> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Security and trust

> What Kiste guarantees, what it does not guarantee yet, and where each claim is explained.

A Kiste is a cloud machine (a Firecracker microVM) running Linux; several are Kisten (see the
[glossary](https://docs.kiste.run/resources/glossary.md)). You keep source code,
credentials and running programs in them, so the questions that matter are who else can reach
a Kiste, what happens to its data, and what you can check yourself. This section answers them
plainly. Each page says what is in place today and, just as clearly, what is not.

> **Info:** Early access
>
> Kiste is in early access. It runs on one compute server in Germany and on Cloudflare's network.
> It holds **no security certification**. The compliance documents describe readiness work, not an
> audit result. Where a protection is planned but not built yet, these pages say so.

## At a glance

| Area | Today | Not yet |
| --- | --- | --- |
| Isolation | Every Kiste is its own microVM with its own kernel, started in a per-Kiste jail with resource limits. | No external penetration test yet. |
| Network | Kisten cannot reach each other, the host, private networks or cloud metadata. Port 25 is blocked. The compute server has no open port on the Internet. |  |
| Encryption in transit | HTTPS only (TLS 1.2 or newer, HSTS). The desktop stream is encrypted end to end between your browser and the server. |  |
| Backups | Automatic checkpoints, encrypted with a key per account before they leave the server, kept in two locations. | A 30-day deletion lock on the backup buckets is being rolled out. |
| Encryption at rest | Off-site checkpoints are encrypted. | Disks of Kisten on the compute server are **not** encrypted at rest yet. |
| Your data | Self-service export and deletion. Deleting an account crypto-shreds its backups. | Automatic clean-up on the compute servers after a deletion is rolling out. Self-service e-mail change. |
| Software you install | Pinned inputs, an inventory (SBOM) and a vulnerability gate for the Kiste image. Checksummed CLI downloads over HTTPS. | Signed CLI releases start with 0.1.1, not yet published. No build provenance attestation. |
| Location | Compute in Germany. Account database and primary backups in the EU jurisdiction. |  |

## Pages

- [Isolation](https://docs.kiste.run/security/isolation.md): How one Kiste is kept apart from another, from the host and from us.
- [Network](https://docs.kiste.run/security/network.md): What a Kiste can and cannot reach, and why port 25 is closed.
- [Encryption](https://docs.kiste.run/security/encryption.md): In transit, in backups and at rest, including what is still missing.
- [Supply chain and updates](https://docs.kiste.run/security/supply-chain.md): How the image and the CLI are built, and how to verify a download.
- [Data location](https://docs.kiste.run/security/data-location.md): Where your data is stored and processed.
- [Subprocessors](https://docs.kiste.run/security/subprocessors.md): Who processes data on Kiste's behalf.
- [Logging and retention](https://docs.kiste.run/security/logging-retention.md): What is logged, for how long, and what never is.
- [Export and deletion](https://docs.kiste.run/security/account-data.md): Download your data or delete your account.
- [Incidents and status](https://docs.kiste.run/security/incidents-status.md): The status page and what happens when something goes wrong.
- [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md): How to report a security issue and what we promise.
- [Compliance](https://docs.kiste.run/security/compliance.md): GDPR documents and certification readiness.

## Shared responsibility

Kiste is responsible for the platform: the isolation between Kisten, the network policy,
the control plane at kiste.run, backups and the image a new Kiste boots from. You are
responsible for what runs inside your Kisten: the software you install, the services you
publish, the credentials you put there, and keeping your own packages up to date. When an
updated image is available, `kiste list` shows it, and nothing changes in your Kiste until you
run `kiste update`.

## Legal documents

The binding texts are on kiste.run:
[Privacy policy](https://kiste.run/privacy),
[Data processing agreement](https://kiste.run/dpa) (Annex 2 lists the technical and organisational measures),
[Subprocessors](https://kiste.run/subprocessors),
[Terms](https://kiste.run/terms),
[Imprint](https://kiste.run/imprint) and
[Security](https://kiste.run/security).
If anything on these pages contradicts them, the legal documents apply.

## Related topics

- [Isolation](https://docs.kiste.run/security/isolation.md)
- [Network](https://docs.kiste.run/security/network.md)
- [Encryption](https://docs.kiste.run/security/encryption.md)
- [Supply chain and updates](https://docs.kiste.run/security/supply-chain.md)
- [Data location](https://docs.kiste.run/security/data-location.md)
- [Subprocessors](https://docs.kiste.run/security/subprocessors.md)
- [Logging and retention](https://docs.kiste.run/security/logging-retention.md)
- [Export and deletion](https://docs.kiste.run/security/account-data.md)
- [Incidents and status](https://docs.kiste.run/security/incidents-status.md)
- [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md)
- [Compliance](https://docs.kiste.run/security/compliance.md)
- Previous: [Rate limits and quotas](https://docs.kiste.run/limits.md)
- Next: [Isolation](https://docs.kiste.run/security/isolation.md)
