security.txt
security.txt (RFC 9116) provides security contact and vulnerability disclosure information.
Location: https://yoursite.com/.well-known/security.txt · Required fields: Contact and Expires
Use this reference
security.txt helps a security researcher find the intended disclosure contact and policy. Flowpane observes /.well-known/security.txt; it does not assume that the response is a physical file rather than CMS-generated content.
Start with What is security.txt for purpose, Check details for the assessment, and Common issues for follow-up. Publishing the file is not a security certification or proof that vulnerabilities are handled within a promised time. Flowpane does not cryptographically verify a signed file.
Confirm that the contact is monitored, that policy links belong to the Site owner, and that the expiry date remains appropriate. Use Review for supported quick corrections and Workbench for full content and drafts. Saving a proposal is separate from publication.