SaaS Ranking

security.txt (RFC 9116) in Knowledge base and wiki

It tells a researcher where to report a vulnerability instead of guessing.

2 of 17 vendors we measured here publish it, that is 12%. Last checked 2026-09-03.

12% here against 13% across every category we measure. Knowledge base and wiki sits below the overall share for this criterion.

Back to security.txt (RFC 9116) across all categories, or to Knowledge base and wiki.

Published

Served at /.well-known/security.txt.

VendorWhat we found
BookStack https://www.bookstackapp.com/.well-known/security.txt
Coda https://coda.io/.well-known/security.txt

No security.txt found.

We reached at least one address for each of these vendors and none of them carried it. That is what we found at the addresses we checked, on the date we checked them, and not a statement about what the vendor has.

VendorWhat we found
Almanac 1 address checked
Anytype 1 address checked
AppFlowy 1 address checked
Bear 1 address checked
Capacities 1 address checked
Docmost 1 address checked
Docusaurus 1 address checked
DokuWiki 1 address checked
Fibery 1 address checked
Guru 1 address checked
HelpDocs 1 address checked
Helpjuice 1 address checked
Heptabase 1 address checked
Logseq 1 address checked
Waybook 1 address checked

Not measured

We could not look at these, or their robots.txt asks us not to. That says something about our measurement, not about them, and they are left out of the percentage above.

VendorWhat we found
Bloomfire The vendor’s server blocked or rate-limited our crawler, so this was not measured.
Craft The vendor’s robots.txt excludes us from at least one of these addresses, so this was not measured.
Papyrs The vendor’s server blocked or rate-limited our crawler, so this was not measured.

Found something we missed? Tell us and the next run picks it up.