Hello,
In fact ASP.NET uses rather server side scripts when it comes to processing data. Of course, there are JavaScripts which could for instance check BizForm fields, however, there is still the server side validation which prevents from multiple hacking techniques (such as SQL injection, XSS, etc.).
At any rate, we are trying to do our best to keep the security service of Kentico
CMS on the highest level. You can take a look at the following security related videos:
Devnet - Security videos.
Best regards
Ondrej Vasil