Specula
All features

Management

security.txt Publishing

When a security researcher finds a hole in your site, how do they reach you? RFC 9116 is the standard answer: a small text file at a known address on your domain. Specula publishes that file at the Cloudflare edge.

  • Without a file on your server

    The file is served at the Cloudflare edge; updates and removal happen from the console. Your server, your repository and your deployment pipeline are untouched.

  • Validity follows the RFC

    You choose 3 months, 6 months or 364 days — the RFC requires under a year. An expired file is not counted as published, because the standard makes it invalid.

  • A team address is recommended

    The contact address is published openly. The console suggests a team address over a personal one, and says so again in the confirmation dialog.

/.well-known/security.txtpublished
Contact: mailto:security@specula.com.tr
Expires: 2027-03-17T00:00:00.000Z
Preferred-Languages: tr, en
Canonical: https://specula.com.tr/.well-known/security.txt

Valid 6 months · an expired file isn't counted as published

Its limits

This feature works only on domains connected through Cloudflare.

Other features

Run this check on your own domain.

Add a domain and Specula finishes the first scan within minutes. No credit card needed.