security-txt.eu

security.txt generator: a valid file in two minutes

Enter your domain and the generator writes the file under RFC 9116 or, if you choose, the stricter BSI TR-03183-3: with a valid expiry date, the prescribed comments and a note on anything still missing.

Standard

Required

Only the domain has to be typed. The generator fills empty fields from the domain; the suggestions are shown in grey.

More fields optional

Your security.txt


      

    Draft CVD policy

    The Policy field points to this policy. The draft contains the minimum content under section 4.4 of TR-03183-3 and uses your addresses. It is a starting point, not a finished text: check every commitment for whether you can keep it with a deputy.

    Language of the draft

    After generating: sign, publish, check

    The file is written in minutes. For tools and reporters to find and trust it, three steps follow.

    1. Sign

      RFC 9116 recommends an OpenPGP signature, the TR requires it (4.2.10). One command wraps it around the text and the file stays readable: gpg --clearsign security.txt

    2. Publish

      The file belongs at /.well-known/security.txt, served over HTTPS as text/plain, without a redirect. Firewalls and bot protection must not lock out checking services (TR 4.2.11).

    3. Check and maintain

      The check fetches the file and verifies structure, links, keys and signature. Renew before the expiry date and, under the TR, review the content quarterly.

    All fields, the differences between RFC 9116 and TR-03183-3 and the most common mistakes are explained in the guide. Complete files for comparison are on the examples page.