Security: no bug bounty until g1t makes money, and fixes are welcome as pull requests
Responsible disclosure says why there is no paid bounty yet, and that the source is open: hardening can come straight in as a pull request, while a fix for an open hole is agreed with us first so the pull request does not disclose it. Not built yet no longer says two-factor is missing; it shipped, so the page points to it, and single sign-on is what remains.