Key Features That Are Delivered by This Generator

  • Full RFC 9116 Compliance: All standard fields are supported, and the file is generated in the exact format required.
  • Field Validation: Emails, URLs, and dates are validated in real time to prevent formatting errors.
  • Optional PGP Signing: The file can be signed with a PGP key directly in the browser; the private key is never sent to a server.
  • Preview and Download: The generated file is displayed and can be downloaded as security.txt.
  • Privacy‑First Design: All data stays in the browser. No contact information is collected.
  • Guidance and Tooltips: Each field includes a tooltip explaining its purpose and recommended content.
  • Integration with Other Tools: If the contact email is to be tested, the email header decoder can analyze any response. The file’s expiration date can be checked with the timestamp converter. A hash of the file can be generated by the SHA hash generator. If the file’s content is stored in a database, the SQL beautifier can format the query. The generated policy URL can be encoded by the URL encoder. Patterns to detect security.txt files across domains are tested by the regex tester. And the site’s overall security posture can be audited with the security headers checker.

Everyday Scenarios for the Security.txt Generator

  • Setting Up a Bug Bounty Program: A company launches a bug bounty and uses the generator to create the security.txt file that points to the bounty platform.
  • Open‑Source Project: A maintainer adds a security.txt to the project’s website so that vulnerabilities can be reported privately.
  • Compliance Requirement: A government website is required to have a security contact; the generator produces the file in minutes.
  • Security Researcher Outreach: A researcher checks a site’s security.txt, finds an email, and reports a vulnerability responsibly.
  • Educational Demonstration: An instructor uses the generator to show students how the RFC defines a standard for vulnerability disclosure.


Contact

Missing something?

Feel free to request missing tools or give some feedback using our contact form.

Contact Us