There is a security tag available in the BTS but as far as I know there's no facility in the
BTS for hiding reports based on it or any other criteria. (I don't know how the security team
tracks things internally, but I'm 99.8% sure it's not using bugs.debian.org.)
I suppose reportbug and reportbug-ng should nag users who report bugs tagged security to send
them to team@security.debian.org (or security@debian.org) instead if the vulnerability isn't
publicly-known; I don't know how many users would know that offhand, though, so I'm not sure
the question would help much.