SaaS Ranking

security.txt (RFC 9116) in Product feedback and updates

It tells a researcher where to report a vulnerability instead of guessing.

3 of 14 companies we measured here publish it, that is 21%. Last checked 2026-09-13.

21% here against 11% across every category we measure. Product feedback and updates sits above the overall share for this criterion.

This page counts companies, not product entries: a company with two products in this category is one company here and two rows below.

Back to security.txt (RFC 9116) across all categories, or to Product feedback and updates.

Published

Served at /.well-known/security.txt.

VendorWhat we found
Featurebase https://www.featurebase.app/.well-known/security.txt
Noticeable https://noticeable.io/.well-known/security.txt
Released https://released.so/.well-known/security.txt

No security.txt found.

We reached at least one address for each of these vendors and none of them carried it. That is what we found at the addresses we checked, on the date we checked them, and not a statement about what the vendor has.

VendorWhat we found
AnnounceKit 1 address checked
Beamer 1 address checked
Changelogfy 1 address checked
Changemap 1 address checked
Feedback Fish 1 address checked
Frill 1 address checked
LoopedIn 1 address checked
ProductLift 1 address checked
Roadmap 1 address checked
Upvoty 1 address checked
UserJot 1 address checked

Not measured

We could not look at these, or their robots.txt asks us not to. That says something about our measurement, not about them, and they are left out of the percentage above.

VendorWhat we found
Canny The vendor’s server blocked or rate-limited our crawler, so this was not measured.

Found something we missed? Tell us. A correction moves that vendor into our next nightly run. That run reads the same fixed addresses we check for every vendor, not the address you send.