Create a valid security.txt in two minutes
Enter your domain and the generator writes the file under RFC 9116 or, if you choose, the stricter BSI TR-03183-3: with a valid expiry date, the prescribed comments and a note on anything still missing.
- Free, no sign-up
- File is built in your browser
- Copy only once it is valid
Your security.txt
Draft CVD policy
The Policy field points to this policy. The draft contains the minimum content under section 4.4 of TR-03183-3 and uses your addresses. It is a starting point, not a finished text: check every commitment for whether you can keep it with a deputy.
If left empty, a placeholder in square brackets remains.
An additional reporting channel. Appears only in the policy, not in the security.txt.
After generating: sign, publish, check
The file is written in minutes. For tools and reporters to find and trust it, three steps follow.
- Sign
RFC 9116 recommends an OpenPGP signature, the TR requires it (4.2.10). One command wraps it around the text and the file stays readable:
gpg --clearsign security.txt - Publish
The file belongs at
/.well-known/security.txt, served over HTTPS as text/plain, without a redirect. Firewalls and bot protection must not lock out checking services (TR 4.2.11). - Check and maintain
The check fetches the file and verifies structure, links, keys and signature. Renew before the expiry date and, under the TR, review the content quarterly.
All fields, the differences between RFC 9116 and TR-03183-3 and the most common mistakes are explained in the guide. Complete files for comparison are on the examples page.