Responsible disclosure

Version 1.0 · Effective 2026-08-12

Paired with our security.txt file (/.well-known/security.txt).

Scope

This policy covers the websites Ramer Enterprise operates:

  • ramerenterprise.com (this site)
  • chipshotlabs.com
  • straylightforge.com

It does not extend to systems belonging to Ramer Enterprise’s clients — vulnerabilities found during an authorized client engagement are reported through that engagement’s own channel, not this one.

Our commitment

If you find a security issue in one of our properties and report it in good faith, we will not pursue or support legal action against you for that research, provided you:

  • do not access, modify, or delete data that is not yours;
  • do not degrade our services or those of our users;
  • do not use social engineering, physical attacks, spam, or public disclosure before we have had time to respond;
  • give us reasonable time to respond before disclosing publicly (see timeline below).

How to report

Email security@ramerenterprise.com with enough detail to reproduce the issue. Please use a clear subject line, such as “Security Issue: [Component]”, so your report reaches the right person quickly. Encrypted reports are welcome where a published key is available — see the contact page.

Response timeline

  • Acknowledgment: within 3 business days
  • Initial assessment: within 10 business days
  • Fix deployed: within 30 days for critical issues, 90 days for lower-risk issues (or public disclosure, whichever comes first, unless you agree to extend)
  • Public disclosure: we will credit you if you wish and the law permits

What is out of scope

  • Denial-of-service attacks
  • Social engineering and phishing testing (contact us separately if you want to discuss an authorized red team)
  • Third-party services and infrastructure we do not control
  • Physical security
  • Username enumeration (acceptable in context of a real vulnerability, but not in isolation)
  • Issues in dependencies without a working exploit or clear path to impact

Why this matters

A security practice that does not accept reports about its own sites is a visible inconsistency. This policy exists because we ask clients to let us test their security. We hold ourselves to the same standard.

Machine-readable pointer

This policy is also referenced from /.well-known/security.txt per RFC 9116, so automated tools and researchers can find it without hunting through the site.


Not legal advice. This policy describes our practices; it is not a substitute for professional legal advice.