security-txt.eu

Create a valid security.txt in two minutes

Enter your domain and the generator writes the file under RFC 9116 or, if you choose, the stricter BSI TR-03183-3: with a valid expiry date, the prescribed comments and a note on anything still missing.

Only the domain is required. The generator fills empty mandatory fields with common addresses and shows them in grey. You then need to set up these mailboxes and pages or replace them with your own.

Required must be in the file Recommended should be optional only if available. The next to a field explains it in more detail.

Standard

The internet standard with the minimum fields Contact and Expires. Done quickly, enough to start with.The stricter BSI version with two mailboxes, a reporting page, a policy and keys. Recommended for manufacturers under the Cyber Resilience Act once these addresses exist.

The address where the file will live, for example www.company.com. The generator derives all empty fields from it.

Role mailbox for reports about your products. If left empty:

Role mailbox for flaws in your website, shop and servers. If left empty:

A web page for reporting without e-mail, anonymously if needed. If left empty: Leave empty if there is none.

Page with your rules for reporters. This tool creates a draft further down. If left empty:

Public key so that reporters can write encrypted. If left empty: Leave empty if there is none.

Key of the IT mailbox. If left empty:

Just under a year is suggested. After that the file counts as expired.

Languages
More languages

The languages in which you accept reports. At least one. English is required.

More fields: acknowledgments, CSAF, bug bounty, hiring

Page where you thank reporters. Leave empty if there is none.

Only if you publish machine-readable security advisories in CSAF format.

Whether you pay reporters through a bug bounty programme.

Job ads for security professionals. Not part of the TR.

Your security.txt


      

    Draft CVD policy

    The Policy field points to this policy. The draft contains the minimum content under section 4.4 of TR-03183-3 and uses your addresses. It is a starting point, not a finished text: check every commitment for whether you can keep it with a deputy.

    optional

    If left empty, a placeholder in square brackets remains.

    optional

    An additional reporting channel. Appears only in the policy, not in the security.txt.

    Language of the draft

    After generating: sign, publish, check

    The file is written in minutes. For tools and reporters to find and trust it, three steps follow.

    1. Sign

      RFC 9116 recommends an OpenPGP signature, the TR requires it (4.2.10). One command wraps it around the text and the file stays readable: gpg --clearsign security.txt

    2. Publish

      The file belongs at /.well-known/security.txt, served over HTTPS as text/plain, without a redirect. Firewalls and bot protection must not lock out checking services (TR 4.2.11).

    3. Check and maintain

      The check fetches the file and verifies structure, links, keys and signature. Renew before the expiry date and, under the TR, review the content quarterly.

    All fields, the differences between RFC 9116 and TR-03183-3 and the most common mistakes are explained in the guide. Complete files for comparison are on the examples page.