Build an RFC 9116 security.txt file: configure Contact, Expires, Encryption, Acknowledgments, Preferred-Languages, Canonical, Policy, and Hiring fields, with live preview and download. Also parses an existing security.txt back into the form.
Per RFC 9116, publish the generated file at /.well-known/security.txt at your domain's root (a legacy /security.txt location is also checked by some tools, but /.well-known/ is canonical). Contact and Expires are the only required fields — set Expires to a date no more than a year out and remember to refresh it before it lapses.
Build an RFC 9116 security.txt file: configure Contact, Expires, Encryption, Acknowledgments, Preferred-Languages, Canonical, Policy, and Hiring fields, with live preview and download. Also parses an existing security.txt back into the form.
Yes. security.txt Generator can generate a security.txt with a PGP key link, directly in your browser.
Yes. security.txt Generator can build a vulnerability disclosure contact file, directly in your browser.
Yes. security.txt Generator can parse an existing security.txt, directly in your browser.
No. This tool runs entirely in your browser — your input is processed locally on your device and is never uploaded or stored on a server.