Implement suggestions made by @xibe in [#848](https://github.com/suitenumerique/docs/pull/848) and [#849](https://github.com/suitenumerique/docs/pull/849) Signed-off-by: virgile-dev <virgile.deville@beta.gouv.fr>
We need a safe way for people to report vulnerabilities. People now can go on SECURITY.md and follow our policy. We want to have a policy for expected behaviour. People can check out CODE_OF_CONDUCT.md.