---
canonical: "https://www.jsolly.com/blog/security-txt-allows-researches-to-contact-you/"
title: "Secure Website With security.txt: Fight Web Vulnerabilities"
description: "Learn how to create a security.txt file, understand its importance, and generate a GPG asymmetric key pair. FANG companies did it, so should you!"
author: "John Solly"
published: "2022-05-08T03:29:59.000Z"
updated: "2022-05-08T03:29:59.000Z"
---

<a id="secure-website-with-securitytxt-fight-web-vulnerabilities"></a>

# Secure Website With security.txt: Fight Web Vulnerabilities

![Bug with bomb legs. Report bugs, observe, verify,  inform](https://d1d7p8ufhgz4ld.cloudfront.net/media/post_metaimgs/report_bugs.png)

http://flickr.com/photos/kaet44/

Two days ago, I talked about [adding a robots.txt file to your site](https://www.jsolly.com/blog/help-google-spider-with-sitemaps-and-robots-file/) to inform web crawlers like Googlebot for better Google search indexing of your website. Today, [with this PR](https://github.com/jsolly/blogthedata/pull/53/files), I have added a security.txt file to blogthedata.com, giving security researchers a way to contact me about new web services vulnerabilities potentially affecting my site.

It’s easy to set this up yourself! You're adding two routes to your app containing information about how to contact you.

[https://blogthedata.com/pgp-key.txt](https://www.jsolly.com/pgp-key.txt)

https://blogthedata.com/.well-known/security.txt

> “When security risks in web services are discovered by independent security researchers who understand the severity of the risk, they often lack the channels to disclose them properly. As a result, security issues may be left unreported. security.txt defines a standard to help organizations define the process for security researchers to disclose security vulnerabilities securely.”
> 
> [https://securitytxt.org](https://securitytxt.org/)

The first step is to fill out a form on [https://securitytxt.org](https://securitytxt.org/). The tricky part is the encryption section. It's asking for the public key of a GPG [asymmetric key pair](https://www.youtube.com/watch?v=AQDCe585Lnc). There are smarter ways of generating keys, but I used this [online PGP generator](https://www.igolder.com/PGP/generate-key/). Once you create the keys, you'll want to stash the private key somewhere safe and put your public key at a publically accessible endpoint. 

Add a security.txt file to your website and join companies like [Google](https://www.google.com/.well-known/security.txt), [Facebook](https://www.facebook.com/.well-known/security.txt), and [Github](https://github.com/.well-known/security.txt) to make the web safer for everyone.

May 8, 2022 in [Web Dev](https://www.jsolly.com/blog/category/web-dev/)

Updated May 8, 2022
