Free tool · RFC 9116

Generate a security.txt vulnerability contact file.

Create a security.txt for /.well-known/security.txt with a contact, canonical location and expiry. Copy the file and publish it over HTTPS. The CRA requires manufacturers to provide vulnerability-reporting contact details; security.txt makes that contact machine-discoverable.

/.well-known/security.txt

Contact: mailto:security@example.eu
Canonical: https://example.eu/.well-known/security.txt
Preferred-Languages: en
Expires: 2027-09-30T11:30:44.664Z

Expires is set one year from today per RFC 9116 guidance. Sign the file with your PGP key where possible. Vellaci records your CVD policy and security.txt status as readiness evidence.

What this file does

A discoverable route for coordinated vulnerability disclosure.

RFC 9116 defines a standard location and fields so researchers and automated tools can find your vulnerability contact details. For CRA manufacturers, it can support the published contact point and coordinated vulnerability disclosure process in Annex I Part II(5)–(6); it does not replace a policy, staffed intake process or reporting decision.

Example: publish the generated plain text as https://example.eu/.well-known/security.txt with a text/plain content type. Keep the Canonical URL aligned with the location you serve and renew the required Expires date before it lapses.

Related standards: RFC 9116 for security.txt and ISO/IEC 29147 for vulnerability disclosure. Vellaci can record the CVD policy, intake decisions, acknowledgements and evidence alongside product vulnerabilities.

How to publish it

From generated file to a live contact point.

  1. Step 1

    Enter a contact

    Add an e-mail address (mailto:), an HTTPS web-form URL, or both. Each is emitted as a Contact field for the team that handles vulnerability reports.

  2. Step 2

    Set the canonical URL and expiry

    Point Canonical to the security.txt URL you will publish. RFC 9116 requires Expires; choose a date within a year and put a reminder in the calendar to renew it.

  3. Step 3

    Add policy, languages and acknowledgements

    Link your coordinated vulnerability disclosure policy, list the languages you accept reports in, and optionally a page that credits researchers.

  4. Step 4

    Publish at /.well-known/security.txt

    Serve the file over HTTPS at https://yourdomain/.well-known/security.txt with a text/plain content type. Set the Canonical field to that URL and, ideally, sign the file with PGP.

Does the CRA require security.txt?
Not by name. Annex I Part II(6) requires manufacturers to provide a contact address for the reporting of vulnerabilities, and Part II(5) requires a coordinated vulnerability disclosure policy. security.txt is the standardised, machine-discoverable way to publish that contact, checked automatically by researchers and scanners.
Where exactly should it live?
At /.well-known/security.txt on each domain that hosts a product or its documentation — the company site at minimum. A copy at /security.txt is a permitted fallback but the .well-known path is the standard location.
What if we have multiple products?
One file per domain is enough; use the Policy field to point at a page that explains scope per product, and route all reports into one intake process so awareness is recorded consistently.

Track the intake, not just the file.

Vellaci records every report, its acknowledgement and the awareness decision it may trigger.