extend docs on security

I touched on #1 (closed), but not sure if this is sufficient to mark it as fixed.

The new text is based on castellum:docs/, which I would remove if this is merged.

