el-safety — on-device, tiered, decoder-time safety (ADR-005).
The [SafetyMode] tier is budget-gated by device profile via
[SafetyModeSelector]. The Lightweight anchor/blacklist filter is fully
implemented here. SecDecoding (two ~1B models) and Csd (claim
backtracking) require model assets and are scaffolded as follow-ups
([SecDecodingSteerer]). No safety path touches the network.