The STEP Framework repository contains documentation only — assessment criteria, scoring guidance, and process templates. There is no running application, no user data, and no credentials stored in this repository.
Security concerns relevant to this repo fall into two categories:
Framework integrity — manipulation of criteria, scoring rubrics, or tier definitions in a way that could harm CSOs or funders who rely on them.
Supply chain — a malicious commit that introduces harmful content into published framework files.
If you believe you have found a content integrity issue, a harmful change, or any other security concern with this repository, please do not open a public GitHub Issue. Instead, contact the maintainers directly:
Email: step-framework@techsoup.org
Subject line: [SECURITY] Brief description
We will acknowledge your report within 5 business days and aim to resolve or publicly disclose confirmed issues within 30 days.
| Version | Supported |
|---|---|
| latest (main) | ✅ Yes |
| older tags | ❌ No — please update to main |
- Typos or factual disagreements with criteria — please use the standard Criteria Feedback process for those.
- Requests to change the scoring model — please use the RFC process.