Free · about 30 seconds

Make it easy to report a bug to you

RFC 9116 gives researchers one standard place to look for your security contact: /.well-known/security.txt. If someone finds an actively exploited vulnerability in your product, this small file decides whether they reach you first or your regulator does. Fill in two boxes below and you are done.

Nothing you type here leaves your browser. This is a free tool from CRA Incident Drill, the 7-minute readiness check for the EU Cyber Resilience Act's 24-hour reporting rule, which goes live on 11 September 2026.