security.txt Publishes a Machine-Readable Vulnerability Contact
A vulnerability report can lose value before triage begins if the reporter cannot identify a current, organization-controlled contact. RFC 9116 addresses that routing problem with security.txt, a machine-parsable text file published at a predictable HTTPS location. The file does not grant testing permission, establish a bug bounty, or prove that a listed recipient is trustworthy. Its narrower role is to publish vulnerability disclosure metadata in a format that people and automated tools can retrieve consistently.