What we do, and what we do not have yet.
Every line below is a verifiable statement with a date on which it was measured. What is not listed here, we do not have. That is the whole idea of this page.
Of the eight points below, 1 of 8 currently carry a real measurement date. Until that is eight of eight, this page stays on noindex and does not go public: a page that promises a date per point must not break that promise itself.
Eight statements, each with a measurement date.
None of these sentences is a quality mark. They are things we have set up and measure again when something changes.
- 01
Our server runs at an ISO 27001:2022-certified European provider.
openThe certification belongs to the provider, not to basestep. We check the certificate every year for its number and validity date, and the scope must cover the service we use.
- 02
Backups are encrypted (AES-256) before they go to European storage in Amsterdam.
measuredWe make a local backup every day, an encrypted copy goes to a second European location every week, and restoring has been proven with a real test.
- 03
The database cannot be reached from the internet.
openThis is a network configuration you can point to, not a policy intention: the database does not listen on a public address.
- 04
Encrypted connections (TLS 1.2 and 1.3, HSTS).
openAll traffic runs over TLS. HSTS is on; we deliberately do not mention preload here, because that is only allowed once the domain is actually on the preload list.
- 05
Two-step verification required for administrators.
openTechnically enforced, not just written down as policy.
- 06
We never ask for your BSN (the Dutch citizen service number).
openA product choice you can verify: there is no field for it, and the tax engine does not need it. Since 2020, the VAT identification number of a sole proprietorship (eenmanszaak) has been separate from the BSN.
- 07
We do not automatically read your documents.
openNo OCR on your receipts, no automatic document processing. You keep your receipts yourself; the platform does not store files.
- 08
We measure without cookies.
openThat is why there is no cookie banner on this site. The basis is Article 11.7a(3) of the Dutch Telecommunications Act (Telecommunicatiewet): measurement that is strictly necessary and does not track a device needs no consent.
Just as important, and so just as visible.
A security page that only tells what goes well tells half the story. This is the other half.
You can read what is and is not planned on the roadmap, and where we process your data will soon be in the privacy statement.
Report it, and do not publish it.
If you find a vulnerability, mail info@basestep.io with enough detail to reproduce it. Do not publish anything until it is fixed. The same address is in our security.txt. What we do not promise: there is no bug bounty programme and no committed response time.
Honest about what is there.
Also honest about what is not there yet: that is above, not in the small print.