Security at Woven
Your productions matter. So does protecting them.
Woven is designed for professional production, where unreleased content, creative IP and commercially sensitive information are part of the everyday workflow.
Security therefore isn’t an optional feature. It’s part of how we build and operate the platform.
We also believe enterprise customers deserve clarity about what protections are in place today — and what is still being developed.
Your content remains your content.
The productions, assets and creative material you bring into Woven remain yours.
Woven does not claim ownership of your production or creative IP.
Where Woven connects to third-party AI models, the handling of data may also be subject to the terms and policies of those providers. We work to give production teams clarity over the models and services being used within their workflows.
Customer productions, assets and prompts are never used to train Woven’s own models. Where a third-party model is used, we select providers whose enterprise terms exclude customer data from training by default, and we surface each model’s data policy inside the app before a generation runs.
Enterprise access and control.
Woven is designed to give organisations control over who can access their productions and how their teams work within the platform.
- Role-based permissions across organisation, workspace and project
- SSO via SAML 2.0 and OIDC, with enforced multi-factor authentication
- Workspace and project-level membership controls
- Audit logs covering access, generation and approval events
- Per-project credit caps and model allow-lists
- Session length and device revocation controls
Enterprise teams can also bring their own model keys where supported, allowing organisations to use their own commercial relationships with model providers within the Woven environment.
Your data.
We take the security of production data seriously.
- Encryption in transit
- TLS 1.3 on all connections
- Encryption at rest
- AES-256 across media and metadata
- Hosting
- AWS, London (eu-west-2)
- Backups
- Encrypted daily, 30-day retention
- Isolation
- Per-organisation logical separation
- Retention
- Configurable, with deletion on request
Our Privacy Policy explains how personal data is processed, and enterprise customers can request appropriate data-processing documentation as part of their procurement process.
Third-party AI models.
Woven is model-neutral and can connect production teams with a range of third-party generative AI providers.
When a production uses one of these models, relevant data may need to be processed by that provider in order to perform the requested generation.
For enterprise customers, we can discuss model selection, Bring Your Own Key arrangements and the data policies associated with the models used in your workflow.
Security standards and certification.
We believe in being clear about where we are.
Woven is not currently SOC 2 or ISO 27001 certified.
As we scale our enterprise offering, we are developing our security and compliance programme around the requirements of professional studios, broadcasters, agencies and production companies.
We would rather be transparent about our current position than imply certifications or controls we don’t yet have.
Security questions?
If you’re evaluating Woven for your organisation, we’re happy to work with your technology, security, legal or procurement teams.
We can provide more detailed information about our infrastructure, data handling, third-party providers and current security controls as part of an enterprise review.
Talk to us
