Coordinated Vulnerability Disclosure (CVD)
Help us keep our products secure
At WoodWing, we take the security of our products, services and customer data seriously.
Despite the care we take to secure our systems, vulnerabilities may still exist. If you discover a potential security vulnerability in one of our products or services, we would like to hear from you. This Coordinated Vulnerability Disclosure Policy (hereafter “policy”) explains how you can report a vulnerability to us, what we expect from you, what you can expect from us, and which products and environments fall within the scope of this policy.
This policy does not constitute a contract, offer or promise. By submitting a vulnerability report, you acknowledge that you have read and understood this policy, but your submission does not create any contractual relationship with WoodWing.
We appreciate the efforts of security researchers and others who help us identify potential vulnerabilities in our products and improve the security of our products in a responsible and coordinated way.
Scope of this policy
This policy applies to security vulnerabilities in the following products and environments:
| Product | Environment in scope |
| Assets 6 | Your own environment |
| Assets 10 | Your own environment |
| Scienta | https://cvd.myscienta.com |
| Studio | Your own environment |
| Xtendis | Your own environment |
For Assets 6, Assets 10 and Studio and Xtendis, testing must only be performed in an environment that you own, operate or are explicitly authorised to use. You must not perform testing on customer environments, production environments or environments belonging to third parties.
For Scienta, testing must only be performed against the dedicated CVD environments listed above, unless we have given prior written permission.
Any system, service, domain, customer environment, production environment, API or third-party service not explicitly listed above is outside the scope of this policy. If you are unsure whether something is in scope, please contact us before testing.
Out of scope
The following activities and findings are out of scope and should not be performed or reported under this policy:
-
Denial-of-service attacks, load testing or stress testing
-
Social engineering, phishing or impersonation of our employees, customers, partners or suppliers
-
Physical attacks against our offices, data centres or infrastructure
-
Attempts to access, modify, delete, copy or exfiltrate data that does not belong to you
-
Testing in customer environments or third-party environments
-
Testing in production environments, unless the environment is explicitly listed as in scope
-
Malware, ransomware, persistence mechanisms or destructive testing
-
Brute force attacks, credential stuffing or automated high-volume login attempts
-
Spam or mass registration of accounts
-
Attacks against third-party services, suppliers or integrations
-
Reports based solely on missing security headers without a demonstrable security impact
-
Reports based solely on automated scanner output without validation
-
Clickjacking or CSRF reports without a realistic security impact
-
Publicly known vulnerable libraries without evidence that they are exploitable in our products or environments
-
Disclosure of version numbers without a demonstrable vulnerability
-
Best-practice recommendations without a concrete security impact
This policy is intended for reporting genuine security vulnerabilities. General questions, support requests, privacy requests or complaints should be submitted through our regular support or contact channels.
What we ask from you
When investigating and reporting a vulnerability, we ask you to act responsibly and in good faith.
Please:
-
Report the vulnerability to us as soon as possible after discovery.
-
Provide enough information for us to understand and reproduce the issue.
-
Limit your testing to what is strictly necessary to demonstrate the vulnerability.
-
Only test products and environments that are explicitly in scope.
-
Use your own environment where this policy requires you to do so.
-
Avoid any action that could affect the availability, integrity or confidentiality of our systems or data.
-
Do not access, copy, modify, delete, download, store or disclose any data that does not belong to you, including personal data or customer data.
-
Do not use the vulnerability to gain further access than necessary to demonstrate the issue.
-
Do not share the vulnerability with any third party, or publish any information about the vulnerability, at any time without our prior written consent.
-
Allow us such time as we, in our sole discretion, consider necessary to investigate and resolve the vulnerability.
-
Comply with all applicable laws and regulations.
If you accidentally access data that does not belong to you, stop immediately, securely delete any copies, and notify us without delay.
What you should include in your report
To help us assess your report quickly and accurately, please include as much relevant information as possible:
-
A clear description of the vulnerability
-
The affected product
-
The affected environment, URL, API endpoint or version
-
Step-by-step instructions to reproduce the issue
-
The potential impact of the vulnerability
-
Any prerequisites, user roles or permissions required
-
Screenshots, logs or a proof of concept, where appropriate
-
The date and time of your testing Your contact details
-
Whether you would like to be considered for a reward
Please do not include sensitive personal data, customer data, confidential business information or large data extracts in your report. If such information is necessary to explain the issue, please describe it without including the actual data.
How to report a vulnerability
Please use this form to report a vulnerability
What you can expect from us
If you report a vulnerability in accordance with this policy, we will:
-
Acknowledge receipt of your report within 3 business days.
-
Perform an initial assessment of the report.
-
Keep you reasonably informed about the status of the investigation where we consider it appropriate to do so.
-
Treat your report confidentially.
-
Work to remediate confirmed vulnerabilities based on severity, impact and business risk.
-
Not pursue legal action against you for good-faith research conducted in accordance with this policy.
-
Consider your report for a discretionary reward if we determine, in our sole discretion, that it is valid, relevant and helpful.
We will endeavour to resolve confirmed vulnerabilities in a timely manner, taking into account complexity, severity, affected products, customer impact and required testing. Indicative resolution timeframes will be communicated on a case-by-case basis. This paragraph does not create any binding obligation as to timing
Rewards
We value high-quality vulnerability reports that help us improve the security of our products and services. We do not operate a formal bug bounty programme. Any rewards are discretionary tokens of appreciation, determined solely by WoodWing, and may be withdrawn or varied at any time. Nothing in this policy creates any legal entitlement to a reward.
Whether a report qualifies for a reward is determined at our sole discretion. We may consider factors such as:
-
The severity of the vulnerability
-
The quality and completeness of the report
-
The actual security impact
-
Whether the vulnerability was previously known to us
-
Whether the report falls within the scope of this policy
-
Whether the researcher complied with this policy
-
Whether the report enabled us to improve the security of our products or services
Only the first person to report a previously unknown vulnerability will normally be eligible for a reward. Duplicate reports, out-of-scope reports, reports without clear security impact, reports based only on automated scanner output, or reports that do not comply with this policy are normally not eligible for a reward.
Any reward, if offered, may consist of a monetary payment, recognition, or another form of appreciation, depending on the nature and quality of the report and at our sole discretion. Public acknowledgement is not guaranteed and will only be offered where we consider it appropriate and with your consent.
Public disclosure
We support coordinated disclosure. Vulnerabilities should not be publicly disclosed until we have had a reasonable opportunity to investigate and remediate the issue.
You shall not publicly disclose, share or publish details of the vulnerability without our prior written agreement. Unauthorised disclosure will be treated as a material breach of this policy, and any commitments we have made, including any consideration of reward or non-referral to law enforcement, will be void. If public disclosure is appropriate, we will coordinate the timing and content with you, which may include publication after the vulnerability has been resolved or mitigated.
Important notice regarding legal action
Where you comply with all requirements of this policy, we do not intend to pursue civil legal action against you or to refer your activities to law enforcement authorities. However, we expressly reserve the right to take any legal action we consider appropriate in our absolute discretion, including in circumstances where:
-
you have failed to comply with any requirement of this policy;
-
your conduct has caused or risked privacy violations, data loss, service disruption, damage to our systems or data, or harm to any third party;
-
you have exploited the vulnerability beyond what we, in our sole judgment, consider necessary to demonstrate it;
-
you have accessed, modified, deleted, copied, exfiltrated or disclosed any data, including data belonging to us, our customers or any third party;
-
you have tested any product, system or environment that is not explicitly listed as in scope in this policy;
-
you have failed to report the vulnerability to us promptly and confidentially; or
-
we otherwise consider, in our absolute discretion, that legal action is warranted.
No permission to access customer data
This policy does not give you permission to access customer data, personal data, confidential information or systems that are not explicitly in scope.
You must not test customer environments, third-party environments or production environments unless explicitly listed as in scope or unless we have given prior written permission.
If you encounter customer data, personal data or confidential information during your investigation, you must stop immediately, securely delete any copies, and report this to us. You must not save, copy, transfer, analyse or further access the data. Failure to comply may result in legal action.
Liability
To the maximum extent permitted by applicable law, WoodWing and its affiliates shall have no liability whatsoever to any party in connection with this policy or any security research conducted under this policy.
Changes to this policy
We may update or withdraw this policy at any time and for any reason, without prior notice. Your continued submission of vulnerability reports after any change constitutes your acceptance of the revised policy.
Version 8 - 18 aug 2026
Wij helpen je grip te krijgen op je content en informatie met onze oplossingen van wereldklasse.
Nieuwsbrief ontvangen?