Site setupAdministrator · Log out
Example Plone site
Site setup / Security policy
Classic UI control panel
Security policy expires soon. Review it now to keep security.txt available.

Security policy

Manage the information published at /.well-known/security.txt.

Draft Last saved 8 minutes ago
1. Contact2. Disclosure3. Extensions4. Review

Contact and expiry

The minimum information needed to publish.

Required
Add at least one Contact before publishing.
Exact instant; published in UTC. Approaching-expiry warnings begin 30 days before this date.Expiry must be in the future.

Disclosure information

Optional links that help researchers act on the policy.

Recommended information is missing.
All listed languages have equal priority.

Extension fields

Use registered or forward-compatible custom field names.

Rows publish after the standard fields in this order. Drag handles would support reordering in the real form.

LifecycleDraftOwner intent + effective state
Expiry210 daysNo action needed
Endpoint404Current anonymous response
At least one Contact is required to publish.
This date has passed.
Extension fields (2)

Generated preview

Unsigned bytes
State for a separate frontend
Step 1

Write the policy

Structured fields and extensions
Step 2

Review the output

Resolve blockers and warnings
Step 3

Publish and maintain

Endpoint, signing, expiry

1. Write the policy

Start with the required fields, then add useful disclosure information.

6 of 8 recommended
Required before publication.
Choose a future date.
Optional standard fields and extensions

Encryption, acknowledgments, preferred languages, canonical, policy, hiring, and 2 extension rows.

2. Review

Blocking errors must be fixed; warnings are advice.

Generated representation
State exposed to a separate frontend

3. Publish

Signing

Signing is an optional deployment capability. A website owner can only enable it when the server reports that it is available and correctly configured.

Maintenance

    A — Guided form

    PROTOTYPE ONLY — no data is saved. Use arrows to compare the three information architectures; use the scenario menu to inspect lifecycle states.