Free tool · RFC 9116
Generate a security.txt vulnerability contact file.
Create a security.txt for /.well-known/security.txt with a contact, canonical location and expiry. Copy the file and publish it over HTTPS. The CRA requires manufacturers to provide vulnerability-reporting contact details; security.txt makes that contact machine-discoverable.
/.well-known/security.txt
Contact: mailto:security@example.eu Canonical: https://example.eu/.well-known/security.txt Preferred-Languages: en Expires: 2027-09-30T11:30:44.664Z
Expires is set one year from today per RFC 9116 guidance. Sign the file with your PGP key where possible. Vellaci records your CVD policy and security.txt status as readiness evidence.
What this file does
A discoverable route for coordinated vulnerability disclosure.
RFC 9116 defines a standard location and fields so researchers and automated tools can find your vulnerability contact details. For CRA manufacturers, it can support the published contact point and coordinated vulnerability disclosure process in Annex I Part II(5)–(6); it does not replace a policy, staffed intake process or reporting decision.
Example: publish the generated plain text as https://example.eu/.well-known/security.txt with a text/plain content type. Keep the Canonical URL aligned with the location you serve and renew the required Expires date before it lapses.
Related standards: RFC 9116 for security.txt and ISO/IEC 29147 for vulnerability disclosure. Vellaci can record the CVD policy, intake decisions, acknowledgements and evidence alongside product vulnerabilities.
How to publish it
From generated file to a live contact point.
- Step 1
Enter a contact
Add an e-mail address (mailto:), an HTTPS web-form URL, or both. Each is emitted as a Contact field for the team that handles vulnerability reports.
- Step 2
Set the canonical URL and expiry
Point Canonical to the security.txt URL you will publish. RFC 9116 requires Expires; choose a date within a year and put a reminder in the calendar to renew it.
- Step 3
Add policy, languages and acknowledgements
Link your coordinated vulnerability disclosure policy, list the languages you accept reports in, and optionally a page that credits researchers.
- Step 4
Publish at /.well-known/security.txt
Serve the file over HTTPS at https://yourdomain/.well-known/security.txt with a text/plain content type. Set the Canonical field to that URL and, ideally, sign the file with PGP.
- Does the CRA require security.txt?
- Not by name. Annex I Part II(6) requires manufacturers to provide a contact address for the reporting of vulnerabilities, and Part II(5) requires a coordinated vulnerability disclosure policy. security.txt is the standardised, machine-discoverable way to publish that contact, checked automatically by researchers and scanners.
- Where exactly should it live?
- At /.well-known/security.txt on each domain that hosts a product or its documentation — the company site at minimum. A copy at /security.txt is a permitted fallback but the .well-known path is the standard location.
- What if we have multiple products?
- One file per domain is enough; use the Policy field to point at a page that explains scope per product, and route all reports into one intake process so awareness is recorded consistently.
Read next
- Guide
Coordinated vulnerability disclosure under the CRA: policy, intake and security.txt
Annex I Part II requires manufacturers to enforce a coordinated vulnerability disclosure policy and publish a contact address. What the policy must contain, how to align it with ISO/IEC 29147 and 30111, how to run intake, and how it connects to Article 14.
- Guide
CRA readiness checklist for software and connected-product manufacturers
A practical CRA checklist across governance, SBOM, vulnerability handling, disclosure, incidents, reporting, support period and documentation, with evidence to keep and current transition milestones.
- Docs
Security settings
MFA, SSO, approvals, tokens, auditors, retention, deletion.
Track the intake, not just the file.
Vellaci records every report, its acknowledgement and the awareness decision it may trigger.