MYMONDAY.AISecurityLens

Local security.txt validator

Check security.txt before a researcher needs it.

Inspect pasted security.txt content for RFC 9116 contact, expiry, canonical, and policy fields in this browser tab.

* Nothing is uploaded. SecurityLens parses the text locally and never fetches your security policy.

Local security.txt validator

Keep vulnerability reporting reachable

01

Paste the exact UTF-8 security.txt content served from /.well-known/security.txt.

02

SecurityLens checks required Contact and Expires fields, URI schemes, Canonical entries, and common optional links.

03

Fix findings, then deploy the file at the well-known path and verify it over HTTPS with your own operational process.

FAQ

What does RFC 9116 require?

Does SecurityLens fetch my site?

No. It only evaluates the security.txt text you paste and never contacts the listed URLs.

Why does Expires matter?

A stale security.txt file can leave researchers without current reporting guidance. The tool checks that one Expires date exists and is in the future.

Does a clean result prove disclosure readiness?

No. It checks file syntax and common fields. Your contact channel, policy, response process, and deployment still need operational verification.