What it is
security.txt tells researchers how to report a security problem. RFC 9116 defines the format: a contact address at minimum, then optionally a disclosure policy, a PGP key, preferred languages and an expiry date. It belongs at /.well-known/security.txt.
Why it matters
Without a published contact, whoever finds a vulnerability either gives up or reports it somewhere public. The file is informative in its own right: a current, complete one suggests a team that expects reports, and the PGP key carries metadata of its own.