Security policy
Manage the information published at /.well-known/security.txt.
Contact and expiry
The minimum information needed to publish.
Disclosure information
Optional links that help researchers act on the policy.
Extension fields
Use registered or forward-compatible custom field names.
Rows publish after the standard fields in this order. Drag handles would support reordering in the real form.
Extension fields (2)
Generated preview
Unsigned bytesState for a separate frontend
Write the policy
Structured fields and extensionsReview the output
Resolve blockers and warningsPublish and maintain
Endpoint, signing, expiry1. Write the policy
Start with the required fields, then add useful disclosure information.
Optional standard fields and extensions
Encryption, acknowledgments, preferred languages, canonical, policy, hiring, and 2 extension rows.
2. Review
Blocking errors must be fixed; warnings are advice.
Generated representation
State exposed to a separate frontend
3. Publish
Signing
Signing is an optional deployment capability. A website owner can only enable it when the server reports that it is available and correctly configured.