chore: close reference conformity gaps in project docs
Adds AGENTS.md (written from the real tree, docs site included), the CLAUDE.md shim, CODE_OF_CONDUCT.md, and .reference.yaml; merges the DCO, federal-employee, and scope-first sections into CONTRIBUTING.md; retrofits the CHANGELOG header (Keep a Changelog link, Changelog: trailer convention, merge-request-workflow link); adds "What to expect" and "Severity" sections to SECURITY.md.
Content stamped from gitlab-com/public-sector/reference templates, adapted to what is true of this repo. Remaining audit failures after this: encryption (FIPS in build config) and osv-verdict adoption, both tracked separately.