> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Encryption

> Encryption in transit, in backups and at rest, with the parts that are still missing.

## In transit

- **Web and API.** kiste.run, desktop.kiste.run and kiste.stream accept HTTPS only, with TLS 1.2
  or newer (TLS 1.0 and 1.1 are refused). HSTS is set for one year, including subdomains.
- **Desktop stream.** Video, audio and input travel over WebRTC with DTLS-SRTP, encrypted end to
  end between your browser and the compute server. When a TURN relay is needed, it forwards
  encrypted packets only.
- **Inside the platform.** kiste.run reaches the compute server only through an encrypted
  Cloudflare Tunnel, and every request carries a secret the server checks. The compute server
  reaches its database through an access-controlled, encrypted tunnel as well.
- **SSH.** End to end between your SSH client and your Kiste's SSH server. kiste.run carries
  the encrypted SSH stream but cannot read it.

## Credentials Kiste stores

| What | How it is stored |
| --- | --- |
| Your password | PBKDF2-SHA-256, 100,000 iterations, a per-user salt and a server-side secret pepper. Compared in constant time. |
| Sessions, CLI tokens, API keys, desktop and terminal links | Only as SHA-256 hashes. The plain value exists only on your side. API keys are shown once. |
| Secret files of environments, webhook signing secrets, published-service capabilities | Encrypted with AES-256-GCM. |

Browser sessions expire after 7 days and CLI tokens after 30 days. You can see and revoke every
sign-in, or sign out everywhere, which also ends open desktop and terminal sessions.

## Backups (off-site checkpoints)

Every running Kiste is checkpointed automatically, and each checkpoint is copied off the
compute server. Before anything leaves the server:

1. The disk is split into chunks, and each changed chunk is compressed.
2. Each chunk is encrypted with **AES-256-GCM** under a key derived from your account's own
   random data key. Two accounts never share a stored object.
3. The list of chunks that makes up a checkpoint is encrypted as well.
4. Your account key is itself stored only in wrapped (encrypted) form.

The storage provider (Cloudflare R2) receives ciphertext only and holds no key. Chunks that are
byte-identical to the public base image are stored once for everyone. They are compressed but
not encrypted, because they are the published image and contain nothing you wrote. Your
encrypted checkpoint records the digest of each such chunk, and the digest is checked on restore.

**Crypto-shredding.** When you delete your account, its data key is deleted. From that moment
every remaining copy of its checkpoints, in every location, is undecryptable. The ciphertext
itself is removed afterwards (see [Export and deletion](https://docs.kiste.run/security/account-data.md)).

**Protection against deletion (being rolled out).** The backup buckets are getting a 30-day lock,
so that no credential, including the compute server's own, can delete or overwrite a backup
object younger than 30 days. The second copy is moving to a write path that cannot delete at
all. Once both are live, someone who took over the compute server could not erase the last 30
days of backups. Until then, the second copy protects against losing a storage location, not
against a compromised server.

## At rest on the compute server

> **Warning:** Not encrypted at rest yet
>
> The disks, memory snapshots and local checkpoints of Kisten on the compute server are **not
> encrypted at rest today**. Someone with physical access to the server's drive, or with root on
> the server, could read them. Encryption of the whole storage pool of Kisten (LUKS2 with a
> hardware-bound key) is specified and scheduled, but it is not in place. This page will change
> when it is.

What protects this data in the meantime: the server is in the operator's own premises in
Germany; it has no open port on the Internet; operator access is key-based and limited to one
person; and a drive that leaves our control is securely erased or destroyed. Off-site backups
are encrypted regardless (see above).

Data held by Cloudflare (account database, release downloads, backups) is encrypted at rest by
Cloudflare.

## What we do not offer yet

- Customer-managed keys (bring your own key).
- Encryption at rest of Kiste disks on the compute server (see above).

## Related topics

- [Security and trust](https://docs.kiste.run/security.md)
- [Isolation](https://docs.kiste.run/security/isolation.md)
- [Network](https://docs.kiste.run/security/network.md)
- [Supply chain and updates](https://docs.kiste.run/security/supply-chain.md)
- [Data location](https://docs.kiste.run/security/data-location.md)
- [Subprocessors](https://docs.kiste.run/security/subprocessors.md)
- [Logging and retention](https://docs.kiste.run/security/logging-retention.md)
- [Export and deletion](https://docs.kiste.run/security/account-data.md)
- [Incidents and status](https://docs.kiste.run/security/incidents-status.md)
- [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md)
- [Compliance](https://docs.kiste.run/security/compliance.md)
- Previous: [Network](https://docs.kiste.run/security/network.md)
- Next: [Supply chain and updates](https://docs.kiste.run/security/supply-chain.md)
