tpm: add a deployment security review packet
A reviewer-facing REVIEW.md: scope, threat model, the security properties the
code enforces (with source references), the audit trail of issues found and
fixed, the independent-audit result, the residual limitations, and the
evidence (tests, fuzz, live swtpm smoke, merlint). It is written to make an
independent human security review fast and is explicit that it does not
replace one.