Add SECURITY.md pointing to ASF policy page
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000..8a2cdcd
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,3 @@
+Please follow the Apache Software Foundation's Security Team instructions when
+reporting any vulnerabilities:
+https://www.apache.org/security/