Building on this, this would be a great feature and eliminate a lot of manual work. We typically place a security.txt file in each site, but the ability to just deploy this would be great and configure via the .well-known configuration.
I could be wrong, but could this be done at the "platform" level or would it have to be in each package?
For example, pretty easy in the WordPress Developer Package, where we just create the folder, drop the file, and add a .htaccess redirect for domain.tld/security.txt to domain.tld/.well-known/security.txt.