Kinesis

Security & Privacy at Kinesis Cloud

Overview of security and privacy protocols, controls, and commitments at Kinesis Cloud, including infrastructure, network, data, compliance, and transparency.

Our commitment to your data and workloads.

At Kinesis Cloud, we take the security and privacy of our customers' workloads very seriously. Our platform is designed to protect containerized applications across datacenters, clouds, and customer-owned infrastructure.

This document provides an overview of our security posture and the measures we take to protect your data and workloads.

1. Infrastructure Security

Trusted Datacenter ProvidersCompute and network capacity is sourced from providers such as AWS, Google Cloud, OVH, Hyperstack, and similar operators that maintain SOC 2 and ISO/IEC 27001 certifications, with strong physical and operational security controls.

Multi-Datacenter ArchitectureOur platform spans multiple facilities and providers, ensuring redundancy and resiliency through geographic diversity and minimizing single-point-of-failure risks.

Customer-Owned InfrastructureCustomers may connect their own machines to the Kinesis Cloud control panel. Physical and local infrastructure security for customer-owned machines remains the customer's responsibility.

2. Network & Transport Security

Encrypted ConnectionsAll communications use TLS/SSL encryption. Node-to-node and inter-datacenter communication runs over WireGuard VPN tunnels with modern cryptography.

Segmentation & IsolationCustomer workloads remain logically isolated at the network and orchestration layers.

Resilient GatewaysHAProxy and Nginx provide TLS termination, traffic management, and high-availability load balancing.

3. Platform & Container Security

Container RuntimeWorkloads run on Docker, hardened with additional controls and monitoring.

Host Hardening & UpdatesStandardized on Ubuntu LTS with hardened configurations and strict patching processes, ensuring nodes receive the latest security fixes.

Automatic FailoverServer or datacenter disruption triggers automatic workload rescheduling to healthy environments.

Customer ImagesCustomers control container content. Best practices are encouraged, including signed images, vulnerability scanning, and minimal base layers.

4. Application & Data Layer

Backend StackThe control plane and services are built with C# and Go, selected for performance, reliability, and maintainability.

Database SecurityMongoDB Atlas provides a fully managed service with recommended release levels, automated patching, built-in encryption, and backups.

Encryption at Rest & in TransitAll sensitive data is encrypted at rest and protected in transit with TLS.

5. Data Protection & Privacy

Customer Data OwnershipCustomers retain full ownership of their images, data, and workloads. Kinesis Cloud does not access application data except when explicitly required for support.

Minimal Metadata CollectionOnly telemetry necessary for platform operation and improvement is collected. Logs and control plane data are retained only as long as necessary.

Privacy by DesignOur architecture minimizes unnecessary exposure of customer information and adheres to industry best practices.

6. Monitoring & Operations

Continuous MonitoringSystems continuously track cluster health, network integrity, and anomalies.

Incident ResponseA documented incident response process ensures rapid isolation, remediation, and transparent communication.

Proactive PatchingAll critical components (Ubuntu, WireGuard, HAProxy, Nginx, Docker, MongoDB Atlas) are patched promptly and systematically.

7. Leadership & Expertise

Experienced TeamLeadership includes industry veterans from AWS, Microsoft, Meta, Mozilla, and IBM. Many bring direct security expertise, shaping policies and practices from inception.

Culture of SecuritySecurity is integrated into the development lifecycle and operational playbooks rather than being an afterthought.

8. Shared Responsibility

Security in the cloud is a shared responsibility:

Kinesis CloudSecures the orchestration system, control plane, networking fabric, and provided infrastructure.

CustomersSecure their images, application code, secrets, and any infrastructure they connect to the control plane.

9. Compliance Alignment

While we are actively pursuing formal certifications, our controls align with globally recognized standards:

ISO/IEC 27001 (Information Security Management)

SOC 2 (Trust Services Criteria)

CSA STAR (Cloud Security Alliance) best practices

Additional documentation is available to support customer audits and due diligence.

10. Commitment to Transparency

Security depends on trust and openness. Our commitment includes:

Publishing clear documentation of our controls

Engaging directly with customers during security reviews

Continuously improving our posture as threats evolve