This is the org-wide default security policy, used for any
kaappi repository that doesn't have its own
SECURITY.md. It is maintained at
kaappi/community/SECURITY.md,
the canonical copy — see that file for the reporting process and supported
versions.
A repo with its own threat model documents it in its own SECURITY.md; for
example, kaappi/kaappi
covers its sandbox mode and FFI trust boundary.