Private vulnerability reporting is now enabled on the repo, so the
advisory link in this policy resolves. Adds security@bmadcode.com as a
second channel, replaces the unmet response SLA with best-effort
language, and adds a Security Model section so scope decisions rest on a
stated trust boundary rather than case-by-case argument.
Claude-Session: https://claude.ai/code/session_014nrWo411353cGjRBpMLpfV
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Expanded the security policy to include supported versions, reporting guidelines, response timelines, security scope, and best practices for users.
Co-authored-by: Alex Verkhovsky <alexey.verkhovsky@gmail.com>