Skip to content
EchelonVPS
policy · 2025-09-22

What we hand over, and what we do not

Fourteen law-enforcement requests reached us last year. This is what we gave, what we refused, and why the answer is usually short.

Updated
2025-09-22
Policy
7 min
All
4 / 10

We publish this annually because a no-KYC host that never talks about legal process is either lying or has not been asked yet. We have been asked.

YearRequestsCompliedRefusedData produced
20251468Email address, invoices, 72 h NetFlow
20241156Email address, invoices
2023945Email address, invoices, 72 h NetFlow

The test we apply

We respond to an order that is valid in the jurisdiction where the server physically sits. Not where the company is registered, not where the requester is, not where the complainant would prefer. An American subpoena for a machine in Chișinău gets a polite letter explaining the correct route.

Why the answers are short

Because we hold almost nothing. An email address the customer chose, invoices with a company name we never verified, the configuration of the instance, and seventy-two hours of NetFlow-level metadata. No identity documents, no payment identity, no phone number, no address. Several requests have been withdrawn once the requesting authority understood how little there was to collect.

Notification

We tell the customer when a request touches their account, unless a court explicitly bars us. In 2025 that applied to two of the six we complied with; the other four customers were notified within 48 hours.

The strongest privacy guarantee is not a promise. It is an empty directory.