# security.txt: tell people and agents where to report a vulnerability

> security.txt is a small text file at `/.well-known/security.txt` that says how to report a security problem. It is not part of the grade's score; it is here because it answers the question the other files answer: can a machine find the right door?

Checked 2026-09-30 against Agent-Readiness Grade 1.3.0. HTML version: https://grade.agentexchange.work/fix/security-txt

## What the grade checks

- Not scored: the grade does not fetch security.txt today. This guide accompanies the [security.txt generator](https://grade.agentexchange.work/tools/security-txt-generator).

Not scored.

## Why it matters for AI agents and crawlers

[RFC 9116](https://www.rfc-editor.org/rfc/rfc9116) (April 2022) defines the format. `Contact` (one or more, as `mailto:`, `tel:` or `https://` URIs, most preferred first) and `Expires` (exactly once, an RFC 3339 date-time, recommended less than a year ahead) are required; `Encryption`, `Acknowledgments`, `Canonical`, `Policy`, `Hiring` and `Preferred-Languages` are optional.

The file must be served over HTTPS at `/.well-known/security.txt` as `text/plain` with a utf-8 charset; a copy or redirect at `/security.txt` is allowed for older clients. It applies only to the host that serves it, not to subdomains.

Web links inside the file must start with `https://`. After `Expires` the file should be treated as stale, so set a reminder to renew it.

## How to fix it

### 1. Write the file

The [security.txt generator](https://grade.agentexchange.work/tools/security-txt-generator) builds this from a form and checks the dates.

security.txt:

```text
Contact: mailto:security@example.com
Contact: https://example.com/security
Expires: 2027-09-29T00:00:00.000Z
Preferred-Languages: en
Canonical: https://example.com/.well-known/security.txt
Policy: https://example.com/security-policy
```

### 2. Publish it at /.well-known/security.txt

The `.txt` extension gets you `text/plain` almost everywhere.

#### Static site

Save it as `.well-known/security.txt` in the web root (Jekyll hosts need `include: [".well-known"]` in `_config.yml`).

#### WordPress

Upload `.well-known/security.txt` to the WordPress root folder by SFTP or the host's file manager.

#### Next.js

Save it as `public/.well-known/security.txt`.

#### Cloudflare

Deploy it with your static assets, or answer the path from the Worker:

Cloudflare Worker:

```js
if (url.pathname === "/.well-known/security.txt" || url.pathname === "/security.txt") {
  return new Response(SECURITY_TXT, { headers: { "content-type": "text/plain; charset=utf-8" } });
}
```

### 3. Sign it (optional)

RFC 9116 allows an OpenPGP cleartext signature over the whole file; if you sign, include a `Canonical` line so readers can check the file applies to the URL they fetched.

shell:

```sh
gpg --clearsign --output security.txt.asc security.txt
```

## How to verify

Check the status and content type, then the two required fields.

```sh
curl -s -o /dev/null -w "%{http_code} %{content_type}\n" https://example.com/.well-known/security.txt
curl -s https://example.com/.well-known/security.txt | grep -E '^(Contact|Expires):'
```

`200 text/plain; charset=utf-8`, at least one `Contact:` line and exactly one `Expires:` line in the future.

## Questions

### Is security.txt required?

No law requires it; RFC 9116 is an informational IETF document. It is the common convention for vulnerability contacts.

### What happens when Expires passes?

RFC 9116 says the file should then be considered stale, so reporters may ignore it. Renew it before the date.

### Can I list a phone number?

Yes, as a tel: URI, and only if someone answers it.

## Sources

- [RFC 9116: A File Format to Aid in Security Vulnerability Disclosure](https://www.rfc-editor.org/rfc/rfc9116) (IETF)
- [securitytxt.org](https://securitytxt.org/) (security.txt project)

## Related

- [Legal notices](https://grade.agentexchange.work/fix/legal-notices.md): Six notices, each with a way to send the request, found on your policy pages.
- [agent-card.json](https://grade.agentexchange.work/fix/agent-card-json.md): The A2A agent card at /.well-known/agent-card.json; one of four files for the agent-surface point.
- [security.txt generator](https://grade.agentexchange.work/tools/security-txt-generator)
- [All fix guides](https://grade.agentexchange.work/fix)
