No-KYC hosting: the complete list of what we refuse to collect
Why identity verification exists at all, why removing card payments removes the reason, exactly which fields we hold, and the honest limits of what a provider can do for your anonymity.
Elias Roth
Payments & Billing
Published
Why identity verification exists in hosting at all
It is worth understanding the mechanism, because it explains why the practice is nearly universal and why we are an exception rather than a maverick.
A host that accepts credit cards faces a specific problem: a stolen card plus instant provisioning equals a free server for an attacker, and a chargeback plus a fee for the host a few weeks later. When we accepted cards in 2021, 2.3% of transactions ended in a dispute and 89% of those were not fraud against the cardholder at all โ they were customers who had used a server for weeks and then called their bank.
There are exactly two defences: verify who the buyer is, or review every order by hand. Most hosts do both, which is why signup asks for a phone number and why "your order is under review" is a message you have seen.
We took the third option and stopped accepting cards in February 2022. With payments final on confirmation there is no fraud to mitigate, so there is nothing for a KYC check to accomplish. We cut list prices 30% the same day and delivery went from three-to-six hours to four minutes. No-KYC was not the goal of that decision โ it was a consequence, which is precisely why it is stable.
The complete list of what we never ask for
- Legal name, date of birth, nationality
- Government identification, passport, driving licence
- Photograph, selfie, liveness or video check
- Home, billing or business address
- Telephone number
- Company registration or tax identification number
- Payment card or bank account details
- Source-of-funds declaration
- A stated reason for the purchase
There is no threshold โ no spend level, account age, plan size or region โ at which any of this changes. A customer running twenty Ultra instances has given us exactly what a customer running one Nano has given us.
The complete list of what we do hold
| Data | Why it exists | Retention |
|---|---|---|
| Email address | Delivering credentials, invoices, incident notices | Life of account + 24 months |
| Password hash | Authentication. scrypt โ irreversible | Life of account |
| Invoice records | Tax law. Not optional for us | 7 years |
| Support tickets | Answering you, and context next time | 36 months |
| Sign-in log (IP, time) | So you can spot a takeover on your security page | 90 days |
| Hypervisor metrics | Capacity planning, faults, your usage graphs | 13 months |
| Sampled netflow headers | DDoS detection. Headers, never payloads | 72 hours |
I want to be precise about one of these, because "no logs" is a phrase the industry abuses. We keep a sign-in log for the client area โ IP address and timestamp, 90 days. It is visible to you on your own security page, and it exists so that you can see an unfamiliar login and act on it. We do not keep logs of your server's traffic, and there is no agent inside your instance. Those are different claims and we try never to blur them.
The consequence nobody mentions: account recovery
Here is the trade-off, stated plainly rather than buried.
A bank can restore your account because it holds your identity. We cannot, because we do not. If you lose your email address and your two-factor device at the same time, the ordinary route back in does not exist.
What we can verify is control of a payment. Open a ticket with an order ID and the transaction hash it was paid with โ ideally signed from the sending wallet โ and support restores access. It works, and it is slower than a bank.
The practical advice: save your two-factor recovery codes somewhere that is not the device running your authenticator, and use an email address you will not lose. Those two habits remove the problem entirely.
What no-KYC does not give you
Skipping our identity form is one link in a chain, and the chain is only as strong as its weakest link โ which is usually not us.
- Your email address. If it is
[email protected], we have your identity anyway, we just did not ask for it. Use an alias. - Your payment. Bitcoin and every other transparent chain we accept is pseudonymous, not anonymous. A withdrawal from a verified exchange account to our invoice address is a link that chain-analysis firms sell as a product. Monero does not have this property, which is why we accept it.
- Your connection. Our sign-in log holds the IP you used for 90 days. A VPN or Tor removes that.
- Your application. The biggest one by a wide margin, and entirely outside our reach. A personal domain in a mail header, an analytics account shared with your other properties, a reused SSH key, a git config with your name in it โ any of these undoes everything above.
We are not going to tell you that buying a server here makes you anonymous. What we can tell you is that we did not collect anything, so there is nothing here to leak, sell, or be compelled to produce. The rest is your operational security, and pretending otherwise would be doing you a disservice.
Does no-KYC mean anything goes?
No, and this deserves to be said directly because the two ideas travel together in this market.
Not asking who you are and not caring what you do are unrelated positions. Our acceptable use policy prohibits spam, phishing, malware distribution and command-and-control, credential stuffing, DDoS origination and CSAM, and those prohibitions are enforced identically in every region including the offshore ones. Abuse reports are triaged within four hours, 24/7.
We can enforce that policy without knowing your name โ the enforcement acts on the server, not the person. And we have a strong incentive to: a network with a bad reputation is a bad product for everyone on it.
Elias Roth
Payments & Billing
Co-founder. Built the crypto billing pipeline in 2022 and still answers billing tickets on weekends.
Put this into practice for $5 a month
Windows RDP from $12/month, Linux VPS from $5/month, delivered in about four minutes with a 72-hour money-back guarantee.