DocumentationCommerceAdmin Systems Guide

PaaS only

Security issue reporting

Last update: May 29, 2025
  • Topics:
  • Configuration
  • Security

CREATED FOR:

  • Beginner
  • Intermediate
  • Admin

The security.txt file contains contact information and security-related links that can be used by security researchers to report security concerns about your site. If your security information changes over time, ensure that the information in the security.txt file is up to date.

To configure security.txt:

  1. On the Admin sidebar, go to Stores > Settings > Configuration.

  2. In the left panel under Security, click Security.txt.

  3. In the General section, set Enable to Yes.

    General security configuration

  4. Under Contact Information, enter the following:

    • The email address and phone number of the person who manages security issues for your store.

    • The URL of your store’s Contact Page. This page could either be a list of store security contacts or your Contact Us page.

    Contact Information configuration

  5. Under Other Information, enter the following:

    • The URL of your public Encryption key. For example: https://example.com/pgp-key.txt

    • The URL of an Acknowledgments page where security researchers are recognized for their efforts on behalf of your store.

    • Your Preferred Languages for security-related communications. Enter the standard two-character language code for each supported language, separated by a comma. For example, to specify English, Spanish, and French, enter en, es, fr. All specified languages have the same priority, regardless of their order of appearance.

    • The URL of a Hiring page that lists security-related employment opportunities with your store.

    • The URL of your security Policy page.

    • The URL of a digital Signature file that is saved on your server. For example: https://mystore.com/.well-known/security.txt.sig

    The digital signature must be set up from the CLI (command-line interface) of the server. To learn more, see Security.txt on GitHub.

    Other Information

  6. When complete, click Save Config.

Commerce

  • Admin Systems Guide
  • Introduction to Admin systems
  • System menu
  • Admin user accounts
    • Admin permissions
    • Manage user accounts
    • User roles
  • System notifications
  • Variables
    • Predefined variables
    • Custom variables
    • Variables reference
    • Markup tags
  • Communications
    • Email templates
    • Customize email templates
    • Configure email
  • Data transfer
    • Overview
    • CSV files
    • Import
      • Import process
      • Product images
    • Export
    • Product data attributes reference
    • Customer data attributes reference
    • Update tax rate data
    • Examples
      • Import bundle products
      • Import configurable products
      • Import downloadable products
      • Import tier price data
    • Scheduled import and export
    • Data Management Dashboard
  • Action logs
    • Overview
    • Action logs report
    • Log archive
    • Bulk actions
  • System tools and settings
    • Cache management
    • Index management
    • System backups
    • Cron (scheduled tasks)
    • Developer tools
    • Support tools
  • Integrations
  • Security
    • Overview
    • Encryption key
    • Security scan
    • Configure Admin security
    • CAPTCHA
      • Standard CAPTCHA
      • Google reCAPTCHA
    • Two-Factor Authentication (2FA)
      • Overview
      • User account setup for 2FA
      • Manage 2FA
    • Session management
    • Browser capabilities detection
    • Security issue reporting
  • Return to Admin User Guides
Experience League

Learn

  • Playlists
  • Tutorials
  • Instructor-led training
  • Browse all learning content

Documentation

  • Documentation home
  • Experience Cloud release notes
  • Document Cloud release notes

Certifications

  • Certifications home

Events

  • Events home

Community

  • Community home
  • Advertising Cloud
  • Analytics
  • Audience Manager
  • Campaign Standard
  • Experience Cloud
  • Experience Manager
  • Experience Platform
  • Magento Commerce
  • Marketo Engage
  • Target
  • Workfront, an Adobe company
  • Feedback Program

Support

  • Experience Cloud Support
  • Document Cloud Support
  • Community forums

Resources

  • Adobe I/O
  • Adobe Status

Adobe Account

  • Profile
  • Bookmarked content

Adobe

  • About
  • Careers
  • Newsroom
  • Corporate responsibility
  • Investor Relations
  • Supply chain
  • Trust Center
  • Events
  • Diversity & Inclusion
  • Integrity
DeutschEnglishEspañolFrançaisItalianoNederlandsPortuguêsSvenska中文 (简体)中文 (繁體)日本語한국어
Copyright © 2025 Adobe. All Rights Reserved./Privacy/Terms of Use/Cookie preferences/Do not sell my personal information/ AdChoices