There is now a security page. It sets out how we handle your source code and your account, what we do not claim, and how to report a security problem to us. The same contact details are published in the standard machine-readable place, /.well-known/security.txt.
The footer on every page now shows our support address, a link to the security page, and a link to the service status page, so you can check whether Monterva is up without writing to us first.