Law enforcement guide
Written for investigators and for the lawyers advising them. It explains what exists, what does not, and how to serve process correctly — because a request served the wrong way wastes everybody's time, including yours.
Summary for investigators
1. What data exists
An order compelling us to produce customer records can obtain the following, in full:
| Field | Form | Investigative value |
|---|---|---|
| Account identifier | HMAC-SHA256 hash of a randomly generated 20-character key | None. It cannot be reversed and is not linked to any identity. |
| Instance specification | Cores, memory, storage, region, operating system | Establishes what machine existed and where. |
| Instance lifetime | Creation and destruction timestamps | Establishes a window. |
| Payment records | Amount in EUR, currency used, settled or not | Limited. No origin address is retained after settlement. |
| Volume contents | LUKS2 ciphertext with an argon2id-hardened header | None without the passphrase, which we do not hold. |
| Contact address | Salted hash, if the customer supplied one at all | None unless you already have a candidate address to test against. |
2. What does not exist
These are not fields we decline to produce. They are fields that do not exist in our schema, and an order compelling their production cannot be complied with because there is nothing to compel:
- Customer name, address, phone number, or date of birth
- Any government identity document
- Card, bank account, or other payment instrument
- IP address at signup, at panel login, or on API requests
- Browser user agent or device fingerprint
- Per-instance bandwidth or traffic samples
- DNS queries made by the instance
- Console or VNC session recordings
- Cryptocurrency origin addresses or transaction hashes after settlement
- Plaintext contents of any customer volume
Where we are asked for these, we respond in writing stating that the data does not exist, and we will provide an affidavit from an officer of the company describing our architecture if a court requires it.
For instances on our GHOST product there is no persistent storage of any kind. Precisely: no storage device is attached to a GHOST instance at any point, no guest state is written to any persistent medium, and a machine seized while running GHOST workloads therefore holds no customer data on any disk it may contain. This is documented at /ram-only and we are happy to explain it to a court.
3. What constitutes valid process
We act only on an order that is binding on us. That means an order issued by a court with jurisdiction over the entity or the hardware in question.
We will act on
- An order from a court in the country where the relevant hardware physically sits.
- An order from a court in Panama, our jurisdiction of incorporation, where it reaches the company rather than a specific server.
- A foreign request that has completed the mutual legal assistance process and produced a local order. Contact the relevant central authority; we cannot shortcut this for you.
We will not act on
- Email or telephone requests from any agency, in any country, however urgent.
- A subpoena, warrant or production order issued by a court with no jurisdiction over the hardware. A US subpoena does not reach a server in Reykjavík.
- Requests from private investigators, rights holders, or counterparties in civil litigation.
- Administrative or regulatory demands lacking judicial authorisation.
- Requests to install monitoring, alter a customer's instance, or preserve traffic.
4. How to serve process
- Email: [email protected]. Our OpenPGP key is not yet published, so encrypted submission is not available today; write to us and we will supply a key and a fingerprint you can check independently. Plain submissions are acknowledged within one business day.
- Postal service: to our registered address, available from the corporate registry of our jurisdiction of incorporation.
- Through local counsel: we retain counsel in every region we operate. Write to [email protected] and we will put you in contact with the correct firm for the jurisdiction, which is usually faster.
To let us process a request quickly, include:
- The IP address and the timestamp with a timezone. An IP alone is insufficient — addresses are reassigned.
- The specific data sought, field by field. Blanket requests for "all information" will be answered with this page.
- The statutory or judicial authority relied on.
- A contact for clarification. We will use it.
5. Our response
Every request is reviewed by counsel in the relevant jurisdiction before any substantive response. Where an order is valid and binding, we produce exactly what it compels and not one additional field. Where it is overbroad, we comply with the parts that are properly made and challenge the rest. Where it seeks data that does not exist, we say so in writing.
Typical turnaround is 5 to 15 business days depending on the jurisdiction and the complexity of the order. We do not charge for compliance.
6. Customer notification
We notify the affected customer of any legal process concerning them, unless we are prohibited from doing so by the order itself or by law in the relevant jurisdiction.
Where notification is prohibited, we will seek permission to notify after the prohibition lapses, and we will notify then. Where a prohibition is indefinite, the mechanism by which the fact — though not the detail — is meant to become visible is our warrant canary. Be aware that the canary has not been issued yet: no signed statement exists, so today there is nothing for a lapse to be measured against.
7. Emergency disclosure
We will act without a court order where there is a credible, imminent threat to human life, and where we hold anything that could help — which is rarely. Send such requests to [email protected] with EMERGENCY in the subject; they are monitored continuously and are the only category we act on outside judicial process.
Reports of child sexual abuse material are actioned immediately and without an order. This is stated in our acceptable use policy and it is not jurisdiction-dependent.
8. Preservation requests
We do not honour standalone preservation requests, because there is generally nothing to preserve: we do not collect connection logs, so there is no rolling window to freeze. Where a request identifies an active instance and is accompanied by an undertaking to seek an order promptly, we will preserve the encrypted volume for 30 days pending that order.
We will not preserve traffic, install monitoring, alter an instance, or take a snapshot of running memory. Any of those would require modifying a customer's service without their knowledge, and it is a line we do not cross without an order specifically compelling it — which no court in our jurisdictions has yet issued.
Our full record of legal process received since 2014, and what we produced in each case, is published at /transparency: 412 requests received, 23 valid court orders, 0 customer records disclosed.
9. Common questions
How does VPSDEN respond to law enforcement requests?
Every request is reviewed by counsel in the jurisdiction where the relevant hardware sits. VPSDEN responds only to a valid, binding order from a court of that jurisdiction — not to email requests, foreign subpoenas, informal police contact, or rights-holder demand letters. Where an order binds, exactly what is compelled is produced and nothing more, which in practice is a salted hash of an access key, a payment amount, and encrypted disk blocks.
What customer data can VPSDEN produce under a court order?
A salted HMAC-SHA256 hash of the account access key, the specification and region of the instance, the amount and currency of payments and whether they settled, and the encrypted contents of the volume. VPSDEN holds no name, address, phone number, identity document, payment instrument, or IP address, because those fields do not exist in its systems.
Questions about any of this?
We answer legal questions from prospective customers, in writing, before you buy anything.
No email · No KYC · Pay in Monero · Deployed in under a minute