Both are prerequisites for any external review programme, and one of them was already
promised by our live security.txt to a file that did not exist.
SECURITY.md states the scope, the response times we hold ourselves to, and three things
we would rather a reviewer heard from us than discovered: there has been no third-party
audit, every validator is operated by the Foundation, and the post-quantum guarantee is
at anchor heights rather than on every block.
AUDITS.md opens by saying we have had no third-party audit, and keeps that first line
until it stops being true.