> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Compliance

> Kiste's GDPR documents, and where it stands on ISO/IEC 27001, BSI C5 and SOC 2. That is readiness work, not certification.

> **Warning:** No certification
>
> Kiste holds **no** ISO/IEC 27001 certificate, no BSI C5 attestation and no SOC 2 report. What
> follows is readiness work: the documents and controls an audit would examine, written from the
> running system. No accredited auditor has reviewed them yet, and no external penetration test
> has been done.

## GDPR

Kiste is a German service and is built around the GDPR, the German Federal Data Protection Act
(BDSG) and the TDDDG.

| Document | Where |
| --- | --- |
| Privacy policy | [kiste.run/privacy](https://kiste.run/privacy) ([Deutsch](https://kiste.run/datenschutz)) |
| Data processing agreement (Art. 28), with technical and organisational measures (Annex 2) and subprocessors (Annex 3) | [kiste.run/dpa](https://kiste.run/dpa) ([Deutsch](https://kiste.run/avv)) |
| Subprocessors | [kiste.run/subprocessors](https://kiste.run/subprocessors) |
| Terms | [kiste.run/terms](https://kiste.run/terms) ([Deutsch](https://kiste.run/agb)) |
| Imprint | [kiste.run/imprint](https://kiste.run/imprint) ([Deutsch](https://kiste.run/impressum)) |

Kiste also keeps the internal records the GDPR requires: a data inventory, records of processing
activities (Art. 30), a retention and deletion schedule, procedures for data subject requests and
for personal data breaches, a DPIA screening and a transfer impact assessment. Cookies are limited
to what the service strictly needs; there are no advertising or analytics cookies.

## Information security management

Kiste maintains an information security management system modelled on ISO/IEC 27001:2022:

- a manual covering clauses 4 to 10, policies (access, cryptography, incidents, change, secure
  development, vulnerabilities, logging, backup, suppliers),
- a risk register with treatment decisions,
- a Statement of Applicability covering all 93 Annex A controls,
- mappings to the BSI C5:2020 criteria areas and to the SOC 2 Trust Services Criteria,
- a gap list that names every control not yet met, with an owner.

These documents are internal. Customers with a legitimate need (for example their own vendor
assessment) can ask for an excerpt.

## Continuous security review

Every Kiste repository carries a security review system with tracks for architecture, threat
modelling, service and API penetration testing, cryptographic implementation, system audit,
code quality and operations. The rules are strict:

- every finding is verified independently, by a different reviewer than the one who found it,
- every fix is re-verified independently, never by the person who made it,
- a review that finds nothing is not treated as a pass, and every pass needs its own
  independent verification,
- the registers are validated automatically on every change.

## Known gaps, stated openly

- Disks of Kisten on the compute server are not yet encrypted at rest
  (see [Encryption](https://docs.kiste.run/security/encryption.md)).
- Compute runs on one server in the operator's own premises, not in a certified data centre.
  Moving compute to a certified data centre is a precondition for a C5 attestation.
- No external penetration test and no certification audit yet.
- Self-service e-mail change and a restriction-of-processing switch are not built yet.

## Related topics

- [Security and trust](https://docs.kiste.run/security.md)
- [Isolation](https://docs.kiste.run/security/isolation.md)
- [Network](https://docs.kiste.run/security/network.md)
- [Encryption](https://docs.kiste.run/security/encryption.md)
- [Supply chain and updates](https://docs.kiste.run/security/supply-chain.md)
- [Data location](https://docs.kiste.run/security/data-location.md)
- [Subprocessors](https://docs.kiste.run/security/subprocessors.md)
- [Logging and retention](https://docs.kiste.run/security/logging-retention.md)
- [Export and deletion](https://docs.kiste.run/security/account-data.md)
- [Incidents and status](https://docs.kiste.run/security/incidents-status.md)
- [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md)
- Previous: [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md)
- Next: [Status](https://docs.kiste.run/resources/status.md)
