> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Incidents and status

> The public status page, how outages are detected, and what happens when security or personal data is affected.

## Status page

**[kiste.run/status](https://kiste.run/status)** shows the current state of the platform, open
incidents and planned maintenance, with a 7-day uptime per component. The same data is available
as JSON at `https://kiste.run/status.json` for your own monitoring.

| Component | What it means |
| --- | --- |
| kiste.run | The website, console and API |
| Compute 1, 2, … | Each compute server that runs Kisten |
| Off-site checkpoints | Whether backups leave the compute servers on time |
| Machine storage | Whether the compute servers have storage headroom |

Uptime only appears once enough checks exist to compute it. The page never shows a made-up figure.

## How problems are detected

- An external check, run from outside Cloudflare every 10 minutes, tests that kiste.run and the
  status data answer.
- kiste.run checks every compute server every 5 minutes; two failures in a row open an incident.
- Server errors are counted per 5 minutes; an unusual number opens an incident.
- Each compute server reports whether its backups are uploading and how full its storage is.

An incident notifies the operator at once and again every 6 hours while it stays open. It appears
on the status page and closes automatically when the checks pass again. Planned maintenance is
announced on the page and does not count against uptime.

## Security incidents

Security incidents follow a written procedure: contain first (revoke secrets, end sessions, stop
affected Kisten, switch the affected feature off), then record, assess and fix. Every fix is
checked independently by someone other than the person who made it, and a review with root cause
and lessons follows within 14 days of closing the incident.

## When personal data is affected

- The supervisory authority (the State Commissioner for Data Protection of Baden-Württemberg) is
  notified **within 72 hours** of becoming aware of a breach that poses a risk to people, as the
  GDPR requires.
- If the contents of customers' Kisten are affected, Kiste, as your processor, informs the affected
  customers **without undue delay, with a target of 24 hours**, with the facts you need for your
  own notification duties. Any unauthorised access to the contents of Kisten is treated as notifiable.
- If a breach is likely to pose a high risk to you, we tell you directly: what happened, what it
  means, what we did, and what you should do (for example rotate credentials stored in your
  Kisten).
- Every incident involving personal data is recorded, whether or not it had to be notified.

## Report a problem

Outages: check the status page first. Security issues: see
[Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md).

## Related topics

- [Security and trust](https://docs.kiste.run/security.md)
- [Isolation](https://docs.kiste.run/security/isolation.md)
- [Network](https://docs.kiste.run/security/network.md)
- [Encryption](https://docs.kiste.run/security/encryption.md)
- [Supply chain and updates](https://docs.kiste.run/security/supply-chain.md)
- [Data location](https://docs.kiste.run/security/data-location.md)
- [Subprocessors](https://docs.kiste.run/security/subprocessors.md)
- [Logging and retention](https://docs.kiste.run/security/logging-retention.md)
- [Export and deletion](https://docs.kiste.run/security/account-data.md)
- [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md)
- [Compliance](https://docs.kiste.run/security/compliance.md)
- Previous: [Export and deletion](https://docs.kiste.run/security/account-data.md)
- Next: [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md)
