Vulnerability reporting policy for the C-axis trust program: private disclosure address, response process, and an honest pre-1.0 supported- versions statement (no fabricated version table, no SBOM claim).