Let's talk about your project

security.txt file

A standard text file published in a site's /.well-known/ directory that shows security researchers whom to report a flaw to and how.

  1. 01

    Why it matters

    If someone who notices a flaw cannot find the right contact, the report gets lost or goes to the wrong channel. security.txt gathers the contact address, preferred languages, disclosure policy and the file's expiry date in one standard place. Preparing it takes a few minutes.

  2. 02

    Example

    A researcher finds a flaw on a site and writes to the address in the site's security.txt file. The team receives the report the same day, fixes the flaw and thanks the researcher.

  3. 03

    Common mistake

    Publishing the file and never updating its expiry date and contact address. An expired file or an address nobody reads can be worse than having no file at all.

  4. 04
Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.