Security in Sage

In addition to my current development work, I'm working on a paper examining Sage from a computer security perspective. As a open source, widely distributed software system, that must be a concern. The server components that can execute potentially arbitrary code on the server make security even more of a concern.

Is there any documentation that talks about Sage's security precautions?--My initial research i.e. googling and searching the documentation failed to turn anything up.

Are there people who work on that aspect who would be willing to answer a few email questions in the next two weeks?

Is there anything else I should know? I plan to do some fiddling and testing on my own to see what I can turn up.