compliance(adr-011): formalise ATO evidence statement for policy-trace coverage

Source: adr-011-hardcoded-policy-values-sweep plan Potential Improvements.

The CI gates landed by Phase 1 (cargo xtask policy audit, cargo xtask rules check, the threshold/input drift gates) collectively constitute compliance evidence for the ATO package. Formalise this into a written statement: every policy value is either (a) in jurisdiction.toml with a citations.toml entry, (b) in rulesets/federal/*.json with a _citation field, or (c) in an explicit allowlist with a written rationale. Document this under the security baseline as the official ADR-011 ATO posture.

Acceptance: docs/modules/ROOT/pages/compliance/adr-011-ato-evidence.adoc lists the gates, what each one proves, and how to regenerate the evidence; cross-referenced from the security baseline.