Putting a security.txt file up on our site has generated a ton of noise from people sending us their interpretations of burp suite results. Nothing substantial, yet everyone wants a payout and sends follow up after follow up. Feels like the Hacktoberfest Github thing. If you have a real security issue that someone cares enough to disclose to you, they'll find a way to contact you.