RESPONSIBLE VULNERABILITY DISCLOSURE
security.txt Builder and Validator
Create the standard contact file security researchers expect or validate the version already published on your domain.
RFC 9116
Create the file, then verify the live publication.
The builder runs locally. Live validation requests only the public HTTPS security.txt path for the domain you enter.
Build a starter file
Contact and Expires are required by the format.
/.well-known/security.txt
TXTReady for review
LIVE VALIDATION
Check the public file.
Only public HTTPS domains are accepted; internal and reserved addresses are blocked.
PRIVACY BY DESIGN
Know where each calculation happens.
Only the public technical data needed for the requested check is queried. Monitoring stores the verified domain, alert email and result history.
