Agent-Readiness Grade

Agent-Readiness Grade / Fix guides / security.txt

security.txt: tell people and agents where to report a vulnerability

security.txt is a small text file at /.well-known/security.txt that says how to report a security problem. It is not part of the grade's score; it is here because it answers the question the other files answer: can a machine find the right door?

Checked 2026-09-30 against grader version 1.3.0 and the 2 sources listed below.

Not scored by the grade.

What the grade checksWhy it mattersHow to fix itVerifyQuestionsSources

What the grade checks

Not scored. The full scoring rules are on the methodology page.

Why it matters for AI agents and crawlers

RFC 9116 (April 2022) defines the format. Contact (one or more, as mailto:, tel: or https:// URIs, most preferred first) and Expires (exactly once, an RFC 3339 date-time, recommended less than a year ahead) are required; Encryption, Acknowledgments, Canonical, Policy, Hiring and Preferred-Languages are optional.

The file must be served over HTTPS at /.well-known/security.txt as text/plain with a utf-8 charset; a copy or redirect at /security.txt is allowed for older clients. It applies only to the host that serves it, not to subdomains.

Web links inside the file must start with https://. After Expires the file should be treated as stale, so set a reminder to renew it.

How to fix it

  1. Write the file

    The security.txt generator builds this from a form and checks the dates.

    security.txt

    Contact: mailto:security@example.com
    Contact: https://example.com/security
    Expires: 2027-09-29T00:00:00.000Z
    Preferred-Languages: en
    Canonical: https://example.com/.well-known/security.txt
    Policy: https://example.com/security-policy
  2. Publish it at /.well-known/security.txt

    The .txt extension gets you text/plain almost everywhere.

    Static site

    Save it as .well-known/security.txt in the web root (Jekyll hosts need include: [".well-known"] in _config.yml).

    WordPress

    Upload .well-known/security.txt to the WordPress root folder by SFTP or the host's file manager.

    Next.js

    Save it as public/.well-known/security.txt.

    Cloudflare

    Deploy it with your static assets, or answer the path from the Worker:

    Cloudflare Worker

    if (url.pathname === "/.well-known/security.txt" || url.pathname === "/security.txt") {
      return new Response(SECURITY_TXT, { headers: { "content-type": "text/plain; charset=utf-8" } });
    }
  3. Sign it (optional)

    RFC 9116 allows an OpenPGP cleartext signature over the whole file; if you sign, include a Canonical line so readers can check the file applies to the URL they fetched.

    shell

    gpg --clearsign --output security.txt.asc security.txt

Free generator: security.txt generator. Writes an RFC 9116 security.txt with the required fields checked.

How to verify

Check the status and content type, then the two required fields.

shell

curl -s -o /dev/null -w "%{http_code} %{content_type}\n" https://example.com/.well-known/security.txt
curl -s https://example.com/.well-known/security.txt | grep -E '^(Contact|Expires):'

200 text/plain; charset=utf-8, at least one Contact: line and exactly one Expires: line in the future.

Grade your site for the checks that are scored:

$49 AI Visibility Full Report

The fixes on this site are free. The paid next step is the $49 AI Visibility Full Report (what ChatGPT, Claude and Perplexity say about your brand, with a prioritized fix list) from aivisibility.agentexchange.work. It includes:

  • 8 real buyer questions tested across ChatGPT-class models
  • Competitor share-of-voice: who AI names, how often, versus you
  • Full GEO site audit with prioritized, specific fixes
  • Agent-Readiness Score: crawler access, llms.txt, schema, discovery manifest
  • Custom 30/60/90-day action plan to get cited by ChatGPT, Perplexity and Google AI Overviews
  • Shareable report, generated in about 60 seconds after checkout

Get the Full Report — $49 Stripe checkout; you enter your brand and site right after paying.

Questions

Is security.txt required?

No law requires it; RFC 9116 is an informational IETF document. It is the common convention for vulnerability contacts.

What happens when Expires passes?

RFC 9116 says the file should then be considered stale, so reporters may ignore it. Renew it before the date.

Can I list a phone number?

Yes, as a tel: URI, and only if someone answers it.

Sources

Primary documentation, read 2026-09-30. Vendors change these pages; follow the link before relying on a detail.