RFC 9116

A file format to aid in security vulnerability disclosure.

Listen

A podcast overview of RFC 9116 made with Google NotebookLM.

About href="#about"

RFC 9116 sets rules for the “security.txt” file, which helps organizations share how to report security problems. This file, usually found at /.well-known/security.txt, makes it easier for security experts to report issues. It includes details like contact info, encryption keys, and policy links. The file can be digitally signed to ensure its authenticity. With this standard format, organizations can handle security reports more efficiently and respond to problems faster.

Related

Topics

On this page

Supporters

Thank you to these organizations for supporting Project ScanGov:

ScanGov

Government. Digital. Experience.

Get ScanGov