Documentation, service status, and the security whitepaper.
Live service status.
Architecture, threat model, disclosure policy.