Security Architecture & Responsible Disclosure
Storefront application defenses, RFC 9116 vulnerability reporting procedures, OpenPGP keys, and supply-chain verification for Raw Carbon.
Responsible Vulnerability Disclosure & Safe Harbor
Raw Carbon (operated by Abrams Research LLC) welcomes responsible vulnerability reports from the independent security community. If you discover a potential vulnerability in our storefront or order flow, please report it directly to our security team.
OpenPGP Encryption Key
Encrypt sensitive vulnerability submissions using our official RSA-4096 OpenPGP public key:
Research Scope & Prohibitions
rawcarbon.storestorefront and catalog routes- Shopping cart context and RFQ submission flows
- MIME type sniffing defenses and strict CSP compliance
- Cross-Origin Isolation and COEP headers
- Denial of Service (DoS / DDoS) testing
- Automated fuzzing that causes customer downtime
- Physical supply-chain or warehouse facility testing
- Social engineering or phishing of customer support
Architectural Controls & Standards Alignment
Active security manifest published at /.well-known/security.txt with annual rolling expiry.
Armed with COEP: credentialless and COOP: same-origin to eliminate side-channel leakage.
Strict Content-Security-Policy with object-src 'none', base-uri 'self', and form-action 'self'.
Build-time CycloneDX software bill of materials tracking all dependencies and subcomponents.