Reference

What is security.txt?

security.txt is a standardised plain-text file published at /.well-known/security.txt, giving security researchers a documented route to report a vulnerability to you. It is defined by RFC 9116, and in practice it is the difference between a researcher emailing you privately and a researcher publishing what they found.

Also called: RFC 9116

What it contains

  • Contact — an email address or reporting form
  • Expires — a required date, so the file cannot silently go stale
  • Preferred-Languages, Policy and Canonical as optional fields

Why it is worth ten minutes

Someone who finds a problem needs somewhere to send it. Without a route they either give up, post publicly, or contact a random address that nobody reads — and none of those outcomes is good for you.

The procurement angle

It appears in security questionnaires and is trivially verifiable by whoever is assessing you. For a small supplier it is a cheap, checkable signal of competence, sitting alongside properly configured security headers.

The Expires field is the part people get wrong. RFC 9116 requires it, and a file whose expiry date has passed is treated as stale — so it needs to be generated on each build rather than written once and forgotten.

Where this is covered in depth

A definition can only go so far. Technical SEO, in the order the problems actually block you covers this properly — 4 minutes, free, no email required.

Who wrote this

Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan. These definitions come from client work rather than from a content brief — where an entry describes a mistake, it is usually one found on a real site. More about how I work.

Related terms

All 184 terms in the glossary →

Want this handled rather than explained?

Send the brief and you get a reply within one business day — either questions, or a scoping call. If your project is not something I should take on, I will say so then.

Response
Replies within 1 business day
Hours
Mon–Fri, 09:00–18:00 PKT — overlaps 05:00–14:00 UK, 00:00–09:00 US Eastern
Booking
Booking projects from October 2026
WhatsApp — opens a chat with +92 346 5348466 in a new tab