Tracks implementation of docs/SecurityPractice.md. T01 (Security
Genome record) and T02 (deny-escalation lockout) are already done,
shipped in the prior commit -- both were dependency-free. T03-T06
depend on key-cape, flex-auth, tenant-engine, and a Railiance
placement decision respectively, and are flagged as such rather than
assumed completable from this repo alone.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>