A security product whose agent runs as root had no way to receive a private
report. Adds an RFC 9116 security.txt (served at /.well-known/security.txt)
and a SECURITY.md that GitHub surfaces as the repo's Security tab: a contact,
a private-first disclosure ask, the in-scope surfaces, and what we commit to
(signed-before-parse, degrade-safe, no telemetry). Closes the last open
trust gap from the review.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>