From 148fa84550b7652772e693e4da1fcd0acd53288d Mon Sep 17 00:00:00 2001 From: ulziibay-kernel <253135130+ulziibay-kernel@users.noreply.github.com> Date: Thu, 27 Aug 2026 15:16:24 +0000 Subject: [PATCH] Say no shared host OS rather than no host in the isolation claim The sentence read "there is no traditional host to escape to," which overstates the architecture: there is no host operating system shared with other tenants, but there is a hypervisor and a physical host beneath each session. The looser wording invites the reading that no boundary exists below the VM, which is the opposite of what the paragraph is arguing. --- security.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/security.mdx b/security.mdx index ab1b0aac..22c4820e 100644 --- a/security.mdx +++ b/security.mdx @@ -60,7 +60,7 @@ Reports are triaged and investigated by our security team. We are committed to w Kernel's platform includes built-in security features: -- **Unikernel Isolation** — Every Kernel browser session runs inside a dedicated Unikraft-based unikernel virtual machine, isolated at the hypervisor level. Unlike container-based approaches where multiple tenants share a host kernel, each Kernel session is a single-tenant VM with no shared operating system underneath. There is no traditional host to escape to — the unikernel is the entire system for that session. This architecture provides significantly stronger isolation guarantees than containers or processes, comparable to how other VM-based sandbox providers safely grant root access because VM boundaries make it secure. In Kernel's case, features like [SSH access](/browsers/ssh) and full shell control are safe by design: users operate within their own ephemeral VM, and any modifications are contained to that session with no impact on other customers or platform infrastructure. +- **Unikernel Isolation** — Every Kernel browser session runs inside a dedicated Unikraft-based unikernel virtual machine, isolated at the hypervisor level. Unlike container-based approaches where multiple tenants share a host kernel, each Kernel session is a single-tenant VM with no shared operating system underneath. There is no shared host operating system to escape to — the unikernel is the entire operating system for that session, and the boundary beneath it is the hypervisor rather than a kernel shared with other tenants. This architecture provides significantly stronger isolation guarantees than containers or processes, comparable to how other VM-based sandbox providers safely grant root access because VM boundaries make it secure. In Kernel's case, features like [SSH access](/browsers/ssh) and full shell control are safe by design: users operate within their own ephemeral VM, and any modifications are contained to that session with no impact on other customers or platform infrastructure. - **Encryption** — All data is encrypted in transit (TLS 1.2+ minimum) and at rest (AES-256) using cloud provider key management services with keys rotated at least annually - **Multi-Factor Authentication** — MFA is enforced for administrative access to the production platform, company email, version control, and cloud infrastructure - **Logical Separation** — Customer environments are logically separated, with production systems isolated from non-production environments