RE security: 100% agree with everything you said. This is at the end of the day a security product. Even though we're very early, we've put a ton of thought into the security and especially the cryptography behind our product (e.g. we decided E2EE since the start) and intend on maximizing security posture in the coming months and years ahead — earning trust will definitely be an uphill battle but we hope to do it and have an optimal solution for everyone.
RE SSO: Initially, we started by exploring what other solutions on the market are doing about this and noticed SSO as an enterprise ask even for security products like Bitwarden. That said, I think you have a great point here that I'll discuss with the team: SSO doesn't have to be available/not available across plans but that it could be available across all plans and larger organizations would need to pay for it anyways on the basis of needing it for more users — this preserves the SSO benefit for individuals and small teams as well as enterprises.
PS: I'll work on doing a better job responding to security reports; I appreciate everyone's input a lot in this thread and hope to express that better over writing...