Security and trust
What Kiste guarantees, what it does not guarantee yet, and where each claim is explained.
Last updated: 6 October 2026
A Kiste is a cloud machine (a Firecracker microVM) running Linux; several are Kisten (see the glossary). You keep source code, credentials and running programs in them, so the questions that matter are who else can reach a Kiste, what happens to its data, and what you can check yourself. This section answers them plainly. Each page says what is in place today and, just as clearly, what is not.
Early access
Kiste is in early access. It runs on one compute server in Germany and on Cloudflare's network. It holds no security certification. The compliance documents describe readiness work, not an audit result. Where a protection is planned but not built yet, these pages say so.
At a glance
| Area | Today | Not yet |
|---|---|---|
| Isolation | Every Kiste is its own microVM with its own kernel, started in a per-Kiste jail with resource limits. | No external penetration test yet. |
| Network | Kisten cannot reach each other, the host, private networks or cloud metadata. Port 25 is blocked. The compute server has no open port on the Internet. | |
| Encryption in transit | HTTPS only (TLS 1.2 or newer, HSTS). The desktop stream is encrypted end to end between your browser and the server. | |
| Backups | Automatic checkpoints, encrypted with a key per account before they leave the server, kept in two locations. | A 30-day deletion lock on the backup buckets is being rolled out. |
| Encryption at rest | Off-site checkpoints are encrypted. | Disks of Kisten on the compute server are not encrypted at rest yet. |
| Your data | Self-service export and deletion. Deleting an account crypto-shreds its backups. | Automatic clean-up on the compute servers after a deletion is rolling out. Self-service e-mail change. |
| Software you install | Pinned inputs, an inventory (SBOM) and a vulnerability gate for the Kiste image. Checksummed CLI downloads over HTTPS. | Signed CLI releases start with 0.1.1, not yet published. No build provenance attestation. |
| Location | Compute in Germany. Account database and primary backups in the EU jurisdiction. |
Pages
Isolation
How one Kiste is kept apart from another, from the host and from us.
Network
What a Kiste can and cannot reach, and why port 25 is closed.
Encryption
In transit, in backups and at rest, including what is still missing.
Supply chain and updates
How the image and the CLI are built, and how to verify a download.
Data location
Where your data is stored and processed.
Subprocessors
Who processes data on Kiste's behalf.
Logging and retention
What is logged, for how long, and what never is.
Export and deletion
Download your data or delete your account.
Incidents and status
The status page and what happens when something goes wrong.
Vulnerability disclosure
How to report a security issue and what we promise.
Compliance
GDPR documents and certification readiness.
Shared responsibility
Kiste is responsible for the platform: the isolation between Kisten, the network policy,
the control plane at kiste.run, backups and the image a new Kiste boots from. You are
responsible for what runs inside your Kisten: the software you install, the services you
publish, the credentials you put there, and keeping your own packages up to date. When an
updated image is available, kiste list shows it, and nothing changes in your Kiste until you
run kiste update.
Legal documents
The binding texts are on kiste.run: Privacy policy, Data processing agreement (Annex 2 lists the technical and organisational measures), Subprocessors, Terms, Imprint and Security. If anything on these pages contradicts them, the legal documents apply.