SaaS Ranking

security.txt (RFC 9116) in Compliance automation

It tells a researcher where to report a vulnerability instead of guessing.

0 of 12 vendors we measured here publish it, that is 0%. Last checked 2026-09-02.

0% here against 14% across every category we measure. Compliance automation sits below the overall share for this criterion.

Back to security.txt (RFC 9116) across all categories, or to Compliance automation.

Published

Served at /.well-known/security.txt.

None of the vendors we measured here published this.

No security.txt found.

We reached at least one address for each of these vendors and none of them carried it. That is what we found at the addresses we checked, on the date we checked them, and not a statement about what the vendor has.

VendorWhat we found
Akitra 1 address checked
Anecdotes 1 address checked
Apptega 1 address checked
Archer 1 address checked
Ciqualia 1 address checked
Hyperproof 1 address checked
MetricStream 1 address checked
Neumetric 1 address checked
Optro 1 address checked
Thoropass 1 address checked
Trustcloud 1 address checked
Trustero 1 address checked

Not measured

We could not look at these, or their robots.txt asks us not to. That says something about our measurement, not about them, and they are left out of the percentage above.

VendorWhat we found
Drata The vendor’s server blocked or rate-limited our crawler, so this was not measured.

Found something we missed? Tell us and the next run picks it up.