↓ Skip to main content

#rfc

Not as well-known as it should be: shipping security.txt

security.txt (RFC 9116) is a small, predictable file at /.well-known/security.txt that tells researchers where to report vulnerabilities -- contact, policy, expiry, and related fields. The format is simple and widely referenced, yet adoption is uneven: some flagship sites ship rich signed files, while others omit Expires or skip the file entirely. This post covers the well-known location rules, what good-enough looks like in practice, and a curated look at live examples worth opening in a tab. It also walks through a practical shipping checklist and the file this site now publishes. An update from September 2026 adds a European software-vendor adoption scan to the picture.