Encryption in transit, in backups and at rest, with the parts that are still missing.
Last updated: 6 October 2026
In transit
- Web and API. kiste.run, desktop.kiste.run and kiste.stream accept HTTPS only, with TLS 1.2 or newer (TLS 1.0 and 1.1 are refused). HSTS is set for one year, including subdomains.
- Desktop stream. Video, audio and input travel over WebRTC with DTLS-SRTP, encrypted end to end between your browser and the compute server. When a TURN relay is needed, it forwards encrypted packets only.
- Inside the platform. kiste.run reaches the compute server only through an encrypted Cloudflare Tunnel, and every request carries a secret the server checks. The compute server reaches its database through an access-controlled, encrypted tunnel as well.
- SSH. End to end between your SSH client and your Kiste's SSH server. kiste.run carries the encrypted SSH stream but cannot read it.
Credentials Kiste stores
| What | How it is stored |
|---|---|
| Your password | PBKDF2-SHA-256, 100,000 iterations, a per-user salt and a server-side secret pepper. Compared in constant time. |
| Sessions, CLI tokens, API keys, desktop and terminal links | Only as SHA-256 hashes. The plain value exists only on your side. API keys are shown once. |
| Secret files of environments, webhook signing secrets, published-service capabilities | Encrypted with AES-256-GCM. |
Browser sessions expire after 7 days and CLI tokens after 30 days. You can see and revoke every sign-in, or sign out everywhere, which also ends open desktop and terminal sessions.
Backups (off-site checkpoints)
Every running Kiste is checkpointed automatically, and each checkpoint is copied off the compute server. Before anything leaves the server:
- The disk is split into chunks, and each changed chunk is compressed.
- Each chunk is encrypted with AES-256-GCM under a key derived from your account's own random data key. Two accounts never share a stored object.
- The list of chunks that makes up a checkpoint is encrypted as well.
- Your account key is itself stored only in wrapped (encrypted) form.
The storage provider (Cloudflare R2) receives ciphertext only and holds no key. Chunks that are byte-identical to the public base image are stored once for everyone. They are compressed but not encrypted, because they are the published image and contain nothing you wrote. Your encrypted checkpoint records the digest of each such chunk, and the digest is checked on restore.
Crypto-shredding. When you delete your account, its data key is deleted. From that moment every remaining copy of its checkpoints, in every location, is undecryptable. The ciphertext itself is removed afterwards (see Export and deletion).
Protection against deletion (being rolled out). The backup buckets are getting a 30-day lock, so that no credential, including the compute server's own, can delete or overwrite a backup object younger than 30 days. The second copy is moving to a write path that cannot delete at all. Once both are live, someone who took over the compute server could not erase the last 30 days of backups. Until then, the second copy protects against losing a storage location, not against a compromised server.
At rest on the compute server
Not encrypted at rest yet
The disks, memory snapshots and local checkpoints of Kisten on the compute server are not encrypted at rest today. Someone with physical access to the server's drive, or with root on the server, could read them. Encryption of the whole storage pool of Kisten (LUKS2 with a hardware-bound key) is specified and scheduled, but it is not in place. This page will change when it is.
What protects this data in the meantime: the server is in the operator's own premises in Germany; it has no open port on the Internet; operator access is key-based and limited to one person; and a drive that leaves our control is securely erased or destroyed. Off-site backups are encrypted regardless (see above).
Data held by Cloudflare (account database, release downloads, backups) is encrypted at rest by Cloudflare.
What we do not offer yet
- Customer-managed keys (bring your own key).
- Encryption at rest of Kiste disks on the compute server (see above).