SaaS Ranking

security.txt (RFC 9116) in Design and prototyping

It tells a researcher where to report a vulnerability instead of guessing.

3 of 23 vendors we measured here publish it, that is 13%. Last checked 2026-09-06.

13% here against 12% across every category we measure. Design and prototyping sits above the overall share for this criterion.

Back to security.txt (RFC 9116) across all categories, or to Design and prototyping.

Published

Served at /.well-known/security.txt.

VendorWhat we found
Anima https://www.animaapp.com/.well-known/security.txt
Kittl https://www.kittl.com/.well-known/security.txt
Recraft https://www.recraft.ai/.well-known/security.txt

No security.txt found.

We reached at least one address for each of these vendors and none of them carried it. That is what we found at the addresses we checked, on the date we checked them, and not a statement about what the vendor has.

VendorWhat we found
Eraser 1 address checked
Flair 1 address checked
Knapsack 1 address checked
Locofy 1 address checked
Mockplus 1 address checked
Motiff 1 address checked
Onlook 1 address checked
Pacdora 1 address checked
Pebblely 1 address checked
Pencil 1 address checked
Photoroom 1 address checked
Reweb 1 address checked
Rive 1 address checked
Specify 1 address checked
Spline 1 address checked
Supernova 1 address checked
Tokens Studio 1 address checked
UXPin 1 address checked
Visily 1 address checked
Zeroheight 1 address checked

Not measured

We could not look at these, or their robots.txt asks us not to. That says something about our measurement, not about them, and they are left out of the percentage above.

VendorWhat we found
Pixelcut None of the addresses could be reached, so this was not measured.

Found something we missed? Tell us and the next run picks it up.