security.txt check details
Flowpane reviews the public security.txt at its well-known location, including Contact, Expires and the syntax of other supported RFC 9116 fields.
Review findings against your disclosure policy and confirm that contact information and policy links are correct. A syntax check does not authenticate a researcher, verify the person behind a contact or establish trust in a signing key.
Signed files
Changing a signed file invalidates its existing signature. Review and sign the finished content through your signing process before publication. Flowpane’s assessment does not cryptographically verify OpenPGP signatures.
See RFC 9116 compliance and Common issues.
Interpreting the result
Present means the response was obtained, not that every declaration is correct. Missing means it was not found at the checked location. Blocked or Error prevents a dependable current content assessment; read the explanation before drafting a replacement.
For a missing file, ask the owner for an approved disclosure contact before publishing a starter. Do not put an unmonitored address into a security process.
An Editor or Admin on an eligible plan can prepare a draft; public publication requires the appropriate authority. After publishing, run a new check and compare the resulting observation time. See troubleshooting.