This file is read by automated agents (security scanners, code analyzers, AI assistants) operating on this repository. It points them at the human-authored references they should consult before producing output.
Security model: SECURITY.md → THREAT_MODEL.md
Agents that scan this repository should consult SECURITY.md and the linked
THREAT_MODEL.md for the project's threat model — in particular the
control-plane API/UI authentication posture, the controller's failover
authority over managed Kvrocks clusters, metadata-store trust, and the SSRF
surface of node registration — before reporting issues.