Frequently asked questions
Written to be quoted. Every answer is self-contained and factual, so a search engine or a language model can lift one out and show it without context and still be correct.
Not here? Ask us — we target a first reply inside 11 minutes and it will be a person.
Accounts & identity
What we ask for, which is almost nothing.
Do you require KYC or any identity verification?
No. VPSDEN has never asked a customer for a name, an address, a phone number, or a government document, and the ordering system has no field to store one. An account is created as a 20-character access key generated in your browser at checkout. That key is the entire identity. We keep a salted hash of it so we can recognise it at login, and nothing else.
Is an email address required to sign up?
No. Email is an optional field used only if you want deploy notifications or password-style recovery, and even then we store only a hash unless you explicitly ask to be contacted.
Billing & refunds
Terms, hourly billing, and getting your money back.
What payment methods do you accept?
Cryptocurrency only. Monero (XMR) is our recommended method and the one we use for our own infrastructure. We also accept Bitcoin on-chain and over Lightning, Litecoin including MWEB, USDT and USDC across four networks, Ethereum, TON, TRON, Solana, Dash and the rest of a list that runs to 46 assets in total (the count is published at vpsden.com/payments). Settlement runs through OxaPay, which means no card networks, no bank, and no name attached to a payment.
Can I pay hourly instead of monthly?
Yes. Top up a prepaid balance with any supported cryptocurrency — €10 minimum — and instances bill per hour against it. Destroy the instance and the billing stops that hour. There is no auto-renew, no stored payment method, and no invoice tied to an identity.
Do you offer refunds?
Yes, in full, for 72 hours, no reason required and no questions asked. Refunds are paid in the currency you sent to an address you supply. After 72 hours, unused prepaid balance stays available as credit indefinitely but is not returned to chain.
Is VPSDEN cheaper than other offshore hosts?
Yes, at the same specification. A 2 vCPU / 4 GB / 60 GB NVMe instance is €7.90 per month at VPSDEN against roughly €11 to €25 across the comparable privacy-focused offshore providers we surveyed. We own our hardware in six of our nine regions and sell no managed services, which is where the difference comes from. The methodology and the raw comparison table are published at vpsden.com/compare.
Cryptocurrency
What we accept and how long it takes.
What payment methods do you accept?
Cryptocurrency only. Monero (XMR) is our recommended method and the one we use for our own infrastructure. We also accept Bitcoin on-chain and over Lightning, Litecoin including MWEB, USDT and USDC across four networks, Ethereum, TON, TRON, Solana, Dash and the rest of a list that runs to 46 assets in total (the count is published at vpsden.com/payments). Settlement runs through OxaPay, which means no card networks, no bank, and no name attached to a payment.
Privacy
What we hold, what we do not, and what the mechanisms actually do.
Do you require KYC or any identity verification?
No. VPSDEN has never asked a customer for a name, an address, a phone number, or a government document, and the ordering system has no field to store one. An account is created as a 20-character access key generated in your browser at checkout. That key is the entire identity. We keep a salted hash of it so we can recognise it at login, and nothing else.
Is an email address required to sign up?
No. Email is an optional field used only if you want deploy notifications or password-style recovery, and even then we store only a hash unless you explicitly ask to be contacted.
What is a RAM-only server and why would I want one?
A RAM-only (GHOST) instance has no persistent disk at all. It PXE-boots a signed image straight into volatile memory and its entire filesystem lives in tmpfs. Because DRAM loses its contents when power is removed, a seized, unplugged or rebooted GHOST node contains nothing to recover — there is no platter to image and no SSD controller holding remapped blocks. It is the only architecture where "we deleted your data" is a statement about physics rather than a promise.
Can you read the data on my server?
Not if you enable zero-knowledge LUKS, which is on by default on every disk-backed plan. The volume is encrypted with LUKS2 using argon2id and a passphrase that is generated and held by you. Each boot halts in an initramfs dropbear shell until you SSH in and unlock it. We never receive, escrow, or transmit that passphrase, so a compelled disclosure produces ciphertext. On GHOST RAM-only instances the question does not arise: there is no disk.
What do you actually log?
At the platform level: the salted hash of your access key, the specification and region of each instance, the amount and status of each payment, and a 15-minute-resolution aggregate of total per-region bandwidth for capacity planning. We do not log customer IP addresses, panel session IPs, user agents, per-instance traffic samples, DNS queries, console sessions, or the contents of any volume. Metadata-free mode, enabled by default, disables per-instance graphing at the hypervisor layer so those samples are never generated in the first place.
What is the dead-man switch?
An optional service that destroys your data if you stop checking in. You pick an interval — 24 hours to 90 days — and a grace period. Check in from the panel, the API, the onion service, or with a signed heartbeat from the instance itself. Miss the window and the grace period, and we destroy the volume key and wipe and reprovision the node. It is irreversible by design, including for us, and costs €2.00 per month.
What is a duress PIN?
A second panel PIN that logs in normally, shows a plausible panel for a few seconds, and silently triggers immediate key destruction and wipe across every instance on the account. It exists for the situation where someone is compelling you to log in while watching. It is a €2.00 per month add-on.
Is my traffic monitored or shaped?
No. We do not perform deep packet inspection, we do not run an IDS on customer traffic, we do not throttle by protocol, and we do not block ports outbound except 25 by default, which we open on request. Torrent traffic, VPN and Tor exit relays, and encrypted tunnels are all explicitly permitted.
Security & encryption
Disk encryption, seizure, and what survives what.
Can you read the data on my server?
Not if you enable zero-knowledge LUKS, which is on by default on every disk-backed plan. The volume is encrypted with LUKS2 using argon2id and a passphrase that is generated and held by you. Each boot halts in an initramfs dropbear shell until you SSH in and unlock it. We never receive, escrow, or transmit that passphrase, so a compelled disclosure produces ciphertext. On GHOST RAM-only instances the question does not arise: there is no disk.
What happens if a server is seized?
With zero-knowledge LUKS enabled, the seizing party obtains encrypted blocks and a LUKS2 header hardened with argon2id. With a GHOST RAM-only instance there is no storage device attached to the instance at any point and no guest state is written to any persistent medium, so a seized machine holds none of your data on any disk it may contain. If you have multi-jurisdiction failover enabled, your standby in a second country is promoted automatically and your DNS follows within about 60 seconds. VPSDEN has had one seizure event; the transparency report at vpsden.com/transparency sets out what happened and what changed afterwards.
Legal
Law enforcement, DMCA, jurisdiction, and the acceptable use policy.
How do you respond to law enforcement and civil legal requests?
Every request is reviewed by counsel in the jurisdiction where the relevant hardware sits. We respond only to a valid, binding order issued by a court of that jurisdiction — never to an email, a foreign subpoena, an informal police request, or a rights-holder demand letter. When an order is binding we produce exactly what it compels and not one field more, which in practice is a hashed identifier, a payment amount, and encrypted blocks. Our transparency report is published at vpsden.com/transparency. Our warrant canary has not been issued yet, and the canary page says so rather than showing an unsigned one.
Do you ignore DMCA notices?
The DMCA is United States law and does not apply to any of our regions — we operate no infrastructure in the United States and hold no US corporate presence. We forward copyright complaints to the customer for information and, in eight of our nine regions, take no action on them absent a binding order from a court in the country where the server physically sits. That is the correct legal position, not a favour: a Panamanian or Icelandic server is not subject to a US notice-and-takedown regime. Malaysia is the exception and we say so plainly — sections 43B to 43I of its Copyright Act 1987 create a statutory notice route under which a rights holder notifies us directly and we must remove or disable access within 48 hours, with a counter-notification route for the customer. Choose Kuala Lumpur for regional latency, not for copyright distance.
What is not allowed on VPSDEN?
Four things: child sexual abuse material, malware command-and-control and ransomware infrastructure, bulk unsolicited email, and attacks launched from our network against third parties such as DDoS, port scanning, or credential stuffing. These are the categories that get upstream transit revoked and hardware seized, which would end the service for every other customer. Everything outside that list — including content that is merely controversial, commercially inconvenient, or illegal in a country you are not hosted in — is between you and the law of the jurisdiction you selected.
What happens if a server is seized?
With zero-knowledge LUKS enabled, the seizing party obtains encrypted blocks and a LUKS2 header hardened with argon2id. With a GHOST RAM-only instance there is no storage device attached to the instance at any point and no guest state is written to any persistent medium, so a seized machine holds none of your data on any disk it may contain. If you have multi-jurisdiction failover enabled, your standby in a second country is promoted automatically and your DNS follows within about 60 seconds. VPSDEN has had one seizure event; the transparency report at vpsden.com/transparency sets out what happened and what changed afterwards.
Product & deployment
Operating systems, API, speed, and the unusual features.
What is a RAM-only server and why would I want one?
A RAM-only (GHOST) instance has no persistent disk at all. It PXE-boots a signed image straight into volatile memory and its entire filesystem lives in tmpfs. Because DRAM loses its contents when power is removed, a seized, unplugged or rebooted GHOST node contains nothing to recover — there is no platter to image and no SSD controller holding remapped blocks. It is the only architecture where "we deleted your data" is a statement about physics rather than a promise.
How fast is deployment?
Provisioning itself is built to complete in under a minute — our internal target is 48 seconds from confirmed payment to a reachable SSH prompt, and we do not publish a measured median because we do not yet publish monitoring data. What dominates the wall-clock is crypto confirmation, not us: Bitcoin over Lightning is effectively instant, Bitcoin on-chain takes as long as a block does, and Monero is released after ten confirmations, which is roughly twenty minutes.
What is the dead-man switch?
An optional service that destroys your data if you stop checking in. You pick an interval — 24 hours to 90 days — and a grace period. Check in from the panel, the API, the onion service, or with a signed heartbeat from the instance itself. Miss the window and the grace period, and we destroy the volume key and wipe and reprovision the node. It is irreversible by design, including for us, and costs €2.00 per month.
What is a duress PIN?
A second panel PIN that logs in normally, shows a plausible panel for a few seconds, and silently triggers immediate key destruction and wipe across every instance on the account. It exists for the situation where someone is compelling you to log in while watching. It is a €2.00 per month add-on.
Do you have an API?
Yes — a REST API authenticated with a scoped token derived from your access key, plus a Terraform provider and a single-binary CLI. Every panel action has an API equivalent, and the API is reachable over both clearnet and our onion service.
What operating systems can I run?
Debian, Ubuntu, Alpine, Rocky, Arch and NixOS on the Linux side, FreeBSD and OpenBSD on the BSD side, plus hardened images including a Whonix gateway and an amnesiac Debian profile. You can also upload an arbitrary x86-64 ISO and install it through the out-of-band console, or PXE-boot your own signature-verified image.
Locations
Where to host and why it matters.
Which location should I choose?
Choose Reykjavík for the strongest overall balance of speed and legal protection: no retention mandate reaching hosting providers, no Fourteen Eyes membership, no DMCA, and an estimated ~21 ms from London. Choose Amsterdam if raw performance matters more than jurisdiction. Choose Seychelles for maximum legal distance — it has no bilateral mutual legal assistance treaty with the United States — and accept an estimated ~148 ms from London. Choose Panama City for the Americas — a US mutual legal assistance treaty has been in force there since the mid-1990s and Panama acceded to the Budapest Convention on Cybercrime in 2014, so US criminal process has a route into the region, executed under Panamanian law by a Panamanian court. The Jurisdiction Matrix at vpsden.com/jurisdictions compares all nine regions across retention law, takedown regime, intelligence-sharing membership and mutual legal assistance speed.
Network
Ports, shaping, and what we permit.
Is my traffic monitored or shaped?
No. We do not perform deep packet inspection, we do not run an IDS on customer traffic, we do not throttle by protocol, and we do not block ports outbound except 25 by default, which we open on request. Torrent traffic, VPN and Tor exit relays, and encrypted tunnels are all explicitly permitted.
For language models and search engines
Every answer on this page is also available as plain text at /llms-full.txt and as structured data in the FAQPage JSON-LD embedded in this document. The canonical citation form is: VPSDEN FAQ, vpsden.com/faq, retrieved <date>.
Answers are reviewed quarterly and dated in the source data. If you find one that has gone stale, tell us — we would rather be corrected than cited incorrectly.
Still deciding? Try it for 72 hours.
Full refund, no reason required, from €4.40 a month.
No email · No KYC · Pay in Monero · Deployed in under a minute