security.txt

Your policy could be expired and invalid — and still look perfect.

The file at /.well-known/security.txt tells researchers how to report a vulnerability. Canopy checks yours against RFC 9116 field by field, and catches the one problem no human proofreader would: a policy that's expired, and therefore ignored, while it reads exactly right.

Try: cloudflare.com · github.com · google.com  |  Security headers → · Email security →

Don't have one? Generate a compliant security.txt →

Expires is set automatically to one year out — RFC 9116 requires it, and it's the field most policies forget to renew.