Industries
Industries

We know your challenges

icon-woodwing-agencies

Agencies

Optimized workflow, improved collaboration, and brand consistency

icon-woodwing-finance

Finance

Modern document and quality management helps you manage risks and improve processes

icon-woodwing-museum

Museums

Preserve your collection with software designed for managing and sharing cultural assets

icon-woodwing-healthcare

Healthcare

Always access the latest version of each process, protocol, guideline, or agreement

icon-logo-woodwing-housing-corporations

Housing Associations

Document management from context, always up-to-date, complete and accurate documents

icon-woodwing-manufacturing

Manufacturing

Reduce costs by increasing the quality and improving compliance

icon-woodwing-publishing

Publishing

Efficient content creation, collaboration, and multichannel publishing

icon-woodwing-retail-ecommerce

Retail & eCommerce

Streamlined catalog and marketing content production for faster time-to-market

icon-woodwing-pension-fund-

Pension Funds

Manage large quantities of sensitive pension data and keep it safe and accessible


Featured content piece

Bauer Media Group

How Bauer unified editorial workflows and improved collaboration across Germany, the UK, and Poland.

Read this case
Solutions
Solutions

Content Orchestration

icon-woodwing-content-creation

Content Creation

Collaborate and create high-quality channel-neutral content

icon-woodwing-dam

Digital Asset Management

Manage and distribute digital assets for streamlined content

icon-woodwing-multichannel-publishing

Multichannel Publishing

Maximize reach with seamless multi-channel content publishing

icon-woodwing-content-orchestration

Content Orchestration

Managing content at scale has never been easier or more profitable


Operational Excellence

icon-logo-woodwing-document-management

Document Management

Centralize and control your documents, ensuring secure access

icon-woodwing-information-management

Information Management

Become more agile, reduce risks and benefit from available data

icon-woodwing-knowledge-management

Knowledge Management

Bring knowledge and people together to work on quality

icon-woodwing-process-management

Process Management

Describe, organize, and make processes accessible to everyone

icon-logo-woodwing-quality-management

Quality Management

Collectively ensure that you do the right things in the right way

icon-woodwing-risk-management

Risk Management

Gain insight and control over every aspect of risk management


Services

icon-woodwing-customer-strategy

Customer Strategy

Shape new business models with strategic guidance

icon-woodwing-professional-services

Professional Services

Accelerate digital transformation with expert help for lasting results

icon-woodwing-integrations

WoodWing Connect

Integrate WoodWing seamlessly into your existing tech stack

icon-woodwing-cloud

WoodWing Cloud

Experience stress-free hosting, software maintenance, and more


FEATURED CONTENT

Integrations Marketplace

Explore our Integrations Marketplace and find the right apps and solutions to boost the interconnectivity and productivity of your IT environment.

Explore
Products
Products

Take charge of your content

WoodWing Studio

Solution for streamlined content creation and multichannel publishing

Assets Logo (base)

System to efficiently store and manage large amounts of digital files

WoodWing Scienta

Software to make use of your organization's knowledge and collaborate on quality

WoodWing Xtendis

Secure and certified digital archiving and document management system

Connect Logo (base)

Powerful integration suite for seamless connectivity and automation

WoodWing Smart Styles

Efficient plugin for enhanced Adobe InDesign design workflows

Inspiration
Inspiration

Learning centre

icon-woodwing-blogpost

Blog posts

Explore our extensive blog section

icon-woodwing-events-and-webinars

Events & Webinars

Nothing beats personal contact; attend an event or webinar

icon-woodwing-ebooks-whitepapers

eBooks & Whitepapers

Dive into into one of our free and informative downloads

icon-woodwing-success-stories

Success Stories

Discover how organizations achieve success with WoodWing solutions

icon-logo-woodwing-videos

Videos

A video can be worth more than a thousand words. Give it a try!


Latest articles

Why publishers need a multi-revenue strategy in the AI era

Why publishers need a multi-revenue strategy in the AI era

Why delaying your ISO 9001:2026 transition until 2029 is a costly mistake

Why delaying your ISO 9001:2026 transition until 2029 is a costly mistake

Four benefits of content orchestration for supermarkets

Four benefits of content orchestration for supermarkets

View all blog articles

Featured content piece

Hearst magazines

How Hearst Magazines transformed its multi-brand publishing operations, uniting global editorial teams and workflows with WoodWing Studio and Assets.

Read this case
Company
Company

About us

icon-woodwing-about-woodwing

About WoodWing

Discover our company's vision, mission, and innovative solutions

icon-logo-woodwing-esg

ESG policy

See how WoodWing actively approaches ESG goals

icon-woodwing-ai-innovation

AI innovations

Learn how we use AI to make your business smarter and more efficient

icon-woodwing-management-team

Management team

Meet the leaders driving WoodWing's success and growth

icon-woodwing-contact

Contact

Reach out to us for inquiries, support, and collaboration


Jobs & news

icon-woodwing-job-opportunities

Job opportunities

Explore exciting career opportunities and join our team

icon-woodwing-press-release

Press releases & news

Stay updated with our latest company news and announcements

icon-woodwing-events-and-webinars

Events & Webinars

Nothing beats personal contact; attend an event or webinar


Partners

icon-woodwing-partners

Partners

Explore our partners for local support and expanded capabilities

icon-woodwing-become-a-partner

Become a partner

Join our global partner network and grow with us


AI-driven technologies

AI innovations

WoodWing invests heavily in AI-driven innovations that we deploy to help companies automate their workflows, ensure quality, and scale faster.

How we use AI
English
Select language
Support Support Support Contact sales Contact sales Contact sales Login Login Login
Login

Choose a product

icon-woodwing-login-scienta

WoodWing Scienta

icon-woodwing-login-swivle

WoodWing Swivle


Contact us
Search Support Support Support Contact sales Contact sales Contact sales Login Login Login

Choose a product

icon-woodwing-login-scienta

WoodWing Scienta

icon-woodwing-login-swivle

WoodWing Swivle

English English

Nederlands

Industries

We know your challenges

icon-woodwing-agencies

Agencies

Optimized workflow, improved collaboration, and brand consistency

icon-woodwing-finance

Finance

Modern document and quality management helps you manage risks and improve processes

icon-woodwing-museum

Museums

Preserve your collection with software designed for managing and sharing cultural assets

icon-woodwing-healthcare

Healthcare

Always access the latest version of each process, protocol, guideline, or agreement

icon-logo-woodwing-housing-corporations

Housing Associations

Document management from context, always up-to-date, complete and accurate documents

icon-woodwing-manufacturing

Manufacturing

Reduce costs by increasing the quality and improving compliance

icon-woodwing-publishing

Publishing

Efficient content creation, collaboration, and multichannel publishing

icon-woodwing-retail-ecommerce

Retail & eCommerce

Streamlined catalog and marketing content production for faster time-to-market

icon-woodwing-pension-fund-

Pension Funds

Manage large quantities of sensitive pension data and keep it safe and accessible

Featured content piece

Bauer Media Group

How Bauer unified editorial workflows and improved collaboration across Germany, the UK, and Poland.

Read this case
Solutions

Content Orchestration

icon-woodwing-content-creation

Content Creation

Collaborate and create high-quality channel-neutral content

icon-woodwing-dam

Digital Asset Management

Manage and distribute digital assets for streamlined content

icon-woodwing-multichannel-publishing

Multichannel Publishing

Maximize reach with seamless multi-channel content publishing

icon-woodwing-content-orchestration

Content Orchestration

Managing content at scale has never been easier or more profitable


Operational Excellence

icon-logo-woodwing-document-management

Document Management

Centralize and control your documents, ensuring secure access

icon-woodwing-information-management

Information Management

Become more agile, reduce risks and benefit from available data

icon-woodwing-knowledge-management

Knowledge Management

Bring knowledge and people together to work on quality

icon-woodwing-process-management

Process Management

Describe, organize, and make processes accessible to everyone

icon-logo-woodwing-quality-management

Quality Management

Collectively ensure that you do the right things in the right way

icon-woodwing-risk-management

Risk Management

Gain insight and control over every aspect of risk management


Services

icon-woodwing-customer-strategy

Customer Strategy

Shape new business models with strategic guidance

icon-woodwing-professional-services

Professional Services

Accelerate digital transformation with expert help for lasting results

icon-woodwing-integrations

WoodWing Connect

Integrate WoodWing seamlessly into your existing tech stack

icon-woodwing-cloud

WoodWing Cloud

Experience stress-free hosting, software maintenance, and more


FEATURED CONTENT

Integrations Marketplace

Explore our Integrations Marketplace and find the right apps and solutions to boost the interconnectivity and productivity of your IT environment.

Explore
Products

Take charge of your content

WoodWing Studio

Solution for streamlined content creation and multichannel publishing

WoodWing Studio

Collaborative content creation and multichannel publishing solution that simplifies workflows and streamlines production processes.

Assets Logo (base)

System to efficiently store and manage large amounts of digital files

WoodWing Assets

Digital asset management solution that streamlines your creative workflow and simplifies collaboration among team members by centralizing your files.

WoodWing Scienta

Software to make use of your organization's knowledge and collaborate on quality

WoodWing Scienta

Quality management platform for regulated industries that simplifies compliance, knowledge sharing, and collaboration.

WoodWing Xtendis

Secure and certified digital archiving and document management system

WoodWing Xtendis

Digital archiving and document management system that allows organizations to store, manage, and access their digital assets securely.

Connect Logo (base)

Powerful integration suite for seamless connectivity and automation

WoodWing Connect

Powerful integration suite, including APIs, webhooks, plugins, and the best-in-class iPaaS solution (powered by Workato).

WoodWing Smart Styles

Efficient plugin for enhanced Adobe InDesign design workflows

WoodWing Smart Styles

Plugin for Adobe InDesign that streamlines design workflows by allowing designers to apply predefined styles quickly.

Inspiration

Learning centre

icon-woodwing-blogpost

Blog posts

Explore our extensive blog section

icon-woodwing-events-and-webinars

Events & Webinars

Nothing beats personal contact; attend an event or webinar

icon-woodwing-ebooks-whitepapers

eBooks & Whitepapers

Dive into into one of our free and informative downloads

icon-woodwing-success-stories

Success Stories

Discover how organizations achieve success with WoodWing solutions

icon-logo-woodwing-videos

Videos

A video can be worth more than a thousand words. Give it a try!


Latest articles

Why publishers need a multi-revenue strategy in the AI era

Why publishers need a multi-revenue strategy in the AI era

Why delaying your ISO 9001:2026 transition until 2029 is a costly mistake

Why delaying your ISO 9001:2026 transition until 2029 is a costly mistake

Four benefits of content orchestration for supermarkets

Four benefits of content orchestration for supermarkets

View all blog articles

Featured content piece

Hearst magazines

How Hearst Magazines transformed its multi-brand publishing operations, uniting global editorial teams and workflows with WoodWing Studio and Assets.

Read this case
Company

About us

icon-woodwing-about-woodwing

About WoodWing

Discover our company's vision, mission, and innovative solutions

icon-logo-woodwing-esg

ESG policy

See how WoodWing actively approaches ESG goals

icon-woodwing-ai-innovation

AI innovations

Learn how we use AI to make your business smarter and more efficient

icon-woodwing-management-team

Management team

Meet the leaders driving WoodWing's success and growth

icon-woodwing-contact

Contact

Reach out to us for inquiries, support, and collaboration


Jobs & news

icon-woodwing-job-opportunities

Job opportunities

Explore exciting career opportunities and join our team

icon-woodwing-press-release

Press releases & news

Stay updated with our latest company news and announcements

icon-woodwing-events-and-webinars

Events & Webinars

Nothing beats personal contact; attend an event or webinar


Partners

icon-woodwing-partners

Partners

Explore our partners for local support and expanded capabilities

icon-woodwing-become-a-partner

Become a partner

Join our global partner network and grow with us


AI-driven technologies

AI innovations

WoodWing invests heavily in AI-driven innovations that we deploy to help companies automate their workflows, ensure quality, and scale faster.

How we use AI
Contact us
Home Legal

Coordinated Vulnerability Disclosure (CVD)

Help us keep our products secure

At WoodWing, we take the security of our products, services and customer data seriously.

Despite the care we take to secure our systems, vulnerabilities may still exist. If you discover a potential security vulnerability in one of our products or services, we would like to hear from you. This Coordinated Vulnerability Disclosure Policy (hereafter “policy”) explains how you can report a vulnerability to us, what we expect from you, what you can expect from us, and which products and environments fall within the scope of this policy.

This policy does not constitute a contract, offer or promise. By submitting a vulnerability report, you acknowledge that you have read and understood this policy, but your submission does not create any contractual relationship with WoodWing.

We appreciate the efforts of security researchers and others who help us identify potential vulnerabilities in our products and improve the security of our products in a responsible and coordinated way.

Scope of this policy

This policy applies to security vulnerabilities in the following products and environments:

Product Environment in scope
Assets 6 Your own environment
Assets 10 Your own environment
Scienta https://cvd.myscienta.com
Studio Your own environment
Xtendis Your own environment

For Assets 6, Assets 10 and Studio and Xtendis, testing must only be performed in an environment that you own, operate or are explicitly authorised to use. You must not perform testing on customer environments, production environments or environments belonging to third parties.

For Scienta, testing must only be performed against the dedicated CVD environments listed above, unless we have given prior written permission.

Any system, service, domain, customer environment, production environment, API or third-party service not explicitly listed above is outside the scope of this policy. If you are unsure whether something is in scope, please contact us before testing.

Out of scope

The following activities and findings are out of scope and should not be performed or reported under this policy:

  • Denial-of-service attacks, load testing or stress testing

  • Social engineering, phishing or impersonation of our employees, customers, partners or suppliers

  • Physical attacks against our offices, data centres or infrastructure

  • Attempts to access, modify, delete, copy or exfiltrate data that does not belong to you

  • Testing in customer environments or third-party environments

  • Testing in production environments, unless the environment is explicitly listed as in scope

  • Malware, ransomware, persistence mechanisms or destructive testing

  • Brute force attacks, credential stuffing or automated high-volume login attempts

  • Spam or mass registration of accounts

  • Attacks against third-party services, suppliers or integrations

  • Reports based solely on missing security headers without a demonstrable security impact

  • Reports based solely on automated scanner output without validation

  • Clickjacking or CSRF reports without a realistic security impact

  • Publicly known vulnerable libraries without evidence that they are exploitable in our products or environments

  • Disclosure of version numbers without a demonstrable vulnerability

  • Best-practice recommendations without a concrete security impact

This policy is intended for reporting genuine security vulnerabilities. General questions, support requests, privacy requests or complaints should be submitted through our regular support or contact channels.

What we ask from you

When investigating and reporting a vulnerability, we ask you to act responsibly and in good faith.

Please:

  • Report the vulnerability to us as soon as possible after discovery.

  • Provide enough information for us to understand and reproduce the issue.

  • Limit your testing to what is strictly necessary to demonstrate the vulnerability.

  • Only test products and environments that are explicitly in scope.

  • Use your own environment where this policy requires you to do so.

  • Avoid any action that could affect the availability, integrity or confidentiality of our systems or data.

  • Do not access, copy, modify, delete, download, store or disclose any data that does not belong to you, including personal data or customer data.

  • Do not use the vulnerability to gain further access than necessary to demonstrate the issue.

  • Do not share the vulnerability with any third party, or publish any information about the vulnerability, at any time without our prior written consent.

  • Allow us such time as we, in our sole discretion, consider necessary to investigate and resolve the vulnerability.

  • Comply with all applicable laws and regulations.

If you accidentally access data that does not belong to you, stop immediately, securely delete any copies, and notify us without delay.

What you should include in your report

To help us assess your report quickly and accurately, please include as much relevant information as possible:

  • A clear description of the vulnerability

  • The affected product

  • The affected environment, URL, API endpoint or version

  • Step-by-step instructions to reproduce the issue

  • The potential impact of the vulnerability

  • Any prerequisites, user roles or permissions required

  • Screenshots, logs or a proof of concept, where appropriate

  • The date and time of your testing Your contact details

  • Whether you would like to be considered for a reward

Please do not include sensitive personal data, customer data, confidential business information or large data extracts in your report. If such information is necessary to explain the issue, please describe it without including the actual data.

How to report a vulnerability

Please use this form to report a vulnerability

What you can expect from us

If you report a vulnerability in accordance with this policy, we will:

  • Acknowledge receipt of your report within 3 business days.

  • Perform an initial assessment of the report.

  • Keep you reasonably informed about the status of the investigation where we consider it appropriate to do so.

  • Treat your report confidentially.

  • Work to remediate confirmed vulnerabilities based on severity, impact and business risk.

  • Not pursue legal action against you for good-faith research conducted in accordance with this policy.

  • Consider your report for a discretionary reward if we determine, in our sole discretion, that it is valid, relevant and helpful.

We will endeavour to resolve confirmed vulnerabilities in a timely manner, taking into account complexity, severity, affected products, customer impact and required testing. Indicative resolution timeframes will be communicated on a case-by-case basis. This paragraph does not create any binding obligation as to timing

Rewards

We value high-quality vulnerability reports that help us improve the security of our products and services. We do not operate a formal bug bounty programme. Any rewards are discretionary tokens of appreciation, determined solely by WoodWing, and may be withdrawn or varied at any time. Nothing in this policy creates any legal entitlement to a reward.

Whether a report qualifies for a reward is determined at our sole discretion. We may consider factors such as:

  • The severity of the vulnerability

  • The quality and completeness of the report

  • The actual security impact

  • Whether the vulnerability was previously known to us

  • Whether the report falls within the scope of this policy

  • Whether the researcher complied with this policy

  • Whether the report enabled us to improve the security of our products or services

Only the first person to report a previously unknown vulnerability will normally be eligible for a reward. Duplicate reports, out-of-scope reports, reports without clear security impact, reports based only on automated scanner output, or reports that do not comply with this policy are normally not eligible for a reward.

Any reward, if offered, may consist of a monetary payment, recognition, or another form of appreciation, depending on the nature and quality of the report and at our sole discretion. Public acknowledgement is not guaranteed and will only be offered where we consider it appropriate and with your consent.

Public disclosure

We support coordinated disclosure. Vulnerabilities should not be publicly disclosed until we have had a reasonable opportunity to investigate and remediate the issue.

You shall not publicly disclose, share or publish details of the vulnerability without our prior written agreement. Unauthorised disclosure will be treated as a material breach of this policy, and any commitments we have made, including any consideration of reward or non-referral to law enforcement, will be void. If public disclosure is appropriate, we will coordinate the timing and content with you, which may include publication after the vulnerability has been resolved or mitigated.

Important notice regarding legal action

Where you comply with all requirements of this policy, we do not intend to pursue civil legal action against you or to refer your activities to law enforcement authorities. However, we expressly reserve the right to take any legal action we consider appropriate in our absolute discretion, including in circumstances where:

  • you have failed to comply with any requirement of this policy;

  • your conduct has caused or risked privacy violations, data loss, service disruption, damage to our systems or data, or harm to any third party;

  • you have exploited the vulnerability beyond what we, in our sole judgment, consider necessary to demonstrate it;

  • you have accessed, modified, deleted, copied, exfiltrated or disclosed any data, including data belonging to us, our customers or any third party;

  • you have tested any product, system or environment that is not explicitly listed as in scope in this policy;

  • you have failed to report the vulnerability to us promptly and confidentially; or

  • we otherwise consider, in our absolute discretion, that legal action is warranted.

No permission to access customer data

This policy does not give you permission to access customer data, personal data, confidential information or systems that are not explicitly in scope.

You must not test customer environments, third-party environments or production environments unless explicitly listed as in scope or unless we have given prior written permission.

If you encounter customer data, personal data or confidential information during your investigation, you must stop immediately, securely delete any copies, and report this to us. You must not save, copy, transfer, analyse or further access the data. Failure to comply may result in legal action.

Liability

To the maximum extent permitted by applicable law, WoodWing and its affiliates shall have no liability whatsoever to any party in connection with this policy or any security research conducted under this policy.

Changes to this policy

We may update or withdraw this policy at any time and for any reason, without prior notice. Your continued submission of vulnerability reports after any change constitutes your acceptance of the revised policy.

Version 8 - 18 aug 2026

divider-bottom-small-black-teal