Wandercraft
Healthcare
Home
Walking in Everyday Life
Meet Eve
Clinic
Gait Training in Rehabilitation
Discover Atalante X
Clinical Resources
Evidence, Studies, and Guides
Find a walking center
Try Eve or Atalante X near you
Industrial
Industry
Factory work
Deploy Calvin-40
NewsAbout Us
Request a demoEN

Legal Notices

Overview

This website is owned by Wandercraft, a simplified joint-stock company (Société par Actions Simplifiée) with a share capital of €82,288.40, whose registered office is located at 88 rue de Rivoli, 75004 PARIS (France), registered with the Versailles Trade and Companies Register (RCS Versailles) under SIRET number 788 627 198 000 21, and whose intra-Community VAT number is FR02788627198.

Wandercraft's Marketing and Communications Department is responsible for monitoring the site and is located at 88 rue de Rivoli, Paris.

Phone number (France): 01 79 35 09 49

U.S. phone number: 646-448-4787

Email: contact@wandercraft.health

Website Hosting

The website www.wandercraft.eu is hosted by Webflow, Inc., whose headquarters are located at 398 11th Street, 2nd Floor, San Francisco, CA 94103

Email: contact@webflow.com

Complaints

If you have a complaint about the content of the site or your experience with our products, please send an email to contact@wandercraft.health

Photo credits

Photos: Wandercraft

Videos: Wandercraft

Common Vulnerability Disclosure Policy

Updated May 2026

Wandercraft recognizes the important role that security researchers—whether individuals or organizations—play in helping to promote secure design practices and security risk mitigation, both within the medical device industry specifically and across the healthcare ecosystem. This policy is intended to provide security researchers with clear guidelines for conducting vulnerability discovery activities and to outline our preferences regarding how to report discovered vulnerabilities to us.

This policy describes which systems and types of research are covered by this policy, how to submit vulnerability reports to us, and how long we ask security researchers to wait before publicly disclosing vulnerabilities.

We encourage you to contact us to report potential vulnerabilities in our systems.

Purpose

The purpose of the Wandercraft Coordinated Vulnerability Disclosure Program is to coordinate the investigation and disclosure of potential new vulnerabilities in Wandercraft products. The shared goal of security researchers and Wandercraft should always be to reduce risk, while giving due consideration to the entire operating environment affected by any discovered vulnerability.

Scope

This Coordinated Vulnerability Disclosure Statement applies to all commercially available Wandercraft products, including associated apps (“Wandercraft Products”).

This process is intended for reporting potential new vulnerabilities in Wandercraft Products. Vulnerabilities in operating systems and other third-party components should not be reported through this process.

Although we develop and maintain other systems and services accessible via the Internet, we ask that active research and testing be conducted only on the systems and services covered by the scope of this document. If there is a particular system not included in the scope that you believe warrants testing, please contact us to discuss it first. We will expand the scope of this policy over time.

Reporting Prerequisites

Security researchers must comply with the following prerequisites throughout the research and disclosure process, including initial research and testing:

  • Comply with all applicable laws and regulations in your location and in the location where the Wandercraft Product is located;
  • Do not use a vulnerability to take disproportionate action, such as exploiting a vulnerability for any purpose other than to prove its existence, collecting more data than is minimally necessary to substantiate the vulnerability, altering or removing sensitive data from the product, or creating a backdoor within the product or otherwise introducing further vulnerabilities into it for subsequent use;
  • Do not conduct research or testing on systems where there is any risk of harm to patients;
  • Do not test products or network infrastructure in clinical settings or other active environments where Wandercraft Products are being used for any type of patient diagnosis, treatment, care, or monitoring, or could inadvertently be used in this way;
  • Any Wandercraft product intended for subsequent use in a clinical setting should be restored to its original condition once testing is complete. Contact Wandercraft for service assistance;
  • Be sure to obtain written permission from the owner of the Wandercraft Product before conducting any testing to ensure that the scope is clear.
  • Do not disclose details of the vulnerability to the public until the timeframe mutually agreed upon with Wandercraft has expired;
  • Do not operate outside the scope described in this document; and
  • Please provide us with details of any communications to regulatory agencies or other third parties regarding any discovered vulnerability, without delay.

Once you have determined that a vulnerability exists or have encountered any sensitive data (including personally identifiable information, protected health information, financial information, intellectual property, proprietary information, or trade secrets of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else.

Test method

The following test methods are not permitted:

  • Network denial-of-service (DoS or DDoS) tests or other tests that impair access to or damage a system or data
  • Physical testing (e.g., office access, open doors, tailgating), social engineering (e.g., phishing, vishing, smishing), or any other non-technical vulnerability testing

Reporting a Vulnerability

To report a potential new vulnerability to Wandercraft’s Product Security Team, please send an email to (cvd@wandercraft.health). Please use our PGP key or other suitable encryption tools to protect any sensitive information. Please do not include sensitive data (e.g., identifiable patient data, protected health information) in the body of the email or in any attachments (e.g., screenshots, images, or log files).

Information submitted under this policy will be used solely for defensive purposes—to mitigate or remediate vulnerabilities.

This CVD email address should not be used for inquiries regarding vulnerabilities that have already been disclosed or vulnerabilities in third-party components (not within the Wandercraft Product). Information regarding previously disclosed vulnerabilities can be requested by contacting Wandercraft.

What we ask of you

To help us triage and prioritize submissions, we recommend that your reports:

  • Describe the location where the vulnerability was discovered and the potential impact of its exploitation.
Wandercraft
Come visit us at our walk-in centers
Healthcare
Eve for home useAtalante X for RehabilitationClinical ResourcesFind a walking center
Industrial
Calvin-40
Company
About UsCareersNews
Legal
Privacy PolicyLegal NoticeTerms of ServiceCookie Policy
Stay in touch
Sign up for our newsletterRequest our press kit
InstagramFacebookLinkedInTikTokYouTubeX
Wandercraft
©2026 Wandercraft. All rights reserved.