Security and trust

Logging and retention

What Kiste logs, what it never logs, who can read logs and how long everything is kept.

Last updated: 6 October 2026

What is logged

Every component writes structured log lines with the time, the component, the event, an error code where there is one, and a request id. The CLI sends one request id per command, and it is carried from the CLI through kiste.run to the compute server. When you report a problem, that id lets us find exactly your request and nothing else.

Logs identify your account by a random account id, never by your e-mail address, and name a Kiste by its name.

Never logged: passwords, tokens, API keys, cookies, Authorization headers, payment secrets and e-mail addresses. Redaction removes values under secret-looking keys and masks Kiste token formats and e-mail addresses inside free text. Kiste does not log the contents of your Kisten, your SSH sessions, your terminal or your desktop stream.

Your own audit trail

Security-relevant actions on your account (sign-ins, sign-outs, revoked sessions and computers, CLI approvals) are recorded as audit events. They let you and us reconstruct what happened to an account.

Who can read logs

Only the operator. Edge logs live in Cloudflare's logging for the kiste.run workers. Logs of the compute server stay on that server and can only be queried read-only, through an access-controlled path. Nothing about logs is exposed on the Internet.

Retention

DataKept for
Edge logs (kiste.run)7 days
Compute server logs30 days (or 10 GiB, whichever comes first)
Audit events of your account12 months
Browser sessions7 days from sign-in, or until you sign out
CLI tokensvalid 30 days, deleted 30 days after expiry or revocation
Revoked or expired API keysdeleted 30 days later
Command history (metadata of commands run with kiste exec)30 days after the command finished
Events and alerts of Kisten90 days
Webhook deliveries14 days
Payment event ids (de-duplication only)90 days
Disks and memory snapshots of Kistenuntil you delete the Kiste
Off-site checkpointsevery checkpoint of the last hour, the newest per hour for 24 hours and the newest per day for 14 days; named snapshots until you delete them
Account datauntil you delete the account
Payment records after account deletionthe statutory retention period for accounting records, without your e-mail address

Every period above is enforced by an automatic job, not by hand. When a store is added or a period changes, this table and the privacy policy change with it.

On this page