Since AI-driven "researchers" are submitting more bug reports these days in hopes of adding CVEs to their CVs, we're probably going to need to publish a more formalized security policy on the openldap.org web site. This is an example of what we're starting with. Feedback welcome.