Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion security.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ Reports are triaged and investigated by our security team. We are committed to w

Kernel's platform includes built-in security features:

- **Unikernel Isolation** — Every Kernel browser session runs inside a dedicated Unikraft-based unikernel virtual machine, isolated at the hypervisor level. Unlike container-based approaches where multiple tenants share a host kernel, each Kernel session is a single-tenant VM with no shared operating system underneath. There is no traditional host to escape to — the unikernel is the entire system for that session. This architecture provides significantly stronger isolation guarantees than containers or processes, comparable to how other VM-based sandbox providers safely grant root access because VM boundaries make it secure. In Kernel's case, features like [SSH access](/browsers/ssh) and full shell control are safe by design: users operate within their own ephemeral VM, and any modifications are contained to that session with no impact on other customers or platform infrastructure.
- **Unikernel Isolation** — Every Kernel browser session runs inside a dedicated Unikraft-based unikernel virtual machine, isolated at the hypervisor level. Unlike container-based approaches where multiple tenants share a host kernel, each Kernel session is a single-tenant VM with no shared operating system underneath. There is no shared host operating system to escape to — the unikernel is the entire operating system for that session, and the boundary beneath it is the hypervisor rather than a kernel shared with other tenants. This architecture provides significantly stronger isolation guarantees than containers or processes, comparable to how other VM-based sandbox providers safely grant root access because VM boundaries make it secure. In Kernel's case, features like [SSH access](/browsers/ssh) and full shell control are safe by design: users operate within their own ephemeral VM, and any modifications are contained to that session with no impact on other customers or platform infrastructure.
- **Encryption** — All data is encrypted in transit (TLS 1.2+ minimum) and at rest (AES-256) using cloud provider key management services with keys rotated at least annually
- **Multi-Factor Authentication** — MFA is enforced for administrative access to the production platform, company email, version control, and cloud infrastructure
- **Logical Separation** — Customer environments are logically separated, with production systems isolated from non-production environments
Expand Down
Loading