Enter your supported versions, contact email, and disclosure process, and the tool assembles a SECURITY.md policy file for your repository.
Place it at the repository root or in .github/SECURITY.md — GitHub links to it automatically from the repo's Security tab.
Yes, as a starting point — review names, paths, and details against your actual project before committing.
No. Everything is built client-side in your browser; nothing is sent anywhere until you commit it yourself.