How to report a security vulnerability in a PlayIt Software product.
PlayIt Software produces radio playout and broadcast software, much of which runs unattended and on air. We take reports of security vulnerabilities in our products seriously. This document sets out how to report one and what to expect in response.
Email info with SECURITY: at the start of the subject line.
Please do not report a suspected vulnerability by opening a public issue, posting on the forum, posting on our Facebook page or in the Facebook group, or commenting on YouTube. Disclosure through a public channel exposes stations that have not yet applied a fix.
Please include as much of the following as you are able to:
Proof-of-concept code is welcome. Please do not include real user data, and please do not test against other customers' stations or against our production systems in any manner that would degrade service.
| Stage | Timing |
|---|---|
| We acknowledge your report | Within 3 working days |
| We confirm whether we can reproduce the issue, and give our initial assessment of severity | Within 10 working days |
| We release a fix, or a documented mitigation | Within 90 days of acknowledgement |
We will provide an update at each of these stages, including where a stage is going to take longer than stated.
Our commitment is to make a fix or a documented mitigation available within 90 days of acknowledging a valid report, and to keep you informed if more time is required.
We ask that the details of a vulnerability are not disclosed publicly until that fix is available, so that customers have the opportunity to apply it first.
Where a vulnerability is already being exploited, we will work with you to issue a warning promptly, together with any mitigation customers can apply in the interim.
We credit reporters in the release notes accompanying the fix, unless you prefer otherwise.
PlayIt Software does not operate a bug bounty programme and does not pay for vulnerability reports. This applies regardless of the severity of the finding and is not subject to negotiation. What we provide is a prompt response, a fix, and public credit where it is wanted.
We ask that reports are not made conditional on payment, and that a request for valuation is not sent in place of the report itself. We will not enter into such discussions.
A report submitted with a demand for payment, or with a threat to publish, sell or otherwise pass on the details unless payment is made, will not be treated as a security report. We will not negotiate. The safe harbour set out below will not apply, the correspondence will be retained, and the matter will be referred to law enforcement and to the relevant CERT.
The same applies to any party holding data or access obtained without authorisation who offers its return in exchange for payment.
These provisions are directed at that conduct alone. Researchers acting in good faith are unaffected by them, and their reports remain welcome.
Where you make a good-faith effort to comply with this policy in the course of your research, we will regard that research as authorised. We will not pursue or support legal action against you, and should a third party bring action against you in respect of work conducted under this policy, we will confirm that the research was authorised.
Good faith requires that you do not access, modify or delete data belonging to others; that you retain no copies of any data encountered; that you do not degrade service for our customers; that you use a finding only to demonstrate it; that you report promptly; and that you attach no conditions, demands or deadlines to the report.
Where research ceases to meet these conditions, this protection ceases to apply from that point.
In scope:
Out of scope:
Where we become aware that a vulnerability in one of our products is being actively exploited, EU Regulation 2024/2847 (the Cyber Resilience Act) requires us to report it to ENISA and the relevant national CSIRT within prescribed deadlines, beginning with an early warning within 24 hours. This obligation applies from 11 September 2026.
Such a report concerns the vulnerability and the affected product. We will not disclose your identity or contact details as part of it unless you ask us to.
Security updates are delivered through the standard update mechanism for each product.
PlayIt updates are free. No PlayIt product requires payment to update, and a premium module licence remains valid across versions regardless of when it was purchased.
Current versions do carry system requirements. A computer or operating system too old to meet them may need to be updated first, which is a cost outside our control. A system in that position will normally also be outside its own vendor's security support, which is a broader exposure than any PlayIt update can address.
The current version of each product receives security fixes as a matter of course.
Where a customer would rather not move to the current version, we will provide a security fix for the version immediately preceding it on request, provided that version was released within the previous twelve months. For example, where PlayIt Live 2.18 is current, a fix for 2.17 is available on request for as long as 2.17 was released less than twelve months ago.
Either route requires installing an update, as security fixes are not applied automatically. The difference is that a fix for the preceding version leaves the rest of the software unchanged, rather than also introducing newer features that you have not yet tested in your own setup.
A machine-readable summary of our security contact details is published at https://www.playitsoftware.com/.well-known/security.txt, in accordance with RFC 9116.
Last reviewed: 8 September 2026.
PlayIt Software is based in the heart of Cambridge, England, United Kingdom.
You can get in touch with us by the following methods: