Responsible disclosure
Paired with our security.txt file (/.well-known/security.txt).
Scope
This policy covers the websites Ramer Enterprise operates:
- ramerenterprise.com (this site)
- chipshotlabs.com
- straylightforge.com
It does not extend to systems belonging to Ramer Enterprise’s clients — vulnerabilities found during an authorized client engagement are reported through that engagement’s own channel, not this one.
Our commitment
If you find a security issue in one of our properties and report it in good faith, we will not pursue or support legal action against you for that research, provided you:
- do not access, modify, or delete data that is not yours;
- do not degrade our services or those of our users;
- do not use social engineering, physical attacks, spam, or public disclosure before we have had time to respond;
- give us reasonable time to respond before disclosing publicly (see timeline below).
How to report
Email security@ramerenterprise.com with enough detail to reproduce the issue. Please use a clear subject line, such as “Security Issue: [Component]”, so your report reaches the right person quickly. Encrypted reports are welcome where a published key is available — see the contact page.
Response timeline
- Acknowledgment: within 3 business days
- Initial assessment: within 10 business days
- Fix deployed: within 30 days for critical issues, 90 days for lower-risk issues (or public disclosure, whichever comes first, unless you agree to extend)
- Public disclosure: we will credit you if you wish and the law permits
What is out of scope
- Denial-of-service attacks
- Social engineering and phishing testing (contact us separately if you want to discuss an authorized red team)
- Third-party services and infrastructure we do not control
- Physical security
- Username enumeration (acceptable in context of a real vulnerability, but not in isolation)
- Issues in dependencies without a working exploit or clear path to impact
Why this matters
A security practice that does not accept reports about its own sites is a visible inconsistency. This policy exists because we ask clients to let us test their security. We hold ourselves to the same standard.
Machine-readable pointer
This policy is also referenced from /.well-known/security.txt per RFC 9116, so automated tools and researchers can find it without hunting through the site.
Not legal advice. This policy describes our practices; it is not a substitute for professional legal advice.