Management
security.txt Publishing
When a security researcher finds a hole in your site, how do they reach you? RFC 9116 is the standard answer: a small text file at a known address on your domain. Specula publishes that file at the Cloudflare edge.
Without a file on your server
The file is served at the Cloudflare edge; updates and removal happen from the console. Your server, your repository and your deployment pipeline are untouched.
Validity follows the RFC
You choose 3 months, 6 months or 364 days — the RFC requires under a year. An expired file is not counted as published, because the standard makes it invalid.
A team address is recommended
The contact address is published openly. The console suggests a team address over a personal one, and says so again in the confirmation dialog.
Contact: mailto:security@specula.com.trExpires: 2027-03-17T00:00:00.000ZPreferred-Languages: tr, enCanonical: https://specula.com.tr/.well-known/security.txt
Valid 6 months · an expired file isn't counted as published
Its limits
This feature works only on domains connected through Cloudflare.
Other features
Run this check on your own domain.
Add a domain and Specula finishes the first scan within minutes. No credit card needed.