Security and trust

Security and trust

What Kiste guarantees, what it does not guarantee yet, and where each claim is explained.

Last updated: 6 October 2026

A Kiste is a cloud machine (a Firecracker microVM) running Linux; several are Kisten (see the glossary). You keep source code, credentials and running programs in them, so the questions that matter are who else can reach a Kiste, what happens to its data, and what you can check yourself. This section answers them plainly. Each page says what is in place today and, just as clearly, what is not.

Early access

Kiste is in early access. It runs on one compute server in Germany and on Cloudflare's network. It holds no security certification. The compliance documents describe readiness work, not an audit result. Where a protection is planned but not built yet, these pages say so.

At a glance

AreaTodayNot yet
IsolationEvery Kiste is its own microVM with its own kernel, started in a per-Kiste jail with resource limits.No external penetration test yet.
NetworkKisten cannot reach each other, the host, private networks or cloud metadata. Port 25 is blocked. The compute server has no open port on the Internet.
Encryption in transitHTTPS only (TLS 1.2 or newer, HSTS). The desktop stream is encrypted end to end between your browser and the server.
BackupsAutomatic checkpoints, encrypted with a key per account before they leave the server, kept in two locations.A 30-day deletion lock on the backup buckets is being rolled out.
Encryption at restOff-site checkpoints are encrypted.Disks of Kisten on the compute server are not encrypted at rest yet.
Your dataSelf-service export and deletion. Deleting an account crypto-shreds its backups.Automatic clean-up on the compute servers after a deletion is rolling out. Self-service e-mail change.
Software you installPinned inputs, an inventory (SBOM) and a vulnerability gate for the Kiste image. Checksummed CLI downloads over HTTPS.Signed CLI releases start with 0.1.1, not yet published. No build provenance attestation.
LocationCompute in Germany. Account database and primary backups in the EU jurisdiction.

Pages

Shared responsibility

Kiste is responsible for the platform: the isolation between Kisten, the network policy, the control plane at kiste.run, backups and the image a new Kiste boots from. You are responsible for what runs inside your Kisten: the software you install, the services you publish, the credentials you put there, and keeping your own packages up to date. When an updated image is available, kiste list shows it, and nothing changes in your Kiste until you run kiste update.

The binding texts are on kiste.run: Privacy policy, Data processing agreement (Annex 2 lists the technical and organisational measures), Subprocessors, Terms, Imprint and Security. If anything on these pages contradicts them, the legal documents apply.

On this page