Skip to content
EchelonVPS
Identity

A no-KYC VPS, and the short list of what we do ask for.

An email address creates the account. No passport scan, no selfie, no utility bill, no phone verification, no card on file. We never collect what we would then have to protect.

Founded
2014
42 accepted assets
42
Median deploy
55 s

What we ask for

  1. 01Email address
  2. 02Cryptocurrency, settled in minutes

What we never ask for

  • 01Government identity documents
  • 02Selfies or liveness checks
  • 03Utility bills or proof of address
  • 04Phone number verification
  • 05A card on file or a billing name
  • 06Social accounts or referrals
01

Why we work this way

Why we work this way

Data you never collect cannot be leaked, subpoenaed, sold or lost. We keep an email address, an invoice, and 72 hours of connection logs for abuse handling. Everything else is deleted at termination, and we publish what we hold in the privacy notice.

DataPurposeRetention
Email addressServer credentials, invoices, renewal noticesUntil the account is closed
InvoicesStatutory accounting record10 years, no verified identity attached
Server configurationRunning the instanceUntil the instance is destroyed
NetFlow connection metadataAbuse investigation only72 hours, then discarded
Support ticketsContinuity across an issue24 months
Payment identityNever collected — crypto only
Identity documentsNever collected
Phone numberNever collected

The English text is the binding version of this document.

02

Where the line sits

Where the line sits

No KYC is not no rules. Phishing, spam, botnet command-and-control, CSAM and outbound attacks get terminated without refund and without appeal. Our acceptable use policy is two pages long and we mean all of it.

01

No chargebacks, therefore no fraud scoring, therefore no KYC

A PDF invoice is issued for every payment, with a company name of your choosing.

02

Monero and Litecoin MimbleWimble supported

Refunds are returned in the asset you paid with, at the rate on the day of purchase.

03

Read the acceptable use policy

No KYC is not no rules. Phishing, spam, botnet command-and-control, CSAM and outbound attacks get terminated without refund and without appeal. Our acceptable use policy is two pages long and we mean all of it.

03

Questions

Frequently asked questions

01Do I really not have to verify my identity?
Correct. Ordering requires an email address and a payment, and that is the whole list. There is no document upload, no selfie, no phone verification, no address check and no card on file. We have never run identity verification and we do not plan to start — the cheapest way to protect customer documents is to never hold any.
02What do you actually store about me?
Your email address, your invoices, the configuration of your servers, and 72 hours of NetFlow-level connection metadata used only for abuse investigation. Nothing else. When you close the account, all of it is erased within 24 hours except invoices, which accounting law makes us keep for ten years — those hold an invoice name of your choosing and no verified identity.
03Can I sign up with a throwaway or aliased email?
Yes, and plenty of customers do. Anything that reliably reaches you works — Proton, Tuta, SimpleLogin, addy.io, a catch-all on your own domain. The only thing to keep in mind is that server credentials and renewal notices go there, so if you lose access to the mailbox you lose access to the account.
04Can I order over Tor or a VPN?
Yes. The order flow, the console and the API all work over Tor and over any VPN. We do not fingerprint browsers, we do not score orders for fraud risk, and we do not block exit nodes.
05No KYC — so anything goes?
No. No identity checks means we do not care who you are; it does not mean we do not care what leaves our network. Phishing, spam, malware distribution, botnet command-and-control, credential stuffing, outbound attacks and material involving minors get the instance terminated immediately, without refund and without appeal. The acceptable use policy is two pages, written in plain language, and we apply all of it.
06Can I run a VPN, a Tor relay or a proxy?
Yes to all three, and thousands of customers do. Tor exit nodes are permitted in Amsterdam, Reykjavík, Chișinău and Bucharest, and we ask you to run the standard reduced exit policy and set an abuse contact. Exits are not permitted in the remaining regions, because their upstreams do not tolerate them and we would rather tell you that than have your server disappear.
07What happens if someone files an abuse report about my server?
We forward it to you with the evidence and give you 24 hours to respond, except for active outbound attacks and CSAM, which are cut immediately. We do not suspend on receipt of an unverified complaint, and we do not hand over customer data without an order valid in the jurisdiction the server sits in. When we do receive such an order, we tell you unless we are legally barred from doing so.
08Who runs Echelon?
A team of nineteen, mostly in Europe, operating our own hardware in leased space since 2014. We are not a reseller of somebody else's cloud, we have taken no outside investment, and the company has been profitable since 2017 — which is why we can afford to turn business away.