{# security.html — threat model + CVE status + security headers visible. No decoration; informational only. #} {% extends "base.html" %} {% block content %}

Security

Threat model and CVE status. Honest by construction: alerts reflect what the framework actually does, not what we'd like it to do.

{{ alerts_markup|safe }}

Threat model

{{ cards_markup|safe }}
{% endblock %}