Security

Security & Responsible Disclosure

Operator:
Science Communications Worldwide e.V. (Science Communications Worldwide – Verein zur weltweiten Verbreitung wissenschaftlicher Kommunikation)
Last updated:
3 September 2026
Version:
2.1 — supersedes the revision dated 25 August 2026
Machine-readable:
/.well-known/security.txt

In short

Security reports are welcome. Email info@world-wide.org with reproduction steps, give us reasonable time to fix the issue before publishing, don’t access other people’s data, and don’t disrupt the service. Good-faith research that follows these rules will not be met with legal action from us.

How we protect the platform

We apply technical and organisational measures appropriate to the risks of operating a public research platform (Article 32 GDPR), including:

  • encryption in transit (HTTPS/TLS) across the entire service;
  • passwordless authentication — sign-in via identity providers and passkeys, with optional two-factor authentication and self-service session revocation;
  • least-privilege access to production systems, with security-relevant actions written to an append-only audit trail;
  • uploaded files are isolated and malware-scanned before publication or delivery;
  • perimeter filtering, rate limiting, and abuse detection on all public endpoints;
  • pseudonymisation of network identifiers in telemetry — raw IP addresses are not written to our database;
  • layered browser protections (content-security policy, security headers, forgery protection);
  • automated backups and tested recovery procedures.

No system is perfectly secure. We prefer to hear about weaknesses from researchers before attackers find them — that is what the rest of this page is for.

Reporting a vulnerability

Report suspected vulnerabilities to info@world-wide.org with “Security” in the subject line. A useful report includes:

  • the affected URL, endpoint, or component;
  • steps to reproduce, with a proof of concept where possible;
  • the impact you believe the issue has;
  • your contact details for follow-up (anonymous reports are accepted).

Please do not include other people’s personal data in a report beyond the minimum needed to demonstrate the issue. We aim to acknowledge reports within 5 business days and to keep you informed while we investigate and remediate.

Rules of engagement

  • do not degrade or disrupt the service — no denial-of-service, no resource exhaustion, no destructive testing;
  • do not access, modify, or exfiltrate data belonging to others; if a flaw exposes such data, stop at the first evidence and report it;
  • use your own test accounts wherever possible;
  • no social engineering, phishing, or physical attacks against the association, its members, or its users;
  • keep automated scanning to a rate that cannot affect service quality;
  • do not demand payment for withholding a finding.

Coordinated disclosure

Give us a reasonable period to remediate before any public disclosure — 90 days from acknowledgement is our default, and we will tell you if we need longer for a structurally difficult fix or if we finish early. We are happy to credit reporters who want to be named once a fix has shipped; we equally respect anonymity.

Good-faith research

We will not initiate legal action against researchers for security research conducted in good faith that respects the rules on this page. This commitment covers our own platform only — we cannot authorise testing of third-party services the platform uses (identity providers, map or video providers, infrastructure operators); their own policies apply.

Scope

In scope: world-wide.org and its APIs. Out of scope: vulnerabilities in third-party services we embed or depend on; findings that require physically compromised devices; reports that a public page is public; missing hardening flags without demonstrated impact; and the behaviour of intentionally public resources such as our open content listings.

If a breach happens

If a security incident results in a personal-data breach, we assess it without undue delay and notify the Austrian supervisory authority and affected people where Articles 33 and 34 GDPR require it. What we log, how long we keep it, and how deletion works are described in the Data Retention & Deletion Policy and the Privacy Notice.

Contact

For legal, privacy, and policy inquiries, email info@world-wide.org.

We do not currently claim certification under ISO/IEC 27001, SOC 2, NIS2 frameworks, or similar schemes, and this page makes no such representation. It describes the practices we actually operate.

We use essential cookies to run the site. Analytics cookies are optional and help us improve World Wide. Learn more.

Security & Responsible Disclosure | World Wide - World Wide