Security and trust

Incidents and status

The public status page, how outages are detected, and what happens when security or personal data is affected.

Last updated: 6 October 2026

Status page

kiste.run/status shows the current state of the platform, open incidents and planned maintenance, with a 7-day uptime per component. The same data is available as JSON at https://kiste.run/status.json for your own monitoring.

ComponentWhat it means
kiste.runThe website, console and API
Compute 1, 2, …Each compute server that runs Kisten
Off-site checkpointsWhether backups leave the compute servers on time
Machine storageWhether the compute servers have storage headroom

Uptime only appears once enough checks exist to compute it. The page never shows a made-up figure.

How problems are detected

  • An external check, run from outside Cloudflare every 10 minutes, tests that kiste.run and the status data answer.
  • kiste.run checks every compute server every 5 minutes; two failures in a row open an incident.
  • Server errors are counted per 5 minutes; an unusual number opens an incident.
  • Each compute server reports whether its backups are uploading and how full its storage is.

An incident notifies the operator at once and again every 6 hours while it stays open. It appears on the status page and closes automatically when the checks pass again. Planned maintenance is announced on the page and does not count against uptime.

Security incidents

Security incidents follow a written procedure: contain first (revoke secrets, end sessions, stop affected Kisten, switch the affected feature off), then record, assess and fix. Every fix is checked independently by someone other than the person who made it, and a review with root cause and lessons follows within 14 days of closing the incident.

When personal data is affected

  • The supervisory authority (the State Commissioner for Data Protection of Baden-Württemberg) is notified within 72 hours of becoming aware of a breach that poses a risk to people, as the GDPR requires.
  • If the contents of customers' Kisten are affected, Kiste, as your processor, informs the affected customers without undue delay, with a target of 24 hours, with the facts you need for your own notification duties. Any unauthorised access to the contents of Kisten is treated as notifiable.
  • If a breach is likely to pose a high risk to you, we tell you directly: what happened, what it means, what we did, and what you should do (for example rotate credentials stored in your Kisten).
  • Every incident involving personal data is recorded, whether or not it had to be notified.

Report a problem

Outages: check the status page first. Security issues: see Vulnerability disclosure.

On this page