headers by 0x6a03448f4d
← All headers
Best practice

security.txt

Give researchers a way in.

What it is

A file at /.well-known/security.txt (RFC 9116) that lists how to report a vulnerability to you.

Why it matters

Turns a found bug into a responsible disclosure instead of a public dump or a sale.

Risk without it

Not a vulnerability itself, but its absence means researchers may not know how (or bother) to reach you.

Recommended

Publish Contact and Expires fields; keep Expires in the future.

Set it

Contact: mailto:security@example.com
Expires: 2027-01-01T00:00:00.000Z
Preferred-Languages: en, pt
Canonical: https://example.com/.well-known/security.txt

References