The Mission

Make Security.txt files and basic VDPs a common part of the internet.

Security.txt files are still rare. This both prevents people from being able to do the right thing and also opens the door for bad actors to take advantage of businesses. The cause of this isn't because businesses don't care about security, but often a lack of awareness or it being put in the too hard basket. Meanwhile, curious security researchers skip over sites without security.txt files or are left guessing who to tell about vulnerabilities, and often give up or turn to public naming and shaming.

We want to close that gap. It isn't a new goal. Many have had the same mission and built the foundation. We're adding our touch to bring this to small businesses through awareness, tooling, and dedicated support that aims to make vulnerability disclosures as painless as possible. We want publishing a baseline security.txt to be a five-minute task for any team, and for the organisations that are ready, to have a path to a full vulnerability disclosure program that researchers can trust.

Our free tools get you a baseline template ready for internal approval. The paid options help you filter out the people trying to take advantage of you and make sure that your vulnerability disclosure process will always meet the expectations you've set without overwhelming your key internal staff.