# Your logins, sessions and data stay yours.

Kaabist runs on infrastructure it operates itself, in the EU. Secrets are encrypted per organisation, job traffic leaves through a single guarded gateway, and every sensitive action is written to an audit log.

## Six things we never cut corners on.

- **Encrypted per organisation** Stored passwords, sessions and provider credentials use envelope encryption: a data key per organisation, wrapped by a master key in OpenBao. Plain text never leaves the worker's memory.

- **Redacted before capture** Password fields are redacted before a page is snapshotted or screenshotted. Secrets never appear in logs, snapshots, screenshots or webhooks.

- **One way out** Job traffic reaches the internet only through Kaabist's egress gateway. It refuses private, loopback, link-local and metadata addresses, and connects only to the address it checked.

- **Isolated browsers** Browser contexts run with site isolation and no file system access. Files leave only through an explicit download step, capped at 20 MB.

- **Short-lived access** Live views and hosted pages use tokens scoped to one job that expire after 15 minutes. Screencast frames are never stored.

- **Everything sensitive is audited** Approvals, takeovers, key and role changes, sessions, billing, exports and deletions are logged with who did it, from where, and when.

## In the EU by default. Deleted when you say.

The platform runs on servers in Germany, and the EU is the default region. Kaabist follows the GDPR, and KVKK for its entity in Türkiye.

An organisation can delete its data through the API: snapshots, results and sessions are purged within 24 hours.

The list of sub-processors and the data processing agreement are published with our legal pages.

Found a vulnerability? Write to security@kaab.ist.

## Questions from your security team? We will answer them.
