security.txt
Your policy could be expired and invalid — and still look perfect.
The file at /.well-known/security.txt tells researchers how to report a vulnerability. Canopy checks yours against RFC 9116 field by field, and catches the one problem no human proofreader would: a policy that's expired, and therefore ignored, while it reads exactly right.
- RFC 9116, field by field
- Catches expired policies
- Starter file if missing
- Free, no account
Try: cloudflare.com · github.com · google.com | Security headers → · Email security →
Don't have one? Generate a compliant security.txt →
Expires is set automatically to one year out — RFC 9116 requires it, and it's the field most policies forget to renew.