Agent-Readiness Grade / Fix guides / security.txt
security.txt: tell people and agents where to report a vulnerability
security.txt is a small text file at /.well-known/security.txt that says how to report a security problem. It is not part of the grade's score; it is here because it answers the question the other files answer: can a machine find the right door?
Checked 2026-09-30 against grader version 1.3.0 and the 2 sources listed below.
Not scored by the grade.
What the grade checksWhy it mattersHow to fix itVerifyQuestionsSources
What the grade checks
- Not scored: the grade does not fetch security.txt today. This guide accompanies the security.txt generator.
Not scored. The full scoring rules are on the methodology page.
Why it matters for AI agents and crawlers
RFC 9116 (April 2022) defines the format. Contact (one or more, as mailto:, tel: or https:// URIs, most preferred first) and Expires (exactly once, an RFC 3339 date-time, recommended less than a year ahead) are required; Encryption, Acknowledgments, Canonical, Policy, Hiring and Preferred-Languages are optional.
The file must be served over HTTPS at /.well-known/security.txt as text/plain with a utf-8 charset; a copy or redirect at /security.txt is allowed for older clients. It applies only to the host that serves it, not to subdomains.
Web links inside the file must start with https://. After Expires the file should be treated as stale, so set a reminder to renew it.
How to fix it
Write the file
The security.txt generator builds this from a form and checks the dates.
security.txt
Contact: mailto:security@example.com Contact: https://example.com/security Expires: 2027-09-29T00:00:00.000Z Preferred-Languages: en Canonical: https://example.com/.well-known/security.txt Policy: https://example.com/security-policyPublish it at /.well-known/security.txt
The
.txtextension gets youtext/plainalmost everywhere.Static site
Save it as
.well-known/security.txtin the web root (Jekyll hosts needinclude: [".well-known"]in_config.yml).WordPress
Upload
.well-known/security.txtto the WordPress root folder by SFTP or the host's file manager.Next.js
Save it as
public/.well-known/security.txt.Cloudflare
Deploy it with your static assets, or answer the path from the Worker:
Cloudflare Worker
if (url.pathname === "/.well-known/security.txt" || url.pathname === "/security.txt") { return new Response(SECURITY_TXT, { headers: { "content-type": "text/plain; charset=utf-8" } }); }Sign it (optional)
RFC 9116 allows an OpenPGP cleartext signature over the whole file; if you sign, include a
Canonicalline so readers can check the file applies to the URL they fetched.shell
gpg --clearsign --output security.txt.asc security.txt
Free generator: security.txt generator. Writes an RFC 9116 security.txt with the required fields checked.
How to verify
Check the status and content type, then the two required fields.
shell
curl -s -o /dev/null -w "%{http_code} %{content_type}\n" https://example.com/.well-known/security.txt
curl -s https://example.com/.well-known/security.txt | grep -E '^(Contact|Expires):'
200 text/plain; charset=utf-8, at least one Contact: line and exactly one Expires: line in the future.
Grade your site for the checks that are scored:
$49 AI Visibility Full Report
The fixes on this site are free. The paid next step is the $49 AI Visibility Full Report (what ChatGPT, Claude and Perplexity say about your brand, with a prioritized fix list) from aivisibility.agentexchange.work. It includes:
- 8 real buyer questions tested across ChatGPT-class models
- Competitor share-of-voice: who AI names, how often, versus you
- Full GEO site audit with prioritized, specific fixes
- Agent-Readiness Score: crawler access, llms.txt, schema, discovery manifest
- Custom 30/60/90-day action plan to get cited by ChatGPT, Perplexity and Google AI Overviews
- Shareable report, generated in about 60 seconds after checkout
Get the Full Report — $49 Stripe checkout; you enter your brand and site right after paying.
Questions
Is security.txt required?
No law requires it; RFC 9116 is an informational IETF document. It is the common convention for vulnerability contacts.
What happens when Expires passes?
RFC 9116 says the file should then be considered stale, so reporters may ignore it. Renew it before the date.
Can I list a phone number?
Yes, as a tel: URI, and only if someone answers it.
Sources
Primary documentation, read 2026-09-30. Vendors change these pages; follow the link before relying on a detail.
- RFC 9116: A File Format to Aid in Security Vulnerability Disclosure (IETF)
- securitytxt.org (security.txt project)