security

What we do, and what we do not have yet.

Every line below is a verifiable statement with a date on which it was measured. What is not listed here, we do not have. That is the whole idea of this page.

this page is not complete yet

Of the eight points below, 1 of 8 currently carry a real measurement date. Until that is eight of eight, this page stays on noindex and does not go public: a page that promises a date per point must not break that promise itself.

what we do

Eight statements, each with a measurement date.

None of these sentences is a quality mark. They are things we have set up and measure again when something changes.

  1. 01

    Our server runs at an ISO 27001:2022-certified European provider.

    open

    The certification belongs to the provider, not to basestep. We check the certificate every year for its number and validity date, and the scope must cover the service we use.

    measurement date still missing: the provider's certificate number and validity date

  2. 02

    Backups are encrypted (AES-256) before they go to European storage in Amsterdam.

    measured

    We make a local backup every day, an encrypted copy goes to a second European location every week, and restoring has been proven with a real test.

  3. 03

    The database cannot be reached from the internet.

    open

    This is a network configuration you can point to, not a policy intention: the database does not listen on a public address.

    measurement date still missing: date of the network measurement

  4. 04

    Encrypted connections (TLS 1.2 and 1.3, HSTS).

    open

    All traffic runs over TLS. HSTS is on; we deliberately do not mention preload here, because that is only allowed once the domain is actually on the preload list.

    measurement date still missing: date of the TLS and HSTS measurement, and whether the domain goes on the preload list

  5. 05

    Two-step verification required for administrators.

    open

    Technically enforced, not just written down as policy.

    measurement date still missing: date on which the enforcement was checked

  6. 06

    We never ask for your BSN (the Dutch citizen service number).

    open

    A product choice you can verify: there is no field for it, and the tax engine does not need it. Since 2020, the VAT identification number of a sole proprietorship (eenmanszaak) has been separate from the BSN.

    measurement date still missing: no measurement needed, but a date on which it was established

  7. 07

    We do not automatically read your documents.

    open

    No OCR on your receipts, no automatic document processing. You keep your receipts yourself; the platform does not store files.

    measurement date still missing: no measurement needed, but a date on which it was established

  8. 08

    We measure without cookies.

    open

    That is why there is no cookie banner on this site. The basis is Article 11.7a(3) of the Dutch Telecommunications Act (Telecommunicatiewet): measurement that is strictly necessary and does not track a device needs no consent.

    measurement date still missing: date on which the measurement setup was checked

what we do not have yet

Just as important, and so just as visible.

A security page that only tells what goes well tells half the story. This is the other half.

No external pentest.It is on the roadmap, without a date as long as none has been set.
No certification of our own.The ISO certification above belongs to our provider. basestep itself is not certified and does not say so anywhere else either.
No disk encryption on the server itself.The backups are encrypted; the server disk is not. It is on the roadmap.
No measured availability.We do not publish an uptime percentage, because we do not measure it. A status page is on the roadmap.

You can read what is and is not planned on the roadmap, and where we process your data will soon be in the privacy statement.

found something

Report it, and do not publish it.

If you find a vulnerability, mail info@basestep.io with enough detail to reproduce it. Do not publish anything until it is fixed. The same address is in our security.txt. What we do not promise: there is no bug bounty programme and no committed response time.

Honest about what is there.

Also honest about what is not there yet: that is above, not in the small print.