#SecurityTxt
you had one job #securitytxt
October 17, 2025 at 1:12 PM
📦 heineref/kirby-securitytxt 0.2

'SecurityTxt' creates a 'security.txt' file in accordance with RFC 9116

🔗 https://github.com/HeinerEF/kirby-securitytxt
September 28, 2026 at 1:03 AM
🚀I've published my #GetMailprotection #PowerShell Script v1.15 to #PowerShellGallery.
the Script checks diffrent DNS Informations about a Domain - mostly about Mailsecurity Settings. #DNSSEC #CAA #MX #SPF #DMARC #MTASTS #DANE #TLSRPT #TenantID #SecurityTXT and many more
bit.ly/4fyhoXh
November 20, 2024 at 9:30 PM
RFC 9116 (@securitytxt) is 2 years old and already obsolete at some companies.

16years.secvuln.info
May 15, 2024 at 4:51 AM
I don't care if your turnover is in the Thousands, Millions, or Billions. Please, Put up a #securitytxt

Let us good guys help you out.
November 18, 2023 at 10:56 PM
always a frustrating experience. @securitytxt
May 23, 2024 at 12:53 PM
TIL about /.well-known/ - a free, open index of well-known resources, such as @securitytxt (RFC 9116). Check it out here: well-known.dev
Search
An open index of well-known resources.
well-known.dev
December 21, 2023 at 10:53 PM
🚨 BREAKING 🚨

Our @securitytxt 2024 version is updated containing a new CTF-like challenge. Check it out now: swisscom.ch/.well-known/...
January 9, 2024 at 10:30 AM
Engagement Sécurité : J'adopte le standard security.txt
La sécurité web n'est pas une option, c'est une fondation. En tant que freelance, je m'engage et vous ?
webmaster67.fr/politique-de...
#Freelance #Cybersécurité #Securitytxt #VDP #BonnesPratiques #Webmaster #Confiance #Transparence
webmaster67 expert WordPress et PrestaShop
Expert en création de sites WordPress en Alsace. Webmaster67 vous propose des solutions sur mesure, optimisées SEO. Obtenez votre devis gratuit !
webmaster67.fr
October 24, 2025 at 3:21 PM
🚀I have released a new Version of the Get-Mailprotection #PowerShell Script to the #PowerShellGallery
- Moved from Resolve-DNS to DNS over Https (DoH) dns.google/resolve
bit.ly/3TJQBy8
#NS #MX #SPF #DKIM #DMARC #BIMI #MTASTS #DANE #TLSRPT #CAA #SECURITYTXT #DNSSEC
September 28, 2024 at 8:44 AM
September 18, 2026 at 11:04 AM
Hugging Face の security.txt が見せた、やりすぎない開示の作法
https://papoo.work/doc/8b5fe20abd0ff520
#huggingface #securitytxt #脆弱性報告 #aiセキュリティ #cybergym
Hugging Face の security.txt が見せた、やりすぎない開示の作法
papoo.work
September 18, 2026 at 10:52 AM
llms.txt is two years old and already outnumbers security.txt 10 to 1. Would you rather tell a model how to read your site than tell someone how to report a hole in it?

#llmstxt #SecurityTxt #robotstxt #WebDev #WebSecurity #SEO
September 13, 2026 at 8:12 PM
📦 vdlp/oc-securitytxt-plugin 2.0.1

Define security policies for your website.

🔗 https://github.com/vdlp/oc-securitytxt-plugin
July 16, 2026 at 11:27 AM
Cloudflare launches free Security.txt generator to boost website security: New tool simplifies vulnerability disclosure process, aligning with industry standards for enhanced web security practices. #Cloudflare #WebSecurity #CyberSecurity #VulnerabilityDisclosure #SecurityTXT
Cloudflare launches free Security.txt generator to boost website security
New tool simplifies vulnerability disclosure process, aligning with industry standards for enhanced web security practices.
ppc.land
December 24, 2024 at 4:03 PM
Cloudflare launches free Security.txt generator to boost website security: New tool simplifies vulnerability disclosure process, aligning with industry standards for enhanced web security practices. #Cloudflare #WebSecurity #CyberSecurity #VulnerabilityDisclosure #SecurityTXT
Cloudflare launches free Security.txt generator to boost website security
New tool simplifies vulnerability disclosure process, aligning with industry standards for enhanced web security practices.
ppc.land
December 24, 2024 at 4:03 PM
𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆.𝘁𝘅𝘁

A proposed standard which allows websites to define security policies. security.txt defines a standard to help organizations define the process for security researchers to disclose security vulnerabilities securely.

https://thewhale.cc/posts/securitytxt

#Security #Standard
security.txt
A proposed standard which allows websites to define security policies. security.txt defines a standard to help organizations define the process for security researchers to disclose security vulnerabilities securely.
thewhale.cc
April 24, 2026 at 10:00 AM
英語化して dev.to に公開しました > What Is security.txt and How Can It Help Improve Website Security? - DEV Community https://dev.to/route06/what-is-securitytxt-and-how-can-it-help-improve-website-security-3kij
What Is security.txt and How Can It Help Improve Website Security?
Introducing security.txt, an effective tool for strengthening website security measures, with examples
dev.to
December 9, 2024 at 2:17 AM
また会社の Tech Blog 記事を書きました > ウェブサイトのセキュリティ対策の強化に有効な security.txt - ROUTE06 Tech Blog https://tech.route06.co.jp/entry/2024/12/05/120000
ウェブサイトのセキュリティ対策の強化に有効な security.txt
<p>こんにちは。ソフトウェアエンジニアの <a class="hatena-id-icon" href="http://blog.hatena.ne.jp/masutaka26/"><img alt="" class="hatena-id-icon" height="16" src="https://cdn.profile-image.st-hatena.com/users/masutaka26/profile.png" width="16"/>id:masutaka26</a> です。</p> <p>プロダクトの OSS 化を進める過程で security.txt を知りましたので、軽くご紹介します。</p> <ul class="table-of-contents"> <li><a href="https://tech.route06.co.jp/entry/2024/12/05/120000#securitytxt-の概要">security.txt の概要</a></li> <li><a href="https://tech.route06.co.jp/entry/2024/12/05/120000#securitytxt-のフォーマット">security.txt のフォーマット</a></li> <li><a href="https://tech.route06.co.jp/entry/2024/12/05/120000#ROUTE06-Inc-におけるテンプレート">ROUTE06, Inc. におけるテンプレート</a></li> <li><a href="https://tech.route06.co.jp/entry/2024/12/05/120000#ROUTE06-Inc-における設置例">ROUTE06, Inc. における設置例</a></li> <li><a href="https://tech.route06.co.jp/entry/2024/12/05/120000#まとめ">まとめ</a></li> <li><a href="https://tech.route06.co.jp/entry/2024/12/05/120000#付録-各社の設置例">付録: 各社の設置例</a><ul> <li><a href="https://tech.route06.co.jp/entry/2024/12/05/120000#Supabase">Supabase</a></li> <li><a href="https://tech.route06.co.jp/entry/2024/12/05/120000#その他">その他</a></li> </ul> </li> </ul> <h2 id="securitytxt-の概要">security.txt の概要</h2> <p>security.txt はウェブサイトのセキュリティに関する情報を提供するための、標準的なテキストファイルです。2022 年 4 月に公開された <a href="https://www.rfc-editor.org/rfc/rfc9116">RFC 9116</a> で定義されており、ウェブサイトの <code>/.well-known/security.txt</code> に設置します。</p> <p>security.txt を設置することで、以下の恩恵を受けられます。</p> <ul> <li>セキュリティ研究者や善意のハッカーは、ウェブサイトのセキュリティ問題を報告する際の連絡先や指針を容易に見つけられる</li> <li>企業は、セキュリティ問題の報告を容易に受け取り、対応することができる</li> </ul> <p>security.txt を設置しなかったり連絡先が不明確な場合、ウェブサイトのセキュリティ問題が発見されても、報告されないことがあります。</p> <h2 id="securitytxt-のフォーマット">security.txt のフォーマット</h2> <p>最大 8 種類のフィールドを記載します。</p> <pre class="code txt" data-lang="txt" data-unlink=""># 必須 Contact: # 報告フォームの URL やメールアドレス。複数ある場合は、Contact フィールドを優先順に複数行書く Expires: # 有効期限を日時で指定。security.txt が廃れることを防ぐため、1 年未満が奨励されている # 任意 Preferred-Languages: # 対応可能な言語。複数指定可 Policy: # セキュリティポリシーページの URL Acknowledgements: # 過去報告者への謝辞掲載ページの URL Hiring: # セキュリティ関連職種の採用ページの URL Canonical: # この security.txt の URL Encryption: # 暗号化キーのある URL 等の場所。報告者とのやり取りを PGP 等で暗号化したい場合に記載する</pre> <p>記載例です。<a href="https://securitytxt.org/">https://securitytxt.org/</a> でも作れます。</p> <pre class="code txt" data-lang="txt" data-unlink=""># 必須 Contact: mailto:security@example.com Expires: 2025-11-30T23:59:59Z # 任意 Preferred-Languages: en, ja Policy: https://example.com/security-policy.html Acknowledgements: https://example.com/hall-of-fame.html Hiring: https://example.com/security-jobs.html Canonical: https://example.com/.well-known/security.txt Encryption: https://example.com/pgp-key.txt</pre> <h2 id="ROUTE06-Inc-におけるテンプレート">ROUTE06, Inc. におけるテンプレート</h2> <p>弊社では以下を security.txt のテンプレートとしました。</p> <pre class="code txt" data-lang="txt" data-unlink="">Contact: # セキュリティ窓口のメールアドレスを mailto: 形式で記載する Expires: # 1 年以内の日時を記載する。定期的に更新すること Preferred-Languages: en, ja Policy: # https://github.com/{org}/{repo}/security/policy または、セキュリティポリシーページの URL を記載する Canonical: # この security.txt の URL を記載する</pre> <p>💡 Expires フィールドの更新忘れと、他のフィールドが廃れることを防ぐために、弊社では <a href="https://github.com/route06/actions/blob/main/.github/workflows/create_gh_issue.yml">route06/actions/.github/workflows/create_gh_issue.yml</a> を使って、定期的に更新用 issue を作っています。</p> <ul> <li>更新用 issue の例: <a href="https://github.com/giselles-ai/giselle/issues/146">[Action Required] Update security.txt - 2024/12 Maintenance · Issue #146 · giselles-ai/giselle</a></li> </ul> <h2 id="ROUTE06-Inc-における設置例">ROUTE06, Inc. における設置例</h2> <p>弊社の Giselle というサービスでの設置例です。</p> <ul> <li><a href="https://studio.giselles.ai/.well-known/security.txt">https://studio.giselles.ai/.well-known/security.txt</a></li> </ul> <p>💡 Giselle は生成 AI を活用した、エージェントやワークフローをノーコードで構築できる SaaS です。サービスサイト <a href="https://giselles.ai/">https://giselles.ai/</a> で、詳細な情報を確認できます。OSS として、リポジトリ <a href="https://github.com/giselles-ai/giselle">giselles-ai/giselle</a> も公開されています。</p> <h2 id="まとめ">まとめ</h2> <p>ウェブサイトのセキュリティに関する情報を提供するための security.txt とともに、弊社 ROUTE06, Inc. での設置例も紹介しました。</p> <p>単なるテキストファイルであるため作成が容易ですし、報告者としても確実に使える窓口が分かることは良さそうです。</p> <h2 id="付録-各社の設置例">付録: 各社の設置例</h2> <h3 id="Supabase">Supabase</h3> <p><a href="https://supabase.com">https://supabase.com</a> の security.txt は、GitHub の SECURITY.md も兼ねています。</p> <ul> <li><a href="https://supabase.com/.well-known/security.txt">https://supabase.com/.well-known/security.txt</a> が配置されている</li> <li><a href="https://github.com/supabase/supabase/blob/v1.24.09/SECURITY.md">https://github.com/supabase/supabase の SECURITY.md</a> は、同リポジトリ <a href="https://github.com/supabase/supabase/blob/v1.24.09/apps/docs/public/.well-known/security.txt">apps/docs/public/.well-known/security.txt</a> へのシンボリックリンク</li> <li>apps/docs/public/.well-known/security.txt は <a href="https://supabase.com/.well-known/security.txt">https://supabase.com/.well-known/security.txt</a> としてデプロイされる</li> <li>同リポジトリに SECURITY.md が commit されているので、<a href="https://github.com/supabase/supabase/security">Security</a> タブからも、同じものが見える</li> </ul> <h3 id="その他">その他</h3> <ul> <li><a href="https://www.google.com/search?q=inurl:.well-known/security.txt&amp;gl=us&amp;hl=en&amp;gws_rd=cr&amp;pws=0">各サイトの security.txt - Google Search</a></li> </ul>
tech.route06.co.jp
December 5, 2024 at 3:15 AM
February 12, 2024 at 5:51 AM
October 14, 2025 at 6:46 AM
The CVR to securitytxt Pipeline: How Ethical Hackers Are Secretly Probing Your Danish Company’s Defenses

Introduction: A recent talk at BSides Copenhagen 2025 revealed how security researchers are systematically assessing Danish companies' security readiness through public data and standardized…
The CVR to securitytxt Pipeline: How Ethical Hackers Are Secretly Probing Your Danish Company’s Defenses
Introduction: A recent talk at BSides Copenhagen 2025 revealed how security researchers are systematically assessing Danish companies' security readiness through public data and standardized vulnerability reporting protocols. Emil Hørning's "CVR to security.txt" methodology demonstrates how ethical hackers leverage commercial registry data to identify organizations lacking proper security reporting channels, highlighting critical gaps in Denmark's cybersecurity posture. Learning Objectives: Understand how security researchers map CVR data to organizational assets&hellip;
undercodetesting.com
November 8, 2025 at 11:04 PM
The State of Vulnerability Disclosure in Danish Companies: A securitytxt Analysis

Introduction The security.txt file is an emerging standard that helps organizations define a clear process for security researchers to report vulnerabilities. Despite Denmark’s growing focus on cybersecurity, a…
The State of Vulnerability Disclosure in Danish Companies: A securitytxt Analysis
Introduction The security.txt file is an emerging standard that helps organizations define a clear process for security researchers to report vulnerabilities. Despite Denmark’s growing focus on cybersecurity, a recent scan of over 1.2 million .dk domains revealed only 0.11% had a security.txt file—highlighting a critical gap in vulnerability disclosure maturity. Learning Objectives Understand the role of security.txt in secure vulnerability disclosure.
undercodetesting.com
June 20, 2025 at 10:25 AM
July 2, 2026 at 6:12 AM