Wandercraft
Health
Home
Going about daily life
Get to Know Eve
Clinic
Group Training in Rehabilitation
Discover the Atalante X
Clinical Resources
Evidence, Studies, and Guidelines
Find a Gang School Center
Test drive the Eve or Atalante X near you
Industry
Industry
Working in the factories
Using Calvin-40
NewsAbout Us
Request a DemoFROM

Legal Notices

Overview

This website is owned by Wandercraft, a simplified joint-stock company under French law (société par actions simplifiée) with a share capital of €82,288.40, headquartered at 88 rue de Rivoli, 75004 Paris (France), registered in the Versailles Trade and Companies Register (RCS), SIRET number 788 627 198 000 21, VAT identification number FR02788627198.

Wandercraft's Marketing and Communications Department is responsible for maintaining the website and is located at 88 rue de Rivoli in Paris.

Phone number (France): 01 79 35 09 49

Phone number in the U.S.: 646-448-4787

Email: contact@wandercraft.health

Website Hosting

The Website www.wandercraft.eu is hosted by Webflow, Inc., located at 398 11th Street, 2nd Floor, San Francisco, CA 94103

Email: contact@webflow.com

Complaints

If you have a complaint regarding the content of the website or your experience with our products, please send an email to contact@wandercraft.health

Image Credits

Photos: Wandercraft

Videos: Wandercraft

Guidelines for the Coordinated Disclosure of Vulnerabilities

As of: May 2026

Wandercraft recognizes the important role that security researchers—whether individuals or organizations—play in promoting secure design practices and mitigating security risks, both within the medical device industry specifically and within the healthcare ecosystem as a whole. This policy is intended to provide security researchers with clear guidelines for conducting vulnerability discovery activities and to communicate our preferences regarding how discovered vulnerabilities should be reported to us.

This policy describes which systems and types of research it covers, how to submit vulnerability reports to us, and how long we ask security researchers to wait before disclosing vulnerabilities publicly.

We encourage you to contact us to report potential vulnerabilities in our systems.

Purpose

The purpose of Wandercraft’s coordinated vulnerability disclosure program is to coordinate the investigation and disclosure of potential new vulnerabilities in Wandercraft products. The shared goal of security researchers and Wandercraft should always be risk mitigation, with due consideration given to the overall operational environment affected by a discovered vulnerability.

Scope of Application

This statement regarding the coordinated disclosure of vulnerabilities applies to all Wandercraft products available on the market, including the associated apps (“Wandercraft Products”).

This procedure should be used to report potential new vulnerabilities in Wandercraft products. Vulnerabilities in operating systems and other third-party components should not be reported through this procedure.

Although we develop and operate other systems and services accessible via the Internet, we ask that you conduct active research and testing only on the systems and services covered by the scope of this document. If you believe that a specific system outside the scope of this document should be tested, please contact us first to discuss this. We will expand the scope of this policy over time.

Requirements for Registration

Security researchers must comply with the following requirements throughout the entire research and disclosure process, including initial investigations and testing:

  • Comply with all applicable laws and regulations in your location and in the location where the Wandercraft product is located;
  • Do not use a vulnerability to take disproportionate actions, such as exploiting a vulnerability beyond proving its existence, collecting more data than is strictly necessary to demonstrate the vulnerability, modifying or removing sensitive product data, creating a backdoor in a product, or otherwise introducing additional vulnerabilities into a product for later use;
  • Do not conduct research or testing on systems that pose a risk of harm to patients;
  • Do not test any products or network infrastructures in clinical settings or other active environments where Wandercraft products are used—or could be used unintentionally—for the diagnosis, treatment, care, or monitoring of patients of any kind;
  • Any Wandercraft product that is subsequently to be used in a clinical setting must be restored to its original condition after testing is complete. Please contact Wandercraft for service support;
  • Before conducting any tests, obtain written permission from the owner of the Wandercraft product to ensure that the scope of the tests is clearly defined.
  • Do not publicly disclose details of vulnerabilities before the period mutually agreed upon with Wandercraft has expired;
  • Do not act outside the scope described in this document; and
  • Please promptly provide us with details of any communication with regulatory authorities or other third parties regarding discovered vulnerabilities.

As soon as you discover a vulnerability or come across sensitive data (including personal data, protected health information, financial data, intellectual property, confidential information, or trade secrets belonging to any party), you must stop your test, notify us immediately, and not disclose this data to anyone.

Test Methods

The following test methods are not permitted:

  • Network-based denial-of-service (DoS or DDoS) tests or other tests that interfere with or damage access to a system or data
  • Physical tests (e.g., access to offices, open doors, “tailgating”), social engineering (e.g., phishing, vishing, smishing), or other non-technical vulnerability tests

Reporting a Vulnerability

To report a potential new vulnerability to the Wandercraft Product Security Team, please send an email to (cvd@wandercraft.health). Please use our PGP key or other appropriate encryption tools to protect sensitive information. Please do not include any sensitive data (e.g., identifiable patient information or protected health information) in the body of the message or in attachments (e.g., screenshots, images, or log files).

The information provided under this policy will be used exclusively for defensive purposes—to mitigate or resolve vulnerabilities.

This CVD email address is not to be used for inquiries regarding vulnerabilities that have already been disclosed or vulnerabilities in third-party components (outside of Wandercraft products). Information regarding previously disclosed vulnerabilities can be requested from Wandercraft.

What We Ask of You

To help us review and prioritize submissions, we recommend that your reports:

  • Describe the location where the vulnerability was discovered, as well as the potential consequences of exploiting it.
Wandercraft
Come visit us at our gait training centers
Health
Eve for HomeAtalante X for RehabilitationClinical ResourcesFind a Gang School Center
Industry
Calvin-40
Company
About UsCareerNews
Legal Information
Privacy PolicyLegal NoticesTerms of UseCookie Policy
Stay in Touch
Subscribe to the newsletterRequest a press kit
InstagramFacebookLinkedInTikTokYouTubeX
Wandercraft
©2026 Wandercraft. All rights reserved.