Flowpane / Docs
In this section

Common security.txt issues

Expires field missing

RFC 9116 requires exactly one. Add an authored future RFC 3339 date-time; review the value with the policy owner and re-sign any changed signed file.

Expires date has passed

Publish a newly reviewed future RFC 3339 value.

Wrong location

Should be at /.well-known/security.txt, not /security.txt.

Canonical not set

Canonical is optional. If you include it, use the verified public URL from which the file is served.

Clear-signed file changed

Any changed Proposed payload is unsigned and must be signed again before publication. Flowpane preserves signature evidence but does not perform OpenPGP cryptographic verification.

Resolve the cause, then verify

First compare the finding with the obtained Current content. If the expected text URL returns a theme page, challenge or redirect, ask the responsible host or CMS maintainer to correct that response. A browser-visible page does not establish that the resource was readable to Flowpane.

Confirm that the contact is monitored, that policy links belong to the Site owner, and that the expiry date remains appropriate.

Prepare a focused correction, check authored details and use your authorised publication process. Publishing the file is not a security certification or proof that vulnerabilities are handled within a promised time. Flowpane does not cryptographically verify a signed file. A saved draft or dismissed notice is not proof of remediation; repeat the public check afterwards.

Reading article

Copy manually

Automatic copying is unavailable. The text is selected; use your device’s copy command.