security.txt (RFC 9116) in Network connectivity
It tells a researcher where to report a vulnerability instead of guessing.
1 of 8 companies we measured here publish it, that is 13%. Last checked 2026-09-30.
13% here against 11% across every category we measure. Network connectivity sits above the overall share for this criterion.
This page counts companies, not product entries: a company with two products in this category is one company here and two rows below.
Back to security.txt (RFC 9116) across all categories, or to Network connectivity.
Published
Served at /.well-known/security.txt.
| Vendor | What we found |
|---|---|
| ngrok | https://ngrok.com/.well-known/security.txt |
No security.txt found.
We reached at least one address for each of these vendors and none of them carried it. That is what we found at the addresses we checked, on the date we checked them, and not a statement about what the vendor has.
| Vendor | What we found |
|---|---|
| localhost.run | 1 address checked |
| Netmaker | 1 address checked |
| Packetriot | 1 address checked |
| Pangolin | 1 address checked |
| Pinggy | 1 address checked |
| Router Architects | 1 address checked |
| ZeroTier Central | 1 address checked |
Not measured
We could not look at these, or their robots.txt asks us not to. That says something about our measurement, not about them, and they are left out of the percentage above.
None. Every vendor here was measured for this criterion.
Other criteria in Network connectivity
- Data processing agreement
- Data location stated
- Status page with history
- Public pricing
- Certifications named
- Uptime SLA with a figure
- HTTPS enforced with HSTS
- No third-party tracking before consent
- Notice before subprocessors change
- Named privacy contact
security.txt (RFC 9116) in related categories
Found something we missed? Tell us. A correction moves that vendor into our next nightly run. That run reads the same fixed addresses we check for every vendor, not the address you send.