Security
Security & Responsible Disclosure
- Operator:
- Science Communications Worldwide (Science Communications Worldwide - Verein zur weltweiten Verbreitung wissenschaftlicher Kommunikation)
- Last updated:
- 21 September 2026
- Effective:
- 21 September 2026
- Version:
- 2.4 — supersedes the revision dated 5 September 2026
- Machine-readable:
- /.well-known/security.txt
In short
How we protect the platform
We apply technical and organisational measures appropriate to the risks of operating a public research platform (Article 32 GDPR), including:
- HTTPS for public connections and certificate-verified TLS for database connections;
- passwordless authentication — sign-in via identity providers and passkeys, with optional two-factor authentication and self-service session revocation;
- least-privilege access to production systems, with security-relevant actions written to an append-only audit trail;
- uploaded files are isolated and malware-scanned before publication or delivery;
- perimeter filtering, rate limiting, and abuse detection on all public endpoints;
- pseudonymisation of network identifiers in telemetry — raw IP addresses are not written to our database;
- layered browser protections (content-security policy, security headers, forgery protection);
- automated backups and tested recovery procedures.
No system is perfectly secure. We prefer to hear about weaknesses from researchers before attackers find them — that is what the rest of this page is for.
Reporting a vulnerability
Report suspected vulnerabilities to info@world-wide.org with “Security” in the subject line. A useful report includes:
- the affected URL, endpoint, or component;
- steps to reproduce, with a proof of concept where possible;
- the impact you believe the issue has;
- your contact details for follow-up (anonymous reports are accepted).
Please do not include other people’s personal data in a report beyond the minimum needed to demonstrate the issue. We aim to acknowledge reports within 5 business days and to keep you informed while we investigate and remediate.
Rules of engagement
- do not degrade or disrupt the service — no denial-of-service, no resource exhaustion, no destructive testing;
- do not access, modify, or exfiltrate data belonging to others; if a flaw exposes such data, stop at the first evidence and report it;
- use your own test accounts wherever possible;
- no social engineering, phishing, or physical attacks against the association, its members, or its users;
- keep automated scanning to a rate that cannot affect service quality;
- do not demand payment for withholding a finding.
Coordinated disclosure
Give us a reasonable period to remediate before any public disclosure — 90 days from acknowledgement is our default, and we will tell you if we need longer for a structurally difficult fix or if we finish early. We are happy to credit reporters who want to be named once a fix has shipped; we equally respect anonymity.
Good-faith research
For World Wide systems that we control, we consider research conducted in good faith within this page’s scope and rules to be authorised. We will not pursue civil action, make a criminal referral, or support a claim based solely on that compliant activity. If you accidentally reach another person’s data, stop, retain no more than the minimum evidence needed for the report, and notify us promptly; continued access is outside this authorisation. This is not a promise of payment, immunity from generally applicable law, or permission to violate anyone else’s rights.
This commitment covers our own platform only. We cannot authorise testing of third-party services the platform uses (identity providers, map or media providers, infrastructure operators), and we cannot bind law-enforcement agencies or third parties; their own rules and legal powers apply. If a third party questions activity that we verify as compliant with this policy, we may confirm that it was authorised for our systems.
Scope
In scope: world-wide.org and its APIs. Out of scope: vulnerabilities in third-party services we embed or depend on; findings that require physically compromised devices; reports that a public page is public; missing hardening flags without demonstrated impact; and the behaviour of intentionally public resources such as our open content listings.
If a breach happens
If a security incident results in a personal-data breach, we assess it without undue delay and notify the Austrian supervisory authority and affected people where Articles 33 and 34 GDPR require it. What we log, how long we keep it, and how deletion works are described in the Data Retention & Deletion Policy and the Privacy Notice.
Contact
For legal, privacy, and policy inquiries, email info@world-wide.org.