1. This website
This site is a set of static pages served from a server we operate. It sets no cookies, loads nothing from third parties — the typefaces are hosted here — and runs no third-party analytics. What it records about a visit, and for how long, is set out in full in the privacy statement.
Traffic to the site is encrypted in transit with TLS. Administrative access to the server is limited to the people who need it and requires multi-factor authentication.
2. Sub-processors for this website
- Hetzner Online GmbH — hosting — Germany, EEA — ISO 27001-certified data centres, processing agreement in place.
- Proton AG — email — Switzerland — covered by the European Commission adequacy decision of 15 January 2024, so no additional transfer safeguard is required; processing agreement in place.
This list is for the website. Sub-processors for our products are listed in each product's own documentation, because they differ per deployment: a product can run against a model hosted by us, against an external API on the customer's own account, or entirely on the customer's own infrastructure with a model of their choosing.
We update this list when it changes, and the date above is the date it was last checked.
3. Reporting a vulnerability
If you think you have found a security problem, we want to hear about it. Write to security@juststeps.io. The same details are machine-readable at /.well-known/security.txt.
What is in scope
juststeps.io and its subdomains. Out of scope: systems belonging to our customers, third-party services we use, and findings produced by an automated scanner without a demonstrated impact.
What we ask of you
- Tell us as soon as you find it, and give us reasonable time before you publish.
- Go no further into the system than you need to in order to demonstrate the problem.
- Change nothing and delete nothing.
- Copy no more data than the minimum needed as proof, and delete that once the report is made.
- Use the finding for nothing else.
- No denial-of-service, no social engineering, no physical intrusion, no malware, no brute forcing, and no testing of systems that are not ours.
If you come across personal data, stop, do not copy it, and tell us that you found it. We would rather have a thin report and intact data.
What we will do
- Acknowledge your report within two working days.
- Keep it confidential, and not pass your details to anyone without your consent.
- Tell you how we are getting on while we work on it.
- Aim to disclose within 60 days of your report, coordinated with you — longer only if the fix genuinely takes longer, and we will say so.
- Credit you by name if you would like us to.
What we will not do
If you keep to the rules above, we will not report you to the police and we will not bring a civil claim against you.
We cannot promise more than that, and you should be wary of anyone who does. Unauthorised access to a computer system is a criminal offence in the Netherlands (art. 138ab Sr), and the decision to prosecute belongs to the Openbaar Ministerie, not to us. Its published position is that it will generally not prosecute someone who reports a vulnerability where there was a substantial public interest, where they went no further than necessary, and where no less intrusive route was available. The rules above are written to track that test. If it ever came to it, we would tell the OM that you followed our policy.
4. Review
This page is reviewed at least once a year, and whenever something on it changes. The date at the top is the date of the last review.