Loading
Loading
A specification website and generator for publishing clear security testing boundaries, giving ethical hackers and automated tools a machine-readable way to understand what is allowed, where, and under which constraints.


The product is deliberately legible at first glance: a security-focused spec, an example directive file, a generator, and a dark interface that feels native to the audience it serves.
Security researchers and automated scanners often have to infer testing boundaries from scattered legal pages, bug bounty programs, or silence. hacker.txt creates a clearer contract by letting a website publish explicit pentesting rules, scope, contact details, and disallowed activity in one standardized text file.
Framed the product around a concrete operator benefit instead of abstract security messaging: publish one plain-text file at the root of a domain and make testing expectations explicit.
Made the website prove the standard quickly with an example hacker.txt file, visible core directives, documentation, and a generator path that lowers adoption friction.
Used the visual language of terminal-green security tooling without losing clarity, so the product feels credible to developers, researchers, and teams responsible for security intake.
Positioned hacker.txt as a bridge between policy and automation: readable by humans, simple to host, and structured enough for tools to interpret safely.