Default security adapter.
Behavior:
- Inbound verify is permissive by default, but denies explicit sender claim mismatches and channel-reported authorization failures.
- Outbound sanitize applies deterministic per-channel text normalization before optional channel-specific sanitize hooks.