KLANG Vulnerability Disclosure Policy

Last updated: 11 September 2026

Reporting a security issue

KLANG welcomes good-faith reports of potential security vulnerabilities in our products, firmware, applications and supporting services. Please send reports to security@klang.com. If you need encrypted communication, use our PGP key at https://www.klang.com/.well-known/security-pgp-key.txt.

Please include, where possible:

  • affected product, model, hardware revision and software/firmware version;
  • a clear description, impact and reproducible steps or proof of concept;
  • relevant logs, packet captures or screenshots, with personal data removed where possible;
  • your preferred contact details and whether you wish to be credited.

Our commitment

We aim to acknowledge a report within 3 business days, provide a triage update within 10 business days, and keep the reporter reasonably informed while we investigate. Timelines depend on severity, reproducibility and the availability of a safe fix.

We handle reports confidentially. We will not pursue legal action against researchers who act in good faith, test only on systems and networks they own or are explicitly authorised to test, avoid privacy violations and service disruption, and follow this policy. This does not authorise access to data that does not belong to you, physical attacks, social engineering, denial-of-service or volumetric testing, or testing against customer production systems, live events or third-party control networks without written permission.

Coordinated disclosure

Please give us a reasonable opportunity to investigate and remediate before publishing details. We may coordinate disclosure with the reporter, affected suppliers, CERT/CSIRT bodies and customers. If a vulnerability is actively exploited or presents an urgent risk, we may issue mitigation guidance earlier.

Out of scope

We welcome reports about our products, their firmware, our applications and our update mechanisms. The following are outside this policy and we will normally close them without further correspondence:

  • missing security headers, TLS configuration preferences or similar findings on our informational web pages, without a demonstrated exploit;
  • reports that name only a software version or a CVE identifier, without a demonstrated exploitable path in a KLANG product — a component version alone does not establish that the vulnerable code can be reached. We still check the named component against our software bill of materials; what we do not owe is a reply to every version number;
  • output of automated scanners submitted without analysis or demonstrated impact;
  • self-XSS, or issues that require a person to paste code into their own browser;
  • rate limiting, brute force or account enumeration without demonstrated impact;
  • social engineering of KLANG staff, customers or partners; physical attacks; volumetric or stress testing; any testing against live shows, customer production systems or third-party control networks without written permission;
  • exercising documented KLANG control interfaces within their documented purpose, including commands that affect audio, where the only impact is the documented effect of the command. Bypassing an implemented access control is in scope. Robustness failures are in scope: please report crashes, hangs, reboots, memory corruption or failure to recover caused by malformed, unexpected or out-of-sequence input, tested only on equipment and networks you own or are explicitly authorised to test;
  • vulnerabilities in third-party services that KLANG does not operate — please report those to the operator.

If you believe an item in this list does have real impact on a KLANG product, tell us why and we will look at it. The list exists to keep our security mailbox usable for the reports that matter, not to avoid inconvenient ones.

Recognition, and no bounty

KLANG does not operate a bug bounty programme and does not pay for vulnerability reports. We say so plainly so that nobody invests time expecting otherwise.

What we do offer: a person replies to every report that falls within this policy, tells you what we found and what we did about it, and will credit you by name in any advisory we publish if you would like us to. We do not send automated acknowledgements.

Security updates and advisories

Published advisories and security updates are available at https://www.klang.com/software. For urgent security matters, contact security@klang.com; do not use ordinary product-support channels.

Privacy

When submitting a security vulnerability report, please provide only the information necessary for us to understand, assess and reproduce the reported issue. Please avoid including unnecessary personal data, sensitive information or data relating to third parties. Any personal data included in your report will be processed in accordance with our Privacy Policy and applicable data protection laws.

We process report information only to investigate, remediate and communicate about the reported issue. See https://www.klang.com/privacy-policy for details.