Security and trust

Compliance

Kiste's GDPR documents, and where it stands on ISO/IEC 27001, BSI C5 and SOC 2. That is readiness work, not certification.

Last updated: 6 October 2026

No certification

Kiste holds no ISO/IEC 27001 certificate, no BSI C5 attestation and no SOC 2 report. What follows is readiness work: the documents and controls an audit would examine, written from the running system. No accredited auditor has reviewed them yet, and no external penetration test has been done.

GDPR

Kiste is a German service and is built around the GDPR, the German Federal Data Protection Act (BDSG) and the TDDDG.

DocumentWhere
Privacy policykiste.run/privacy (Deutsch)
Data processing agreement (Art. 28), with technical and organisational measures (Annex 2) and subprocessors (Annex 3)kiste.run/dpa (Deutsch)
Subprocessorskiste.run/subprocessors
Termskiste.run/terms (Deutsch)
Imprintkiste.run/imprint (Deutsch)

Kiste also keeps the internal records the GDPR requires: a data inventory, records of processing activities (Art. 30), a retention and deletion schedule, procedures for data subject requests and for personal data breaches, a DPIA screening and a transfer impact assessment. Cookies are limited to what the service strictly needs; there are no advertising or analytics cookies.

Information security management

Kiste maintains an information security management system modelled on ISO/IEC 27001:2022:

  • a manual covering clauses 4 to 10, policies (access, cryptography, incidents, change, secure development, vulnerabilities, logging, backup, suppliers),
  • a risk register with treatment decisions,
  • a Statement of Applicability covering all 93 Annex A controls,
  • mappings to the BSI C5:2020 criteria areas and to the SOC 2 Trust Services Criteria,
  • a gap list that names every control not yet met, with an owner.

These documents are internal. Customers with a legitimate need (for example their own vendor assessment) can ask for an excerpt.

Continuous security review

Every Kiste repository carries a security review system with tracks for architecture, threat modelling, service and API penetration testing, cryptographic implementation, system audit, code quality and operations. The rules are strict:

  • every finding is verified independently, by a different reviewer than the one who found it,
  • every fix is re-verified independently, never by the person who made it,
  • a review that finds nothing is not treated as a pass, and every pass needs its own independent verification,
  • the registers are validated automatically on every change.

Known gaps, stated openly

  • Disks of Kisten on the compute server are not yet encrypted at rest (see Encryption).
  • Compute runs on one server in the operator's own premises, not in a certified data centre. Moving compute to a certified data centre is a precondition for a C5 attestation.
  • No external penetration test and no certification audit yet.
  • Self-service e-mail change and a restriction-of-processing switch are not built yet.

On this page