Report a security concern
Security reports help us protect players, families and cricket organisations. We welcome good-faith reports and will handle them carefully.
Policy version 1.0 ยท 8 August 2026How to contact us
Email [email protected] with the subject Security report. Do not include real children's data, identity documents, passwords, private video or access tokens in the first message. We will arrange a safer way to share sensitive evidence if needed.
What to include
- the affected page, function or service;
- clear reproduction steps using test or fictional data;
- the likely impact and who could be affected;
- screenshots or minimal evidence with personal data removed;
- how you would prefer us to contact and credit you.
Good-faith research
Please stop as soon as you have enough evidence to report the issue. Do not access, change, download, retain or share another person's information. Do not upload malware, use social engineering, disrupt the service, weaken safeguarding controls, attempt denial of service, or test third-party services without their permission.
Use your own account and fictional test data. If you unexpectedly encounter personal data, stop, tell us, and delete any local copy after we confirm it is no longer needed for the report.
What you can expect
- We aim to acknowledge a report within three working days.
- We will triage it according to risk, with child safety and unauthorised data access treated as the highest priority.
- We will keep you updated when it is safe and appropriate to do so.
- We will coordinate disclosure and ask that you do not publish details before a fix or agreed disclosure date.
- We will not pursue legal action against good-faith research that follows this policy, though we cannot authorise testing of systems owned by other organisations.
Incidents involving a child
If the issue may place a child at immediate risk, say so clearly at the top of the message. For an immediate danger or crime in progress, contact the emergency services first. Our safeguarding page explains the separate safeguarding route.
Our security approach
The Player Vault uses privacy and security by design: private child records, server-side authorisation, row-level database controls, private media storage, verified and scoped adult access, access logging, minimal data sharing and fail-closed release gates. Our programme is aligned to ISO/IEC 27001:2022 principles and uses the UK Government Software Security and Cyber Governance Codes of Practice as baselines.
We are not currently ISO/IEC 27001 certified, and these statements are not an ICO approval or guarantee that no vulnerability exists. We publish factual controls, test them and keep outstanding launch risks documented.
Security updates and support
We provide security fixes for the hosted service while it is offered. Before a planned end of support for a paid or private service, we will give customers at least 12 months' notice and provide an export and deletion route. An urgent security, safeguarding or legal issue may require us to restrict or withdraw an affected feature sooner; if that happens, we will explain the protective action and the safest available route for your information.