We know we are going to get emails to security@ and security-help@ and it's 99% that these will be managed as collab google inboxes. These are first points of contact which can escalate to a security issue with UBN, a security issue that gets backlogged, an RFS, etc. Probably needs some guidelines, workflow, or something sketched out onwiki.
@Dsharpe I'll throw this your way as you have the most skin in the game here off the bat.