Five years of data reveals a standard struggling to gain traction, propped up by platform automation rather than organic adoption.
Introduction
In April 2022, the IETF published RFC 9116, formalizing security.txt as an official standard for vulnerability disclosure.(1) The concept is simple: place a text file at /.well-known/