Expanded the security policy to include details on reporting vulnerabilities, CVE coordination, scope of issues, and disclosure policy.