Transparency report
Every category of legal process we have received since 2014 and exactly what we produced. Including the entry we would rather not publish: hardware physically seized. These are cumulative totals. We do not yet publish a per-year breakdown, and the table that used to sit here has been removed rather than estimated.
Not published
There is no per-year table on this page. There used to be one, and it did not come out of a record — so it is gone rather than adjusted. The totals above are the figures we stand behind; a breakdown by year will appear here when it can be reconciled against correspondence rather than against a headline number.
Read the absence as an absence. It is not a claim that the distribution is flattering.
What we received and what we did about it
Most of what arrives is not legal process at all. It is a demand letter, an email from a police officer, or a foreign subpoena with no force where our hardware sits.
Copyright complaints (DMCA-style notices)
247Forwarded to the customer for information. No action taken — the DMCA does not apply to any region we operate. The one exception is Kuala Lumpur, where a notification under s.43H of the Malaysian Copyright Act 1987 starts a 48-hour removal clock; see /legal/dmca.
Informal police requests by email
88Declined. We replied with our law-enforcement guide and the correct procedure for the relevant jurisdiction.
Foreign subpoenas with no local force
31Declined as non-binding. Requesting party directed to the MLAT process.
Civil demand letters from rights holders
22Forwarded to the customer. No action taken absent a court order.
Valid local court orders
23Reviewed by local counsel. 23 complied with, producing only what was compelled — which in every case was a salted hash, a payment amount, and encrypted blocks.
Requests for encryption keys
1Refused. We do not hold customer LUKS passphrases and cannot produce what does not exist.
The one we lost hardware to
Authorities executed a warrant at our Bucharest facility and removed 3 chassis. The order related to a criminal matter concerning one customer and was issued by a court with jurisdiction over the hardware. It was valid, and we did not contest it.
What we can state about it:
- Every affected volume was LUKS-encrypted with a key we did not hold. What was seized was ciphertext and a LUKS2 header. We were asked for the passphrases; we did not have them, and said so in writing.
- Affected customers were reimbursed in full. Those with multi-jurisdiction failover enabled were promoted to their standby region automatically; those without it lost their instances.
- Three defaults changed afterwards. Zero-knowledge LUKS became the default on every disk-backed plan instead of an opt-in. Multi-jurisdiction failover was rebuilt from a manual runbook into an automatic mechanism with health checks at three independent external vantage points. And we started the GHOST programme — encrypted disks are a good answer, and no disk is a better one.
We have deliberately not published a minute-by-minute post-mortem here. The numbers that used to appear in this section — affected customer counts, failover timings, who accepted what — were not reconstructed from records, so they have been removed rather than rounded. If you are evaluating us on this incident, ask and we will answer in writing with what the records actually show.
Transparency questions
How many customer records has VPSDEN disclosed to law enforcement?
0, out of 412 requests received since 2014. 23 of those were valid local court orders, and 23 were complied with — but compliance produced only a salted hash of an access key, a payment amount, and encrypted disk blocks, because that is the entirety of what we hold. There has never been a customer record in the sense of a name, address or identity document to disclose, because we have never collected one.
Has a VPSDEN server ever been seized?
Once. 3 chassis were removed from our Bucharest facility under a court order relating to a criminal matter concerning one customer. Every affected volume was LUKS-encrypted with a key we did not hold, so what was seized was ciphertext. Affected customers were reimbursed in full. We have not published a per-incident post-mortem for it and will not publish one written from memory.
How does VPSDEN respond to a law enforcement request?
Every request goes to counsel in the jurisdiction where the relevant hardware sits. We respond only to a valid, binding order from a court of that jurisdiction — never to an email, a foreign subpoena, an informal request, or a rights-holder demand letter. Where an order is binding we produce exactly what it compels and not one field more, and we notify the affected customer unless the order specifically prohibits it.
Zero disclosures in 12 years — because there is nothing to disclose.
No KYC, no email, no IP logs. Read exactly what we do hold.
No email · No KYC · Pay in Monero · Deployed in under a minute