What is security.txt
A machine-readable file that tells security researchers how to report vulnerabilities. Without it, researchers may not know how to reach your security team.
Required fields
- Contact — email or URL for reporting security issues
- Expires — date after which the file is stale
Optional fields
Encryption, Acknowledgments, Preferred-Languages, Canonical, Policy, Hiring
When to use it
Confirm that the contact is monitored, that policy links belong to the Site owner, and that the expiry date remains appropriate.
For a missing file, ask the owner for an approved disclosure contact before publishing a starter. Do not put an unmonitored address into a security process.
Location and responsibility
Use /.well-known/security.txt and confirm which CMS, plugin or file serves it. Publishing the file is not a security certification or proof that vulnerabilities are handled within a promised time. Flowpane does not cryptographically verify a signed file.
Refer to security.txt specification (RFC 9116) for the external specification or convention. Use Flowpane’s check details to understand what its own assessment covers; a product score is not a certification.