NeroTool

Security.txt Generator

Create a security.txt file with responsible disclosure contact details directly in your browser. No upload is required.

How to use the security.txt generator

Enter the contact address security researchers should use, then add any optional policy, language, expiration and acknowledgment information that applies to your website. Generate the file, review the output and download it as security.txt.

Where to publish security.txt

The conventional location is /.well-known/security.txt. After deployment, make sure the URL in your Canonical field matches the public location of the file and that the file can be fetched without authentication.

Keep the information current

Use an active security contact and an appropriate expiration date. If your reporting process changes, update the file rather than leaving researchers with an obsolete address or policy.

Local processing

Your entries are processed in your browser. NeroTool does not upload your contact information or generated file.

Frequently asked questions

What is security.txt?

security.txt is a standard text file that tells security researchers how to report vulnerabilities to a website or organization.

Where should security.txt be placed?

It is normally published at the /.well-known/security.txt path on the website.

Is Contact required?

Yes. A valid security.txt file should provide a Contact field so researchers know where to report security issues.

Does NeroTool upload my information?

No. The generator builds the file entirely in your browser and does not need an upload or account.

AdvertisementAd space — reserved, no network calls until AdSense is enabled