Software half of #28: parser fuzzing (found and fixed a decodeArmor slice bug), CSP and security headers, govulncheck (circl bump), threat model doc, audit script. Host half: systemd sandboxing, unattended-upgrades, fail2ban, sshd throttling, monitoring heartbeat. Leaving #28 open — it is an umbrella; this closes the concrete items.