Security & vulnerability reporting

Development placeholder. The security contact and coordinated-disclosure process are not finalized yet (PLAN-015).

CurriBloom uses defense in depth, deny by default, and least privilege. A private vulnerability-reporting channel will be published before external beta.