Security at Woven

Your productions matter. So does protecting them.

Woven is designed for professional production, where unreleased content, creative IP and commercially sensitive information are part of the everyday workflow.

Security therefore isn’t an optional feature. It’s part of how we build and operate the platform.

We also believe enterprise customers deserve clarity about what protections are in place today — and what is still being developed.

01 · Ownership

Your content remains your content.

The productions, assets and creative material you bring into Woven remain yours.

Woven does not claim ownership of your production or creative IP.

Where Woven connects to third-party AI models, the handling of data may also be subject to the terms and policies of those providers. We work to give production teams clarity over the models and services being used within their workflows.

Model training

Customer productions, assets and prompts are never used to train Woven’s own models. Where a third-party model is used, we select providers whose enterprise terms exclude customer data from training by default, and we surface each model’s data policy inside the app before a generation runs.

02 · Access

Enterprise access and control.

Woven is designed to give organisations control over who can access their productions and how their teams work within the platform.

  • Role-based permissions across organisation, workspace and project
  • SSO via SAML 2.0 and OIDC, with enforced multi-factor authentication
  • Workspace and project-level membership controls
  • Audit logs covering access, generation and approval events
  • Per-project credit caps and model allow-lists
  • Session length and device revocation controls

Enterprise teams can also bring their own model keys where supported, allowing organisations to use their own commercial relationships with model providers within the Woven environment.

03 · Data

Your data.

We take the security of production data seriously.

Encryption in transit
TLS 1.3 on all connections
Encryption at rest
AES-256 across media and metadata
Hosting
AWS, London (eu-west-2)
Backups
Encrypted daily, 30-day retention
Isolation
Per-organisation logical separation
Retention
Configurable, with deletion on request

Our Privacy Policy explains how personal data is processed, and enterprise customers can request appropriate data-processing documentation as part of their procurement process.

04 · Models

Third-party AI models.

Woven is model-neutral and can connect production teams with a range of third-party generative AI providers.

When a production uses one of these models, relevant data may need to be processed by that provider in order to perform the requested generation.

For enterprise customers, we can discuss model selection, Bring Your Own Key arrangements and the data policies associated with the models used in your workflow.

Model selectionBring Your Own KeyPer-model data policiesProvider allow-lists
05 · Standards

Security standards and certification.

We believe in being clear about where we are.

Woven is not currently SOC 2 or ISO 27001 certified.

As we scale our enterprise offering, we are developing our security and compliance programme around the requirements of professional studios, broadcasters, agencies and production companies.

We would rather be transparent about our current position than imply certifications or controls we don’t yet have.

Security questions?

If you’re evaluating Woven for your organisation, we’re happy to work with your technology, security, legal or procurement teams.

We can provide more detailed information about our infrastructure, data handling, third-party providers and current security controls as part of an enterprise review.

Talk to us