Operating since 20149 jurisdictions412 legal requests · 0 customer records disclosed
Offshore compute for people who were never asked who they are.
No KYC. No email. No name on any invoice. Disks encrypted with a key we never receive, RAM-only servers that keep nothing at all, and payment in Monero. From €4.40 a month — well under what the rest of the offshore market charges for the same silicon. The workings are on /compare.
Most privacy hosts sell you a promise. We sell you a mechanism.
A no-logs policy is a sentence in a document. It survives exactly as long as the company's willingness to honour it. Every feature below is engineered so that our willingness stops being relevant.
Only host that sells it as a product
GHOST: servers with no disk at all
A GHOST instance PXE-boots a signed image directly into RAM. Its entire filesystem is tmpfs. Pull the power and the data is gone — not deleted, not overwritten, gone, because DRAM cannot hold state without current. There is no platter to image, no SSD controller quietly hoarding remapped blocks, no swap file. It is the one place where "your data is unrecoverable" is a claim about physics instead of a promise about our intentions.
Choose an interval between 24 hours and 90 days. Check in from the panel, the API, the onion service, or with a signed heartbeat from the instance itself. Miss the window plus your grace period and we destroy the volume key, then wipe and reprovision the node. It is irreversible — for you, for a court, and for us. Some customers use it as a legal shield; more use it because they travel.
A second PIN that logs in, renders a completely normal-looking panel, and spends the next four seconds silently destroying every volume key on the account. To an observer standing behind you it is indistinguishable from a successful login. It exists because "just don't log in" is useless advice when someone is holding your laptop.
Seizure is a failure mode, so we engineered for it
Multi-jurisdiction failover
Pick a second country. Your instance replicates to it continuously. If the primary is seized, raided, cut off by an upstream, or simply goes dark, the standby is promoted and DNS follows within about sixty seconds. Most hosts treat a raid as an event that ends the conversation. We treat it as an availability zone going down.
LUKS2 with argon2id, keyed by a passphrase generated in your browser that never touches our infrastructure. Every boot stops in an initramfs dropbear shell and waits for you. If we are handed a binding order for your disk, we comply — by handing over ciphertext. That is the only honest version of a no-logs promise: one that survives us being compelled.
Nine regions compared across data-retention law, takedown regime, intelligence-sharing membership, MLAT responsiveness and constitutional protections — including the two regions where we tell you outright not to host if your threat model is adversarial. It is the document we wanted when we started, and it is free whether or not you buy anything.
We own our hardware in six of nine regions, we sell no managed services, and we do not employ a sales team. That is the entire explanation for the price difference — there is no trick and no first-month promo that doubles on renewal.
Choosing a country is the most important decision you will make. So we documented it properly.
Every offshore host lists flags on a map. None of them tell you that Amsterdam is a Nine Eyes member with fast MLAT cooperation, or that Romania's Constitutional Court struck down data retention twice. We do — including where it costs us a sale.
Not a summary. Not “we may collect certain information.” The actual, exhaustive list — because a privacy policy that needs a lawyer to interpret is not a privacy policy.
Never collected
Your legal name
A billing address
A phone number
Any government document
A card or bank account
Your IP address at signup
Panel session IP addresses
Browser user-agent strings
Per-instance bandwidth samples
DNS queries made by your server
Console or VNC session recordings
The contents of your volume
Fields that do not exist in a schema cannot be produced under subpoena, sold in a bankruptcy, or leaked in a breach. This is the cheapest security control there is.
Three steps, none of which involve telling us your name
01
Configure
Pick a plan or move every slider yourself: cores, memory, NVMe, transfer, region, OS, and twenty add-ons. The price updates as you drag, with no hidden setup fee waiting at the end.
02
Pay in crypto
Checkout hands you an OxaPay invoice. Send Monero, Bitcoin, Lightning, USDT or any of the other accepted assets. No card form, no billing address, no 3-D Secure redirect to your bank.
03
Keep your access key
You get a 20-character key. That is your entire account — no username, no password, no recovery email. Write it down. We keep only a salted hash, so if you lose it, it is genuinely gone.
Short answer
How long does the whole process take?
We build for 48 seconds from confirmed payment to a reachable SSH prompt. What dominates the clock is blockchain confirmation, not us: Bitcoin over Lightning is effectively instant, on-chain Bitcoin takes as long as a block does, and Monero is released after ten confirmations, which is about twenty minutes.
Honest comparison
What the offshore market actually offers
Composite of the features publicly advertised by well-known privacy and offshore hosts as of July 2026. Where a provider offers something we do not, we say so.
The first issue has not been signed, so there is nothing here to verify and we are not going to pretend otherwise. What is described is the mechanism: a PGP-signed statement, reissued monthly, asserting what we have not been compelled to do, embedding a recent Bitcoin block hash so the signature cannot have been produced in advance, and mirrored as JSON at /canary.json so you can watch it with a cron job instead of remembering to look.
412 requests received. 0 customer records disclosed.
We publish every category of legal process we receive, what jurisdiction it came from, and what we produced. Including the uncomfortable entry: 1 seizure event, in which 3 chassis were removed under a court order that bound us. Every volume on them was LUKS-encrypted with a key we do not hold.
No. VPSDEN has never asked a customer for a name, an address, a phone number, or a government document, and the ordering system has no field to store one. An account is created as a 20-character access key generated in your browser at checkout. That key is the entire identity. We keep a salted hash of it so we can recognise it at login, and nothing else.
Is an email address required to sign up?
No. Email is an optional field used only if you want deploy notifications or password-style recovery, and even then we store only a hash unless you explicitly ask to be contacted.
What payment methods do you accept?
Cryptocurrency only. Monero (XMR) is our recommended method and the one we use for our own infrastructure. We also accept Bitcoin on-chain and over Lightning, Litecoin including MWEB, USDT and USDC across four networks, Ethereum, TON, TRON, Solana, Dash and the rest of a list that runs to 46 assets in total (the count is published at vpsden.com/payments). Settlement runs through OxaPay, which means no card networks, no bank, and no name attached to a payment.
What is a RAM-only server and why would I want one?
A RAM-only (GHOST) instance has no persistent disk at all. It PXE-boots a signed image straight into volatile memory and its entire filesystem lives in tmpfs. Because DRAM loses its contents when power is removed, a seized, unplugged or rebooted GHOST node contains nothing to recover — there is no platter to image and no SSD controller holding remapped blocks. It is the only architecture where "we deleted your data" is a statement about physics rather than a promise.
Can you read the data on my server?
Not if you enable zero-knowledge LUKS, which is on by default on every disk-backed plan. The volume is encrypted with LUKS2 using argon2id and a passphrase that is generated and held by you. Each boot halts in an initramfs dropbear shell until you SSH in and unlock it. We never receive, escrow, or transmit that passphrase, so a compelled disclosure produces ciphertext. On GHOST RAM-only instances the question does not arise: there is no disk.
What do you actually log?
At the platform level: the salted hash of your access key, the specification and region of each instance, the amount and status of each payment, and a 15-minute-resolution aggregate of total per-region bandwidth for capacity planning. We do not log customer IP addresses, panel session IPs, user agents, per-instance traffic samples, DNS queries, console sessions, or the contents of any volume. Metadata-free mode, enabled by default, disables per-instance graphing at the hypervisor layer so those samples are never generated in the first place.
How do you respond to law enforcement and civil legal requests?
Every request is reviewed by counsel in the jurisdiction where the relevant hardware sits. We respond only to a valid, binding order issued by a court of that jurisdiction — never to an email, a foreign subpoena, an informal police request, or a rights-holder demand letter. When an order is binding we produce exactly what it compels and not one field more, which in practice is a hashed identifier, a payment amount, and encrypted blocks. Our transparency report is published at vpsden.com/transparency. Our warrant canary has not been issued yet, and the canary page says so rather than showing an unsigned one.
Do you ignore DMCA notices?
The DMCA is United States law and does not apply to any of our regions — we operate no infrastructure in the United States and hold no US corporate presence. We forward copyright complaints to the customer for information and, in eight of our nine regions, take no action on them absent a binding order from a court in the country where the server physically sits. That is the correct legal position, not a favour: a Panamanian or Icelandic server is not subject to a US notice-and-takedown regime. Malaysia is the exception and we say so plainly — sections 43B to 43I of its Copyright Act 1987 create a statutory notice route under which a rights holder notifies us directly and we must remove or disable access within 48 hours, with a counter-notification route for the customer. Choose Kuala Lumpur for regional latency, not for copyright distance.
What is not allowed on VPSDEN?
Four things: child sexual abuse material, malware command-and-control and ransomware infrastructure, bulk unsolicited email, and attacks launched from our network against third parties such as DDoS, port scanning, or credential stuffing. These are the categories that get upstream transit revoked and hardware seized, which would end the service for every other customer. Everything outside that list — including content that is merely controversial, commercially inconvenient, or illegal in a country you are not hosted in — is between you and the law of the jurisdiction you selected.
Nine countries. No paperwork. Live before your coffee is cold.
From €4.40 a month. 72-hour refund, no reason required, paid back to an address you supply.