Reporting security issues
If you find a security issue, please report it privately to niko@kiwihacks.org.
Please don't report security bugs in public Slack channels or GitHub issues.
Infrastructure Security
The identity platform runs on a dedicated server that is isolated from the rest of KiwiHacks' infrastructure. Server access is restricted to a small number of KiwiHacks team members, each using physical second-factor authentication tokens.
All production console access is logged and audited.
Identity documents are encrypted at rest with a unique AES-256-GCM key per file via SSE-C in Cloudflare R2 storage.
Questions?
For security concerns or questions, email niko@kiwihacks.org.