Report vulnerabilities privately via GitHub Security Advisories on this repository. Do not file a public issue for an unfixed vulnerability.
Default-deny is specified in docs/architecture/03-security.md and
crates/keld-guard. Privileged operations must not bypass keld-guard.
This note is the disclosure entry point, not a complete security RFC. KEL-20 architectural sign-off is still open.