Expanded the security policy to include detailed reporting guidelines, vulnerability scopes, testing guidelines, and response processes.