Security Report vulnerabilities privately. In scope: build pipeline, policy gates, attestation/surfaces, enrollment boundaries.