security.txt Setup
How to configure, preview, and serve your RFC 9116-compliant security.txt file, the primary discovery mechanism for ethical hackers.
Why It Matters
security.txt is the internet’s standard signal for “here’s how to report a security issue to us.” Defined in RFC 9116, it gives researchers a standard way to find disclosure contacts and policies. Separately, CISA Binding Operational Directive 20-01 requires federal civilian executive branch agencies to publish a vulnerability disclosure policy and maintain supporting processes. Security researchers, vulnerability scanners, and government agencies automatically query /.well-known/security.txt when evaluating an organization’s security posture.
Publishing a valid security.txt signals that your program is legitimate and staffed. Absence signals the opposite, and increasingly raises flags with auditors and enterprise procurement teams.
Kit publishes security.txt automatically when you enable VDP. No configuration is required.
What Is security.txt
A plain-text file served at /.well-known/security.txt over HTTPS. The following table covers six directives from RFC 9116:
| Directive | Required | Description |
|---|---|---|
Contact |
Yes | Email or URL where vulnerability reports should be sent |
Expires |
Yes | ISO 8601 datetime after which the file should no longer be trusted |
Policy |
No | URL to your full disclosure policy page |
Acknowledgments |
No | URL to your Hall of Fame or thanks page |
Hiring |
No | URL to your security team job postings |
Encryption |
No | URL to a PGP public key for encrypted communications |
Kit also appends Preferred-Languages: en automatically.
A minimal valid file looks like this:
Contact: mailto:[email protected]
Expires: 2027-02-27T00:00:00Z
Policy: https://example.com/security/acme/.well-known/security.txt
Preferred-Languages: en
A fully configured file includes all six directives:
Contact: mailto:[email protected]
Expires: 2027-02-27T00:00:00Z
Policy: https://example.com/security/acme/policy
Acknowledgments: https://example.com/security/acme/hall-of-fame
Hiring: https://example.com/careers/security
Encryption: https://keys.example.com/pgp-key.asc
Preferred-Languages: en
Configuring security.txt
Navigate to VDP > Program Settings > security.txt. Configure the following fields:
| Field | Default | Description |
|---|---|---|
| Contact Email | Empty | Used in the Contact: directive. Use a monitored security alias, not a personal inbox. If left blank, the generated file falls back to your security portal report URL. |
| Policy URL | Auto-generated | Link to your disclosure policy page. Kit generates this from your program slug. |
| Acknowledgments URL | Auto-generated | Link to your Hall of Fame page. Kit generates this automatically. |
| Hiring URL | Blank | Link to your security team job openings. Optional. |
| PGP Encryption URL | Blank | URL to your PGP public key hosted externally. Optional. |
| Expiration Days | 365 | Number of days ahead the Expires: directive is set. RFC 9116 recommends no more than one year. |
The Contact Email and Expiration Days are the only fields most programs need to change. Policy and Acknowledgments URLs are generated from your program configuration and update automatically.
The preview beside the form updates as you type. Save the settings to apply them to the public file.
Where It’s Served
Kit serves your security.txt at two URLs:
| URL | When to Use |
|---|---|
/security/{program-slug}/.well-known/security.txt |
Kit-hosted; works immediately after enabling VDP |
/.well-known/security.txt (your custom domain) |
Production; requires custom domain setup in Account Settings |
For custom domain serving, configure your domain in Account Settings > Custom Domains. Once configured, Kit serves /.well-known/security.txt at the root of your domain automatically. This is the URL you want researchers and scanners to discover.
The file is served with Content-Type: text/plain; charset=utf-8 per RFC 9116. Both URLs return identical content.
Auto-Regeneration
Kit handles security.txt lifecycle automatically:
- On config save: Saved settings apply to the public file immediately. Kit also records when the configuration was renewed.
- Slack reminder: A daily check compares time since the last configuration save with Expiration Days. When 14 days or fewer remain, Kit notifies your connected Slack workspace. This requires a contact email and a previously saved configuration.
-
Public expiry date: The public file calculates
Expires:at request time as the current date plus Expiration Days. Saving the settings, even unchanged, separately renews the timestamp used for reminders.
Use the reminder to review contacts and policies, then save the settings. The reminder follows the last-save timestamp; the public file’s expiry date moves with the current date.
Previewing the File
The inline preview in Program Settings helps you check the form before saving. Use it to:
- Verify the
Contact:email is correct and monitored - Confirm the
Expires:date is set to the intended future date - Check that
Policy:andAcknowledgments:URLs resolve correctly - Review any optional directives (
Hiring,Encryption) before publishing
The preview reflects current form values, including unsaved changes. After saving, check the public file too: its Preferred-Languages is currently en, while the preview uses the interface language.
Validating Your Setup
After enabling VDP and configuring security.txt, verify it’s working:
- Open
/.well-known/security.txton your portal’s custom domain, or use the Kit-hosted program URL listed above if you have no custom domain - Confirm the file renders as plain text with all expected directives
- Verify the
Expires:date is in the future and within one year - Check that the
Contact:email or URL is correct - If using a custom domain, verify HTTPS is active; RFC 9116 requires the file to be served over HTTPS
External validators like securitytxt.org can parse your file and flag any RFC 9116 compliance issues.
Quick Checklist
- Enable VDP (security.txt is auto-generated at activation)
- Set your contact email to a monitored security alias (not a personal inbox)
-
Verify
/.well-known/security.txtresolves on your custom domain - Set the Policy URL so researchers know the rules before submitting
-
Confirm the
Expires:date is no more than one year out - Schedule a calendar reminder at 11 months to review the contact details and policy. Kit also sends a Slack reminder during the 14-day window described above
Next Steps
- Configuring Your Program: all program settings including scope, bounty matrix, and SLAs
- Vulnerability Disclosure Overview: what the included Security workflow covers