Security

Reporting security issues

If you find a security issue, please report it privately to niko@kiwihacks.org.
Please don't report security bugs in public Slack channels or GitHub issues.

Infrastructure Security

The identity platform runs on a dedicated server that is isolated from the rest of KiwiHacks' infrastructure. Server access is restricted to a small number of KiwiHacks team members, each using physical second-factor authentication tokens.

All production console access is logged and audited.

Identity documents are encrypted at rest with a unique AES-256-GCM key per file via SSE-C in Cloudflare R2 storage.

Questions?

For security concerns or questions, email niko@kiwihacks.org.